The Tukwila, Wash.-based credit union encrypts all its data written to tape using Decru Inc.'s DataFort T-Series storage security appliances, to protect against theft or unauthorized access, regardless of where its tapes are stored."There's been a heightened sense of attention in this area because of a lot of security breaches … and there may be future legislation," said Daniel Chow, IT systems and security engineer at BECU. About a year ago, the company took a look at disk-based storage encryption, but quickly realized the real vulnerability in its system was around data leaving the company's sites on backup tapes. BECU employs Iron Mountain Inc. to truck its tapes off site for long-term archival, and 30 different express courier services to transport tapes from four major sites to BECU's disaster recovery site.
During the installation process, BECU ran into some problems hooking up the DataFort appliances to its HP equipment. The DataFort did not recognize HP's Fibre Channel to SCSI bridge, but this was eventually resolved. "The SAN environment is very complicated already, but we had help from Decru's engineers to get it working," Chow said. He admits the product is expensive, but claims his company is willing to spend the money to preserve the company's name. "We would be unable to operate without the trust of our customers," he said. Decru pricing starts at around $20,000 for a single appliance.Chow said he is hoping Decru will add support for WORM and optical platters to its product and would like to see it tied in to an ILM offering so that they are able to move data around more effectively. "Decru needs more vendor support and forums of user groups where we can talk to other users," he added. Jon Oltsik, senior analyst with Enterprise Strategy Group, noted that BECU is one of the first financial institutions to speak publicly about its encryption process, but that banks everywhere are either evaluating this technology or deploying it. "Given the insecurity of the entire off-site tape rotation process, tape encryption should be a minimum requirement for all financial institutions," he said. Click here for more of today's news.