Recently we explained why it is important to automate PGP encryption, and how a good managed file transfer solution like Diplomat MFT can handle the job reliably no matter how extensive your information supply chain is (or becomes). But there’s another side to the PGP encryption automation coin, and that is the need to also automate PGP decryption.
What is PGP Decryption and Why does it Matter?
Why is PGP decryption important? Your MFT solution is not a one-way street; it receives files as well as sends them, and so having the means to quickly, efficiently, and reliably automate PGP decryption is just as necessary for inbound files as encryption is for outbound files.
Without decryption those incoming files would be unreadable and useless. And a reliance on manual decryption or command line scripts that are managed in-house could create problems that disrupt productivity. Here are a few scenarios:
- Encryption keys expire without notice and a downstream process breaks because it is unable to read a required file.
- A key holder leaves the organization or is unavailable at a critical time and their private key/passcode isn’t escrowed.
- Staff can’t keep up with demand for decryption as information supply chains grow creating a backlog of files
- Transport layer security (TLS) errors due to mismatched systems between the organization and its endpoints, or internally between departments.
When you use your MFT solution to automate PGP encryption, you are doing more than protecting those data files. You are also using it to automate management of encryption keys for you and your trading partners, track current PGP keys and revoke expired keys, make sure the right PGP keys are being used to decrypt the correct files, and verify all exchanges with your trading partners. And
These scenarios are more likely to happen when you rely on staff to handle decryption manually, or if you make assumptions about security and compliance. For example, a recent survey found that 83% of smaller medical practices believed that patient consent obviated the need for encryption. Not so! And we know you love your staff and count on them each day, but even the best of us has bad days, or are occasionally absent, leaving you with the B-team to try and pick up the slack. And when mistakes are made, that creates inefficiencies (at best) and could lead to a data breach and compliance violation (at worst).
Without a way to automate PGP decryption, you could encounter several problematic scenarios:
- Failure to update expired encryption keys: it is a best practice to retire/rotate encryption keys at least once a year. With PGP automation you can establish a regular cadence for key rotation based on your organization’s needs.
- Public key compromise: manual encryption key management increases the risk that unauthorized parties could gain access to your keys and allow them to read intercepted files and messages.
- Configuration errors: establishing PGP management scripts manually can result in configuration errors at the time of inception, or later as changes need to be made. And if there are errors in the process, they may not be noticed right away resulting in lost data, or sensitive files sent in the clear.
- Steep learning curve: learning how to use encryption tools may be difficult or inconvenient for non-technical staff, often leading them to find workarounds that avoid the essential step of PGP decryption and encryption. Automation minimizes that risk.
The Importance of PGP Key Management
In addition to streamlining workflows and ensuring file security and key rotation, other reasons an organization needs to automate PGP decryption align with (and are addressed by the same tools) PGP encryption automation. Top of the list is the role that decryption automation plays in regulatory compliance. In the event of a security incident, auditors looking into potential HIPAA, GLBA, and GDPR violations require proof that all encryption functions are working properly. This may be for your own protection should a violation be triggered by events in your downstream information supply chain.
Of course, you can eliminate all the issues associated with manual PGP decryption by investing in a full-featured managed file transfer solution that automates encryption and decryption. A fully automated MFT solution will tackle PGP decryption and encryption, including key management, without burdening administrative staff, virtually eliminating the risk of operator error.
Moving from Manual PGP Decryption to Automation with Managed File Transfer
The advantages of automating PGP decryption are measured in efficiency, cost savings, and improved security. From a simple dollars-and-cents perspective, estimate the number of hours you’d spend each year on manual workflows, multiply that number by the average hourly wage of the employees responsible for tending to the task—then double it to account for overall lost productivity. Consider disruptions associated with the mistakes that will be made, lost opportunities, reputational penalties and more. The value of a managed file transfer solution that automates the scope of PGP management—encryption, decryption, key rotation, and administration notifications—comes into sharp focus.
Our Diplomat MFT solution is recognized as a top PGP automation software product, handling the full scope of encryption management, including encryption, decryption, and encryption key management for all internal and external managed file transfer workflows.
Security that goes Beyond PGP Management
Designed as a managed file transfer workflow engine with a secure architecture, Diplomat MFT is built to be secure, and engineered to keep files secure. In addition to PGP automation, Diplomat MFT has a long list of state-of-the-art security features that help keep your data and your enterprise secure, including:
- Multifactor authentication and support for authentication applications
- Access control based on the principle of least privilege
- Flexible Roles & LDAP to ensure permissions are synchronized across the enterprise
- Integrated threat intelligence
- Support for post-quantum cryptographic algorithms
- Authorized recipient/destination confirmation
- Dataflow mapping with one-click report generation
- Process data capture for compliance audit reporting
- Workflow testing to ensure correct processes while in “dry run” mode
- Notifications to communication channels of choice (email, text, Slack, Teams, etc.).
And Diplomat MFT recently introduced the file transfer industry’s only MFT solution with PGP automation in its web transfer client, making it the most secure solution for enabling browser-based file transfers. Now you can enforce PGP encryption as a security standard across your entire information supply chain without asking smaller partners to incur extra technology or training costs.
If you are looking for an MFT solution that can also automate PGP decryption, encryption, and key management, try Diplomat MFT from Coviant Software. We’ve been trusted by leading healthcare, financial services, manufacturing, government, retail, and other organizations for more than 20 years of breach-free operation. Contact us today.
