News

Privacy Can Make Security Impossible

← Back to news

Everyone agrees that privacy cannot exist without security. But the fact that privacy requirements sometimes stand in the way of, or even make impossible, that much-needed protection is far less widely recognized.

For example, to prevent privacy-sensitive data from falling into the wrong hands or lingering in the wrong places, it is desirable to apply some form of data loss prevention. Such security technology can detect privacy-sensitive information and apply extra protection, so that this information cannot simply be sent, copied, or even printed. Exactly what is desirable from a privacy perspective.

But to determine whether a planned action—such as copying, emailing, or printing—concerns potentially privacy-sensitive information, all such user actions must be assessed. And that is only possible by monitoring the content of all (planned) user actions. Which in turn means that every time a user wants to email, print, or copy, a check will be made to see whether that is permitted. Yet that is precisely what proponents of a strict privacy regime see as a threat. It is quickly labeled as ‘Big Brother’ watching everyone. Whereas in this case, the aim is genuinely to safeguard the privacy of the stakeholders. This is not primarily about the privacy of those processing the information, but about the privacy of the owners or providers of the information.

There are known situations where the above reasoning led to no data loss prevention technology being implemented. This maximally safeguarded the privacy of the organization’s employees. But it also created a significant chance that the privacy of customers whose information is being processed would at some point be violated, because information could leak.

It becomes even more pressing when it comes to Security Monitoring—an increasingly crucial capability for detecting and ultimately preventing cybersecurity incidents. By definition, with security monitoring you want to record and analyze events and actions that are, in isolation, legitimate and scarcely worth investigating, but which, when combined with other events, may indicate a pattern or a complex attack. Such an attack may target privacy-sensitive data, and to protect that data, it must be possible to monitor and analyze the activities of employees (and perhaps customers). If that were not permitted for (perceived) privacy reasons, it would ultimately not benefit privacy.

When setting and applying privacy rules, you must therefore always consider the ultimate purpose of actions that could potentially interfere with privacy. An overly rigid interpretation of privacy rules may not benefit security. And privacy ends up being the victim as well.

It should therefore be clear that privacy and security are inextricably linked, and that the privacy aspect must always be included in security projects and vice versa, with the most weighty element for the client determining whether privacy is married to security, or security is married to privacy!