The co-op bookstore for avid readers
Book Cover for: Breached!: Why Data Security Law Fails and How to Improve It, Daniel J. Solove

Breached!: Why Data Security Law Fails and How to Improve It

Daniel J. Solove

A novel account of how the law contributes to the insecurity of our data and a bold way to rethink it.

Digital connections permeate our lives-and so do data breaches. Given that we must be online for basic communication, finance, healthcare, and more, it is alarming how difficult it is to create rules for securing our personal information. Despite the passage of many data security laws, data breaches are increasing at a record pace. In Breached!, Daniel Solove and Woodrow Hartzog, two of the world's leading experts on privacy and data security, argue that the law fails because, ironically, it focuses too much on the breach itself.

Drawing insights from many fascinating stories about data breaches, Solove and Hartzog show how major breaches could have been prevented or mitigated through a different approach to data security rules. Current law is counterproductive. It pummels organizations that have suffered a breach but doesn't address the many other actors that contribute to the problem: software companies that create vulnerable software, device companies that make insecure devices, government policymakers who write regulations that increase security risks, organizations that train people to engage in risky behaviors, and more.

Although humans are the weakest link for data security, policies and technologies are often designed with a poor understanding of human behavior. Breached! corrects this course by focusing on the human side of security. Drawing from public health theory and a nuanced understanding of risk, Solove and Hartzog set out a holistic vision for data security law-one that holds all actors accountable, understands security broadly and in relationship to privacy, looks to prevention and mitigation rather than reaction, and works by accepting human limitations rather than being in denial of them. The book closes with a roadmap for how we can reboot law and policy surrounding data security.

Book Details

  • Publisher: Oxford University Press
  • Publish Date: Mar 1st, 2022
  • Pages: 256
  • Language: English
  • Edition: undefined - undefined
  • Dimensions: 9.52in - 6.49in - 1.04in - 1.07lb
  • EAN: 9780190940553
  • Categories: Computer & InternetScience & TechnologyCivil Rights

About the Author

Daniel J. Solove is the John Marshall Harlan Research Professor of Law at the George Washington University Law School. He is also the founder of TeachPrivacy, a company that provides privacy and data security training programs to businesses, law firms, healthcare institutions, schools, and other organizations. One of the world's leading experts in privacy law, Solove is the author of several books and textbooks. Professor Solove blogs at Privacy+Security Blog and as a LinkedIn "thought leader."

Woodrow Hartzog is a Professor of Law and Computer Science at Northeastern University School of Law and the Khoury College of Computer Sciences. He is the author of Privacy's Blueprint, and his research on privacy, media, and robotics has been published in both scholarly and popular publications. He has testified multiple times before Congress and has been quoted or referenced in numerous articles and broadcasts, including NPR, BBC, and The Wall Street Journal.

More books by Daniel J. Solove

Book Cover for: On Privacy and Technology, Daniel J. Solove
Book Cover for: The Eyemonger, Daniel J. Solove
Book Cover for: Understanding Privacy, Daniel J. Solove
Book Cover for: Information Privacy Law, Daniel J. Solove
Book Cover for: The Future of Reputation: Gossip, Rumor, and Privacy on the Internet, Daniel J. Solove
Book Cover for: Nothing to Hide: The False Tradeoff Between Privacy and Security, Daniel J. Solove
Book Cover for: The Digital Person: Technology and Privacy in the Information Age, Daniel J. Solove
Book Cover for: EU Data Protection and the Gdpr: [Connected Ebook], Daniel J. Solove
Book Cover for: Consumer Privacy and Data Protection: [Connected Ebook], Daniel J. Solove

Praise for this book

"Data security is one of the most challenging problems of our times. Solove and Hartzog provide a readable and smart account of how policymakers keep focusing on the wrong details at the expense of the bigger picture. Breached! is a book for anyone who is interested in why data breaches keep happening and what the law should do about it." -- Bruce Schneier, author of Data and Goliath and Click Here to Kill Everybody"Solove & Hartzog have given us an exceptionally insightful overview of key data security challenges and the law's dysfunctional attempts to deal with them. Their scholarship helps move us past the blame-the-victim law of data breaches; it advances the roles of both thoughtful privacy practices and secure design as keys to improving data ecosystem health. Executives, policymakers, lawyers, compliance officers, and engineers will all greatly benefit from their engaging effort to develop a more holistic notion of data security law." -- Edward McNicholas, Global Cybersecurity Practice Co-Leader, Ropes & Gray"A fascinating exploration of the ways that our fixation on individual data breaches has limited the effectiveness of data security law because we so often fail to see beyond the immediate incident in the news and the latest victim. Their brilliant argument that we need a comprehensive legal regime that breaks down the barriers between privacy and security and expands our understanding of the different stakeholders who play a role in protecting against security breaches is a much needed wake-up call. More than that, they also offer a clear roadmap for how to actually do a better job protecting our most valuable digital assets moving forward using not just technical controls but also a wide range of absolutely essential legal and policy tools." -- Josephine Wolff, Associate Professor of Cybersecurity Policy, Tufts University"All too often, discussions of data security are mired in technical jargon and focused too much on data breaches. Breached! cuts through the confusion and explains how and why we have been thinking about data security and breaches in entirely the wrong way. Clearly written and accessible, yet wise and insightful, Breached! offers a sensible way forward for data security. Solove and Hartzog show how the future of data security requires us to look at the problem holistically, to understand how good privacy rules can also promote good security outcomes, and to realize that when it comes to data security, we have to focus on human beings as much as technology. A breath of fresh air on an important and often-ignored topic, this is essential reading not just for policymakers, but for anyone interested in the safety and security of our digital world." -- Neil Richards, Professor of Law, Washington University"A compelling account of where data security law has gone wrong plus convincing advocacy of where it should go. This book should be read by anyone involved in privacy and cybersecurity." -- Paul Schwartz, Professor of Law, Berkeley Law School"With Breached!, Daniel Solove and Woodrow Hartzog have made a foundational contribution to data security law. With deep insight, compelling storytelling, and even humor (and some needed fright), the scholars show that lawmakers must better understand that beneath the high-tech wizardry and data security do's and don'ts are normal, fallible people. This book is a must read for everyone concerned about the security of our personal data. It is creative and practical in its solutions. Bravo!" -- Danielle Keats Citron, Jefferson Scholars Foundation Schenck Distinguished Professor in Law and Caddell and Chapman Professor of Law, University of Virginia School of Law"Solove and Hartog offer a clear, accessible, persuasive case that data security today needs a systematic approach, far beyond just mopping up breaches. I hope every regulator or legislator working on the subject reads this book and follows their advice." -- William McGeveran, Associate Dean for Academic Affairs, Gray, Plant. Mooty, Mooty, and Bennett Professor of Law, University of Minnesota Law School