enterprise security Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/enterprise-security/ Breaking news about the market for products, systems and services for the U.S. intelligence community Sun, 01 Feb 2026 22:24:21 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg enterprise security Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/enterprise-security/ 32 32 59882712 Security at the Enterprise Edge: Top Five Concerns https://intelligencecommunitynews.com/ic-insiders-security-at-the-enterprise-edge-top-five-concerns/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-security-at-the-enterprise-edge-top-five-concerns Sun, 01 Feb 2026 22:23:27 +0000 https://intelligencecommunitynews.com/?p=43755 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies As digital transformation continues...

The post Security at the Enterprise Edge: Top Five Concerns appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

As digital transformation continues driving change in federal agencies’ operating environments, the need for edge-level data protection has never been greater. Cloud and edge environments are essentially becoming micro data centers, taking on many of the IT core infrastructure characteristics formerly reserved for large HQ facilities. Bolstered by renewed interest in the  Modernizing Government Technology Reform Act, there has been a rise in core-level IT capabilities at the network edge government-wide.

This interest, however, introduces some challenges for extending core-level security to edge environments. For example, solutions for these edge environments may be constrained by specific, size, weight and power demands, and may require more elaborate data protection technology.

When developing an ecosystem to protect data at the edge, it’s important to consider several key principles, namely size constraints, the threat of hostile access, managing cryptographic keys, controlling access, protecting mission-critical data in transit, and complying with regulatory requirements.

Right-sizing edge solutions to defend data access

The government’s size, weight and power (SWaP) requirements for equipment in tactical areas are very specific. That, along with the extreme conditions in the physical environment at the network edge, creates demands on both durability and compactness in edge security solutions.

Add to these demands the need for data security in the event of equipment being taken by  other parties during conflict and you begin to understand the scope and complexity of edge network technological capabilities.

Edge equipment must come with a cryptographic erase solution that protects encrypted data. In fact, the military generally follows NIST policies for the destruction of physical media after a sanitation process. This process typically requires overwriting drives multiple times to ensure data is properly erased.

To simplify this process somewhat, data encryption keys can be erased or destroyed, obviating the need to sanitize the storage drive itself. The data itself remains encrypted and inaccessible, no matter who might control the physical equipment.

These simpler types of protective measures are essential for edge products because users at the edge may not have as much experience with data security measures as their counterparts in headquarters data centers. Default configurations must be secure and easy to understand.

Also, keep in mind that edge systems are also susceptible to connectivity issues. Consequently, such systems must be able to store and secure data locally, sending new or updated data  back to the core or the cloud after the connection is restored. As an added concern, multiple connected units must be configurable at the enterprise level.

The importance of centralized key management

We wrote earlier about the usefulness of data encryption keys in limiting data access. Such keys are particularly important at the edge, where an organization’s IT security teams may need to manage multiple cryptographic keys and a variety of encryption solutions.

Unfortunately, native key management solutions are not typically interoperable. As a result,  system administrators often store cryptographic keys in the same location as encrypted data – which does not follow best practices for key management and  practically invites exploitation.

The answer here is to ensure centralized key management. By doing so, an organization has secure storage and backup of encryption keys. Access control policies are defined. Encryption tasks can be separated from key management tasks. The entire key lifecycle is more properly addressed – from key creation, rotation, backup and destruction. In edge environments, where keys can be susceptible to compromise, this approach is indispensable.

When deciding on appropriate cryptographic products, it’s important to look for solutions with hardware security modules (HSMs) as removable tokens. HSMs act as the root of trust for encryption solutions. These removeable tokens can be ideal in edge environments, because detachable tokens keep essential data safe, even in the most remote or hazardous locations. Without the root of trust, encryption keys remain secure on the edge device and are not accessible without the HSM token.

Control access with multi-factor authentication

With apps, services, and data in the cloud, accessed through devices at the edge, everyone becomes an outsider. That creates a genuine need to establish and enforce identity and access security policy safeguards for assets in the cloud, on-premises, and at the edge.

New threats and risks are heightened as operational requirements change, demanding a simple but scalable solution for authentication. Multi-factor authentication, therefore, is the most secure way to limit access to data and applications, particularly at the edge.

