Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Leadership and ManagementLogical SecuritySecurity & Business Resilience

Two critical strategies for enterprise data encryption

By Siamak Nazari
binary code data encryption
March 8, 2022

Data security and regulatory compliance demands are growing across various industries and countries. Organizations are increasingly challenged by evolving threats that require new processes and technologies, further complicating the task of securing and managing their data.

Be it phishing, social engineering or a data breach, there seems to be a new type of attack on the horizon every day. One such attack in particular was related to the decommissioning of unencrypted equipment.

In this highly publicized case, an enterprise agreed to pay $60 million to settle a data breach suit because confidential personal information was compromised via decommissioned data center equipment. Allegedly, a software flaw left unwiped data on old, unused servers in unencrypted form.

How can dark data still be an issue faced by security leaders in 2022? Here’s an example:

Think about a cell phone. Whether it is iPhone, Samsung, or some other mobile phone model, the personal data on the phone is encrypted by default — there is no need to manually encrypt the data or manage an encryption key. However, these are very real issues for enterprise data stored in data centers in various industries, especially ones with large edge deployments: retail, banking, healthcare, etc. So what solution is there for enterprise data centers?

1. Enterprise data encryption should be enabled by default.

Encryption at rest protects data wherever it's stored, whether on a hard drive or in the cloud. The enterprise referenced above may have encountered the data breach because encryption for data at rest was likely never initially enabled for the data on these specific decommissioned servers.

When thinking about encryption, considering the software and the hardware layers together is imperative. In order for third-party software to be secure, security must be built into the hardware. One way to do this is to have an encryption key generated at the hardware layer, which strengthens the protection against potential backdoors linked to software weaknesses. By building a security foundation at the hardware layer, companies can lay the groundwork for secure authentication and encryption key management.

Furthermore, the hardware-generated key should be streamlined at the hardware layer to eliminate the need for users to manage those keys. Not only does this enable application owners to focus on their applications, but it minimizes the risk of human error.

Why does matter? A master, hardware-based encryption key means that, like a smartphone, every time data is written to enterprise hardware, it is encrypted automatically and the user never needs to think about it. Encryption is always on.

For additional security, some companies may want to implement in-flight encryption, which protects against man-in-the middle attacks or someone nefariously accessing the network. Additional security measures like two-factor authentication and role-based access control (RBAC) should also be considered.

2. Automate the process of erasing boot or local data drives on decommissioned servers.

Assuming enterprise data is encrypted from day 1, once the server is decommissioned, the easiest and most effective way to keep user data secure is to destroy the encryption key. It only takes seconds to do, and once an encryption key is destroyed, the data is irrevocably lost. This means that even if the infrastructure is misplaced or stolen, there is no risk of a data breach ever happening.

Again, just as users don’t need to think about managing encryption on their smartphones, this two-pronged approach of “always-on” data encryption and heavy automation of back-end security tasks will help companies protect data residing on decommissioned data center infrastructure devices without requiring an inordinate amount of manual management on the part of users.

After all, just because a device has been discarded doesn’t mean the sensitive data residing on it can be considered “disposed of,” so to speak. Opportunistic hackers could find nefarious uses for that data if the device isn’t protected to the same standard as active hardware currently in use.

KEYWORDS: access control cyber security threat data breach encrypted devices encryption multi-factor authentication

Share This Story

Siamak Nazari is a Founder of Nebulon.

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing