{"id":9687,"date":"2019-02-21T14:18:40","date_gmt":"2019-02-21T19:18:40","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=9687"},"modified":"2023-04-10T10:13:04","modified_gmt":"2023-04-10T14:13:04","slug":"71-of-organizations-dont-know-how-many-certificates-keys-they-have","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/71-of-organizations-dont-know-how-many-certificates-keys-they-have\/","title":{"rendered":"71% of Organizations Don\u2019t Know How Many Certificates &#038; Keys They Have"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-a-new-study-begs-the-question-are-we-having-the-right-conversation\">A new study begs the question: are we having the right conversation?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A new study <a href=\"https:\/\/info.keyfactor.com\/the-impact-of-unsecured-digital-identities-ponemon-report?utm_campaign=Ponemon%20Report%20&amp;utm_source=ppc&amp;utm_medium=google&amp;gclid=CjwKCAiAkrTjBRAoEiwAXpf9CZDraBDsu2rXrulrFvilOyGEeRgQxe7SaBpICzzX-j2MX5AEixo4fBoCJrcQAvD_BwE\">from KeyFactor and the Ponemon Institute<\/a> has shed some interesting light on the pain points most organizations go through when they\u2019re managing their digital certificates and encryption keys.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There were some key takeaways from the study, one of which was simply the scope of the problem. <a href=\"https:\/\/www.thesslstore.com\/blog\/pki-certificate-management-mistakes\/\">Certificate management has become a major burden<\/a> as our digital infrastructure and the role of PKI has continued to grow. The larger an organization gets, the more acute the problem becomes. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But one of the other major takeaways is the fact that for many organizations, the biggest risk they perceive stemming from bad certificate management isn\u2019t compromise, misuse or expiration. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s failing audits or being non-compliant. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And that begs the question, are we, as an industry, having the\nwrong conversation?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-impact-of-unsecured-digital-identities\">The Impact of Unsecured Digital Identities<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Published just last month, KeyFactor and the Ponemon Institute <a href=\"https:\/\/info.keyfactor.com\/the-impact-of-unsecured-digital-identities-ponemon-report?utm_campaign=Ponemon%20Report%20&amp;utm_source=ppc&amp;utm_medium=google&amp;gclid=CjwKCAiAkrTjBRAoEiwAXpf9CZDraBDsu2rXrulrFvilOyGEeRgQxe7SaBpICzzX-j2MX5AEixo4fBoCJrcQAvD_BwE\">created an exhaustive survey<\/a> and spoke with a range of professionals from myriad organizations to put together this information. Let\u2019s just start a little bit with the methodology before we get into the findings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First of all, this study was conducted in the United States and consisted of 30 questions about five potential certificate management disaster scenarios (the five fingers of death). &nbsp;Here\u2019s the breakdown of what positions those surveyed hold in their organizations.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-1.png\" alt=\"Positions those surveyed hold in their organization\" class=\"wp-image-9689\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-1.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-1-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-1-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This survey was originally sent to over 17,000 organizations\nand was returned by just over 600. 58 of those were tossed out for various\nreasons, which means the final sample comes from 596 American organizations.\nHere\u2019s the breakdown of their size. <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-2-1.png\" alt=\"\" class=\"wp-image-9691\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-2-1.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-2-1-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-2-1-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Ok, so with that in mind, let\u2019s look at the key takeaways from the study.<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-61-of-organizations-are-concerned-they-can-t-secure-keys-through-all-stages-of-the-lifecycle\">61% of Organizations Are Concerned They Can\u2019t Secure Keys Through All Stages of the Lifecycle<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"300\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Hashed-Out-Encryption-Icon-300x300.jpg\" alt=\"Lock icon\" class=\"wp-image-9703\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Hashed-Out-Encryption-Icon-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Hashed-Out-Encryption-Icon-768x768.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Hashed-Out-Encryption-Icon-1024x1024.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Hashed-Out-Encryption-Icon.jpg 1600w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Three out of five organizations have serious concerns about their ability to secure encryption keys during all stages of their lifecycle, from issuance to rotation, renewal and revocation. As we\u2019ve discussed before, at its heart SSL\/TLS is really <a href=\"https:\/\/www.thesslstore.com\/blog\/public-key-cryptography-key-exchange\/\">just an elaborate digital mechanism for exchanging the encryption keys<\/a> we\u2019ll use to communicate with the websites or end points we visit. Strip away all of the other terminology and what you are doing every time a <a href=\"https:\/\/www.thesslstore.com\/blog\/tls-1-3-handshake-tls-1-2\/\">handshake<\/a> takes place is authenticating the other party so you can use their public key to encrypt a session key (or the secret that will lead to its generation) so you can communicate securely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Obviously, that\u2019s just in the context of SSL\/TLS, but encryption keys are also used for a number of other purposes like signing email, documents, software, etc. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We cover the <a href=\"https:\/\/www.thesslstore.com\/blog\/heres-what-happens-when-your-private-key-gets-compromised\/\">risks of key compromise <\/a>all the time because it\u2019s a fairly common threat. This underscores the fact that many organizations view it the same way. But there do seem to be some things holding many organizations back from improving their certificate and <a href=\"https:\/\/www.thesslstore.com\/blog\/12-enterprise-encryption-key-management-best-practices\/\">key management practices:<\/a> cost.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Per the study:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Most organizations do not have adequate IT security staff to maintain and secure keys and certificates, especially in the deployment of PKI. Further, most organizations do not know how many keys and certificates that IT security needs to manage. <\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">So, it\u2019s partly a lack of qualified personnel. But that\ncosts money. Additionally:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Pricing models can prevent organizations from investing in solutions that cover every identity across the enterprise. <\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s why it\u2019s generally better to work with an SSL service instead of trying to go direct from a CA, <a href=\"https:\/\/www.thesslstore.com\/partner\/enterprise-solutions.aspx\">but what would we know\u2026<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anyway, the financial concerns don\u2019t end there. This is taken from a part of the survey that dealt with organization\u2019s perceptions of PKI and certificate management in general, it asked respondents to respond with their level of agreement about a given statement from Strongly Agree to Strongly Disagree. Clearly, cost is a major concern:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-3.png\" alt=\"\" class=\"wp-image-9692\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-3.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-3-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-3-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">We actually deal with quite a few Enterprise clients, not every PKI and certificate management solution is cost-prohibitive. In fact, <a href=\"https:\/\/www.thesslstore.com\/pdf\/enterprise-program-control-panel.pdf\">some are quite budget-friendly<\/a>. And we\u2019ve actually got a white paper coming out on Certificate Management best practices next month (so keep an eye out). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a look at the percentage of organizations that are outsourcing all or part of their Public Key Infrastructure deployment. <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-4.png\" alt=\"mPKI outsourcing\" class=\"wp-image-9693\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-4.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-4-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-4-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This is one of the ways we\u2019re probably missing the target as an industry, because the perception of certificate management is that it\u2019s expensive and complicated. <a href=\"https:\/\/www.thesslstore.com\/enterprise\/managed-pki-solutions.aspx\">It doesn\u2019t have to be<\/a>. And in the long run, it\u2019s not a sunken cost \u2013 <a href=\"https:\/\/www.thesslstore.com\/enterprise\/ssl-certificate-management.aspx\">it\u2019s an investment<\/a>. Because as we\u2019re about to unravel, the costs associated with mismanaging certificates is staggering. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But, before we go any further, let\u2019s take one more chance to identify the scope of the problem we\u2019re talking about. Of the nearly 600 respondents, this was the average number of certificates and keys owned by each one (per the survey\u2019s extrapolation).<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-5.png\" alt=\"Average number of keys and certificates per organization\" class=\"wp-image-9694\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-5.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-5-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-5-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As organizations grow larger, certificate and key management become exceedingly difficult. There comes a point where you either need to hire dedicated staff to handle it or you need to outsource it to a third-party security company that knows how to handle it for you. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Doing anything else is just inviting trouble.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And, as we touched on at the start of this section: 61% of these organizations don\u2019t have confidence they can secure these keys and certificates for the entire duration of their lifecycle. Organizations need to be proactive about this before it comes back to bite them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s talk about what kind of trouble you may be inviting by\nnot being proactive with your certificate management policies.