CSO Security Standard Conference NYC 2012

4
Tokenization is Gaining Traction and Here’s Why Ulf Mattsson CTO Protegrity 1

description

 

Transcript of CSO Security Standard Conference NYC 2012

Page 1: CSO Security Standard Conference NYC 2012

Tokenization is Gaining Traction and Here’s Why

Ulf MattssonCTO

Protegrity

1

Page 2: CSO Security Standard Conference NYC 2012

The Evolution of Data Security and TCO

2

Time

Total Cost of Ownership Strong Encryption: 3DES, AES …

I2010

I2005

I2000

Format Preserving Encryption

Vault Based Tokenization

Vaultless Tokenization

High –

Low -

Era Encryption Tokenization

Less KM,More

transparency

Less audit,More

flexibilityScalability,

Cost

PCI DSS Guidelines In Scope Out of Scope

Page 3: CSO Security Standard Conference NYC 2012

Research Brief – August 2012

Tokenization Gets TractionAberdeen has seen a steady increase in enterprise use of tokenization for protecting sensitive data over encryption

Nearly half of the respondents (47%) are currently using tokenization for something other than cardholder data

Over the last 12 months, tokenization users had 50% fewer security-related incidents than tokenization non-users

Case study #1 – Energy company, Protegrity customer

3 Author: Derek Brink, VP and Research Fellow, IT Security and IT GRC

Page 4: CSO Security Standard Conference NYC 2012

Case Study #2

Large US Chain Store, Protegrity CustomerReduced cost

• 50 % shorter PCI audit

Quick deployment• Minimal application changes

• 98 % application transparent

Top performance• Performance better than encryption

Stronger security

Learn more at the Protegrity booth4