- Troy Hunt exposes how companies avoid disclosing data breaches.
- Argues for transparency, disclosure benefits customers and companies’ reputations.
Imagine entrusting your most sensitive information to a company, only to discover months or even years later that it had been compromised in a data breach – a breach the company chose to keep secret. Unfortunately, this scenario, all too common in our digital age, forms the crux of Troy Hunt’s latest thought-provoking piece, “The Data Breach Disclosure Conundrum.”Â
Hunt, a cybersecurity expert known for public education and outreach on security topics, challenges the pervasive culture of silence surrounding data breaches in the article. He makes a compelling case for transparency that both business leaders and consumers need to hear.Â
“An organisation may not need to disclose [breaches] to individuals”, Hunt wrote, addressing the legal landscape surrounding data breach disclosures. He highlights that while regulations like GDPR require reporting to authorities, they often leave room for interpretation when notifying affected individuals. This grey area frequently leads companies to choose non-disclosure, prioritising brand protection over customer awareness.Â
Hunt illustrates this dilemma with the case of Deezer, a French streaming service that experienced a substantial breach affecting 229 million customer records. Despite the scale of the incident, Deezer initially chose not to inform impacted users, citing compliance with data protection regulations.
Is this *finally* the @Deezer disclosure notice to individuals, a month and a half later? It doesn’t look like a new incident to me, anyone else get this? https://t.co/RrWlczItLm
— Troy Hunt (@troyhunt) February 20, 2023
The purpose of Hunt’s article was to share his strong advocacy for full disclosure while presenting several key arguments that challenge this secretive approach:
- Data ownership: Hunt argues that personal information ultimately belongs to individuals, not companies. This ethical standpoint suggests that people have a right to know when their data has been compromised. He questions whether companies can unilaterally withhold information about customer data breaches.
- Risk assessment: Companies often underestimate the potential harm of seemingly benign data exposure. Hunt emphasises that even basic information can be weaponised for phishing or identity theft. He points out that what may seem inconsequential to a company could have significant implications for individuals.
- Filling the information vacuum: When companies remain silent, Hunt warns that misinformation can spread rapidly. Proactive disclosure allows organisations to control the narrative and provide accurate information. He cites examples where the absence of official communication led to speculation and incorrect information circulating on hacking forums and in media reports.
- Long-term reputational damage: Hunt highlights that attempting to conceal a breach often backfires, leading to more severe reputational damage when the truth eventually emerges. He parallels his 2017 piece on “The 5 Stages of Data Breach Grief,” illustrating how companies that double down on concealment often find themselves in an ever-deepening hole.
- Customer trust and decency: Fundamentally, Hunt argues that notifying affected individuals is simply the right thing to do, fostering trust and demonstrating corporate responsibility. He posits that this approach aligns with customer expectations and, increasingly, with government mandates.
The article further delved into the backlash companies face when breaches are eventually revealed after attempted cover-up. The cybersecurity expert cites the infamous example of Uber’s 2016 breach concealment, which resulted in far more negative press than the breach itself. That case study is a cautionary tale, illustrating how non-disclosure can lead to legal consequences and severe reputational damage.
Hunt also addresses the common justification that non-disclosure protects customers, systematically dismantling this argument. He points out that in most cases, the data is already in the hands of malicious actors. By withholding information, companies are leaving their customers vulnerable and uninformed.
He was also right to highlight the evolving landscape of public perception regarding data breaches. According to his observation, we have reached a turning point where organisations are now judged more on how they handle incidents than on their occurrence.
Such a shift in focus underscores the importance of transparent and ethical breach management, and therefore, Hunt calls for organisations to rethink their approach to data breach disclosures.
Author
View all postsDashveenjit is an experienced tech and business journalist with a determination to find and produce stories for online and print daily. She is also an experienced parliament reporter with occasional pursuits in the lifestyle and art industries.