By Eric Kedrosky, CISO, Sonrai Security
Every business runs on data, whether it’s their own or someone else’s. Data is quickly taking the lead in being a top commodity, for better and for worse. The downside is that data is often the pot of gold at the end of a bad-actor’s efforts to compromise your cloud environment. All this being said, data governance, and data classification specifically, is critical to your company’s short and long-term success. That means locating, identifying, organizing, and maintaining data has become a top priority.
Where do you begin on your data security journey? The journey to methodical data classification starts with one simple question: ‘what is my data?’
Finding Your Data
While the question, “What is my data?” is simple, the reality of answering that is not. A basic step in data governance is first finding your data.
Chances are, your company is suffering from data sprawl. The cloud is complex, growing and changing every day. Sometimes it feels impossible to truly have visibility into your whole environment, and locating your data’s home falls under that scope. Your organization may store some of your data locally and the rest on one or more cloud storage platform. The point is, a lot of people think they know where their data is supposed to be, not where it actually exists. Data sprawl can be a serious issue, particularly when it comes to sensitive data.
Even if you track down your data, you still need to classify it. It’s no longer enough to label this data as sensitive and that data is not. In fact, it’s no longer a binary conversation at all, because there are gradations of data sensitivity. And there are different data formats, data structures, and types of data storage, including the software-defined storage infrastructure that proliferates in cloud-based scenarios.
The Data Spectrum
Most organizations have a policy problem with data classification and data control. This stems from treating all data as if it’s equal. A mature security program includes understanding what your data is, evaluating the nuances of how important it is to your business, and implementing tailored controls depending on the degree of sensitivity and therefore urgency.
Ask yourself what data drives your business and pays your bills. If bad actors steal the information on your company blog, for example, it probably won’t destroy your business. On the other hand, if they steal customer data, it could prove catastrophic.
Taming Your Data Conundrum
Your company undoubtedly has one or more documents defining its data classification standards, including access tiers, naming conventions, and so forth. But it probably doesn’t include sufficient details on the potential ramifications of exposure.
That’s why it’s time for you to review those documents. Were they created to protect PDFs and Word documents? What types of data do you have stored in the cloud today? Make sure that your classifications and standards are relevant and that your processes are pertinent to working in the cloud as well. Rewrite your data security policy based on the type of data that you have currently and where it’s stored.
The big takeaway is: Establish clear guidelines that consider what would happen if this particular data was stolen or improperly exposed, and create a viable maintenance plan accordingly.
Evaluating Your Data
When classifying your data, consider two factors in particular – context and risk. Data is an extremely broad word. It can apply to one individual, such as an employee’s performance report, a specific team within the company, or an entirely different company you’re partnering with.
That last example brings us to the next consideration – data that applies to external entities. Many organizations are born in the cloud and offer services in the cloud, and they do data processing services for other companies. What are the potential risks of these types of third-party relationships on your company’s data? Do the different tiers of data applicability or data sensitivity applicability reflect potential negative outcomes?
Consider the following examples to help bring these questions to life:
Let’s say you’re Dyson and that you stored your plans for the next product release in the cloud. That data applies to your entire organization. If it’s compromised, lost, or tampered with, the results on your company alone will be devastating.
However, in the FinTech space, third-party companies routinely take banking records from America’s largest banks, run analytics on them, process them, and provide an agreed-upon service using their data.
With these examples in mind, some questions to ask yourself are:
- How sensitive is the data that you’re sharing with a third party?
- How can you ensure they are taking the right precautions?
- How can you be sure that they’re transferring your data securely?
The Cost of Compromised Data
In today’s world, where consumer’s input is so valuable, a data breach can severely tarnish your company’s reputation. On top of the impact on your organization’s name, laws and regulations like GDPR (General Data Protection Regulation), levy hefty fines for data security breaches that infringe upon their rules. The top fine to date is $746 million euros ($887 million).
Not only can you be fined today, but your business can also be fined from a past lack of compliance. Keeping up with your data security documentation regularly to reflect new and updated regulatory controls and requirements will save you this burden.
And you should monitor your data continuously. Checking every 90 days is no longer a valid methodology. You must audit your data continuously to remain compliant.
Data Classification Solutions
Whether you work in Google Cloud, AWS or Azure, each CSP has tools that can help you implement new or modified categories and security levels to your data. However data sprawl and multicloud environments mean you’ll likely have to manage your data across multiple clouds using multiple tools.
Similarly, if you switch from one cloud provider to another, many of your lessons learned, controls, and processes won’t be applicable. You’ll have to start all over again.
Also, as tempting as it may seem, you can’t take data from one cloud storage account and run an analytics to mix it with similar data from another cloud storage account. The data from both accounts may have been labeled as sensitive, but as we know this is comparing apples to oranges, considering real data classification works on a spectrum of sensitivity.
Sonrai Security has a data classification engine that works across AWS, Azure and GCP so the process doesn’t have to be so cumbersome. Sonrai Dig also includes out-of-the-box classifiers and build-your-own custom classifiers.
If you’re looking to start tackling your data classification journey or just want to learn more about data classification, explore our webinar.
##
ABOUT THE AUTHOR
Eric Kedrosky, CISO, Sonrai Security
Eric Kedrosky is the CISO at Sonrai Security. He’s been in the security game for over 15 years, with stops as head of cyber security at major financial & telecom institutions in the US & Canada. Eric has built cloud security competencies from the ground up for enterprises rich with sensitive customer data in addition to helping many organizations migrate their security from on-premise to public cloud. Most recently, he was the head of security for a financial crime services company.
Today, Eric is tasked with leading Sonrai’s own security efforts and staying on the forefront of cloud security tech. He’s equally interested in the most bleeding edge breach techniques and the more common mistakes that enterprises are making en masse as they move to cloud.
Eric is based in St. John’s in Canada. He’s an avid yogi and loves the outdoors; when he’s not talking security, you’ll find him taking in the natural beauty Newfoundland has to offer.
Twitter: @EricKedrosky
Linkedin: https://www.linkedin.com/in/erickedrosky/





