internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It


  About Us l Contact Us l Privacy
Home News Business Software Hardware Online Marketing Web Management The Basics
Product Watch Buyer's Guide Small Business Essentials Online Forums Glossary Images Events

Search SBC

Search internet.com


Small Business Computing Product of the Year Awards
Winners Announced!


internet.commerce
Be a Commerce Partner
Rackmount LCD Monitor
PDA Phones & Cases
Promote Your Website
Promos and Premiums
GPS Devices
Promotional Golf
Calling Cards
Disney World Tickets
Online Shopping
Memory Upgrades
Prepaid Phone Card
Data Center Solutions
Holiday Gift Ideas
Build a Server Rack

Free Newsletters
Small Business Computing

Ecommerce Guide Daily

Webopedia

E-mail Offers

Newsletter Address Changes
Webopedia Glossary
Enter a Term:

internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

PDAs
PC Notebooks
Printers
Monitors

Get Started with Oracle on Windows DVD
Learn how Oracle gives you the power to grow by providing a scalable, easy-to-use platform for running your business at a price you can afford. Request your free copy of this DVD, containing Oracle Database 11g software, whitepapers, tutorials, etc. Register now! ;
Guide to Oracle 11g and Database Migration
Oracle Database 11g includes more features for self-management and automation, which makes it easier for customers to cost-effectively manage their data. Download this Internet.com eBook for an overview of some of the new features in 11g and for an overview of the issues you need to consider as you prepare for a database migration. ;
Innovate Faster with Oracle Database 11g
Read this in-depth analysis of 56 customers, which shows significant differences between the value software vendors Oracle and SAP deliver to midsize companies. ;
Oracle Business Intelligence Standard Edition One
Find out how Newport Beach, CA-based Mobilitie is shaking up the telecom industry by leveraging technology to provide an entirely different financial model for deploying, upgrading, and owning wireless and wireline network assets. ;
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Quickly implementing an ERP software solution can be of tremendous benefit; however, companies often struggle to balance the benefits of reducing implementation time and cost with the risks of an accelerated deployment. Read this white paper to learn about easy-to-follow best practices for achieving a successful accelerated implementation. ;
Making the Case for Oracle Database on Windows
Users benefit as vendors reduce enterprise complexity and deliver integration. ;



Hot Topics
Driving Business from Bloggers
Demystifying Search Engine Optimization: Part 2
Last Call: Vote Today!


Small Business Essentials
Networking Fundamentals
Be it wired or wireless, building a network can take your small business to new heights in Internet communications, real-time collaboration, webhosting and e-commerce — or simply be setup to connect a series of workstations with a shared printer. Learn how to leverage today's networking technologies at your small business.
[ more ]


Related Articles
E-mail Archiving is for Small Firms, Too
The UPS and Downs of Power Protection
Easy Storage for the Little Guy: Has the Time Come?


Is secure, available data a challenge? Symantec Online Backup can help with an easy to use, secure, web-based solution for your business. Sign up and get your first 30 days free.
News & Trends
Keep it Classified: E-mail Encryption for Small Business
By Drew Robb
June 5, 2007

It isn’t just the big boys that are under the gun on the subject of e-mail privacy; today the bull's-eye is on mid-sized companies. A vice president in Southern Commercial Bank, for example, accidentally included the private information of 40,000 customers in an unencrypted e-mail. The Federal Trade Commission investigated BJ's Wholesale Club for not encrypting data sent over the Internet. Petco experienced a similar violation, and Superior Mortgage suffered a probe for not encrypting Internet e-mails.

The companies listed above represent a shift in the emphasis of investigatory bodies and legislative attacks on the subject of privacy. While the Fortune 500 list contained most of the early targets, it’s the mid-market that now appears to be receiving most attention. Like large corporations, these mid-market players are rolling out security solutions to safeguard them from attack. Thus it’s only a matter of time before small businesses will be feeling the heat in this matter. And the price for getting it wrong could be staggering.

“To date over 54 million identities have been stolen and an estimated 19,000 more identities are stolen each day,” said Fred Moore, president of Horison Information Strategies. “Companies on average are spending over 1,500 hours per incident at a cost of $40,000 to $90,000 per victim.”

With regulators getting tough on privacy slip-ups, it makes sense for small businesses to protect sensitive data. As well as personal data, this includes financial information and other sensitive material. Further, some large companies will only do business with SMBs that comply with business partner agreements for protecting sensitive information.

“The bulk of transactions processing, negotiation and communication from small business to a larger partner is performed via e-mail,” said Ingrum Putz, director of Voltage Security Inc. “Being ready with an e-mail encryption system will facilitate partnership setups.”

Encryption Basics
The word “encryption” comes from “kruptos”, the Greek word for “hidden.” The idea is to convert words into a code that cannot be understood until it is decrypted.

Encryption can be done at various points. Many laptops these days have a feature that allows the hard drive to be encrypted. Even if it is stolen, an outsider won’t be able to read see what’s inside. Storage gear also sometimes has encryption features added and even tape backup gear is now coming onto the market with this feature.

For small business, though, e-mail encryption probably makes the most sense. If the company already has an e-mail server, encryption software or a security appliance can provide an additional layer of security. Any information sent into --or out of -- the company is encoded.

And according to the Gartner analyst group, that’s a very good thing. Gartner figures reveal that 84 percent of high-cost security incidents occur when insiders send confidential data outside the company without properly securing the data.

Obviously, there is no need to encrypt everything. The majority of e-mail communications such as inviting a customer to visit, scheduling a meeting, marketing invitations, sales requests, product news, non-sensitive business communications, HR updates, travel plans and internal communications that stay within the company need not be encrypted. But there are messages that merit protection.

