One crucial line of defense for FinTech is encryption, which is similarly important to conventional finance. Encryption ensures the protection of credentials and other data exchanged between FinTech platforms and users. It hinders cybercriminals from sniffing sensitive information transmitted during account logins and transactions.
One specific type of encryption that is particularly useful for FinTech is application-level encryption (ALE). As the phrase implies, it is about encrypting data within the application, which tends to be more secure compared to at-rest and transport encrypting when it comes to undertaking financial transactions. Wias Issa, CEO of a company specializing in encryption for FinTech, calls it the future of Fintech.
FinTech companies need to start securing their customer data at the application layer of their technology stack, says Issa, who argues that ALE compels the embedding of security into the development cycle itself instead of relying on security assumptions made at the storage layer. Your organization needs to adopt a security-as-code’ culture and bring security teams into the development process much earlier to secure sensitive data at the application layer, Issa adds.
Do these points make sense across the FinTech sector, or is it only applicable to specific instances? Discussed below are the most important reasons FinTech companies, in general, should already start embracing ALE.
Augmenting the security afforded
by TLS
Encryption is not a one-size-fits-all security technology. Different strategies for data encryption have different applications where they can deliver their best or optimum benefits. Organizations use transport layer security (TLS), for example, but it may not be enough when it comes to securing FinTech systems.
While the TLS protocol, which uses the elliptic curve cryptography (ECC) algorithm, protects the data exchanged between different components of an organization’s infrastructure, this may not be enough to secure financial transactions under new platforms. TLS provides protection from eavesdropping between services, but it is limited to that. To achieve end-to-end encryption, it is advisable to use ALE.
Application-level encryption protects data on all underlying layers. It is designed to encrypt data at all layers of storage and sometimes during transit. As such, it can address the vulnerabilities that emerge out of expired TLS certificates. Encryption on the application level also prevents data leaks that may be caused by outdated TLS settings.
Non-reliance on infrastructure
settings or database configurations
As mentioned, ALE entails encryption that happens on the application side of data usage, which means that data is encrypted before it is transmitted. The data that goes through all services or is stored in a database is encrypted and is only decrypted by another application that will use it.
In other words, application-level encryption does not make organizations dependent on the security settings implemented in infrastructure or the security configurations of a database. It supplements the protection provided by TLS and data-at-rest encryption without creating issues like inefficiencies or excessive resource utilization. As current usage demonstrates, ALE can co-exist with these security controls harmoniously.
Why is it necessary for FinTech to do away with the dependence on database or infrastructure settings? FinTech nowadays is often associated with financial decentralization. It would be counterintuitive if FinTech platforms or services are designed to be reliant on the configurations implemented in servers or the infrastructure of a FinTech service. Decentralized finance would be doomed if its security rests on centralized settings.
ALE alone does not create a trustless system, which is what many decentralized finance solutions are trying to achieve. However, it can serve an important role or be one of the components that enable the operation of trustless services.
Protection from most risks
affecting data
Another important advantage of application-level security is its inherent benefit of being effective against most data-related risks. It does not only work in preventing credential sniffing or the hijacking of data being transmitted across services. It also protects enterprise data even in cases of physical disk access, data leakages at the databases themselves, firewall penetration, attacks through a rogue system or database administrator, as well as data theft through logs, automated backups, snapshots, and the exchange of data between application components.
ALE is notably better at providing security against insider attacks. Bad actors may obtain the data storage disks or have privileged access to the databases, but they will not have any use of the contents without the ability to decrypt the data crucial to conducting FinTech transactions.
Moreover, ALE is useful in instituting the principle of least privilege, which calls for a system that only grants access to the encryption keys or the data itself if such access is critical for the completion of a task. This is one of the most effective ways to secure data from various forms of attacks. As Issa asserts, the best way to truly protect your customers‘ information and follow the principle of least privilege is to encrypt data on the application layer.
Collaboration between the app
development and security teams
Can the use of a particular type of encryption method compel the application development team and the security department of a company to work together? To some extent, this is what happens when organizations adopt application-layer encryption.
Developers and security teams are notorious for not having jibing interests. In a presentation at RSA Conference, cybersecurity expert Chris Romeo highlighted this dynamic that some may still find unusual. Developers dislike security and won’t always admit it, Romeo avers.
It is advantageous for FinTech organizations to employ application-level encryption because it creates a reason for some level of collaboration between developers and security teams at the early stage of the application or system development. Developers are not expected to be knowledgeable about security, nor are they required to integrate security policies into the development process. Some even say they dislike security altogether.
Organizations will have to bring in security experts to help in the process of embedding encryption into their apps or systems. Developers can proceed with putting an encryption solution into apps on their own, but as mentioned, they do not have the security expertise so they may end up making wrong choices. Some developers end up using a big-name encryption algorithm that turns out to be dated or not optimized for the purpose it is being used with.
Harder, but stronger
Application-level encryption is more difficult to implement compared to setting up TLS and other simpler methods of encryption. There are also risks of missteps in implementation that render it useless or even possibly create new vulnerabilities. However, the benefits easily outweigh the challenges.
ALE is more secure than the conventional encryption methods used by most organizations. It results in safer customer data, which is crucial for any FinTech service. It also helps in establishing trustless systems and more secure protocols especially when it comes to cloud systems and complex infrastructure.