Cybersecurity Archives | Âé¶ąÔ­´´ News Center /tags/cybersecurity/ Company & Customer Stories | Âé¶ąÔ­´´ Room Wed, 27 Mar 2024 17:57:12 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 Fully Homomorphic Encryption: Data Insights Without Sharing Data /2024/03/fully-homomorphic-encryption-insights-without-sharing-data/ Thu, 28 Mar 2024 12:15:00 +0000 /?p=223900 Carbon footprint calculation, patient privacy, and machine learning based on sensitive data – thanks to advanced encryption methods like fully homomorphic encryption.

Most have been in this situation before: one of the providers or services we use is a victim of a data breach and we want to determine if our personal user data has been impacted. This is where fully homomorphic encryption (FHE) comes into play. With FHE, the encrypted, personal password is compared against the data set of stolen user data and potential matches are identified without ever revealing the user’s password.

Use cases for this type of privacy-enhancing technology (PET) are numerous. They range from applications in medicine, where third-party service providers can analyze health data without compromising a patient’s privacy, to performing machine learning and AI algorithms on encrypted data, allowing organizations to derive insights from sensitive data sets without exposing the data to potential breaches or privacy violations.

How It Works

Fully homomorphic encryption allows calculations to be performed on encrypted data without having to decrypt it first. Confidentiality is maintained, as even the results are encrypted and can be viewed only with the appropriate decryption key. Further techniques for processing encrypted data are multi-party computation (MPC) and trusted execution environments (TEE).

Mathias Kohler, research manager at Âé¶ąÔ­´´ Security Research, outlines the differences: “While FHE is the most known of the encryption technologies, MPC is the ideal candidate if working with several parties exchanging encrypted data across company borders. And it can be substantially faster than FHE.” While both are software-based technologies, TEE is hardware-based, which makes it the fastest choice. The downside: TEEs, unlike MPC and FHE, require decrypting the data for processing. While decryption happens in a trusted hardware environment isolated from the operating system, it can allow data leakage via side-channel attacks. Notably, PETs do not need to be considered in isolation and can augment each other. For example, MPC can encrypt and distribute an FHE decryption key, protecting the FHE key and ensuring no single party can decrypt everything.

Âé¶ąÔ­´´ protects businesses’ applications and data by building, running, and maintaining more-secure operations

Why It’s Relevant

There is a demand for this kind of technology. By 2025, 60% of large organizations will use at least one privacy-enhancing computation technique in analytics, business intelligence, or cloud computing, according to .

Fully homomorphic encryption has numerous applications, especially in scenarios where privacy and security are paramount, such as secure computation in the cloud, privacy-preserving data analysis, and secure outsourcing of computations. As long as one party is performing the data processing centrally, FHE is the encryption method of choice. FHE enables organizations to share encrypted data with partners or third parties for analysis or monetization purposes while maintaining data confidentiality. This is particularly relevant in industries such as advertising and market research.

Interesting use case scenarios from Âé¶ąÔ­´´â€™s perspective could be secure benchmarking and predictive maintenance.

Secure Benchmarking

Companies often assess their competitiveness relative to industry peers and compare business-relevant KPIs, such as automation rate or return rates, with peers and even competitors. With fully homomorphic encryption, all participating parties can share encrypted KPIs without revealing individual data. As a result, they learn about relevant statistics, such as averages or medians, to assess their relative competitiveness and decide where to improve and invest.

Predictive Maintenance

Predictive maintenance is a machine learning technique to forecast demand for maintenance or spare parts based on historical data. “In certain industries, required data, such as usage patterns and failures, is considered sensitive and is not easily shared with data scientists or maintenance operators,” says Anselme Tueno, senior researcher at Âé¶ąÔ­´´ Security Research. By computing on encrypted data, however, no sensitive information is revealed while still allowing for the required insights to be gathered for prediction tasks.

Carbon Footprint Calculation with Multi-Party Computation

While it is early days from a product availability perspective, Âé¶ąÔ­´´ is working on potential use cases with customers and partners. One key example is calculating carbon footprints of products.

Prime examples for complex collaborations are today’s supply chains, intricate networks that encompass various levels of suppliers, manufacturers, and processed goods. Unfortunately, there is often a lack of comprehensive visibility across the entire process – either for technical reasons or because businesses are often reluctant to share sensitive data across supply chains that often include direct competitors.

