IBM today launched a crypto-key management security service across on-premises and multicloud environments that is built on its “Keep Your Own Key” capability. 

The company’s recent reports found that organizations are using more than eight cloud environments on average, with cybercriminals in tow looking to access data residing across multicloud environments. 

Enterprises “want to secure the data, protect the data, ultimately it comes down to data encryption,” Nataraj Nagaratnam, IBM’s CTO of cloud security, told SDxCentral. 

IBM has offered a single-tenant key management service including the Keep Your Own Key encryption technology, which allows customers to have exclusive key control, as opposed to the cloud provider controlling the keys. The newly launched Unified Key Orchestrator builds on this by allowing users to manage their keys across varies environments with a single pane of glass. 

It provides “the key management service capability that now customers can manage keys on multiple instances in Azure, Amazon, or even … on premise,” Nagaratnam explained. “​​Given key management is foundational to compliance, so this way, they can accelerate compliance.” 

IBM offers this key management capability as a service, so customers don’t have to invest in operational expenses and skills, he claims. “Consuming it as a service helps them to focus on doing what they need to do with innovation and let us do the heavy lifting of managing and providing these capabilities as a service that they can integrate with APIs and automate faster.”

The Unified Key Orchestrator supports Amazon Web Services (AWS), Microsoft Azure, IBM Cloud, and on-premise environments with its Key Protect on Satellite service out of the box. IBM plans to expand the support to other cloud providers and software-as-a-service (SaaS) vendors in the future, Nagaratnam said. 

Don’t Even Trust Your Cloud Providers

IBM’s key management services are in line with its data-centric zero-trust approach, Nagaratnam noted. 

From a zero-trust perspective, technologies like Keep Your Own Key enable the complete control of the data, he added. “You don't have to trust anybody, you have complete control of the keys. … Don't even trust the cloud provider.”

Plus, the Unified Key Orchestrator allows consistent policies and controls across different environments, key access governance and segregation services, and access logging capabilities with IBM’s activity tracker, which conform with the zero-trust philosophy, Nagaratnam said.

When dealing with sensitive and confidential data, organizations need a higher level of technical assurance to comply with more stringent regulations and address more cyber-threat challenges, he pointed out. 

“So everything that we are doing with broader confidential computing, initiatives including Keep Your Own Key and Unified Key Orchestrator, we continue to look forward to leading this space with a differentiation around data security,” Nagaratnam concluded.