Apricorn is a 40 year old technology company that is focused on secure, encrypted hardware storage. The company continues to innovate and patent its technology and sees a host of vertical markets (healthcare, legal, video/film, government) use its devices because they are super fast, super high capacity and super secure. To learn more about the company, data protection, cloud backup, and their recently introduced super-fast NVME product, VMblog connected with Kurt Markley, Managing Director, Americas, at Apricorn.
VMblog: Tell me about Apricorn, who you serve and what unique features you bring to the table.
Kurt Markley: Apricorn makes the industry’s best encrypted hardware storage devices that are used by organizations across the globe, spanning industries such as government, healthcare, legal, forensics, technology and more.
For 40 years, the company has been focused on storing the most valuable asset that organizations have: their data. As times have changed, and security threats like ransomware have increased, we’ve continuously delivered products to serve what clients need, which today is ensuring their data is protected from bad actors and security threats that continue to grow in sophistication. That’s why all of our products are software-free. All of the encryption and authentication that happens with our devices is done by way of that device’s own keyboard and internal hardware.
We have patented 10 different products and have brought to market innovations that have become the standard in the industry, most notably Forced Enrollment. Before we created and brought this innovation to market, it was an industry norm to ship out products with factory installed PINS. Apricorn recognized that many users did not change the default PIN, which created a highly insecure situation, so we created Forced Enrollment, which required them to create their own unique PIN before the device could be written to.
Forced Enrollment is a good example of technology Apricorn brought to market that became the market standard. Much like Volvo invented the seat belt to improve automobile safety and saw that innovation adopted by competitors, Forced Enrollment is one of many creative, unique ideas Apricorn designed and that we see across the vendor landscape today.
One last distinctive feature about Apricorn is that all of our products are software-free. Users have to have physical custody of the device, as well as the PIN, to access information. This hardware-centric approach to securely storing data was purposeful and has become a hallmark of our company.
VMblog: Organizations generally know their data is valuable. Are they taking the necessary steps to protect that data?
Markley: Yes and no.
Apricorn puts out an IT Security Survey every year that details data backup, encryption and resiliency protocols for IT professionals in the United States and Canada over the past 12 months. The 2023 survey showed that while the vast majority of respondents – we’re talking almost 95% – say they factor in data backups as part of their cybersecurity strategy, only 25% follow the industry best practice for backing up their organization’s data. The discrepancy there is huge. It’s great that so many are planning for backups, but really scary that so few are doing it according to established best practices. So, there’s massive room for improvement there.
We have also seen a disconnect regarding remote or hybrid work over the past few years. We all know that employees are the biggest risk to an organization’s data security. Whether it’s a lack of security awareness or adherence to policies, simple mistakes, or insider threats, employee apathy is putting data at risk. Our survey showed that 33% of employees working in the office, and 27% working remotely, don’t consider themselves as potential targets. If they don’t think they will be attacked with a phishing email or social engineering scheme, then the chances of those breach attempts being successful goes up.
We also found that half of organizations aren’t encrypting sensitive information for data on the move. So many feel fully protected by the IT policies their organization has in place, but that’s really a false sense of security. There are only two ways for organizations to truly protect their data: hardware encryption and frequent backups that are complete and clean. So, there’s work to do to educate employees and to make these processes simple yet robust – which is what Apricorn does.
VMblog: What best practices does Apricorn recommend to protect data or to help organizations recover from a data breach?
Markley: There are many, but two that come to mind immediately and play off of one another creating and keeping clean backups for the appropriate amount of time, and using the 3-2-1 rule for data resiliency.
We know that most businesses create and keep backups. Our 2023 North American IT Security Survey showed that 37% of respondents have experienced a data loss even in the past 12 months, with 55% reporting they had to restore data from a backup as part of their recovery. However, 16% do not ensure that their data backups are clean and complete and 52% say they keep their backups for only 120 days. That’s four months of time, but we know from an IBM survey that the average breach lifecycle takes 287 days to detect, which is nine and a half months. If businesses are keeping their backups for less than 10 months, they are putting their organization and its data at risk.
Tying into this, it’s hard to exaggerate the importance of the 3-2-1 rule for cyber resiliency. The 3-2-1 rule instructs organizations – whether those are SMBs, enterprises, government agencies, etc. – keep three copies of their data on two different types of media, with one copy being stored offsite. Taking this approach means that no one event is going to destroy all of an organization’s data. So, if you store data in the cloud, great. But also put it on an encrypted drive in a different location so that if the cloud facility experiences an event, organizations have other copies in different locations that they can use to restore their business operations.
In the same survey we referenced above, we found that while 93% of respondents said they factor in data backups as part of their cybersecurity strategy, only 1 in 4 follow the 3-2-1 rule. There’s education that needs to be done to help organizations embrace this simple, proven approach to protecting their data.
From our standpoint, the 3-2-1 rule that recommends keeping one copy of an organization’s data offsite makes a strong case for storing data on encrypted hard drives in order to secure it. We have pioneered technology that ensures bad actors are not going to be able to get into our secure drives, making it simple for organizations to back up, store and restore their data.
VMblog: How does Apricorn ensure that its hardware devices are secure?
Markley: Like I said earlier, we aren’t new to this. Apricorn has a 40 year legacy of innovation that is focused on creating secure storage devices that are used by the most demanding customers, many of whom have strict data security, compliance and regulatory requirements. We have a laundry list of patents and innovations that we’ve brought to the market – which other vendors have then OEM’d into their own products.