“Standard e-mail has the security of a postcard,” says Putz. “Any e-mail should be encrypted if the contents are sensitive in nature. This can mean that the e-mail contains intellectual property, legal information or personally identifiable information such as health information, social security numbers or trade secrets.”

Encryption Methodologies
There are several different approaches to e-mail security. Big companies sometimes utilize digital certificate-based e-mail encryption. This requires understanding the intricacies of certificates or “electronic keys” which are used by the sender and recipient to keep contents free from prying eyes.

“These electronic keys are very similar to numbers on a number lock -- a string of characters used to lock the e-mail,” said Sundar Raghavan, vice president of solutions marketing at Postini Inc., a communications security company. “Once locked, the data looks like a set of garbled characters until it is unlocked. The sender and receiver share a secret electronic key to lock and unlock the messages.”

Most e-mail server-based encryption uses this digital certificate technology. Popular standards such as Transport Layer Security (TLS) or Secure Multipurpose Internet Mail Extensions (S/MIME) use these methods to add encryption to the transmission of e-mail.

Digital certificates, though, can be complex, management intensive and can sometimes exert a drag on server performance. “Encryption and decryption are processor-intensive activities that can slow access to stored data,” warned Moore.

The good news is that some systems are coming on the market that could be classified as small business-friendly. They utilize a variety of tactics to reduce the complexity of key management. Postini provides such technology.

Another methodology is secure Web mail i.e, a link is sent to a message that's kept on a central secure messaging server. The problem for small businesses, however, is that secure Web mail systems require you to maintain multiple e-mail inboxes, limit the ability to select how long messages can be stored and can also require extensive back-end storage and administration.

Yet another possibility is an e-mail encryption appliance. Such appliances eliminate the management complexity. You plug them in to a mail server where they encrypt and decrypt e-mail automatically. Some also add further safeguards against viruses or Web-content filtering.

Voltage Security is an advocate of a hybrid approach, which might be termed “push” encryption e-mail. With Voltage Secure-mail, the e-mail is delivered encrypted directly to the recipient’s inbox. The person’s own e-mail identity is used as the private key in order to protect messages sent from his or her regular Outlook inbox. Further, recipients don’t need anything to read and reply securely; you don't need any special tech knowledge or make any changes to e-mails settings The price is less than $8/month or $95 dollars per person per year.

PGP Corporation also offers small businesses a hosted solution known as PGP Desktop E-mail 9.6 for Windows. “PGP Desktop E-mail is a comprehensive e-mail content security solution that protects confidential information contained in electronic mail from being breached while in motion and at rest on e-mail servers,” said Than Tran, product marketing manager at PGP.

“It provides companies with an automated, transparent set of encryption solutions to consistently secure confidential information in e-mail. With PGP Desktop E-mail, small organizations can protect the business and meet partner and regulatory mandates for information security and privacy,” said Tran. A perpetual license costs $149.

Postini, meanwhile, provides two on-demand encryption services for SMBs. These are available on-demand, with no need to purchase hardware, software, installation, integration or upgrades. Its Transport Encryption Service provides encryption between a company’s e-mail server and those used by others. It employs TLS to automatically encrypt e-mail connections. List pricing starts at $2,500.

”E-mail messages are sent from your business to Postini's secure data centers over an encrypted connection, where messages can be scanned for content to comply with your messaging policies,” said Raghavan. “The messages are then delivered in real-time over an encrypted connection to the recipient's mail server.”

Postini’s Message Encryption, on the other hand, provides encryption at the message level for e-mails to individuals. This is most applicable for companies that communicate sensitive financial and personal information to customers and need a simple mechanism to encrypt those e-mail messages. E-mails you mark as "Confidential" or "Sensitive" are routed to Postini's data centers to be encrypted and sent to the recipient. Recipients retrieve messages using a simple, secure, Web-based mail interface or directly from their desktop e-mail program. Pricing starts at $77 per person.

For smaller businesses, consultants and other sole proprietors out there, PKWare offers SecureZip Standard Version 11 for free. SecureZIP combines ZIP data compression with pass-phrase or certificate-based encryption and digital signature capabilities. It's designed to protect files on hard drives, laptops and portable storage devices, encrypt any e-mail attachments and – in Outlook only – encrypt the content in the body of the e-mail too. PKWare also sells an enterprise version for $49.95 per person.

Get Ready
Anyone who thinks that e-mail encryption has nothing to do with small business needs to look at the numbers. Postini processes two billion messages a day. Based on its traffic analyses, about 15 percent of all traffic is currently encrypted and that number is steadily growing.

More and more SMB customers are choosing to deploy on-demand solutions for encryption,” said Raghavan. “SMBs cannot afford to take the risk being in violation of encryption laws.”

Drew Robb is a Los Angeles-based freelancer specializing in technology and engineering. Originally from Scotland, he graduated with a degree in geology from Glasgow's Strathclyde University. In recent years he has authored hundreds of articles as well as the book, Server Disk Management by CRC Press.

Do you have a comment or question about this article or other small business topics in general? Speak out in the SmallBusinessComputing.com Forums. Join the discussion today!

Tools:
Add smallbusinesscomputing.com to your favorites
Add smallbusinesscomputing.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed

eBook: Evaluating Software as a Service for Your Business. Sponsored by Webroot
Increase your reach with unlimited Webinars for one low rate. Try GoToWebinar FREE.
Five Trends for Application Development. Download Your Complimentary Report. Exclusive. Act Now.
Flash Demo: Learn how IBM Information Server Blade is easy to manage, highly scalable and efficient.
Learn Tools & Techniques to Justify and Fund Your IT Investments. Download Complimentary Report Now!



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES