SYS-CON MEDIA Authors: Liz McMillan, Elizabeth White, Pat Romanski, Gary Arora, Zakia Bouachraoui

Blog Feed Post

Porticor Helps Organizations Meet PCI DSS Compliance and Secure Credit Card Information Stored in the Cloud

Porticor’s Cloud Key Management and Data Encryption Solution Protects Cloud-based Cardholder and Financial Information from Holiday Hackers and Threats at Organizations such as Payze

CAMPBELL, Calif. – Dec. 2, 2014 – Porticor®, a leading cloud data security company delivering the only cloud-based key management and data encryption  solution that infuses trust into the cloud and keeps cloud data confidential, today announced growing customer traction due to its innovative solution enabling organizations to secure cloud-based credit card and financial information, helping them meet Payment Card Industry Data Security Standard (PCI DSS) compliance.  Customer privacy is of particular concern for financial organizations during the holiday season due to the increase in threats and hacker activity.

The Porticor Virtual Private Data (VPD) platform is a cloud key management and encryption solution that delivers the industry’s most secure cloud encryption key management by enabling organizations to securely maintain control of their own encryption keys.  Unlike traditional data encryption solutions, which are complicated and expensive to deploy and manage, Porticor’s split-key encryption and homomorphic key management system is offered as the industry’s first cloud data protection service of its kind, delivering true confidentiality of credit card and financial data in cloud, virtual and hybrid environments by ensuring encryption keys are never exposed.

“At Payze we’ve setup a credit card processing system within AWS, and as part of our PCI requirements we needed a separate key management system in order to comply with PCI policies,” said Joel Paulin, Founder and Chairman of Payze.  “We’ve integrated Porticor into our encryption key setup to provide seamless additional encryption on top of our existing encryption infrastructure.  This additional level of encryption, with keys isolated from our normal system, and using Porticor’s permissions and controls enables us to have a more secure key management posture going for PCI compliance.  What differentiates Porticor is the product: It is polished, easy to configure, easy to integrate, more reliable, and has greater security than the other options we had seen.”

The main focus of PCI DSS is protecting cardholder data in systems and applications, including data in storage, transmission, and in use.  These requirements are more critical when data is stored and processed in the cloud, an activity escalated during holiday shopping.  Porticor VPD is a complete solution that combines patented key management with state-of-the-art encryption to enable organizations to effectively comply with PCI DSS in the cloud.  Porticor encrypts the entire data layer, including virtual disks, databases, files, and object storage.  It also addresses the processes necessary for managing encryption environments and encryption keys, and provides the security needed for compliance in a convenient, cost-effective, fully cloud-based solution.

“We were impressed with the ease of setting up the Porticor appliance,” added Paulin.  “Compared to the other options we considered, we were more confident in the security of Porticor’s solution, and we appreciate the turnkey nature of it.  Also, because the Porticor systems provide automation of key management, we didn’t need to worry about a server crashing and losing our keys since the automated system would correctly provision our instances, which was a risk for other systems.  Finally, the use of a master key on the appliance kept by us helped give us assurance that Porticor did not know our keys and we had the benefit of dual control, which helped us meet our dual control needs for PCI compliance.”

The PCI Council defined 12 high-level security requirements.  Six of the requirements define the need for both encryption and key management in the cloud to protect credit card information from both inside and outside threats, and are addressed by Porticor.  Porticor gives organizations the ability to meet these requirements by requiring two keys to encrypt or decrypt an object.  In addition, each key is encrypted – to protect it while it is resident in a cloud account – using patent-pending homomorphic key management technology.  In addition, Porticor helps address some of the general PCI DSS requirements beyond encryption and key management.  For more information on how Porticor addressed PCI DSS compliance, see: http://www.porticor.com/pci-white-paper-download/

“Financial organizations are under threat at all times, but especially during this time of year with the increased consumer buying activity,” said Ariel Dan, Porticor Co-Founder and Executive VP.  “Porticor’s VPD is uniquely built to address PCI DSS compliance requirements, and the PCI DSS requirements validate the need for Porticor’s unique approach of combining patented split-key encryption and homomorphic key management with encryption technologies.  Key management is an ongoing challenge for organizations, and Porticor’s homomorphic key management solves this problem and enables companies to achieve compliance.  With Porticor, organizations are assured that credit card information and confidential data are kept safe from outside and internal threats.”

Integrating with major players such as HP, AWS and VMware, Porticor provides the industry’s only software-defined, automated solution that uniquely eliminates the need for cumbersome, non-scalable, and expensive hardware security modules for the cloud.  Uniquely combining data encryption with patented split-key encryption and homomorphic key management technologies, Porticor protects critical data in public, private and hybrid cloud environments.  It provides the strong security needed for compliance in a convenient, cost-effective, fully cloud-based solution.

About Porticor

Porticor is the leading cloud security company delivering easy-to-use and scalable security solutions for cloud data encryption and key management.  The Porticor Virtual Private Data (VPD) system is the industry’s first solution combining data encryption with patented split-key encryption and homomorphic key management to protect critical data in public, private and hybrid cloud environments.  Using breakthrough split-key encryption and homomorphic key management, the Porticor VPD is the only system available that offers the ease-of-use of cloud-based key management without sacrificing trust.  Porticor is an Amazon Web Services Technology Partner, a VMware Technology Alliance Partner, an HP technology partner, and supports other clouds.  The company is headquartered in Tel Aviv, Israel, with offices in Silicon Valley, and is venture backed.  For more information, visit: http://www.porticor.com/.

 

###

The post Porticor Helps Organizations Meet PCI DSS Compliance and Secure Credit Card Information Stored in the Cloud appeared first on Porticor Cloud Security.

Read the original blog entry...

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

Latest Stories
Alan Hase is Vice President of Engineering and Chief Development Officer at Big Switch. Alan has more than 20 years of experience in the networking industry and leading global engineering teams which have delivered industry leading innovation in high end routing, security, fabric and wireless technologies. Alan joined Big Switch from Extreme Networks where he was responsible for product strategy for its secure campus switching, intelligent mobility and campus orchestration products. Prior to Ext...
Isomorphic Software is the global leader in high-end, web-based business applications. We develop, market, and support the SmartClient & Smart GWT HTML5/Ajax platform, combining the productivity and performance of traditional desktop software with the simplicity and reach of the open web. With staff in 10 timezones, Isomorphic provides a global network of services related to our technology, with offerings ranging from turnkey application development to SLA-backed enterprise support. Leadin...
On-premise or off, you have powerful tools available to maximize the value of your infrastructure and you demand more visibility and operational control. Fortunately, data center management tools keep a vigil on memory contestation, power, thermal consumption, server health, and utilization, allowing better control no matter your cloud's shape. In this session, learn how Intel software tools enable real-time monitoring and precise management to lower operational costs and optimize infrastructure...
Public clouds dominate IT conversations but the next phase of cloud evolutions are "multi" hybrid cloud environments. The winners in the cloud services industry will be those organizations that understand how to leverage these technologies as complete service solutions for specific customer verticals. In turn, both business and IT actors throughout the enterprise will need to increase their engagement with multi-cloud deployments today while planning a technology strategy that will constitute a ...
Cloud-Native thinking and Serverless Computing are now the norm in financial services, manufacturing, telco, healthcare, transportation, energy, media, entertainment, retail and other consumer industries, as well as the public sector. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that pro...
Every organization is facing their own Digital Transformation as they attempt to stay ahead of the competition, or worse, just keep up. Each new opportunity, whether embracing machine learning, IoT, or a cloud migration, seems to bring new development, deployment, and management models. The results are more diverse and federated computing models than any time in our history.
Andrew Keys is co-founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereum.
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
Data center, on-premise, public-cloud, private-cloud, multi-cloud, hybrid-cloud, IoT, AI, edge, SaaS, PaaS... it's an availability, security, performance and integration nightmare even for the best of the best IT experts. Organizations realize the tremendous benefits of everything the digital transformation has to offer. Cloud adoption rates are increasing significantly, and IT budgets are morphing to follow suit. But distributing applications and infrastructure around increases risk, introdu...
DevOps has long focused on reinventing the SDLC (e.g. with CI/CD, ARA, pipeline automation etc.), while reinvention of IT Ops has lagged. However, new approaches like Site Reliability Engineering, Observability, Containerization, Operations Analytics, and ML/AI are driving a resurgence of IT Ops. In this session our expert panel will focus on how these new ideas are [putting the Ops back in DevOps orbringing modern IT Ops to DevOps].
Financial enterprises in New York City, London, Singapore, and other world financial capitals are embracing a new generation of smart, automated FinTech that eliminates many cumbersome, slow, and expensive intermediate processes from their businesses. Accordingly, attendees at the upcoming 23rd CloudEXPO, June 24-26, 2019 at Santa Clara Convention Center in Santa Clara, CA will find fresh new content in full new FinTech & Enterprise Blockchain track.
While a hybrid cloud can ease that transition, designing and deploy that hybrid cloud still offers challenges for organizations concerned about lack of available cloud skillsets within their organization. Managed service providers offer a unique opportunity to fill those gaps and get organizations of all sizes on a hybrid cloud that meets their comfort level, while delivering enhanced benefits for cost, efficiency, agility, mobility, and elasticity.
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: Driving Business Strategies with Data Science" is responsible for guiding the technology strategy within Hitachi Vantara for IoT and Analytics. Bill brings a balanced business-technology approach that focuses on business outcomes to drive data, analytics and technology decisions that underpin an organization's digital transformation strategy. Bill has a very impressive background which includes ...
On-premise or off, you have powerful tools available to maximize the value of your infrastructure and you demand more visibility and operational control. Fortunately, data center management tools keep a vigil on memory contestation, power, thermal consumption, server health, and utilization, allowing better control no matter your cloud's shape. In this session, learn how Intel software tools enable real-time monitoring and precise management to lower operational costs and optimize infrastructure...
Most organizations are awash today in data and IT systems, yet they're still struggling mightily to use these invaluable assets to meet the rising demand for new digital solutions and customer experiences that drive innovation and growth. What's lacking are potent and effective ways to rapidly combine together on-premises IT and the numerous commercial clouds that the average organization has in place today into effective new business solutions. New research shows that delivering on multicloud e...