FB
F. Bisogni
info
Please Note
<p>This page displays the records of the person named above and is not linked to a unique person identifier. This record may need to be merged to a profile.</p>
5 records found
1
This article investigates the relationship between data breaches and identity theft, including the impact of Data Breach Notification Laws (DBNL) on these incidents (using empirical data and Bayesian modeling). We collected incident data on breaches and identity thefts over a 13-year timespan (2005–2017) in the United States. Our analysis shows that the correlation is driven by the size of a state. Enacting a DBNL still slightly reduces rates of identity theft; while publishing breaches notifications by Attorney Generals helps the broader security community learning about them. We conclude with an in-depth discussion on what the European Union can learn from the US experience.
...
This article investigates the relationship between data breaches and identity theft, including the impact of Data Breach Notification Laws (DBNL) on these incidents (using empirical data and Bayesian modeling). We collected incident data on breaches and identity thefts over a 13-year timespan (2005–2017) in the United States. Our analysis shows that the correlation is driven by the size of a state. Enacting a DBNL still slightly reduces rates of identity theft; while publishing breaches notifications by Attorney Generals helps the broader security community learning about them. We conclude with an in-depth discussion on what the European Union can learn from the US experience.
Information availability and data breaches
Data breach notification laws and their effects
In response to evolving cybersecurity challenges, global spending on information security has grown steadily, and could eventually reach a level that is inefficient and unaffordable. A better understanding of new socio-technical-economic complexities around information security is urgently needed, which requires both reconsideration of traditional cybersecurity issues and investigation of new and unexplored research directions. In recent times, interdisciplinary research has elucidated the many economic and behavioural dimensions of security. This research is rooted in the field of Information Security Economics, and primarily addresses disclosure policy and specifically, data breach notification laws. Data breach notification laws require any business that suffers a data breach, or believes that it suffered a data breach, to notify customers about the incident that entails the unauthorised acquisition of unencrypted and computerised personal information. Such laws offer incentives to the party who owes the notification duty to minimise the number of triggering events and also enable the affected third parties to diminish the consequences, namely identity theft, and to make prudent choices in the future. Public policy that seeks to improve the effects of data breach notification legislation must be informed by a comprehensive understanding of the behaviour and incentives of the organisations and individuals involved in the notification flow. Thus, this dissertation poses the fol-lowing research question: What are the effects of the provisions of data breach notification laws on (1) communications issued by breached organisations to their customers; (2) the timing of breach detection and reaction; (3) the number of data breaches reported; and (4) the volume of identity theft stemming from data breaches? As we live in the era of big data, it was possible to access and utilise data on the number of breaches and the number of notifications sent. However, it was also necessary to examine further the types of breaches that occurred as well as the types of communication sent and how individuals perceived them. This analysis allows to develop specific metrics, activating critical thinking about the measurement and the underlying phenomenon. This dissertation examines these notions and answers the research question through one theoretical peer-reviewed paper and four peer-reviewed empirical studies, each addressing a separate aspect related to the implementation of notification mechanisms, specifically data breach notification laws. Chapter one studies the role of information availability in the cybersecurity landscape and describes a theoretical model for evaluating data breach notification laws as a solution to tackle information asymmetries in the digital arena. Chapter two fo-cuses on the tangible tools needed to implement such laws, specifically the notification process itself, and analyses the extent to which each organisation has leeway to ensure compliance with the law. Drawing on the variation in time for data breach detection and notification and letter content analysis, chapter four discusses the necessity to implement superseding law in order to bring coherence to the diverse approaches used in different geographical areas. Chapter five then addresses underreporting of data breaches. Finally, chapter six explores the relationship between data breaches and identity theft. The dissertation concludes by reflecting on the shared elements across the studies. The conclusion reflects on the role of disclosure policies in the information security arena and on the implications, given the results of these studies, for European data breach notification policies.
...