First and foremost, we use a 100% hardware-centric approach, with full hardware encryption and a software-free design for a completely cross-platform experience. All authentication and encryption functions take place fully within the devices, no critical security parameters are ever shared with their host computer, and tested and validated by NIST to the Federal Information Processing Standards (FIPS 140-2).
Our products have a unique feature set that includes things such as:
- Compatibility with the Apricorn configurator, enabling automated and mass configuration of Apricorn devices
- Forced enrollment – no factory set default PINS
- Programmable PIN length
- Self-destruct PIN
- Programmable number of brute force attempts allowed
- Ability to create recovery PINS to assist users who have forgotten their authentication details
- Ability to toggle between removable media and fixed disk
- Administrator enforced read only
We’ve spent four decades watching how storage and security has changed and have brought to market a host of innovations that are now standards in the industry. For example, in 2013, our Aegis Fortress product was the first keypad authenticated encrypted external drive to attain FIPS 140 2 level 2.
VMblog: We hear a lot about backing up to the cloud. How does Apricorn work in conjunction with cloud storage?
Markley: People seem to think that you store data to either the cloud or to storage devices. The truth is that the two are a good complement to each other.
Businesses have migrated much of their work – including data storage – to the cloud. It’s convenient, it’s, in theory, always on, and the capacity can be easily scaled. That said, the cloud is not foolproof and it does sometimes suffer catastrophic events like when in 2021 a French data center burned to the ground. Because the data stored in that data center was also backed up to another location in the same data center, all copies of data for those organizations was lost forever.
Organizations that are storing data to the cloud and want to continue to should. But they should also employ the 3-2-1 rule that we discussed earlier and ensure that they have another copy on a different medium such as an encrypted hard drive that’s stored in another location. This approach gives the peace of mind that no matter the situation, a backup is available and accessible.
VMblog: You recently introduced a super-fast NVME product. What type of use cases need 1,000 MB/S storage?
Markley: Our Aegis NVXTM is a really interesting product that we’re very proud of. It’s our first product to feature an NVME SSD inside and comes in a variety of capacity offerings. What’s really cool about the NVX is that it is designed for users who are operating ultra-fast devices but have traditionally had to settle for awkward, multi-step means for securing the data they just created.
Take for instance, the filmmaking industry, which hasn’t forgotten the Sony breach from nearly 10 years ago that cost the company not only reputational damage, but upwards of $100 million in repair costs and downtime. It costs, on average, $65 million to make a movie then another $35 million to market it. That’s a lot of money to put in before a ‘product’ can be sold. Film makers are using very fast, very high-quality cameras and need to ensure that the footage they just created is secure. Making a movie involves a lot of small businesses and independent contractors, which makes it hard to get every stakeholder to align on cybersecurity practices. That means there are a lot of attack surfaces for bad actors to get in and steal.
If a filmmaker can encrypt the raw images they are recording in real time to an encrypted, high-capacity drive, they eliminate the risk of this $100 million project being stolen and released. This process of securely storing film as it’s created on an NVX removes the manual, cumbersome, multi-step task that required exchanging external hard drives and batteries, resulting in a lag between the creation of data and the encryption of it. It was really a frustrating task to secure film – they had to constantly move from one hard drive to another, breaking the continuity needed to keep a project on schedule and resulting in high-cost delays.
With a product like the NVX, they store and secure images as quickly as they are made and can rest easy that they are not at risk. While this example is about Hollywood films, you can see how the NVX would similarly be important for healthcare imaging. Radiology takes an image and needs to ensure it’s securely and immediately saved to a patient’s electronic medical record. There are so many use cases across verticals like military intelligence and digital forensics, too.
VMblog: You work with a variety of different vertical markets. How do their storage needs differ?
Markley: With regard to verticals, we work with businesses, agencies and organizations of all kinds. That said, we find that we can really help businesses and organizations that are highly regulated – government, technology, legal (including discovery), and healthcare are good examples.
With regard to how the storage needs of our customers differ, that’s a big question because every business and organization has different needs, from their compliance requirements to the amount of privileged data they store. So, from the filmmaker I referenced above to the attorney who has data pertaining to a trial to government agencies that are storing highly classified data, our products are trusted across industries to secure that data and protect it from bad actors.
What’s consistent across all of our customer use cases is the need to absolutely protect data and to do so in a way that is really simple for the user. That’s why we made our products software-free and use a keypad system that is really straightforward and easy to use.
VMblog: Organizations tend to store data in the cloud and forget about it. What is the business impact of this type of practice and is there a different approach you’d recommend?
Markley: When organizations have data they no longer need and limited visibility into it – which happens a lot – they increase the risk of data breaches and leaks. We are all guilty of saving something, seeing it in our files later and holding on to it because we *think* we’ll need it later, yet the need never arises. Then we forget about it and don’t delete it. Depending on what that data consists of, it could be very appetizing to a bad actor.
Outside of creating an attractive buffet of possible PII for bad guys to try to steal, you have to consider the cost of storing data that is no longer needed. We’re seeing research that shows that cloud spend has overtaken security as the main priority within enterprises for the first time in a decade. Organizations are over provisioning, over saving and aren’t getting the visibility into their cloud spend that they need.
Now, what to do about it? Especially for large enterprises and government agencies, they can easily take information that they don’t want to destroy, but no longer use regularly, and put it on an encrypted storage device for a one-time cost. Not only does this reduce cloud spend in the long run, but it decreases the size of the attack surface that bad actors go after.
##






