Welcome to the KuppingerCole Analyst Chat. I'm your host. My name is Matthias Reinwarth. I'm an analyst and advisor at KuppingerCole Analysts. For today's topic, I have invited two experienced analysts from KuppingerCole to discuss our today's topic, and the topic is post-data privacy world. But first of all, let me welcome my two guests. First of all, hi, Mike Small. Good to have you.
Hi, Matthias. Welcome.
Well, I'm glad to be here. My name is Mike Small, and I'm a senior analyst with KuppingerCole. Right. And handing over to Jonathan Care.
Hi, Matthias. It's a pleasure to be back here. And my name is Jonathan Care, and I'm a lead analyst at KuppingerCole. Great to have you both here. And we have agreed to discuss a topic, which I'm not sure if we end up at a common statement, at a joint assessment, but I think it's such an important topic. So I think we just should start off. First of all, what are we talking about? The provocative statement is we are living in a post-data privacy world. And this is not because everybody has decided to give up their privacy, because it has been decided for them.
Breaches, data breaches are everywhere and they are all around. All our data has been leaked more or less twice or five times or 10 times, and it might just leak right now. So the question is, and this is where I want to spark the discussion, is traditional privacy dead or are we just pessimistic? Maybe. I don't know who wants to start.
Jonathan, a quick intro statement from your side. Thanks, Matthias. I'm basing this on the data I picked up in the EU. And since we're Europeans, let's focus on the EU for now. The average number of breach notifications per day in 2024 was 363. They're a little slightly from about 335 from the previous year. And the companies with the highest number of breach notifications are the Netherlands with 33,471, Germany with 27,829, and Poland with 14,286 notifications. The member states, so Ireland, Data Protection Commission in Ireland received 6,991 valid notifications of personal data.
And in Estonia, in 24, the Estonian DPA received 184 data breach notifications, affecting over 910,000 individuals. There is a lot of prolonged data out there. And I think another indicator there is that the cumulative total of GDPR fines by January of this year was around 5.88 billion euros. And it was one of the largest fines would be META, fine 1.2 billion by the RHDPC in 2023. So my theory is that there is so much purloined data out there. There is so much information that is awash in the dark web.
And actually, there is now companies who are making a tidy living, are hoovering up this data and then reselling it, which is an interesting trend, that we are, I would say, in a post-data, in fact, I would say a post-data security, but that makes my data security friends and colleagues sad. But we're certainly in there where privacy is a thing of the past. I know that my personal data is out in the dark web, has been for some years. And I think we are in a post-data security world. But these are figures. I agree. I think my data is out there.
And if you can check that online every day to see how many leaks you have been involved in, I would agree. But these are just figures. You just mentioned 30,000, 5 billion. Can we make this more concrete? Are there examples where we really can say, okay, data privacy, but also privacy protection or data security is something that is tangible and can be tracked down to real life use cases, not only just to figures? Maybe some thoughts from you, Mike? Yeah. So 20 years ago, Scott McNeely made the famous statement that privacy is dead.
And that statement, I believe, was true then and is becoming even more true now. That irrespective of the data that he's stolen and put on the dark web, we have all given away our data voluntarily to a whole variety of organizations and systems without very much in return. And that is the state of the art, as far as I can see today. There have been a number of implications of this.
And I think that we've moved away from a capital economy to a data economy, that a few organizations now possess all of this data about the people and that they are profiting from it in a way which is not necessarily socially very helpful. The political phrase is selling one's birthright for a metal potage, as they say. So as you say, we've given away our data and there have been innumerable surveys, some humorous, some less so, where people have been asked if they'll disclose some important information, even passwords in exchange for a candy bar or something else like that.
And the Liverpool Street Station is a famous location of people doing this. And I think that nowadays, I mean, people of my son's generation, I suppose, so people early in their careers, in their 20s, don't have any expectation if they're using the social media services. They have little or no expectation that they have any privacy on those services at all.
Right, yes, I can confirm because just being a father myself, just switching on MFA, reminding kids to switch on the MFA, just gets the answer, yeah, but that makes things slower and I need to log in twice or stuff. And it's just more or less a usability issue rather than a security issue that they look at. Maybe that is also something that has changed, but that's a different game.
You said that we're giving away the data, but some of the data that has been leaked about me in, I don't know, 20 or 30 years is definitely nothing that I would have liked to share, which would be my Dropbox credentials, which would be some stuff that is really more personal and has just been leaking out of systems I deemed to be secure. That's an additional thing that I would like to consider. Do you disagree there? Shouldn't we use a service? I think that the privacy legislation derives from another era.
And in that era, the big bad wolf was the government, because it was only the government that had the capability of collecting this vast amount of data on people. Now, it's the commercial organizations that collect it, and they collect it, as you were saying, Jonathan, in response for the equivalent of a piece of chocolate or a candy bar, and do not, in fact, give the value for the real value of what you've given away. And so we need to understand what it is that people want.
And furthermore, the problem of the legislation has been that, in a way, it has created more risks, because it is amazing the number of times that I am contacted by official suppliers of utilities and things like this, who insist, having phoned me up, on demanding that, due to GDPR, I give them my personal information to prove I am who I am. And so, in some ways, it's made it worse.
Sorry, I didn't mean, I wasn't laughing at you, Mike. I was laughing at the people using such a terrible pretext. I think the answer is, due to GDPR, I'm entitled to go jump in the sea. So that's pretty awful. As some of your regular listeners may know, Mattias, I moved to Portugal, enjoying the last dregs of the summer sunshine, dripping through the windows, as we speak. But I still get calls from people saying, oh, you need to buy a new mobile phone subscription through us in the UK. I have as much use for that as a snake has for shoes. Yeah.
Clearly, as you say, numbers in some lists, and people are continuing to call my old UK number, which is, yeah, clearly, there's no compliance with GDPR there. Right. But when you say GDPR, first of all, it's good that they have your own location, not the new location. That means at least there is no recent breach telling them that you're in Portugal right now, which is good news. You just told them, Mattias. Now I'm in trouble.
Yeah, you did yourself. So that's good. So that was implicit consent, but I'm not a lawyer.
But GDPR, maybe that's a point to look at. So is the introduction of the way how we do GDPR and how it's enforced and how it's just done across Europe, is this a systemic issue? Is there a problem behind that? Does that also just contribute to the problem?
Well, like I was saying, the problem with some of the regulations is that they become gold-plated by process-oriented managers and human relations departments to take on a meaning that was well beyond what they originally intended them to mean. You know, when police can turn up at a shop to say, you must take down the photograph of shoplifters because you are breaching their privacy under GDPR, is an example of how far these regulations can be misused. Right.
And I think everybody, at least in Germany, knows that all these consent that you have to give when you first open a website and you have to click here and click there and give consent for whatever. I think just the possibility of giving informed consent is rather ridiculous when you look at terms and conditions. And that makes it even worse when it comes to applying reasonable, usable, and in the end, fruitful regulations to support you in protecting your data. I don't know if that came across correctly, but it's just, it's just the wrong means to achieve maybe a good goal. Jonathan?
I think if I can circle back, actually, something that Mike said resonated very strongly with me. As you say, right now, we do have a lot of government departments being fined by other government departments for breaches of GDPR. This strikes me as pointless bureaucracy and the only people that benefit from this are presumably civil servants who get paid the salaries for administering these cross-departmental fines. We are doing very little to halt the rise in what is called surveillance capitalism.
We're doing very little to deal with the companies who are hoovering up breach data on the dark web and then reselling it as data brokers. We are doing very little about the large tech companies, some of which seem to be determined to make their name in the news, but we're doing very little to rein in the data gathering activities of these social media companies. And I think that it is to our demerit. I don't see them using it to provide us all with easier access paths to trusted sites, as they originally claimed.
And so the original thing was a social media company would then act as a authentication provider. So if they would authenticate you, not only by a password, but by looking at your behavior and so on, that's manifestly not come true. And so I think that, yeah, urgent action is needed. I think it's very difficult because we are, as they say, in the ship, out at sea, and it's very difficult to say, well, wouldn't it be nice to get set back to shore and fix the leaks in the hull? We are out at sea and we are in this, yeah, apparently untenable situation.
I think that I would very much like to see, as you say, the ability for us as EU citizens to take control over our data and have a degree of permission where that data is used, and to be able to make meaningful consent and indeed dissent or withdrawal of consent, meaning that data would be removed. So if I, for example, choose to close my X account, then I could have a reasonable assurance that X would be required to remove all my data.
Yeah, but these are two different kinds of removing the data. The first is removing the data at the source, where you would say, okay, yeah, I want to cancel my X account, which I have done. But all the copies of the data that have been made, most probably illegally or through leaks, they are still out there. The question is, circling back to our original topic, does this really matter at all, or is data out there anyways? Perhaps I could put an alternative line on this, that it's interesting to see how the behavior of the cyber adversaries has changed.
There was a time when they would go for the personal data because they felt that it was valuable, and that they could hold organizations to ransom because they would threaten to do things with the personal data. The interesting thing is the two recent large data cybersecurity incidents in the UK both involved bringing large companies almost to a halt by effectively a denial of business attack, rather than which was the data theft was kind of incidental. That is to say, Marks and Spencer's that was hacked and lost online services for something like six to eight weeks.
The more recent one, the Jaguar Land Rover one, where an organization that makes cars has been reduced to being unable to make cars or service cars because of hacks. Maybe there was some data was breached in that, but the actual cost to the business is the loss of business. That is a more effective tool for a ransom demand than it is to say I've stolen some of your private data, because in spite of the threatened large fines, I don't know of a company that has actually been put out of business because of a data breach.
I think that these are different attack vectors, but maybe Jonathan, you want to add to that? I think they are different attack vectors. I think that is to Marks and Spencer's credit and the Jaguar's credit that they have demonstrated resiliency.
Again, resiliency is a very important topic, but I think it's off the topic of data privacy. They demonstrated resiliency and being able to, as you say, recover and restore normal business operations. It's something we've all been talking about for years. We talk about incident response. Recovery time is a key metric.
I would like to circle back again to something that you said, Matthias, that since we know and there is ample evidence of private organizations that are hoovering up data on dark webs, in some cases, infiltrating dark web forums, and in some cases, purchasing data and then reselling it at a profit, does it matter? Does it matter what governments do? Does it matter what private companies do when, yes, it would appear that not only are stable doors bolted, but people are making a tidy living out of making sure that the horses keep galloping through, if I can mix metaphors that way.
I think we have an existential problem that for many years, we've been preaching the importance of data security and data privacy. However, it would appear that, yes, surveillance capitalism, the entrepreneurial approach to data brokering has meant that this new source of data, which in theory is illegal because it is a result of a data breach, a criminal act, is, however, being sucked up and resold. It strikes me a bit as somebody, I don't know, hoovering up the results of a water treatment plant and then selling it as fertilizer.
I am not convinced that data privacy, as a term, has any meaning anymore. I think from what you've said, there are two distinct points here. One is that there have been the data which is the result of data breaches, which to some extent, because you have personal data in this, is something that can be used by bad actors to commit further crimes. So if somebody gets enough data on me to be able to open a bank account, buy a mobile phone, or other things like that, then the value of that to the hackers is the results of that crime, plus it has an effect on me as a person.
But that's one aspect, that's the bad use of it. The other problem is the legitimate collection of data by the social media, by the online retailers, by all of the various organizations that collect this data as a byproduct of doing business with me or providing me with a service, that they are then able to monetize legitimately to sell to other people on the basis that they know something about me that makes me a marketing qualified lead for some kind of product or another product. Those two are both breaches of, if you will, some kind of privacy.
They both really need a different approach to attack them. But GDPR is primarily concerned with the second of those, and cyber security is primarily concerned with the first of them. Cyber security and privacy overlap in the sense that they both use the same techniques, but cyber privacy is about controlling legitimate access, whereas cyber security is about controlling illegitimate access. I really like that definition. It's not one I've heard, I think, expressed so coherently and precisely before.
Mike, does that mean that as cyber security professionals, we should not be concerned with privacy? That is somebody else's problem. It's a problem, as you say, of human remains. The chief data officer and as cyber security folks, what we should be looking at is safeguarding, prevention, detection, and response.
Well, as a cyber security professional, we are responsible for upholding the law. The law is in two dimensions from what you've described. One is protecting the people that use our computer systems from cyber crime, and to ensure that the way in which the organization uses the legitimately collected data is compliant with the rules and regulations that apply, whether we're a doctor, whether we're a healthcare, whether we are a retailer, or whether we're an industrial complex.
There are different kinds of rules that apply, but in all cases, we're trying to protect our organization and to make sure that the data that that organization holds, whether it's privacy or not, is properly managed and controlled. As society, we have become almost totally dependent upon digital systems to do everything, from banking, to healthcare, to retail.
Basically, everything depends upon digital systems, and we expect these systems to be there when we need them. The people that run systems, the people the organizations depend upon them, need to build resilience in the way these systems are built, operated, and run.
Currently, we see evidence where the majority of data incidents, the majority of cyber incidents, organizations will feel are reasonably successful if they have recovered in between three and six weeks, which is a long time. It is far too long for most things. You would not be satisfied if when there was a train wreck, the trains were not running within a couple of days. You would not be satisfied if there was an accident on a motorway, if you couldn't use it for three or four weeks. Inherently, we have not built sufficient resilience into our systems. That's not the same as high availability.
It's being able to recover after something bad and unexpected has happened. That, because we are now so dependent upon data, that actually comes back to this very same problem of protecting that data so that if we lose it in one way, we can regain it in another way, that we can rebuild our systems, which are more and more data-defined systems, that we can restore the services and recover the business operation. That digital resilience, cyber resilience, is not simply about restoring IT systems anymore.
It's about actually a strategic issue to do with businesses, organizations, and the services which we all depend upon. I like the analogies that you postulated. I think it's worth following the logic of that. As you quite rightly say, if I have a crash on the motorway, I don't really want to wait six weeks for it to be rebuilt. I've actually been paid good money for doing it as well. I've been paid good money for investigating breaches in various different contexts. In most of the cases, what was the root cause of a breach?
It's not the equivalent of a car crash, which is a failure in operational control. It tends to be a systemic flaw. It tends to be a failure in what Mike quite correctly points out, which is the architectural decision to build in resilience.
Now, following that logic through, we might say, surely, anybody with a modicum of sense would build in resilience into their systems. The reason that they don't is that this is expensive. It costs more in hardware. It costs more in net resources. It costs more in software engineering time. It costs more in building operational processes. People take a flawed risk management approach and say, what we can do is we can assume that this particular happening is so unlikely that it's nearly not worth our time building a resiliency defense against it.
As Mike quite correctly says, time after time, that has been proven to be flawed. Why do we do this?
Well, I suspect we as humans are simply not very good at risk management. We are not very good at imagining and envisioning impacts of different risk scenarios. We tend to gravitate towards either low likelihood, low risk, and with the normal homegrown day, or we think about the abstruse and obscure. What happens if an airplane lands on my data center? We don't tend to think what happens if the groundwater plane in which my data center is housed floods.
Or as Mike quite correctly says, if a failure in software engineering, failure in architecture, I would say, to design resilient systems results in significant outages. Then the resulting remediation is not simply clearing the carnage off the motorway, but in fact, is rebuilding the motorway, which has collapsed underneath the impact.
Yes, I think if we delve into the root cause, we follow the logic back to this. We need to be, as cybersecurity professionals, much more cognizant of the impact and we need to make our voices heard. Because as Mike said, it's not just technology that we're dealing with. Technology is the means. What we're dealing with here are significant business-threatening flaws. As I said at the beginning of the call, it's to Jaguar's credit and to Mark's credit that they did not become non-trading organizations permanently as a result of such a significant outage.
But clearly, in hindsight, I hope somebody looked at it and said, we made decisions to circumvent trust and safety measures. In hindsight, it would have served us well to implement despite the additional cost.