<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-five-fingers-of-death\">The Five Fingers of Death<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Indulge me the Kung Fu header while we talk about the five\nnightmare scenarios that this survey presented:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Unplanned outages due to certificate expiration<\/li>\n\n\n\n<li>Failed audits or compliance due to bad certificate\/key management<\/li>\n\n\n\n<li>Server certificate and key compromise\/misuse<\/li>\n\n\n\n<li>Code Signing certificate and key compromise\/misuse<\/li>\n\n\n\n<li>CA compromise; rogue CA for MITM or phishing (<a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-rogue-certificate\/\">rogue certificates<\/a>)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This is where things take an interesting turn, and it goes back to whether we\u2019re having the right conversations as an industry &#8211; this is how the organizations surveyed view these threats.<br><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-6.png\" alt=\"\" class=\"wp-image-9695\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-6.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-6-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-6-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">On a scale of one to five, with five being the most sever, Failed audits\/non-compliance is number one by a wide margin. That shows that for most organizations, data security and secure connections are nice ideals, but where rubber meets the road is in terms of maintaining compliance with industry standards and legal regulations. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There\u2019s a good chance <a href=\"https:\/\/www.thesslstore.com\/blog\/preparing-gdpr-introduction-1\/\">a lot of this stems from the GDPR<\/a>, which went into effect last year and threatens <a href=\"https:\/\/www.thesslstore.com\/blog\/gdpr-fines-are-coming\/\">massive penalties<\/a> for organization\u2019s that fail to comply.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In that sense, the security is a means to an end. The end being compliance. Organizations are less interested in the actual security benefits than they are in maintaining compliance and avoiding <a href=\"https:\/\/www.thesslstore.com\/blog\/google-fined-57000000-for-gdpr-violations\/\">the fines and penalties that come with running afoul of that<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There\u2019s an old anecdote about a salesman who sells drill bits and over time realizes that his customers could really care less about the details of the drill bits themselves \u2013 what they want is a quarter-inch hole. That\u2019s their interaction with the product. What we might be missing is that for many organizations, their quarter-inch hole isn\u2019t cybersecurity at all, that\u2019s a secondary concern to compliance. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But despite the decided advantage failed audits\/non-compliance have in terms of the severity they\u2019re perceived with, they cost organizations about the same as any of the other four certificate\/key management disasters.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>  <strong> Scenario   <\/strong><\/td><td><strong>   Extrapolated Cost   <\/strong><\/td><\/tr><tr><td>\n  Cost of unplanned outages due to certificate expiry\n  <\/td><td>\n  $11,122,100\n  <\/td><\/tr><tr><td>\n  Cost of failed audits\/compliance due to undocumented or poor key\n  management\n  <\/td><td>\n  $14,411,500\n  <\/td><\/tr><tr><td>\n  Cost of server certificate and key misuse\n  <\/td><td>\n  $13,423,250\n  <\/td><\/tr><tr><td>\n  Cost of Code Signing certificate and key misuse\n  <\/td><td>\n  $15,025,150\n  <\/td><\/tr><tr><td>\n  Cost of CA compromise or rogue CA for MITM and\/or phishing attacks\n  <\/td><td>\n  $13,219,850\n  <\/td><\/tr><tr><td>\n  Total Cost\n  <\/td><td>\n  $67,201,850\n  <\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Truth be told, it\u2019s often the other four disasters \u2013 expiration, compromise or rogue certificates \u2013 that lead to failed audits and non-compliance. So, mitigating them is ultimately going to strengthen compliance. These things are all interconnected. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>RELATED:<\/strong> <a href=\"https:\/\/www.thesslstore.com\/blog\/what-happens-when-your-ssl-certificate-expires\/\"><em>This is what happens when your certificate expires&#8230;<\/em><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-it-all-starts-with-visibility\">It All Starts With Visibility<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The biggest pain point for most organizations dealing with large-scale certificate management is visibility. They don\u2019t know how many certificates and keys they have, they don\u2019t know who ordered them all, they don\u2019t know when they expire. That goes for 71% of all organizations surveyed. <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-7.png\" alt=\"Biggest challenges posed by certificate management\" class=\"wp-image-9698\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-7.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-7-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-7-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This is exactly where a <a href=\"https:\/\/www.thesslstore.com\/enterprise\/ssl-certificate-management.aspx\">good certificate management platform<\/a> can pay for itself: by scanning your network and the various CT logs for all relevant certificates and giving you a single interface with which to manage them all. Just by doing that you\u2019ll be minimizing the risk of <a href=\"https:\/\/www.thesslstore.com\/blog\/what-happens-when-your-ssl-certificate-expires\/\">unforeseen expiry<\/a> or <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-rogue-certificate\/\">rogue certificates<\/a>. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a look at what departments control the PKI budgets and certificate\/key management. As you can see it\u2019s a total scattershot. And if you\u2019ve got multiple departments in the same <a href=\"https:\/\/www.thesslstore.com\/blog\/how-pki-works\/\">organization making PKI<\/a> decisions things are only going to grow more complicated.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"900\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-8.png\" alt=\"Who owns the PKI budget?\" class=\"wp-image-9699\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-8.png 900w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-8-300x175.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Certificate-Managment-8-768x448.png 768w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Again, this is where investing in an actual certificate\nmanagement platform pays dividends. You can add multiple users with varying\npermissions so you can better control who touches what and more importantly,\nwho can\u2019t touch it. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s look at some more pain points for organizations in the certificate\/key management department. Or, more specifically, the frequency with which they occur and the likelihood they will continue to be a problem.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>   Event   <\/strong><\/td><td>   <strong>Occurrences   (per 24 months)   <\/strong><\/td><td>  <strong> Future Likelihood   <\/strong><\/td><\/tr><tr><td>\n  Expired Certificates\n  <\/td><td>\n  4\n  <\/td><td>\n  30%\n  <\/td><\/tr><tr><td>\n  Failed Audits\/Non-compliance\n  <\/td><td>\n  5.5\n  <\/td><td>\n  42%\n  <\/td><\/tr><tr><td>\n  Server certificate compromise\n  <\/td><td>\n  4.6\n  <\/td><td>\n  39%\n  <\/td><\/tr><tr><td>\n  Code Signing certificate compromise\n  <\/td><td>\n  3.9\n  <\/td><td>\n  29%\n  <\/td><\/tr><tr><td>\n  Rogue Certificates\n  <\/td><td>\n  2.3\n  <\/td><td>\n  38%\n  <\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">A quick word on the rogue certificates, it&#8217;s easy to dismiss this scenario as unlikely. Don&#8217;t. In just the last 30 days the US Department of Homeland Security issued <a href=\"https:\/\/www.thesslstore.com\/blog\/us-dhs-issues-emergency-directive-warning-about-rogue-certificates\/\">an emergency directive warning of rogue certificates<\/a>. That&#8217;s just the most recent example, but make no mistake about it: rogue certificates are a threat and an extremely costly one at that. Notice it costs organizations about the same over two years as any of the other four scenarios &#8211; despite occurring less frequently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Again, a lot of these things can be avoided simply by investing in a quality certificate management platform. There are good ones from <a href=\"https:\/\/www.thesslstore.com\/partner\/comodo-certificate-management.aspx\">Sectigo<\/a>, <a href=\"https:\/\/www.thesslstore.com\/digicert.aspx\">DigiCert<\/a>, <a href=\"https:\/\/www.thesslstore.com\/partner\/certificate-authority-driver-venafi.aspx\">Venafi<\/a> and a range of other vendors. They help you to scan your networks, provide visibility, an interface to manage all stages of the certificate lifecycle and if you would prefer to just outsource everything, you can even have someone manage it for you. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is something that more organizations need to act on, but it\u2019s also a conversation that we, as an industry, aren\u2019t approaching correctly. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations care deeply about complying with the various laws and industry standards that govern them. There are very real, very tangible ramifications for non-compliance. A certificate expiration that causes a website to go down doesn\u2019t invoke the same level of panic in the C-suite that a failed audit does. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.thesslstore.com\/enterprise\/ssl-certificate-management.aspx\">Certificate management<\/a> won\u2019t solve all of that, it\u2019s not a turn-key solution for compliance across the board. But it does mitigate any risks that digital certificates and encryption keys may pose to your organizational compliance. And in the long run, that could save everyone a lot of money.<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<p class=\"wp-block-paragraph\"><em>As always, leave any comments or questions below\u2026<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"267\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" class=\"wp-image-7276\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>A new study begs the question: are we having the right conversation? A new study from KeyFactor and the Ponemon Institute has shed some interesting light on the pain points&#8230;<\/p>\n","protected":false},"author":6,"featured_media":9706,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[9901,182,9900,228],"class_list":["post-9687","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-certificate-management","tag-encryption","tag-mpki","tag-pki","post-with-tags"],"views":20473,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/02\/Title-Cert-Management-2.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/9687","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=9687"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/9687\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/9706"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=9687"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=9687"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=9687"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}