With multi-factor authentication at the edge, organizations can be assured of better access control across multiple environments. This is true no matter which devices are used, and whether data is maintained locally, on-premises, or in the cloud.

Protecting data in transit

The demand on high-speed wide-area networks has been pushed with cloud migration of data, global collaboration, and bandwidth requirements at the edge.

Huge amounts of data are traversing the network and consequently under constant threat. It is essential to encrypt everywhere – both data in motion and at rest.

Data in transit is best protected by network encryptors which allow people, organizations and locations to securely share information. Network encryptors protect data, video, voice, and metadata from eavesdropping, surveillance, and overt and covert interception which is critical at the edge.

Vendor agnostic interoperability is critically important for these solutions, to make it easier on network architecture and IT professionals. Also important is the flexibility to adapt to changing security and network requirements.

Security compliance policies and regulations

Compliance with security requirements is a critical part of minimizing vulnerability at the edge, where susceptibility to attack is considerably greater. To ensure compliance, enterprise-level security policies must be applied across all architecture, including the edge.

Organizations need to look for solutions that carry certifications from multiple organizations, including FIPS 140; the Commercial Solutions for Classified program, and the Committee on National Security Systems Memo #063-2017. The Department of Defense’s Information Network Approved Product List, which had been a repository for such solutions, was sunset in December 2025. Cybersecurity requirements are in the process of transitioning to the DISA RME Vendor Security Technical Implementation Guides (STIG) program.

The challenge of building an IT infrastructure with hardened security that extends to the very edge can seem daunting. By considering these five aspects, it will become significantly easier to develop a system that appropriately controls access and protects data at rest and in transit – from the core to the cloud to the edge.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

 

The post Security at the Enterprise Edge: Top Five Concerns appeared first on Intelligence Community News.

]]>
43755
DIA to host DESO Industry Day https://intelligencecommunitynews.com/dia-to-host-deso-industry-day/?utm_source=rss&utm_medium=rss&utm_campaign=dia-to-host-deso-industry-day Thu, 20 Feb 2025 14:51:53 +0000 https://intelligencecommunitynews.com/?p=41017 On February 19, the Defense Intelligence Agency (DIA) released information for its upcoming Enterprise Security and Operation (DESO) Indefinite-Delivery/indefinite-Quantity (IDIQ)...

The post DIA to host DESO Industry Day appeared first on Intelligence Community News.

]]>
On February 19, the Defense Intelligence Agency (DIA) released information for its upcoming Enterprise Security and Operation (DESO) Indefinite-Delivery/indefinite-Quantity (IDIQ) Pre-Solicitation/Technical Exchange Meeting with Industry Day. Responses are due by 4:00 p.m. Eastern on February 27.

The Defense Intelligence Agency (DIA) will host a pre-solicitation Industry Day Meeting for the DIA Enterprise Security and Operation IDIQ.

The Industry Day will be held 4-5 March 2025, begining at 8:00a.m. (EST) each day, at the Defense Intelligence Analysis Center (DIAC), at Joint Base Anacostia Boiling (JBAB) in Washington, DC.

Review the DIA DESO Industry Day information.

Source: SAM

The right opportunity can be worth millions. Don’t miss out on the latest IC-focused RFI, BAA, industry day, and RFP information – subscribe to IC News today.

The post DIA to host DESO Industry Day appeared first on Intelligence Community News.

]]>
41017
Enterprise Edge Security: A Strategy Checklist https://intelligencecommunitynews.com/ic-insiders-enterprise-edge-security-a-strategy-checklist/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-enterprise-edge-security-a-strategy-checklist Mon, 06 Mar 2023 13:57:39 +0000 https://intelligencecommunitynews.com/?p=34895 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies In the past, it...

The post Enterprise Edge Security: A Strategy Checklist appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

In the past, it may have been enough to think about data protection at the core or strategic level. Today, however, defense, intelligence and civilian agencies must extend their data protection strategies all the way to the tactical edge.

The reason for this change in strategy is the way federal agencies’ operating environments are being influenced by digital transformation. An agency’s IT core infrastructure capabilities, previously maintained in headquarters data centers, now are available in cloud and edge environments, effectively making them micro data centers.

Take the Department of Defense, for example. Command posts, mobile command centers – even vehicles, ships and planes – now have core-level IT capabilities. Similarly, at the civilian level, micro data centers exist at the edge, in embassies, hospitals, and branch or field offices.