Yes, well, so it's the challenge of balancing being first to market often against the cost of building a robust and resilient system. Sometimes it takes time and bad things to happen for them to be resilient. You can look at how, for example, the railways or the air industry evolved to improve safety by making changes. Some of this was driven by legislation, but some of it was driven by the way in which you build things.
Now, the world telecommunications system is an interesting example of something that is highly resilient. One of the fascinating things to me is that the move from the Strowager-type point-to-point contact system for communications to the internet is inherently much more resilient in the sense that it enables multiple routings to take place so that if you have single points of failure, you can get round things. What we don't typically do when we build systems is think in those terms from the beginning.
It is very often the case that the new digital business application is seen as something to kill the competition rather than to something that's really going to provide a long-term service. I was, earlier in my career, I had the opportunity to build an ISP from scratch, just add cash, as they said. One of the things I did is for my national backbone, I used a SDH ring from a company, let's call them wobble and clueless, to preserve their anonymity. They sold me this ring and they said the advance of the ring is that signals can go in either part.
You have, as Mike said, resiliency. One day, my lovely national backbone went down and I said, how did this happen?
They said, there was a fire. They said, how could this be? You have sold me this wonderful ring with diverse pathways.
They said, ah, yes. Apparently, both parts of the ring went through the same conduit at one point. It was a bit of a flattened ring. I felt hard done by that point. I think that's, as you say, that's the problem that we, again, we rely on resilience in the layers below. As you say, in theory, the internet network will converge, but oftentimes you will find that many networks are sharing the same pathway. Although now we do have many more diverse pathways. I mentioned Portugal. I see there are fibers being laid from Portugal to Brazil and down the coast, down to Africa, down to Cape Town.
We are actually starting to get diverse pathways that don't necessarily all rely on hitting maize. It was Mike who told me more than once that risk management is combined of the probability and the impact. What you just described, Jonathan, the probability of that ring failing was something that you did not expect because it was described differently, but the impact was very high. That is something that also should factor in. I think this is really, it sounds like a truism and it probably is to say, okay, yeah, maybe we should just apply proper risk management.
That's true for Marks and Spencers and that's true for Jaguar, but that is also true for each and every one of us when it comes to the way how we deal with our own personal data and how others are expected to deal with this data. Applying proper risk management would be a good starting point also to cut the way back to this privacy discussion that we had.
I think the resilience part, that is understood and I really like the way how you discussed that just right now, but what can we derive for the final five to ten minutes for the next steps that we can do when it comes to hopefully not being in a post-privacy era? What would be something that we would expect from our own behavior and from those who are managing the data on behalf of us? Where could we start?
If I may, I think that one place we can start is in the technical architecture. We can, as Mike says, when we are looking at our telecommunications infrastructure, we can make choices that hopefully take on as much resilience as possible. Overlaying that with hopefully the resilience in the internet giving us multiple paths I think is certainly a positive way forward. I think also that we need to be thinking of the other layers as well.
How can we make the way that we store and transmit data, so the data layer of our technical architecture, how can we make that resilient against attack, against breach disclosure? Of course, there we're looking, as we say, at data security message such as encrypting, such as masking, truncation, tokenization, so forth. Then further up, how do we make our applications resilient? How do we make our authentication systems resilient? How do we make sure that authorization is not broken? BOLA still remains at the top of the OWASP list.
How do we make sure that broken object level authorization is not a problem? I think it is the challenge as security architects, which is I think still an important discipline, to make sure that we contribute in a meaningful way to technical architectures and that every layer of the architecture we put in, as Mike quite rightly said, cybersecurity controls that safeguard, protect, detect, and respond to abnormal and inappropriate activity. Your thoughts, Mike? So for 20 years, I have been part of a medical research project I am a subject.
Every couple of years, they take blood from me and take various tests to see ultimately what I'm going to dial. Now, I think that that is a valuable use because it is collecting data. That data is not going to help me, but it's going to help the future. I also know, because this is quite readily possible, that medical data can be used and exploited without disrupting my privacy. The data will be anonymized, that it will be capable, whilst it is anonymized, of being exploited and usefully worked on to help to develop future medicine.
