Cybersecurity In the event of major data breaches, such as the recent one at Odido, there is… Michiel Hennink one group that has no say in the handling: the victims. This has to change, because sometimes it is in their interest to pay the criminals, despite the prevailing wisdom.
What do you do when you are robbed at gunpoint on the street – your money or your life? Option one: your money. You curse the criminal, report it and hope it was a one-off. Option two: you don’t want to maintain the revenue model of street robbers, so you let yourself be shot. You choose ‘the social interest’, which is nice, right? Maybe. But most parents will not advise this to their child.
What do we see if we compare the Odido data breach (6.5 million customers) with a street robbery? The Odido management opted for option two: don’t pay, ‘just shoot us’. But with a ‘small’ nuance: it was not the directors who were sacrificed, but their 6.5 million customers, because it was their data that were published.
The Odido case is not an isolated case. There are three important similarities with other major data breaches, such as those at Clinical Diagnostics (population research, almost one million women) and ChipSoft (hospitals, millions of patients and hundreds of thousands of medical records).
Firstly, millions of citizens are affected, but have no voice in decision-making after the data breach. Such as: to negotiate or not to negotiate, to pay or not to pay? Odido was able to buy off the hackers one euro per person affectedbut didn’t. A far-reaching weighing of interests in which the victims’ interests were not (formally) represented.
Generic sentences
A second common denominator is that Odido, Clinical Diagnostics, ChipSoft and the healthcare institutions involved only briefly, impersonally and delayed information. A few sentences with generic information and then radio silence again. Even after the most sensitive (negotiation) phases are over. The newspaper often knows more then victims. Healthcare companies such as ChipSoft and Epic were previously even accused of imposing confidentiality obligations in IT contracts. Transparency as a threat instead of a core value.
The third similarity: companies appear to be digitally vulnerable (regularly culpable, such as Clinical Diagnostics and Odido), but for years they made millions in profits with precisely those vulnerable products and processes. While the painful consequences especially for customers and patients. Compensation law offers those affected relatively few options and leads to drawn-out processes with uncertain outcomes.
The benefits for one, the burdens for the other – such as the chief commercial officer Odido said it cynically towards Nu.nl expressed: “I understand the feeling. But if we give you 10 euros now, it won’t solve anything.” Thanks, commercial officer, but the customer was not asked anything. Moreover, sometimes an acknowledgment of responsibility or compensation may not solve anything, but may still be significant.
These data breaches will not be the last. Next time it might concern UWV inspections, youth care files or popular dating apps. I think it would be desirable that we not ‘do an Odidootje’ again in those situations. Those affected now have little to say, little to know and little to get. They must be stronger.
I think out loud about how things can be better. Firstly, by requiring a more balanced weighing of interests. “Don’t pay”, the official police mantra for every situation regardless of the context, is too simplistic. Certainly, frustrating a criminal revenue model is in the social interest. But so is preventing a serious violation of the privacy of hundreds of thousands of people. The government recognizes this tension and wants it not prohibit the payment of ransoms. Payment offers no guarantees, but is sometimes the only chance you have. Don’t encourage the payment option, but consider it – just like with the highway robber.
Secondly, victims can be given a mandatory, formal voice in decision-making after major data breaches. To negotiate or not to negotiate? How do we help victims? This can be done with a direct voice (for example a customer panel) or via a representative. Consider specialized lawyers who act as formal advocates of the victims in the boardroom.
Thirdly, the information rights of those affected can be strengthened. After the first report of the data breach, communication often starts to falter. Even if the facts are still unclear, or if their publication would play into the hands of criminals, a minimum of process updates may be required. What’s going on, what else can I expect? A data breach has an emotional dimension in addition to a material one. Better communication is therefore crucial.
Canceled flights
Finally, we can oblige large companies to provide victims of a data breach with greater speed and assistance. An initial financial compensation can be standardized, regardless of the legal question of guilt or damage. This is also the case with airlines that pay a fixed compensation for delays or banks that compensate customers phishing.
In the event of data leaks, the amount of compensation could, for example, depend on the sensitivity of the leaked data, the customer’s turnover and/or recent company profits. Moreover, it should be possible to terminate a consumer contract prematurely if a company such as Odido has damaged trust.
Overregulation or letting companies go bankrupt after a data breach is undesirable. But it is also undesirable to dupe hundreds of thousands of people who offer a gratuitous apology with a closed purse and then cheerfully pay out millions in profits in the following years. That non-committal could be reduced a bit.
Source: NRC

