introduction to email encryption for google apps

16
Stop the Leak What Google Apps Admins Need to Know About Email Encryption Will Ackerly Co-Founder & CTO

Upload: charles-gold

Post on 08-Jun-2015

573 views

Category:

Technology


0 download

DESCRIPTION

This presentation provides a brief overview of alternatives email encryption for Google Apps. Presented at GCON 2014, Virtru founder Will Ackerly reviews the emerging need to secure email and offers an overview of alternative approaches.

TRANSCRIPT

Page 1: Introduction to Email Encryption for Google Apps

Stop the LeakWhat Google Apps Admins Need to

Know About Email Encryption

Will Ackerly

Co-Founder & CTO

Page 2: Introduction to Email Encryption for Google Apps

Introduction

Pulling Back the Covers: What You Need to Know

Alternative Approaches to Encryption

Virtru Demo

Page 3: Introduction to Email Encryption for Google Apps

Point to Point (SSL)• Nice if your provider uses it, but can’t guarantee your recipient

uses it

• Just because there is a green lock doesn’t mean it’s a secure communication

What Is Email Encryption? Point-to-Point

EncryptedContent

Sender RecipientMail

ClientGoogle Server

Encrypted

ContentUnencrypte

dContent

Unencrypted

Content

Unencrypted

Content

Unencrypted

Content

Recipient’sMail Server

Mail Client

EncryptedPipe

? ?

May be Encrypted

May be Encrypted

Page 4: Introduction to Email Encryption for Google Apps

Zix and Google Apps Message Encryption• Helps enforce point-to-point encryption

• Requires new account on a new system with distinct user name/password

What Is Email Encryption? Portal-based

Sender

Encrypted

Content

Mail Client

Plain TextContent

Google Server

Plain TextContent

Plain TextContent

GAME Content Server

Encrypted

Content

Mail Client

GAME Portal

Plain TextContent

Encrypted

Content Link to Portal

Recipient1st Interaction

Recipient2nd Interaction

Register Accountor Login

Page 5: Introduction to Email Encryption for Google Apps

Virtru, PGP, S/MIME• Protection at rest and protection in transit• Protects against compromised servers or lost clients• Recipient must have access to encryption keys

What Is Email Encryption? End-to-End

Sender Recipient(Only Interaction)

Encrypted

Content

Stays Encrypted the Entire Time

Encrypted

Content

Encrypted

Content

Mail Client

EncryptedContent

Google Server

EncryptedContent

EncryptedContent

EncryptedContent

Page 6: Introduction to Email Encryption for Google Apps

6

Tin Foil Hat Not Required

encryption becoming mainstream

Page 7: Introduction to Email Encryption for Google Apps

7Mainstream Encryption Requirements

Corporate Risk

CybersecurityRegulations

Page 8: Introduction to Email Encryption for Google Apps

8Regulatory Requirements

Doctor

Specialist

Hospital / Clinic

Health Records/PII Patient

Page 9: Introduction to Email Encryption for Google Apps

9Information Leaks

Customer List

Competitor

Sales [email protected]

Sales [email protected]

Page 10: Introduction to Email Encryption for Google Apps

10

Threat is that unprotected copies proliferate• Senders “Sent Items” on all your computers• Recipients “Inbox” on all their computers• Sender ISP/Company Servers• Recipient ISP/Company Servers

Hacking and Surveillance

Identity Thief

Hacker

Sender Recipient

Cyber Criminal

Page 11: Introduction to Email Encryption for Google Apps

11Doesn’t Google Already do This for Me?

Page 12: Introduction to Email Encryption for Google Apps

12What Capabilities Are Required

Super Easy To Use

Anyone Must Be Able to Read

Give Senders Control of their Content

Page 13: Introduction to Email Encryption for Google Apps

13

Virtru: Simple Email Privacy

As easy as Gmail

Protects emails and files

Send to anyone anywhere

Revoke, expire, control forwards

Control for Google Apps admins

Page 14: Introduction to Email Encryption for Google Apps

DEMO OF VIRTRU FOR BUSINESS

Page 15: Introduction to Email Encryption for Google Apps

15What to do next

Try Virtru for Yourself

www.virtru.com

Try Virtru for Your Company

www.virtru.com/business

Page 16: Introduction to Email Encryption for Google Apps

16

Simple Email Privacy

Sender Recipient(Only Interaction)

MailClient

MailClientEncrypted

Content

Google SSL Connection

GoogleServer

Virtru Key Server

EncryptedContent

KeyKey