However, to accurately assess and disclose a product’s carbon footprint, sensitive production details and associated carbon costs for production-relevant parts and materials are required. Here, MPC can reveal only the required carbon footprint without disclosing associated, proprietary manufacturing details with other supply chain participants.

Currently, Âé¶ąÔ­´´ is working with Bosch on cloud-native software for secure multi-party computation called .

“Âé¶ąÔ­´´ participates in this open-source project and supports the development of Carbyne Stack’s storage and processing services and the deployment of Carbyne Stack on Amazon Web Services (AWS),” Kohler explains. “For Bosch, Carbyne Stack is a type of cloud-native operating system for MPC workloads that manages resources to run as efficiently as possible in multi-cloud deployments.” This effort can help Âé¶ąÔ­´´ in the long run to integrate MPC as technology into Âé¶ąÔ­´´ solutions and services while running in a cloud-native environment.

What’s Next?

Despite all the benefits around processing data, encryption introduces significant computational overhead due to the complexity of performing operations on encrypted data. Slow processing speeds, especially for complex operations and large data sets, makes fully homomorphic encryption impractical for real-time applications or large-scale data processing. Although the performance of FHE has greatly improved in recent years, its practical adoption is still limited due to the processing overhead and performance considerations. Ongoing research is focused on the design of FHE-specific hardware accelerators.

“PETs for computing on encrypted data have the power to amplify data-driven business collaborations and reshape the future of cloud computing,” explains Jonas Böhler, senior researcher at Âé¶ąÔ­´´ Security Research. By safeguarding data, they enable access to previously untapped information while minimizing privacy risks and thwarting data breaches. The future of computing is encrypted.


Follow Âé¶ąÔ­´´ News on LinkedIn to stay up-to-date
]]>
Cybersecurity a Top Priority at Âé¶ąÔ­´´, Early Talent Program Recognized by U.S. Government /2023/09/cybersecurity-top-priority-sap-global-early-talent-program/ Fri, 29 Sep 2023 11:15:00 +0000 /?p=212012 This October will mark the eighth annual celebration of cybersecurity month at Âé¶ąÔ­´´ and the 20th annual in the U.S.

This cybersecurity month is especially noteworthy because the Biden-Harris administration recently recognized Âé¶ąÔ­´´ in its newly announced . Developed with companies, academia, non-profits, and U.S. government bodies, the NCWES aims to reinforce cybersecurity as a top priority and address short- and long-term cyber workforce gaps. The cybersecurity industry is not only important to upholding national security, but to leading in a digital economy where our increasing reliance on technology will only foster a more complex cyber threat environment. 

Persistent Pipeline Problem 

Why is cybersecurity so important today?

As noted in a explaining the new strategy, the U.S. has a persistent cyber talent pipeline problem that has continued to grow – with more than 750,000 cybersecurity jobs vacant in 2023. And it’s not just the U.S. that faces such a talent gap. According to , there’s been a 350% increase in cybersecurity job vacancies globally from 2013 to 2021. In 2023, the number of unfilled cybersecurity jobs lands at a whopping 3.5 million globally. And the disparity between the workforce supply and demand is predicted to remain through at least 2025. 

It’s a crisis, confirms Nora Clark, program lead for the Global Security Early Talent program at Âé¶ąÔ­´´. “The need is there…Attacks are always happening though people may not realize because they’re going on in the background…Every employee is a cybersecurity defender and can influence company security and compliance.” But for young professionals, it can be nearly impossible to start a career in cybersecurity, she explains. Many positions require years of prior experience. Not many universities offer degrees in cybersecurity, and there’s a large learning curve that’s hard to overcome without support. 

That’s why Clark was charged with the task of creating a program at Âé¶ąÔ­´´ to fill the need for early talents in the cyber space. 

Global Security Early Talent Program at Âé¶ąÔ­´´ 

Inaugurated in June 2022, the two-year offers young professionals entry into the cybersecurity space at Âé¶ąÔ­´´ through rotations with company security divisions such as Global Cyber Defense and Design, Physical Security, and Risk and Compliance; team workshops; and mentorships. Candidates who successfully graduate from the program are offered placement on a permanent team at Âé¶ąÔ­´´. 