There are numerous core-level security concerns at these edge environments, ranging from weather conditions to bandwidth issues. Solutions to these edge environment concerns have specific size, weight and power constraints, depending on the environment. Additionally, technology to protect data is necessary for edge environments in case that equipment is compromised.

It’s important, therefore, to create an effective ecosystem that can protect data at the edge. There are several key considerations to ensure a successful strategy. Let’s take a closer look.

Size concerns and protection from hostile access. The physical environment is a serious aspect for edge security. The government maintains specific size, weight and power (SWaP) requirements for equipment in tactical areas, as well as how durable it is in extreme conditions. And because there is also the reality that equipment may fall into the wrong hands, data security strategies for such circumstances is essential. NIST has sanitation policies, emulated in military standards, that address destruction of physical media after overwriting drives multiple times.

Ideally, edge security products should come with a cryptographic erase solution to protect encrypted data. Cryptographic erase enables data encryption keys, used to encrypt/decrypt data, to be erased or destroyed without destroying the storage drive. Regardless of who controls the physical equipment, data will remain encrypted and inaccessible.

Because personnel at the edge may lack experience with data security, edge products must be simple to use, with secure, easy to understand default configurations. And because systems at the edge may potentially suffer connectivity issues, they must be able to store and secure data locally. That data can be sent back to the core once the connection is restored. Units must be configurable at both the enterprise and local level. When connecting multiple units, these units must be manageable and configurable at the enterprise level.

Cryptographic key management. Data encryption at the edge can be difficult for an organization’s IT security teams. These teams must manage multiple cryptographic keys for many different encryption solutions with native key management capabilities. Native key management solutions are usually not interoperable, however; this means that system administrators may end up storing cryptographic keys and encrypted data in the same place.

Because of behaviors like this, centralized key management solutions are essential. Centralized key management solutions allow for secure storage and backup of encryption keys. Access control policies also are better defined and encryption tasks can be separated from key management tasks. These key management solutions provide key lifecycle management- from creation, rotation, backup, and destruction. These tasks are vital at the edge where keys are particularly vulnerable.

Ideally, organizations should look for cryptographic key management solutions that offer hardware security modules as removable tokens. Such products are ideal for the edge, because removing a detachable token keeps encrypted data safe, no matter how remote or hazardous the tactical environment may be.

Authentication and access control. New threats and risks can be worse at the edge because of shifting operational requirements. That calls for simple, scalable solutions for authentication.

The most secure way to limit access to data and applications is through multi-factor authentication. At the edge, it’s important to deploy multi-factor authentication across multiple environments. This will secure access no matter which devices are used, or whether data is maintained locally, on-premises, or in the cloud.

Protection for mission-critical data in transit. Cloud data migration, global collaboration, and bandwidth requirements at the edge have all made much greater demands on high-speed wide-area networks. Data moving across the network is under constant threat, so encrypt everywhere, for both data in motion and at rest.

In transit, data is best protected by network encryptors that enable people, organizations and locations to securely share information. Such network encryptors protect data, video, voice, and metadata from eavesdropping, surveillance, and overt and covert interception. At the edge, that level of encryption is critical.

To make it easier on network architecture and IT professionals, it is critically important to look for solutions with vendor-agnostic interoperability. Flexibility is also important, because as we’ve previously noted, security and network requirements are continually changing in edge environments.

Compliance. IT environments become increasingly susceptible to attack as they move out to the edge. Minimizing vulnerability means ensuring compliance with security requirements. To ensure compliance, the same enterprise-level security policies must be used across the architecture. Consequently, look for solutions with certifications from multiple organizations. These certifications include FIPS 140, the Commercial Solutions for Classified program, Committee on National Security Systems Memo #063-2017, and Department of Defense’s Information Network Approved Product List.

Building an IT infrastructure with hardened security that extends to the very edge might seem like an almost insurmountable challenge. But if you take these considerations into account, you’ll find it much easier to develop a system with appropriate access controls – one that protects data at rest and in transit, from the core to the cloud to the edge.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

The post Enterprise Edge Security: A Strategy Checklist appeared first on Intelligence Community News.

]]>
34895