# Assurance v Security: Reassessing Responsibility for Data Assurance
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-12-06
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: SD-WAN Adoption Risks: Data Assurance Challenges
Meta Description: Discover the explosive growth of SD-WAN adoption and the critical need for high assurance data security in regulated industries. Learn more here.
URL: https://financedigest.com/assurance-v-security-reassessing-responsibility-for-data-assurancehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-1142845130-1736814753328-compressed.jpg)

_The adoption of Software Defined Wide Area Networks (SD-WAN) has exploded in recent years as companies embrace the lower costs and flexibility to accelerate digital transformation. Yet SD-WAN deployments do not offer the assurances demanded by organisations operating within regulated industries. Standard SD-WAN deployments do not ensure the integrity of sensitive data as it travels across the network environment – leaving organisations with the choice of either leaving data unprotected and vulnerable to malicious actors or remaining with expensive legacy WAN deployments. Neither approach is sustainable._

_Even worse, new research bears evidence that the true business impact of [data loss is not understood and businesses are expecting service providers to bear the financial](https://www.financedigest.com/the-financial-sector-must-act-to-tackle-internal-data-security.html "THE FINANCIAL SECTOR MUST ACT TO TACKLE INTERNAL DATA SECURITY") brunt of a breach – a situation accepted by the providers. Critically, despite ever tightening regulatory focus on data assurance, the market remains focused on [network security](https://www.financedigest.com/new-demands-on-network-security.html "NEW DEMANDS ON NETWORK SECURITY"), adding to the risk of breach._

_![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/640-1736814753282-compressed.jpg)_

 _As **Paul German,** CEO, Certes Networks explains, it is now critical to reassess where the perceived responsibility lies in the event of a [data breach; to clearly understand the security functions organisations with SD-WAN are currently able to enact, and the gaps that still exist, if the industry is to improve confidence and achieve high assurance data](https://www.financedigest.com/10-steps-to-stop-lateral-movement-in-data-breaches.html "10 Steps to Stop Lateral Movement in Data Breaches")._

**SD-WAN Adoption**

The speed with which SD-WAN adoption has become ubiquitous underlines the acceleration in [digital transformation](https://www.financedigest.com/redefining-the-human-touch-with-data-driven-digital-transformation.html "Redefining the human touch with data-driven digital transformation") across the world. New, independent research commissioned by Certes Networks shows that 91% of respondent companies confirm they have either started or finished SD-WAN implementation. Over half of respondents cite bandwidth efficiency as the key driver for SD-WAN implementation, followed by significant application performance improvement (47%), long term savings (45%) and WAN simplification (44%).

However, a quarter (25%) consider not sacrificing [security and data](https://www.financedigest.com/the-challenge-of-keeping-data-secure-why-in-house-security-isnt-enough.html "The challenge of keeping data secure: why in-house security isn’t enough") privacy as a driver for implementation, which suggests a widespread lack of understanding, awareness and risk assessment surrounding current security postures. SD-WAN is not a data assurance technology – and for organisations operating in high assurance industries, standard deployments cannot meet regulatory requirements for data integrity, an increasingly vital consideration in an era of rapidly escalating security breaches – including the growing threat of [cyber war](https://www.newscientist.com/article/2309369-will-russias-invasion-of-ukraine-trigger-a-massive-cyberwar/).

**Confused Approach**

Moreover, the research highlighted widespread confusion regarding regulatory compliance. Despite 96% being confident that regulatory requirements do provide sufficient [support and guidance to protect](https://www.financedigest.com/supporting-a-fair-and-resilient-society-by-protecting-access-to-cash.html "Supporting a fair and resilient society by protecting access to cash ") against breaches, almost three quarters (72%) also believe there are risks involved in adopting an approach that focuses primarily on compliance first. 48% believe the main [risk is that security](https://www.financedigest.com/tesla-to-warn-of-data-privacy-risk-from-car-security-cameras-in-germany.html "Tesla to warn of data privacy risk from car security cameras in Germany") regulations lag behind hackers’ abilities, with 45% saying a threat assessment based on historical and industry data is not done and 42% believing it is a guideline on how to breach.

