Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Compliance

Slack Introduces Enterprise Key Management Tool

Slack on Monday announced the introduction of Enterprise Key Management, an Enterprise Grid add-on feature that gives customers complete control over their encryption keys.

Slack on Monday announced the introduction of Enterprise Key Management, an Enterprise Grid add-on feature that gives customers complete control over their encryption keys.

Slack does encrypt data for all organizations, both while it’s at rest and in transit. However, some organizations, particularly in regulated industries where data protection requirements are more stringent, may want to use their own encryption keys.

This helps them gain a better view of their data and provides granular control if certificates need to be revoked in case they become compromised.

First announced last year, the new feature uses Amazon’s AWS Key Management Service (KMS), which provides detailed activity logs for data access events.

“Unlike other solutions, ours isn’t all or nothing. You can revoke access in a very precise way if you need to,” Geoff Belknap, chief security officer at Slack, explained in a blog post. “Customers can decide to revoke access to data at certain times of day and in certain channels, for example. So if there’s a concern, you don’t have to just hit a button and shut down Slack completely, blocking all your different teams and departments from accessing the tool. Of course, you can make that decision, too, but the idea is that this solution makes securing your data much easier without restricting access to features that people rely on to do their day-to-day work.”

CrowdStrike and other companies have already tested Slack Enterprise Key Management.

Advertisement. Scroll to continue reading.

In January, on the company’s 5th anniversary, Slack announced that it had over 85,000 paying customers and a total of more than 10 million daily active users across over 150 countries.

The platform has been increasingly targeted by both security researchers looking to find vulnerabilities and, more recently, cybercriminals who have found ways to abuse it to disguise their malware’s command and control (C&C) communications.

Related: Slack Releases Open Source Secure Development Lifecycle Tool

Related: Slack Flaw Allowed Hackers to Hijack Any Account

Related: Slack Tokens Leaked on GitHub Put Companies at Risk

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

David Cass has joined Grayscale Investments as Chief Risk Officer.

Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.

Alex Stamos has become Chief Information Security Officer at Cognition.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.