Clark chose to have the program span two years because cybersecurity has many applications and the knowledge may not transfer across teams. Two six-month rotations allow candidates to gain their footing and one 11-month rotation consists of completing a project with a cyber team at Âé¶ąÔ­´´. “This is why our program is designed differently than other programs,” she says. “People say it’s really hard to gain the knowledge and then apply it in a short amount of time. That’s why we provide the Global Security Early Talent candidates learning opportunities, mentorships, and more to support them in their cyber career journey.” 

See for yourself why the Global Security Talent Program at Âé¶ąÔ­´´ is so unique

As a real testament to the initiative’s mounting success, candidates now have 43 different rotations to choose from. “I’ve thoroughly enjoyed the opportunity to rotate across various security teams, which has allowed me to delve deep into different security topics and build out my network,” Jacob Winemiller, Global Security Early Talent program participant, says. “As an early talent in this program, I’ve had the opportunity to work on interesting projects and contribute to meaningful initiatives. From day one, my experience has been nothing short of amazing.”

But the program is about more than just gaining the technical knowledge to survive in cybersecurity – it also focuses on developing soft skills like storytelling, presentation skills, and networking. “When we talk about the program, we’re not just talking about being technically skilled in cyber. We’re also looking to see if they are going to be our next leaders, the next experts in the security industry,” Clark explains. Adam Santilli, Global Security Early Talent program participant, confirms: “As trainees, we are encouraged to develop both our soft and hard skills. The opportunity to do that while being a part of three different teams has given me a unique view on security issues today. I have also formed personal and highly valued relationships throughout this process. They have helped me expand my comfort zone and develop my interpersonal skills.” 

Setting an Industry Standard 

When designing the program at Âé¶ąÔ­´´, Clark struggled to find information about early talent cybersecurity programs at other companies to learn from. “When we started this program, there were seemingly no other early talent cybersecurity programs out there. This type of cybersecurity program for people coming fresh out of college is unique.” Indeed, Âé¶ąÔ­´´ was the only foreign entity recognized in the Biden-Harris administration’s NCWES announcement.  

Clark hopes that with the recognition from the U.S. government and more information about the Global Security Early Talent program out there, more companies will establish early talent cybersecurity initiatives and work together to combat the industry’s workforce crisis. “In security, it only works if we communicate with each other,” she says, talking about both the many security teams across Âé¶ąÔ­´´ and the cyber industry at large. “We all have the same issues and we all want to tackle the same thing. [With the program at Âé¶ąÔ­´´] we want to make sure the next generation of security experts have a tight-knit community where they can reach out to each other.” 

Diversity is just as important as communication. It fosters fresh ideas in any industry, but in cybersecurity specifically diversity helps when addressing threats. Clark explains: “There has to be diversity because our adversaries are also diverse and we don’t know where they’re coming from or what their background is.” Likewise, the NCWES stresses the importance of empowering those currently underrepresented in the cyber workforce. 

As a large, global company, Âé¶ąÔ­´´ has a responsibility to prioritize cybersecurity – for itself and its ecosystem. When you add in the workforce crisis and the need for early talents to that equation, it becomes a no-brainer. “We’re continuing to build our program and support the cyber force,” Clark says. “Ultimately, we want to see how we can also help others.” 


Gillian Hixson is an integrated communications specialist at Âé¶ąÔ­´´.

Connect with Âé¶ąÔ­´´ News on LinkedIn
]]>
Zero Trust for the Highest Level of Data Protection, Security, and Privacy in the Cloud /2023/03/zero-trust-data-protection-security-and-privacy-in-cloud/ Thu, 02 Mar 2023 13:15:31 +0000 /?p=203194 When Rihanna sang some of her greatest hits suspended on a platform that hovered 15 to 60 feet above the stadium at this year’s Super Bowl, trust in technology was of utmost importance. On the same note, trust is crucial when it comes to an organization’s security on every platform it operates.

Data privacy, risk management, and cybersecurity remain key priorities for businesses in 2023 to ensure continuous high performance and to catapult to new heights. In a recent , 43% of survey respondents said that they plan to upgrade IT and data security to reduce corporate risks. That includes security and data protection measures to keep their data safe. This becomes even more important when moving to and operating in a cloud enterprise resource planning (ERP) environment to drive continuous innovation. In the same CIO survey, 12% of the respondents said that they are planning to accelerate the move to the cloud as a service.