Clearly, on the one hand, there is a fear that regulation doesn’t go far enough. On the other, organisations are either wilfully or unintentionally overlooking the assurance limitations of SD-WAN in order to maximise the operational and cost benefits.

This research also confirms that not enough companies appreciate the data assurance limitations associated with SD-WAN. Yes, two fifths (39%) highlight concerns that unprotected [data is lying within a protected network, but only a quarter (24%) say that SD-WAN security is not enough and that a data breach in one area could affect the entire organisation](https://www.financedigest.com/avoiding-a-big-data-car-crash-how-to-organise-your-data-to-detect-fraudulent-claims.html "Avoiding a big data car crash: How to organise your data to detect fraudulent claims"), and only 22% flag the lack of onsite security features.

**Open Network**

There is good reason for the [need for more confidence in the security](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") posture. While a SD-WAN overlay looks private, there is still a public internet [connection plugged in to a business that holds both sensitive and non-sensitive data](https://www.financedigest.com/keeping-data-connected-for-greater-business-value.html "Keeping Data Connected for Greater Business Value"). There is a very [real risk that a regulated business could inadvertently end up with sensitive data](https://www.financedigest.com/data-fake-will-be-the-new-real-in-financial-services-in-2023.html "Data: Fake will be the new real in financial services in 2023") on the public internet, through configuration errors or software bugs, and incur a significant regulatory breach in the process.

Furthermore, any businesses that partner with or supply to regulated industries – especially utilities and government – are becoming key targets for hackers looking for another route into [organisations that have already deployed a high assurance data](https://www.financedigest.com/auditing-in-cyber-how-organisations-can-keep-track-of-their-data.html "AUDITING IN CYBER: HOW ORGANISATIONS CAN KEEP TRACK OF THEIR DATA") security model. Adding the sheer flexibility in cloud deployments, the use of local break-out to push day-to-day data created in SaaS tools such as Office365 or Salesforce directly onto the Internet rather than [directed](https://www.financedigest.com/should-insurers-buy-data-direct-from-their-customers.html "Should insurers buy data direct from their customers?") to the corporate data centre further adds to the risk. What happens if the local break-out policy accidentally includes sensitive data?

**Abdicated Responsibility**

Despite (or perhaps because of) the acknowledged risks, too many organisations are handing over responsibility to an IT Service Provider (ITSP) or Managed Services Provider (MSP) – and expecting the provider to pick up the [financial cost](https://www.financedigest.com/how-much-does-cloud-based-financial-software-cost.html "How Much Does Cloud-based Financial Software Cost?") should a data breach occur. Almost 50% of survey respondents confirm that third party organisations are employed to deliver security policies. Businesses [expect ITSPs to cover 48% of the costs](https://www.financedigest.com/five-cost-of-living-trends-expected-in-2023.html "Five cost of living trends expected in 2023") in the event of a data breach – but 73% of ITSPs also consider themselves responsible for paying fines and damages, and believe they should pay 51% of the costs.

Moreover, far too many companies are failing to take into [account the long-term business significance of a data breach](https://www.financedigest.com/5-simple-ways-to-prevent-a-data-breach-from-putting-your-accountancy-practice-out-of-business.html "5 Simple ways to prevent a data breach from putting your accountancy practice out of business"). 40% [say the financial impact in the long term is not considered](https://www.financedigest.com/sega-sammy-says-it-is-considering-buying-angry-birds-maker-rovio.html "Sega Sammy says it is considering buying Angry Birds maker Rovio"), and only 33% consider the long-term business impact of data loss.

Simply relying on a contractual agreement for financial remuneration therefore totally misses the fundamental operational risk associated with inadequately assured SD-WANs. But this approach also highlights the confusion between network [security and data](https://www.financedigest.com/2023-fintech-prediction-secure-and-private-data-usage-is-key.html "2023 FinTech Prediction: Secure and Private Data Usage is Key") assurance that dominates the industry, especially within high assurance markets. Companies [need to take ownership of their data](https://www.financedigest.com/leaders-recognise-the-importance-of-green-transport-at-cop27-but-we-need-data.html "Leaders recognise the importance of green transport at COP27, but we need data"). Yes, an MSP or ITSP running the SD-WAN will put in place standards to secure the network infrastructure – but who is [protecting the data](https://www.financedigest.com/4-steps-you-should-be-taking-to-protect-data.html "4 Steps You Should Be Taking To Protect Data") and how?

This continued focus on [network security](https://www.financedigest.com/uks-morgan-advanced-materials-reports-cyber-security-incident-on-its-network.html "UK’s Morgan Advanced Materials reports cyber security incident on its network") rather than assuring vital data is at odds with the goal of regulators. Security regulation is totally focused on data assurance, on safeguarding [essential information](https://www.financedigest.com/what-is-a-virtual-data-room-unveil-the-essential-information-here.html "What is a Virtual Data Room? Unveil the Essential Information Here!") assets. The solutions traditionally deployed to comply with regulation, however, are about network security, a misguided focus that has left data unassured.

**Taking Control**

So how can organisations maximise the [benefits of SD-WAN _and_ retain control over their sensitive data](https://www.financedigest.com/the-benefits-of-big-data-how-to-convince-your-cfo.html "THE BENEFITS OF BIG DATA – HOW TO CONVINCE YOUR CFO")?

High Assurance SD-WAN introduces an overlay technology that specifically targets the segmentation and [protection of sensitive data within regulated organisations](https://www.financedigest.com/protect-your-organisation-from-fraud.html "Protect your organisation from fraud") by using crypto-segmentation to ensure its integrity and confidentiality. The overlay approach supports the regulatory demand for separation of duties: the network team can configure the SD-WAN, while the data [protection team uses fine-grained policies to define the way](https://www.financedigest.com/5-ways-to-protect-your-company-from-cyber-security-threats.html "5 Ways to Protect Your Company From Cyber Security Threats") data is handled across the network with ownership linked to specific encryption keys. The underlying network has no visibility of either the [data or its classification nor is it impacted](https://www.financedigest.com/dollar-skids-after-soft-u-s-economic-data-impact-of-opec-cuts-fades.html "Dollar skids after soft U.S. economic data; impact of OPEC+ cuts fades") in terms of performance of operational visibility.

Critically, it provides an organisation with [control over the assurance of its data](https://www.financedigest.com/dollar-buoyant-as-robust-u-s-data-keep-fed-hawks-in-control.html "Dollar buoyant as robust U.S. data keep Fed hawks in control"). With High Assurance SD-WAN, organisations no longer have to entrust the ITSP with responsibility for data assurance. Whether the network is public or private, trusted or untrusted, is irrelevant: the organisation’s [data protection team simply needs to define the policy and maintain ownership of the cryptographic keys](https://www.financedigest.com/sterling-edges-lower-ahead-of-key-data.html "Sterling edges lower ahead of key data"), resulting in the confidence that data is always protected wherever it goes.

**Conclusion**

There remains a massive disconnect between the current focus of security postures and the reality of the risk exposure. Yet, [organisations cannot afford to embrace](https://www.financedigest.com/embracing-cloud-computing-how-and-why-organisations-are-set-to-invest-more-in-cloud-computing-in-2023.html "Embracing Cloud Computing: How and why organisations are set to invest more in cloud computing in 2023") the flexibility and business benefits of SD-WAN without considering data assurance. They can no longer afford to hand over responsibility for implementing and delivering their security posture. A mindset shift is now imperative. The concepts of ‘security’ and ‘assurance’ have been confused and misused for decades.

It is only once the responsibility for data assurance is understood by all parties – MSPs and ITSPs included – that the correct steps will be taken to maximise the power of SD-WAN to accelerate business change while mitigating the risk down to the lowest acceptable level.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

