SEATTLE – According to a recently released Osterman Research white paper “The Critical Need for Encrypted Email and File Transfer Solutions”, encrypted email and file transfer solutions, such as MFT, are becoming a business and legal necessity due to the high volume of sensitive content stored within and delivered via email. With increasing governance and regulatory obligations, the punitive consequences associated with failure to protect sensitive data outweigh the cost of deploying encryption capabilities.
The research also indicates that secure/encrypted email will be a top five priority for organizational IT spending through late 2010.
The report was sponsored in part by Smarsh, a managed service provider in secure, email archiving and compliance solutions.
“Email continues to be the dominant communication and file transport mechanism used in business today, and email and attachments are vulnerable to multiple exposures and a variety of associated risks, simply via the nature of the transmission itself,” said Michael Osterman, president of Osterman Research. “A growing number of state and federal statutes mandate that businesses encrypt the transmission of sensitive data. Companies are paying a heavy price for data breaches or content interception. Leaks of confidential corporate data and hardship to consumers carry consequences.”
The study cites several examples in which the lack of encryption or other protection of confidential information led to enormously damaging and expensive mitigation efforts. By the end of 2008, 44 U.S. states had enacted data breach notification laws, and 25 countries had adopted similar rules. Relevant state and federal statutes include:
*Nevada and Massachusetts state laws. These states have developed laws requiring the proactive protection and secure transmission of customers’ personal information, and others are expected to follow.
*HIPAA. The Federal Health Insurance Portability and Accountability Act (HIPAA) requires that policies and procedures must be established and implemented to protect the use and disclosure of individuals’ protected health information (PHI). As part of the American Recovery and Reinvestment Act of 2009, the provisions of HIPAA (and consequences of non-compliance) were significantly expanded to apply to business partners (attorneys, accounting firms, etc.) of entities already covered by HIPAA (pharmacies, healthcare providers, etc.).
*Gramm-Leach-Bliley Act (GLBA) & Regulation S-P. Financial institutions are required to protect sensitive information collected regarding individuals. In accordance with the GLBA, the Securities and Exchange Commission’s Regulation S-P requires financial services firms to adopt written policies and procedures that address the administrative, technical and physical safeguards for the protection of customer records and information.
Non-compliance with email encryption mandates certainly carries consequences. At the same time, the report contends that businesses that proactively demonstrate secure infrastructure for their customers’ sensitive data are more likely to build trust, acquire new business and maintain their customers. Banks use encrypted access to data as a benefit for customers, and physicians are answering a demand from patients by communicating via secure messaging.
The white paper also cites the growing interest and dependence on dedicated, secure file transfer systems. Email attachments continue to increase in size, and transmission of the data within merits secure delivery. A dedicated file transfer system can ease the burden on email servers and benefit users by eliminating the impact of email file-size limits. Email-related storage and costs are reduced, as is impact on network bandwidth.
“Email and file transfer encryption does not need to be disruptive to business processes, cost-prohibitive or burdensome for internal resources,” said Smarsh CEO Stephen Marsh. “There are multiple points at which content can be encrypted and multiple models for deployment, and organizations need to find the right solution to meet their specific needs. The first priority needs to be finding a solution that offers peace of mind with data protection. Beyond that, it is important to put an email encryption system in place that is easy to use and administrate, that doesn’t complicate or impede other email system functions like supervision and that can be implemented cost-effectively.”
Smarsh solutions for data-leak prevention (smarshDLP) and secure messaging (smarshEncrypt) are designed to help users meet email encryption obligations and secure file transfer needs, mitigate risk associated with outbound email and facilitate email supervision.
To access this Osterman Research white paper, click on Smarsh.Com
This column was written by Liam Lahey of ConnectIT, an IntegratedMarCompany
a>>