Adopt a Zero Trust Security Approach for the Cloud

To secure data and operations in a hybrid work environment, companies have been adopting a zero trust approach. defines zero trust as an “information security model that denies access to applications and data by default. Threat prevention is achieved by only granting access to networks and workloads utilizing policy, informed by continuous, contextual, risk-based verification across users and their associated devices.”

According to 2022 global survey data published by , 39% of companies have already begun to roll out a zero trust solution and 41% of companies have plans to adopt a zero trust strategy and are in the early phases of doing so.

My principle in life is to trust people and systems until I am provided a reason not to. The zero trust principle is the exact opposite of this.

The zero trust approach has three key principles: all entities and users are untrusted by default until authorized, the least privilege access is enforced, and extensive security monitoring is in place. In short, no connections to corporate networks and systems should be trusted at sight. All users, devices, and systems need to be authenticated, reverified, and continuously monitored when accessing networks, systems, and data.

Adopting this approach to cloud transformation has become the leading industry standard to keep operations and data safe across the entire virtual and physical network infrastructure.

Here are some best practices for putting an enterprise security plan in place that utilizes zero trust concepts to run operations safely and securely in the cloud.

Define Clear Security Roles and Responsibilities

First and foremost, ensuring security is always a shared responsibility between companies and their cloud transformation partners. It is a common goal and commitment that is independent of the type of cloud path companies take.

Like with any shared responsibility, the best way to approach it is by defining the roles and responsibilities up front. This process starts by asking these key questions: who is managing the cloud, how will everyone work together to secure the cloud, who is responsible for which part, and where are dependencies?

This will ensure that there is a clear strategy and plan to monitor and implement security policies and measures.

Keep an Eye on Users, Devices, Network, Applications, and Monitoring

Based on our experience at Âé¶ąÔ­´´ Enterprise Cloud Services, another best practice is to focus the zero trust security approach on five pillars: users, devices, networks, applications, and monitoring.

Eighty-seven percent of organizations consider the application layer as being the front door for data breaches. Most data breaches through cyberattacks happen because users fail to keep their credentials safe or fall prey to false identities. In addition, the number of remote users with their own devices has significantly increased in enterprise networks as well as the number of cloud-based assets that are not located within an enterprise-owned network boundary.

By regulating and monitoring user access to devices, networks, and applications, companies can protect all their resources, including assets, services, workflows, and network accounts. For example, identity management systems can manage privileged user authentication and access at a very granular level. This includes keeping administrative accounts separate from corporate accounts and applying encryption to several layers in the IT environment. Data classification makes it possible to associate the security levels with specific types of data, regardless of where that data resides – in the cloud, at endpoints, or in owned data centers.

Scaling Security Needs Faster with the Cloud

While managing the complexity of security needs for cloud transformations can be daunting, here is an added merit: companies can scale their security needs much faster in the cloud, according to research. Benefits include better automation capabilities as well as higher storage and data capacity in the cloud. Companies can push infrastructure as code and fix a security problem in real time when operating in the cloud. Automation also helps in increasing the maturity of identity management and security management systems. recommends embracing cybersecurity as a differentiator to promote greater stakeholder trust and better use of cloud-native solutions that take advantage of the cloud’s full potential.

In other words, you can shine like a diamond on your cloud platform of choice with a zero trust security approach for the cloud.

For more information, visit the site and read this chief security officer for Âé¶ąÔ­´´ Enterprise Cloud Services.


Peter Pluim is president of Âé¶ąÔ­´´ Enterprise Cloud Services and Âé¶ąÔ­´´ Sovereign Cloud Services.

]]>
Clarifying the True Meaning of Innovation Drives Meaningful Business Value /2022/09/true-meaning-of-innovation/ Tue, 27 Sep 2022 11:15:28 +0000 /?p=199571 With so many challenges to solve and little time to wait, innovation is usually prioritized above any other business growth initiative. But if you compare a handful of these strategic projects side-by-side, it’s clear that organizations are aspiring to deliver groundbreaking innovations. They want to create that really big splash.

Breakthroughs happen less often than most people are inclined to believe. Instead, I often find that most innovations are incremental in nature. Admittedly, a slow-building approach doesn’t grab the spotlight like more daring alternatives do. Still, it’s no less important – driving countless small improvements that add up to massive transformations and huge gains down the line.

