Ensuring Secure Data Sharing in Cloud Data Stores

5 Feb, 2025

Written by: Daniel Brudner (CISSP, CISA), Vice President Solution Engineering in North America at SecuPi

Organizations often act as custodians of sensitive information, leveraging cloud data stores like Snowflake to efficiently manage and share data with institutions. However, sharing data securely with other institutions using the same cloud data store presents unique challenges. It is crucial to ensure that data is protected, preventing accidental access by unauthorized parties and securing data even if it is mistakenly shared. Additionally, custodians must know and control who accesses the shared data to maintain strict security oversight for auditing purposes. This blog post explores the critical measures and best practices for ensuring secure data sharing in cloud data stores.

The Challenges of Secure Data Sharing

When an organization acting as a data custodian needs to share data with external institutions, they must ensure the right data is shared with the right institution and that only authorized people can access the data they are allowed to access.

In modern cloud environments, when organizations and institutions are using the same cloud data store such as Snowflake, sharing data is very easy but poses some challenges.

The challenges are that custodians need to make sure they share the data with the right institution and that one institution cannot accidentally access another’s data. Additionally, the custodian needs to control and know who accesses the shared data for auditing purposes. This risk is exacerbated when data sharing is necessary for collaboration or business operations. Ensuring that only the intended recipient can access shared data is paramount to maintaining data security and regulatory compliance.

The Solution: Encrypted Data Sharing with Transparent Gateways

To address these challenges, organizations need to implement robust encryption and access control mechanisms. Here’s how:

  • Data Encryption – Encrypt Shared Data: The custodian organization should encrypt the data before sharing it. This encryption should be done in such a way that only the target institution can decrypt and access the data. This ensures that even if the data is mistakenly shared with the wrong party, it remains inaccessible without the proper decryption keys.
  • Dedicated Transparent Gateway – Controlled Access: Provide the relevant institution access to the shared data through a dedicated transparent gateway. This gateway can decrypt the data only for individuals from the intended organization, ensuring that unauthorized users cannot access the information even if they have the data.
  • Access Control and Monitoring – Know and Control Who Accesses the Data: Custodian organizations must have mechanisms to monitor and control who accesses the shared data. Implementing strict access control policies and real-time monitoring ensures that only authorized individuals can access the data. Detailed logging and audit trails provide visibility into data access, allowing custodians to track and review who accessed the data and when, thus maintaining a secure and compliant data-sharing environment.

By implementing these measures, organizations can significantly enhance the security of their data sharing processes, ensuring that sensitive information always remains protected.

Comprehensive Data Security Platform

A comprehensive data security platform supports secure data sharing and provides end-to-end protection for sensitive information. Below are the key components of such a platform:

  • Data Classification – Data classification involves identifying and categorizing data based on its sensitivity and criticality. By classifying data, organizations can apply appropriate security measures and ensure compliance with regulations.
  • Data Access Monitoring – Data Access Monitoring provides real-time visibility into data interactions, helping organizations detect and respond to suspicious activities. It tracks access patterns, identify anomalies, and generate alerts for potential security incidents.
  • Fine-grained Access Control with Attribute Based Access Control (ABAC) – ABAC enhances data security by enforcing access policies based on user attributes and data characteristics. This ensures that only authorized personnel can access or manipulate sensitive data. Access control to data can be coarse from who can access the data in general to fine grain such as:

– Row-level Access Control: Restricts access to specific rows within a table, ensuring that users can only view or modify rows that match their attributes. This minimizes the risk of unauthorized data exposure.

– Column-level Access Control: Restricts access to specific columns within a table, ensuring that users see only the data necessary for their roles.

– Cell-level Access Control: Provides the highest level of data protection by enabling masking or encryption of individual cells based on specific criteria.

– High-Level Data De-Identification with the Right De-Identification Method

– High-level data de-identification techniques remove or obfuscate personal identifiers, making it difficult to trace data back to individuals. This step is essential for compliance with regulations such as GDPR and CCPA.

– Type-safe Masking and Encryption: Ensures that masked data retains its original format and type, supporting compliance with regulations such as HIPAA and Safe Harbor.

– Format-preserving Masking and Encryption: De-identify entire cells while preserving their format, ensuring compatibility with existing systems and workflows.

– Bucketing: Converts multiple different values into one value, helping comply with regulatory requirements by protecting individual identities while enabling aggregate data analysis.

The Path to Secure Data Sharing in the Cloud

Ensuring secure data sharing in cloud data stores is critical for protecting sensitive information and maintaining regulatory compliance. By implementing encrypted data sharing, controlled access through dedicated transparent gateways, and strict access monitoring, organizations can safeguard their data even in complex sharing scenarios. Additionally, a comprehensive data security platform that includes features like data classification, access monitoring, and granular access controls further enhances data protection. Investing in such a platform not only enhances security but also builds trust with customers and stakeholders, ensuring the integrity and confidentiality of critical data.

 

About the Author
Daniel Brudner is the Vice President of Solution Engineering for North America at SecuPi, The Data Security Platform Software Company, where he leads a high-performing team dedicated to securing data through innovative solutions. With over 25 years of experience in information technology and cybersecurity, Daniel holds Degrees in Computer Science and prestigious certifications such as CISSP, CISA and cloud technologies. His expertise spans data security, identity and access management, cybersecurity, Zero Trust Architecture, cloud technologies and artificial Intelligence.

Throughout his career, Daniel has been instrumental in guiding Fortune 1000 organizations to enhance their security postures by leveraging cutting-edge technologies, best practices, and Zero Trust principles. His ability to align technical solutions with business needs has helped organizations achieve scalable and secure operations.

Daniel is an extreme sports adventurer who enjoys hiking to remote and challenging destinations, mountain biking, scuba diving, canyoneering, and kayaking. His adventurous spirit mirrors his innovative and fearless approach to solving complex problems in the cybersecurity world.

Apply for this Job

    Or send your resume at text@secupi.com
    Thank for you applying
    We will be in touch shortly.