Previewed at Frontiers in 2018, and eagerly awaited by IT admins and security officers, Slack has officially launched Enterprise Key Management (EKM).
What is EKM?
EKM is a security control that can be purchased as a bolt-on to Slack Enterprise Grid. It augments Slack’s existing security features by giving customers control over the encryption keys used to encrypt the files and messages within their Slack workspace. “Bring your own encryption” if you have had enough of the BYOx phenomena.
Slack has suggested EKM will provide on-premises level security controls to a cloud app. Former Chief Product Officer, April Underwood, unveiled EKM at the Frontiers conference with the comment of “EKM provides all of the security of an on-premise solution, with all the benefits of a cloud tool.”
I’ll let you decide whether that’s a good thing or a bad thing yourself. Whilst the stigma associated with cloud security remains ever present in business, it could be a turn off for cloud-first organisations. Nevertheless, EKM is a welcomed addition to the Slack portfolio.
EKM can be procured as a standalone product and in both on-premises and cloud deployments. Typical players in this space include the following:
- Amazon Web Services, Inc.
- CA Technologies, Inc.
- Dyadic Security
- Gemalto NV
- Google Inc.
- Hewlett Packard Enterprise
- IBM Corporation
- Oracle Corporation
- Quantum Corporation
- RSA Information Security
- Dell EMC.
- E-Security, Inc.
- Townsend Security
- Venafi
- Winmagic, Inc.
Slack has opted for Amazon Web Services’ EKM offering to power their solution.
What does this mean for Slack users?
Nothing changes for the day to day user of Slack. No addition module or anything to install. With EKM, Slack is the same Slack you know today. Channels, file sharing, search and over 1,500 apps at your disposal.
April Underwood suggested ““It is the same Slack but what it offers administrators is the ability to turn off access to data at any point. You can also turn it off for very specific data sets, channels and timeframes”.
Access can be revoked to certain messages but ultimately Slack is making your messaging experience safer. Slack already encrypts data in transit and at rest. It’s not quite full end to end encryption but it’s the next best thing in Slack’s eyes.
Geoff Belknap, Chief Security Officer at Slack, highlights the revoking functionality as unique.
“Rather than revoking access to the entire product, admins can choose to revoke access in a very granular, highly targeted manner. That granular revocation ensures that teams continue working while admins suss out any risks"
What does this mean for Slack admins?
Initial indications suggested EKM was expected to offer core protection of sensitive data in response to data protection and GDPR requirements. Supposedly, a range of new features to make the desktop experience faster and more secure were due to be enveloped in the feature release.
Slack Enterprise Grid customers now have access to, and ownership of, keys to encrypt and decrypt sensitive data stored in Slack including messages, files and comments.