One prime example of incremental innovation’s impact is the continuous development of mobile devices. The first handheld cellular phone launched nearly 40 years ago. Since then, each new release introduced different sizes – some smaller and some larger – and functionalities such as texting, Internet access, context-driven command, touch screens, tracking and tracing, and many more capabilities now considered standard. In essence, mobile device providers allow themselves to experiment with new ideas while generating revenue that is then reinvested into making the product’s design and purpose more impactful and game-changing in the near future.

Ideas Are Only the Beginning

Ideas are only the start of an innovation journey, no matter how new, novel, or useful. It takes creativity and domain expertise to bring them to life and evolve them gradually by applying the latest lessons learned and scaling capabilities or user experiences to deliver more meaningful value.

As part of Âé¶ąÔ­´´â€™s “reinvent” strategy, my team of customer innovation and maintenance experts from within the Customer Solution Support & Innovation organization at Âé¶ąÔ­´´ focuses on turning ideas into valuable solutions for critical challenges. Working with various industries, including agriculture and life sciences, allows us to innovate and deliver sustainable solutions that accelerate business success – from idea inception and proof of concept to implementation and maintenance.

Customer Solution Support & Innovation offers tremendous industry expertise that can enrich our customers’ growth areas, drive continuous innovation, and deliver prototypes faster to support their transformation into intelligent enterprises. And from our experience, innovations best realize their full value when scaled to add value while they are maintained and developed further to help the world run better and improve people’s lives.

Outcomes Are the Heart of Good Innovation

Our contributions in helping to overcome the impacts of the global COVID-19 pandemic were one of those moments where we revealed the true value of incremental innovation. Developing innovations in partnership under unprecedented conditions, we designed and rolled out numerous digital solutions more quickly and securely for millions of people.

A prime example is the . In only two months development time, we innovated a digital gateway with T-Systems that provides a standard for valid vaccine certification across the European Union and currently supports 600 million users. By removing the risk of falsified documentation, the introduction of this digital certificate represents an important step toward normalizing the freedom of movement within the eurozone and, as a result, stimulating the economy.

In addition, our team worked with Deutsche Telekom AG and Germany’s Federal Ministry of Health to develop the Corona-Warn-App to help identify infections quickly and notify people of their potential exposure. The mobile app, available for iOS and Android, was developed in open-source mode, and the program code was continuously visible to the public on the development platform – all without violating data privacy rights.

While the pandemic marked a significant era of innovation for businesses worldwide, our team has produced innovations important for business security. For instance, our work in detecting and preventing security breaches from cyberattacks plays a vital role in many of our customers’ IT infrastructure. Our experts combine the application – a leading threat detection software – with 24/7 managed security services. The application is continuously upgraded to help detect cyberattacks in on-premise and cloud solutions from Âé¶ąÔ­´´ as they are happening and analyze the threats quickly enough to neutralize them before severe damage occurs.

More recently, we innovated with climate-focused technology company CHOOOSE to deliver a climate app. As one of the first solution extensions developed with existing capabilities available in and Âé¶ąÔ­´´ Concur solutions, helps neutralize carbon emissions through high-quality compensation projects. As a result, our customers can acquire accurate data from their business flights and discover high-impact ways to offset their carbon footprint – all in one place.

We are also working on a prototype – – that marks the first step toward embracing virtual reality for running business. With the sustainability-focused concept, our experts are experimenting with collaboration with targeted data sharing between competing companies and integrating the virtual environment with open ecosystems such as . In addition, a decentralized peer-to-peer network based on Âé¶ąÔ­´´ Business Technology Platform is being created without requiring central persistence.

Innovation That Delivers High Impact

Most companies make the mistake of looking too narrowly at the overall context of their innovation initiative. At Customer Solution Support & Innovation, we are constantly evaluating the Âé¶ąÔ­´´ solution portfolio to find opportunities to adapt and add functionalities that can increase value in ways that can be quickly applied and scaled to meet our customers’ current and future needs.

Embracing the concept of incremental innovation has empowered us to shape a culture that is full of purpose, ingenuity, and discovery. So instead of dedicating all our resources to years-long projects with uncertain outcomes, Âé¶ąÔ­´´ is committed to driving innovation close to our customers’ everyday environmental, social, and governance challenges – and we will continue to do so in the years to come.


Andreas Heckmann is executive vice president of Product Engineering and head of Customer Solution Support and Innovation at Âé¶ąÔ­´´. Follow him on and .

]]>