Drawing insights from many fascinating stories about data breaches, Solove and Hartzog show how major breaches could have been prevented or mitigated through a different approach to data security rules. Current law is counterproductive. It pummels organizations that have suffered a breach but doesn't address the many other actors that contribute to the problem: software companies that create vulnerable software, device companies that make insecure devices, government policymakers who write regulations that increase security risks, organizations that train people to engage in risky behaviors, and more.
Although humans are the weakest link for data security, policies and technologies are often designed with a poor understanding of human behavior. Breached! corrects this course by focusing on the human side of security. Drawing from public health theory and a nuanced understanding of risk, Solove and Hartzog set out a holistic vision for data security law-one that holds all actors accountable, understands security broadly and in relationship to privacy, looks to prevention and mitigation rather than reaction, and works by accepting human limitations rather than being in denial of them. The book closes with a roadmap for how we can reboot law and policy surrounding data security.
Woodrow Hartzog is a Professor of Law and Computer Science at Northeastern University School of Law and the Khoury College of Computer Sciences. He is the author of Privacy's Blueprint, and his research on privacy, media, and robotics has been published in both scholarly and popular publications. He has testified multiple times before Congress and has been quoted or referenced in numerous articles and broadcasts, including NPR, BBC, and The Wall Street Journal.
Data Protection .|. Digital Ethics .|. Digital Trust .|. AI Ethics .|. Human .I. Pan-African. ||. Retweets are not endorsements.
Have struggled with the limited attention to data security. Focusing on the data breach lends credence to act and places heavy responsibility on the controller without dealing with the actual source of the breach. Excerpt from Daniel Solove and Woodrow Hartzog, Breached. https://t.co/GLHpwQ99Mu
Founded by Prof. @DanielSolove, TeachPrivacy provides privacy & data security training. Engaging and interactive 150+ topics: HIPAA, PCI, FERPA, phishing, GDPR
Published in 2022! Daniel Solove & Woodrow Hartzog, BREACHED! WHY DATA SECURITY LAW FAILS AND HOW TO IMPROVE IT (OUP 2022) https://t.co/kCmbc6lOJJ @DanielSolove @Hartzog