In response to evolving cybersecurity challenges, global spending on information security has grown steadily, and could eventually reach a level that is inefficient and unaffordable. A better understanding of new socio-technical-economic complexities around information security is urgently needed, which requires both reconsideration of traditional cybersecurity issues and investigation of new and unexplored research directions. In recent times, interdisciplinary research has elucidated the many economic and behavioural dimensions of security. This research is rooted in the field of Information Security Economics, and primarily addresses disclosure policy and specifically, data breach notification laws. Data breach notification laws require any business that suffers a data breach, or believes that it suffered a data breach, to notify customers about the incident that entails the unauthorised acquisition of unencrypted and computerised personal information. Such laws offer incentives to the party who owes the notification duty to minimise the number of triggering events and also enable the affected third parties to diminish the consequences, namely identity theft, and to make prudent choices in the future. Public policy that seeks to improve the effects of data breach notification legislation must be informed by a comprehensive understanding of the behaviour and incentives of the organisations and individuals involved in the notification flow. Thus, this dissertation poses the fol-lowing research question: What are the effects of the provisions of data breach notification laws on (1) communications issued by breached organisations to their customers; (2) the timing of breach detection and reaction; (3) the number of data breaches reported; and (4) the volume of identity theft stemming from data breaches? As we live in the era of big data, it was possible to access and utilise data on the number of breaches and the number of notifications sent. However, it was also necessary to examine further the types of breaches that occurred as well as the types of communication sent and how individuals perceived them. This analysis allows to develop specific metrics, activating critical thinking about the measurement and the underlying phenomenon. This dissertation examines these notions and answers the research question through one theoretical peer-reviewed paper and four peer-reviewed empirical studies, each addressing a separate aspect related to the implementation of notification mechanisms, specifically data breach notification laws. Chapter one studies the role of information availability in the cybersecurity landscape and describes a theoretical model for evaluating data breach notification laws as a solution to tackle information asymmetries in the digital arena. Chapter two fo-cuses on the tangible tools needed to implement such laws, specifically the notification process itself, and analyses the extent to which each organisation has leeway to ensure compliance with the law. Drawing on the variation in time for data breach detection and notification and letter content analysis, chapter four discusses the necessity to implement superseding law in order to bring coherence to the diverse approaches used in different geographical areas. Chapter five then addresses underreporting of data breaches. Finally, chapter six explores the relationship between data breaches and identity theft. The dissertation concludes by reflecting on the shared elements across the studies. The conclusion reflects on the role of disclosure policies in the information security arena and on the implications, given the results of these studies, for European data breach notification policies.
Estimating the size of the iceberg from its tip
An investigation into unreported data breach notifications
This article investigates the adequateness of data breach notification laws and the possible impact of a federal law in the United States. Based on the analysis of 445 notifications issued in 2014, three observations for law development are presented. First, the question about underreporting is raised and a possible option for facilitating its emergence is proposed. Second, the specification of the dates of the breach detection and of the breach itself are identified as essential to foster consumers’ reaction. Finally, a stricter regulation of the content of the notification is suggested to avoid firms minimizing the actual risk.
...
This article investigates the adequateness of data breach notification laws and the possible impact of a federal law in the United States. Based on the analysis of 445 notifications issued in 2014, three observations for law development are presented. First, the question about underreporting is raised and a possible option for facilitating its emergence is proposed. Second, the specification of the dates of the breach detection and of the breach itself are identified as essential to foster consumers’ reaction. Finally, a stricter regulation of the content of the notification is suggested to avoid firms minimizing the actual risk.
While the discussion about a federal law on data breach notification is ongoing and a rash of large, costly data breaches has galvanized public interest in the issue, this paper investigates on the phenomenon of data breach notification letters. In case of any data breach a company faces a number of dilemmas on how to inform the customers.
The choices that a company makes on the missive content result decisive in having a prompt customers’ reaction against identity theft and eventually in shaping the relations between customers and the organization itself.
Starting from the various regulations in place in US, the analysis has been performed focusing on the content of over 210 letters sent in US in the first semester of 2014. In particular letters are classified based on elements that can be isolated and analysed, e.g. the level of transparency used in communicating the event causing the breach or the time span between data breach identification and its notification to customers. In the end we labeled the data breach notifications according to the message customers might perceive when reading them. As a result six message types have been identified. This investigation contributes to the ongoing debate on the federal law on data breach notifications,
highlighting limitations and effects of the already implemented State laws.
...
While the discussion about a federal law on data breach notification is ongoing and a rash of large, costly data breaches has galvanized public interest in the issue, this paper investigates on the phenomenon of data breach notification letters. In case of any data breach a company faces a number of dilemmas on how to inform the customers.
The choices that a company makes on the missive content result decisive in having a prompt customers’ reaction against identity theft and eventually in shaping the relations between customers and the organization itself.
Starting from the various regulations in place in US, the analysis has been performed focusing on the content of over 210 letters sent in US in the first semester of 2014. In particular letters are classified based on elements that can be isolated and analysed, e.g. the level of transparency used in communicating the event causing the breach or the time span between data breach identification and its notification to customers. In the end we labeled the data breach notifications according to the message customers might perceive when reading them. As a result six message types have been identified. This investigation contributes to the ongoing debate on the federal law on data breach notifications,
highlighting limitations and effects of the already implemented State laws.