European Data Protection Day: The Value of Privacy

25/01/2022
|
The value of privacy - main photo

January 28, European Data Protection Day: The Value of Privacy.

“Our parents, grandparents… were able to regulate the industries of their time. Now it is up to us; this is our moment: we must regulate the activity of big tech; it is time to put an end to the data economy. As long as our data continues to be sold to the highest bidder, there will continue to be abuses of all kinds. Situations of discrimination, marginalisation, and manipulation will continue to occur, such as attempts to change the outcome of an election”.

Carissa Veliz – Privacy Is Power

As a globalised society in constant change and expansion, especially as a result of the Internet, personal data has become the gold of the 21st century.

Data is a valuable asset for businesses and governments, and an accessible target for cybercriminals, who see it as a prized haul.

In recent years, we have been facing an uncontrolled rise in cyberattacks. This is putting the security of our personal data—and therefore our privacy—at risk. The issue is that, today, we are far better at collecting data than protecting it, so cybersecurity—building a cybersecurity culture—will undoubtedly be the major outstanding challenge for businesses in the coming years.

Today, we are far better at collecting data than protecting it; cybersecurity is our major outstanding challenge

As a company, it is worth asking: what is the value of privacy? why is it important to invest in protecting the personal data of our customers, users, employees, etc.? Technology has taken on enormous importance in both our working and personal lives. Creating processes where the protection of personal data is at the heart of our corporate policies must become a reality. After all, our databases—the new oil of the digital society—are highly attractive to cybercriminals.

It is important to understand that a cyberattack is any illegal action carried out through computer systems that seeks to disrupt the normal functioning of the victim’s information systems.

It is also true that we all think cyberattacks are complex and require a major investment of resources by cybercriminals, but in reality what they want is to access as much information as possible with the least possible investment, and the more users and companies, the better. That is why they look for techniques that are simple and that make human error easy.

What are the new techniques cybercriminals are using to get hold of our data?

-Dumpster diving. Through this technique, still little known to the general public, the attacker searches for information in the user’s rubbish bin—information that may be useful to a business or another user. Sometimes it is used to impersonate the user and, in this way, try to access other restricted areas of the hacked user’s online accounts. As the saying goes, “One man’s trash is another man’s treasure.”

-Phishing. Without a doubt, one of the most popular techniques. It refers to sending emails that appear to come from trusted sources (such as banks, energy companies, etc.) but in reality aim to manipulate the recipient in order to steal confidential information. The danger of this type of cyber scam is that it is becoming increasingly sophisticated, making it harder for users to identify the deception.

Example of one of the latest phishing campaigns, this time impersonating Ibercaja, in which cybercriminals attempt to obtain the user’s login details.

Spear phishing. Unlike the technique described above, spear phishing targets a specific employee or executive at a specific company. The attacker studies the victim in detail beforehand and creates fully personalised emails (pretending to be a supplier, for example) in order to access the information they are seeking.

Malware. With this technique, code is created that allows the computer system to be compromised. In this way, the cybercriminal can access or steal information quickly and without leaving a trace.

-Ransomware. All company information—or access to it—is hijacked by encrypting it. The cybercriminal’s objective in this case is to demand a ransom in exchange for providing the key that allows the data to be decrypted.

The value of privacy: added value for companies that want to earn their customers’ trust

In conclusion, it is particularly important for companies to decide to invest in a personal data protection programme that reflects the reality of their organisation, and to implement technical and organisational measures that guarantee the security of that personal data.

The value that privacy has taken on in our personal and professional relationships is proving to be a turning point for many companies, which are taking advantage of this growing awareness among institutions and citizens to improve their policies and earn users’ trust.

PRIDATECT, onBRANDING’s official partner for Data Protection

Digital Identity

Methods for analyzing and
assessing online
reputation damage