The Next Generation

HSM approach delivers unparalleled cost/benefit for organizations

Hardware Security Modules, or HSMs, protect against insider and external threats by delivering confidentiality for encryption keys in a physically hardened appliance. They were initially developed by the military for the military, then were first leveraged commercially in the financial services sector. Now HSMs can be seen in a variety of applications ranging from PKI to code signing to databases.

Despite their strong security benefits, HSMs designed with older generation technology present significant hurdles to adoption. First, they are built using proprietary hardware that has a high initial acquisition cost. Second, they bring significant complexity and cost of operations. In many cases, the personnel costs to manage and operate these HSMs greatly exceed the appliance cost. The total cost and complexity prove to be prohibitive for many organizations, leading to critical gaps in encryption key management for data protection.

However, newer technologies are available today which can enable organizations to reassess their cost/benefit analysis and implement stronger security controls with low initial investment. Organizations are finding that next-generation HSM and Key Management capabilities offered as a subscription-based approach deliver powerful data protection and TCO benefits.

In the past, organizations had only the CAPEX model to purchase HSMs. The hardware typically cost at least $20,000 to deploy, $40,000 for high availability, and multiple times more for a typical enterprise deployment. Most cases required additional components and costs for such features as client-side connectors, partitions, KMIP support, Elliptical Curve algorithms, master key export, remote administration, and maintenance. Added up, deployment costs for real-world use cases often started at $250,000. This cost scenario left most organizations unable to leverage the power of HSMs and open to data breaches and insider attacks.

Next-generation HSMs today offer a subscription, or OPEX, model with flat, predictable pricing and a low barrier of entry, providing an attractive cost/benefit scenario that is attainable for most organizations. The leading appliances use commercial offthe- shelf (COTS) servers hardened for NIST FIPS 140-2 level-3, significantly reducing the initial acquisition cost. A HSM-as-aservice (HSMaaS) subscription software license combined with an all-inclusive model offers predictable pricing for current and future use cases. Additionally, those next-generation HSMs following a software-defined design can even accommodate organizations that prefer to use their own servers for cost or supply chain efficiency purposes.

The CAPEX model bundles software and hardware together and often leads to paying for the software several times.

For example, if an organization, after a few years, needs to upgrade their hardware due to growing demands, they must purchase another hardware and software bundle, effectively duplicating their software payment. Next-generation HSMs’ approach enables organizations to purchase new servers or appliances and transfer the software licenses over, thereby lowering long-term acquisition costs. The OPEX model gives organizations the flexibility to more frequently upgrade to the latest Intel x86 processor, as an example. A higher performance processor means they can do more with less, which lowers overall costs.

HSMs today should be secure, cost-effective, intuitive, and easy to use. They should:

  • Support all NSA Suite B algorithms.
  • Securely generate, manage, and rotate keys; encrypt, hash, and sign.
  • Support all common APIs (including RESTful APIs, KMIP, and traditional cryptographic interfaces) on the same platform.
  • Support multi-tenancy (the ability to securely manage multiple users/customers/departments on the same hardware/software).
  • Provide true separation of duties (ability to manage firmware/ software updates without having access to application keys).
  • Provide secure audit logs that integrate with SIEM tools such as Splunk, and offer configurable alerts.
  • Deliver built-in high availability and load balancing without costly external appliances.

Legacy HSMs require professional services and a weeklong class to get trained on deploying the solution. Additional “soft costs” associated with these deployments can be significant as well. Legacy HSMs have to be offline for firmware/software updates, which means unproductive downtime and admins required to travel worldwide to make administrative changes to data centers. Because they are so difficult to manage, few within a company understand how they work, requiring additional training classes. With next-generation HSMs, there is no downtime during software updates, and centralized remote key management software does not require admins to fly around the globe.

This article originally appeared in the November/December 2018 issue of Security Today.

Featured

  • AI Is Now the Leading Cybersecurity Concern for Security, IT Leaders

    Arctic Wolf recently published findings from its State of Cybersecurity: 2025 Trends Report, offering insights from a global survey of more than 1,200 senior IT and cybersecurity decision-makers across 15 countries. Conducted by Sapio Research, the report captures the realities, risks, and readiness strategies shaping the modern security landscape. Read Now

  • Analysis of AI Tools Shows 85 Percent Have Been Breached

    AI tools are becoming essential to modern work, but their fast, unmonitored adoption is creating a new kind of security risk. Recent surveys reveal a clear trend – employees are rapidly adopting consumer-facing AI tools without employer approval, IT oversight, or any clear security policies. According to Cybernews Business Digital Index, nearly 90% of analyzed AI tools have been exposed to data breaches, putting businesses at severe risk. Read Now

  • Software Vulnerabilities Surged 61 Percent in 2024, According to New Report

    Action1, a provider of autonomous endpoint management (AEM) solutions, today released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024, amid an increasingly aggressive threat landscape. Read Now

  • Motorola Solutions Named Official Safety Technology Supplier of the Ryder Cup through 2027

    Motorola Solutions has today been named the Official Safety Technology Supplier of the 2025 and 2027 Ryder Cup, professional golf’s renowned biennial team competition between the United States and Europe. Read Now

  • Evolving Cybersecurity Strategies

    Organizations are increasingly turning their attention to human-focused security approaches, as two out of three (68%) cybersecurity incidents involve people. Threat actors are shifting from targeting networks and systems to hacking humans via social engineering methods, living off human errors as their most prevalent attack vector. Whether manipulated or not, human cyber behavior is leveraged to gain backdoor access into systems. This mainly results from a lack of employee training and awareness about evolving attack techniques employed by malign actors. Read Now

New Products

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.