So I'm doing that pro bono because I can see there is a good outcome. What I think is missing from this is that there are many commercial organizations that want my data, that collect my data quite legally, quite legitimately, and what I get back from that and what society gets back from that is much less than what that data is valued at. The thing is that as a society, we have the ability to, through these technologies, to gain enormous insights and benefits through that data.
It's not clear to me that those benefits of me giving up that privacy are, in fact, coming back to myself and to society in general. That is, to some extent, a result of the lack of the law. It is to some extent that one or two people have realized, these big organizations have realized the value of that data, whereas other people haven't. I would simply say that most of the cyber adversaries that steal your data have a much greater understanding of its value than many of the organizations that are supposedly keeping hold of it.
We need to redress balances, both at a legal, a societal level, as well as at a cyber security level. One thing that I really learned for today is that this topic is so much bigger than it, so that it cannot fit into one podcast episode. We need to reconvene and discuss many more aspects of this. We focused very much on the resilience part, but we also touched upon the aspect of what is within the power of the individual to say, I want to give data away in a meaningful way and also in a very protected way, as you said, anonymized. You're doing it because you want to and you think it's useful.
This kind of consent, free will... At the moment, consent is irrevocable. I cannot withdraw my consent once I have consented to give my data, not in a meaningful way.
I'm sorry, I just realized I talked over you. Sorry.
No, that's good. It's the same with giving up copyrights or something like that. Once you give it away, it's gone. The same happens here. But as you've mentioned, we have at least technologies that can support us in bad things happening. You've mentioned privacy preserving computation, and I think that's a good starting point. If we are a bit more optimistic, are there a few thoughts that we can use on a lighter tone at the end of this episode while we have to come back to discuss this in more detail when it comes to all these additional aspects that we just missed for today?
A final thought when it comes to maybe giving back control to the individual. About 20 years ago, Jeremy Clarkson read one of these articles on privacy of data and said, I don't care. He published his bank account details in the paper. Sure enough, his bank account was raided. So privacy does matter. We might have lost it, but it's still something that can be painful if it is misused.
Jonathan, your final thoughts? We're not yet through, but we'd be too close down for today. Sure. I think my final thoughts are, as you said, there are technical measures that can make self-sovereign data governance the possibility of giving and withdrawing consent to data usage meaningful, which it currently is not. I think these need to be backed up by meaningful legislation. I think that privacy legislation is important and I think it should be protected and bolstered.
I do think, as Mike quite rightly says, privacy is something that you don't realize how much it means to you until you don't have it. Or we may all learn to our cost. This was intended to be an open discussion and it was an open discussion. I really liked the way how we also worked our way through this topic.
As I said, we need to come back, but I think if we sum it up, we need to make sure that we as organizations or that organizations in general apply proper risk management to prevent the bad things from happening. And we as the individual, we need to make sure that we use our free will and decide where we want to store our data and maybe be more critical when it comes to using services in general. Maybe that's a starting point. But as we are in that post-privacy era, I don't know how long has it been that we said assume breach. How long is this around that term, 10 years, 12 years?
So I think that is something that we should consider, but maybe we can still protect from bad things happening. Without being contributed, you say assume breach and we say zero trust, but I've yet to see that making any meaningful impact in the way people do risk management or indeed technical architecture. I would say there's some final words. There are three different dimensions to privacy. There is the personal dimension, which is what I personally feel is private to me, that there is a societal view of privacy. Privacy is not the same, or what is private is not the same in all societies.
For example, for a long time in Norway, there was an acceptance that everybody's tax returns were publicly available. Finally, there is a legal definition of privacy. What has happened is that we get mixed up between what the law says is private, what we actually feel is private, and what as a community we want to know and keep secret. And those things may be in conflict. Right. I leave it with that as a summary for today or as a final thought for today, which also gives food for thought, at least for me. Thank you very much, Mike and Jonathan, for being my guests today.
For me, it was an inspiring discussion and much to digest afterwards. Let us follow up on that very soon.
Thanks, Mike. Thanks, Jonathan. Thank you very much for inviting me. Thank you. Bye-bye.