Recover from Disasters

Recover from Disasters

Ensure rapid recovery and safeguard against costly data losses and downtime.

Inadequate key and certificate management frustrates disaster recovery plans

Disaster recovery (DR) often evokes data lost in the wake of a natural disaster. However, issues with encryption, which has become the standard for securing sensitive data, can exact equally harsh consequences. Encryption disasters come in two forms—security issues that require a complete certificate refresh and data losses as a result of lost keys.

Incomplete and inaccurate inventories prevent companies from responding to encryption disasters

The following incidents require a company to refresh all certificates affected by the incident:

  • CA private key compromise
  • Encryption algorithm breach
  • Encryption technology defect

Most administrators, who rely on spreadsheets and memory to track certificates, have no idea where to begin a refresh—let alone how to manually perform the 20-step renewal process for each of thousands of certificates without incurring extensive and costly downtime.

Poor key management processes result in lost data and interrupted services

In a recent Venafi study, 43% of respondents admitted that they had lost data due to lost or withheld keys.

If administrators struggle to track keys during normal operations, they have little hope to deliver seamless recovery in a true DR situation. Investing in a DR site does little good unless all necessary encryption keys are properly deployed to that site. In addition, if servers in a fail-over site have expired certificates, the services will not fail over correctly at the critical moment.

Measureable Successful Results

Analyst Coverage

"Organizations with roughly 200 or more documented X.509 certificates in use are high-risk candidates for unplanned expiry and having certificates that have been purchased but not deployed." Full Report

"To support the broader deployment of encryption, organizations with top performance have looked towards increased automation and centralized, heterogeneous approaches to key lifecycle management. Venafi is well-aligned with this Best-in-Class approach."

"Venafi's primary differentiator is its broad entity support for systems that utilize asymmetric keys and certificates. In addition, it implements flexible key lifecycle policies and administration functionality and automated discovery of keys and certificates in systems that support such activity."

"Venafi offers compelling advantages, such as being the early mover in this market, with proven deployments at marquee customers demonstrating its ability to scale and provide breadth of integration."

"When there are many hundreds of certificates from a variety of certificate authorities, the only ecumenical [universal], nonproprietary provider of a certificate management solution is Venafi. Other CA management systems are biased toward the particular CA by, for example, only supporting renewals from that specific CA." Full Report

"The emphasis on orchestration, in tandem with its scalability and interoperability, is tied to the evolution of Venafi's competitive landscape, and to the potential to frame its value in the context of risk management."