The Simple Solution To The IBM-SLA Data Breach: Encryption in Use
- SEMNET TEAM
- Jul 6
- 4 min read

According to CNA, personal data of about 70,000 individuals was compromised after unauthorised access to a dataset created for vendor development and testing. The exposed information reportedly included names, NRIC numbers and past property addresses.
This is not just another cybersecurity incident.
It exposes a deeper problem in the way many organisations still think about data protection.
The Real Problem
Based on the public reports, the affected dataset was created for testing purposes and was meant to contain only mock or anonymised data. However, it was later found to contain real personal information.
That is the important lesson.
If sensitive information exists in a readable form inside any environment i.e. production, testing, development, backup or vendor-managed cloud then a breach of that environment will quickly become a breach of the data. Many organisations still rely on the assumption that if the system is protected, the data is protected. That assumption is no longer enough.
Traditional Security Protects the Container
Most cybersecurity strategies focus on firewalls, access controls, endpoint protection, MFA, SIEM, monitoring tools and cloud security. These controls are necessary and we work with our customers to ensure the fundamentals are in place as much as possible.
But they mainly protect the container around the data. The actual asset is the data itself. If attackers gain access to the right system, account, database, administrator privilege or test environment, sensitive records may still become readable. That is why the industry needs to move from system-centric security to data-centric security.
Why Conventional Encryption Is Not Enough
Most organisations already use encryption at rest and encryption in transit. Encryption at rest protects data while it is stored. Encryption in transit protects data while it moves between systems. Both are important. But there is still a major gap: what happens when the data is being used? The solution remains hard. In many conventional environments, data is decrypted inside the application, database, workflow or user interface so that people and systems can work with it. At that point, if the wrong user, vendor, administrator or compromised account gains access, the data may become readable. This is the missing layer. The future is not just encryption at rest. It is not just encryption in transit. The future is encryption in use.
What Encryption in Use Means
Encryption in use means sensitive data remains encrypted by default and is decrypted only at the right moment, for the right authorised user, for the right permitted action. Just as importantly, it must happen seamlessly. Security should not slow down business workflows. It should not force users to download files, move data manually or create workarounds that introduce more risk.
The ideal model is simple:
Data stays encrypted.
The authorised user requests what they are allowed to see.
Only the specific data needed is decrypted.
Once the action is completed, the data returns to a protected state.
This is the philosophy behind Vaultrex.
How Vaultrex Changes the Model
Vaultrex is designed to protect sensitive data directly, not just the environment around it. Unlike conventional models where system access can often lead to data access, Vaultrex is built around controlled, just-in-time decryption. Data is encrypted by default. It is revealed only when authorised, only when needed, and automatically re-encrypted once no longer in use. SEMNet’s Zero Trust Data Vault page describes Vaultrex as applying encryption directly to sensitive data, with on-demand decryption for authorised users, multi-key cryptographic verification and field-level access control. This is important because system access should not automatically mean data access. Vendor access should not automatically mean readable data. Administrator access should not automatically mean the ability to decrypt everything. Cloud access should not mean the cloud can see everything.
Reducing the Blast Radius
In a traditional breach, once the wrong party gains access to a database or environment, large volumes of sensitive information may become exposed.
Vaultrex is designed to reduce that blast radius.
Only the specific field, record or data element required for an authorised purpose should be revealed. Everything else should remain encrypted.
This matters across many environments:
Production systems.
Testing environments.
Development environments.
Backups.
CRMs.
AI tools.
Email.
File sharing.
Vendor-managed platforms.
The IBM-SLA incident shows why this matters. The affected environment was reportedly separate from SLA’s live operational systems, and SLA said property ownership and lodgment records in STARS and ELS remained secure and unaffected.
But the breach still mattered because real personal data was present in the affected dataset.
That is the issue enterprises must now solve.
Sensitive information should not be exposed simply because it was copied, stored or used in another environment.
The Simple Lesson
The lesson from this incident is not that every breach can be prevented.
That is unrealistic.
The more important and practical question should be:
When a breach happens, does the data remain protected?
If the answer is no, then the organisation has not truly protected the data.
It has only protected the doorway.
Modern cybersecurity must assume that systems can fail, credentials can be compromised, vendors can be breached, and data can appear in places where it should not.
That is why encryption must move closer to the data itself.
Not just at rest.
Not just in transit.
But also in use.
Conclusion
The IBM-SLA data breach points to a simple but important direction for enterprise cybersecurity.
Protect the data itself.
Keep it encrypted by default.
Decrypt it only at the right moment.
Reveal it only to the right authorised user.
Expose only what is needed.
Then protect it again automatically.
That is the future of data protection.
That is encryption in use.
That is the Vaultrex approach.



Comments