Enterprises with servers deployed in co-location facilities need to rapidly provision servers in bare-metal cloud environments to accommodate expanding processing needs or spikes in demand for information processing. As businesses grow, enterprises frequently face delays in provisioning new servers in existing co-location facilities or simply running out of space in existing infrastructure.
Although enterprises may encrypt sensitive information while at rest, a security gap remains because the information is unprotected and “in the clear” when in use. Servers in co-location facilities and in the cloud can process and manipulate sensitive information including:
Personally identifiable information (PII): Loss of PII can trigger state data breach laws or national data protection laws
Non-public Information (NPI): The loss of NPI such as financial information can trigger regulatory action.
Proprietary Information: Intellectual property provides competitive advantage, and the loss of such property can lead to lost competitive advantage and revenues
Electronic Protected Health Information (ePHI): Both employee and client ePHI are subject to regulatory oversight
Encryption keys: Stealing of encryption keys for data-at-rest while in memory can enable hackers to decipher and access encrypted data stored on disks.
Organizations reducing business delays often want the utilize the public cloud for rapid deployment, yet information security concerns may remain a significant barrier. Bare-metal cloud offerings provide a way to quickly scale processing power, but security concerns have previously obviated this option.
Bare-metal cloud computing provides an attractive option for enterprises needing to quickly provision hardware capacity when existing co-location environments lack additional capacity. While bare-metal clouds can provide the necessary elasticity of processing power, they typically lack the physical security measures that enterprises typically expect from a server infrastructure handling sensitive information. Bare-metal cloud environments lack physical isolation between tenants and typically do not provide sufficient protection against physical server access, particularly against threats that could compromise server memory. Such cloud environments do not provide robust security to counter the possibility of hackers pilfering information, competitors snooping to discover secrets with a resulting loss of competitive advantage as well as enterprises being unaware of lawful requests for enterprise information.
IT directors and security personnel have historically had to consider tradeoffs between security, speed of deployment, and revenue. Limiting servers to secure co-location environments that are managed and provisioned by the enterprise minimizes the security risk of information being compromised. However, such an approach may hinder the ability to grow the business.
PrivateCore vCage protects sensitive information located in bare metal clouds, enabling enterprises to securely deploy servers in an environment that would otherwise be off-limits due to security concerns. The PrivateCore software-only security solution encrypts all memory contents, mitigating against the possibility of compromised data-in-use. vCage memory encryption enables service providers and enterprises to safely deploy more servers.
Want to try vCage? Click here to download free vCage Manager software!