Sony breach a strong case for online insurance

 

Guest opinion: Why online service providers need to cover their users.

Users of online services will rightly be sceptical about the safety and confidentiality of their information held by online service providers following the breach of Sony’s PlayStation Network late last month.

Sony's PlayStation Network (PSN) is pushing hard to win back user confidence after reportedly losing as many as 77 million customer records, and 10 million credit card numbers.

Sony has apologised to users, offered all PSN customers a month of free PlayStation Plus membership, and extended subscriptions of PlayStation Plus and Music Unlimited customers.

If Sony were to compensate users for the inconvenience, the cost would be in the millions of dollars. Most importantly, the cost of winning back user confidence will be much higher.

Data breaches do come at considerable cost to victims. Sony's users are concerned about the privacy and safety of their personal and financial information. If their financial details are used illegitimately, they may end up suffering thousands of dollars of financial loss. Identity theft might haunt some users’ for the rest of their lives.

Is insurance a solution?

To build user confidence, online service providers should consider bundling their services with insurance to protect themselves from any financial consequences.

Insurance will help both sides: educating users that online systems are not 100 percent secure; and ensuring that providers are responsible for user data and are prepared to compensate users for any financial loss.

Transferring the risk to an insurance provider and sharing the cost of insurance will cover both service providers as well as users.

 

Tanveer A Zia, Senior Lecturer
Charles Sturt University

But this does not mean that by educating users about the security risk and providing insurance, online service providers will have less responsibility to protect their systems.

 

Cybercrime affects not only Sony users; every day, there are millions of users making online transactions, using internet banking, and supplying their personal and financial information to dozens of vendors.

If a vendor such as Sony, which defines itself as a cutting-edge technology provider, has been exposed to such a mass online security breach, how about the other vendors? There is a need for tougher security procedures and for these procedures to be enforced. 

Any breach that involves an online system will have a significant impact not only on the consumers, but the entire industry. Cybercrime regulations need to be redefined, with clear descriptions of offenses and consequences for offenders.

The Privacy Act in Australia – which regulates how personal information is collected, used and disclosed – makes the vendor responsible for the breach and the penalties include changes to vendor practices or procedures, and compensation for financial or non-financial loss.  

Such regulations should be enforced on service providers and any weaknesses in security processes need to be taken very seriously.

Besides PSN users, several legislative authorities have called for answers from Sony about the breach. These include the US House of Representative subcommittee on Energy and Commerce, the UK Information Commissioner's Office, the Law and Regulations Commission of Taipei, Taiwan, Canada’s Privacy Commission, and the Australian Privacy Commissioner.

Sony claims it had no evidence that personal financial information was compromised and therefore it didn’t violate any laws by not notifying users sooner. This is debatable and the legal consequences for not notifying users sooner should be assessed by the authorities in each state or country.

Dr Tanveer Zia is a senior lecturer at the Charles Sturt University's School of Computing and Mathematics.

Copyright © iTnews.com.au . All rights reserved.


Sony breach a strong case for online insurance
 
 
 
 
Top Stories
Photos: AusCERT 2013 day one
First day of the Queensland security conference.
 
CenITex to move from IT provider to broker
Documents reveal new strategy.
 
eHealth measures missing the point
Opinion: When will the PCEHR lead to patient outcomes?
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Bankwest builds continuous delivery capability
Bankwest builds continuous delivery capability
To automatically deploy test/dev sandboxes by mid-year.
Veterans' Affairs sets sights on modernisation
Veterans' Affairs sets sights on modernisation
Data safe with Human Services, CIO says.
Citi Australia drops platform customisations
Citi Australia drops platform customisations
Technology chief shifts focus from building to leveraging systems.
VicRoads restructures IT team
VicRoads restructures IT team
Department moves to align with industry benchmarks.
Zurich Australia extends IT team offshore
Zurich Australia extends IT team offshore
Malaysian staff served from Australian data centres.
Leigh Berrell - Utilities CIO of the Year
Leigh Berrell - Utilities CIO of the Year
Yarra Valley Water CIO Leigh Berrell accepts his Benchmark Award for Utilities CIO of the Year.
Wayne McMahon - Retail CIO of the Year
Wayne McMahon - Retail CIO of the Year
Domino's Pizza CIO Wayne McMahon accepts his Benchmark Award for Retail CIO of the Year.
Inside Perpetual's ongoing IT transformation
Inside Perpetual's ongoing IT transformation
CIO Jenny Levy discusses how outsourcing will help the firm "simplify, refocus and grow".
Managing Complexity - Defence's Daniel McCabe
Managing Complexity - Defence's Daniel McCabe
Daniel McCabe, Assistant Secretary of Australia's Department of Defence, provides the audience at the iTnews Data Centre Strategy Summit with a deep dive into the organisation's data centre consolidation program.
How Facebook designed the data centre from scratch - Marco Magarelli
How Facebook designed the data centre from scratch - Marco Magarelli
The full keynote by Facebook data centre architect Marco Magarelli at the Australian Data Centre Strategy Summit. Magarelli details the design considerations behind the social network's Prineville, Oregon; North Carolina and Luleå, Sweden data centres.
Modernising Legacy Data Centres - Telstra's Jon Curry
Modernising Legacy Data Centres - Telstra's Jon Curry
Telstra general manager of managed data centres Jon Curry guides the audience at the iTnews Australian Data Centre Summit through the build of the telco's Clayton, Victoria data centre.
NSW Government launches NABERS data centre rating tools
NSW Government launches NABERS data centre rating tools
Matthew Clark from the NSW Department of Environment guides facilties managers through the details of the new NABERS data centre energy rating tool at the Australian Data Centre Strategy Summit.
NABERS launch panel: Australian Data Centre Strategy Summit
NABERS launch panel: Australian Data Centre Strategy Summit
Matthew Clark (NSW Dept of Environment), Greg Boorer (Canberra Data Centres), Glenn Allan (National Australia Bank), Mike Andrea (Strategic Directions) and Bob Sharon (Green Global Consulting) discuss the impact of the NABERS data centre rating.
Judges notes: Fortescue Metals [The Benchmark Awards]
Judges notes: Fortescue Metals [The Benchmark Awards]
iTnews' panel of judges discuss Fortescue Metals 'New World of Work" project, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Retail [The Benchmark Awards]
Judges notes: Retail [The Benchmark Awards]
iTnews' panel of judges discuss the shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: Pacific Aluminium [The Benchmark Awards]
Judges notes: Pacific Aluminium [The Benchmark Awards]
iTnews' panel of judges discuss Pacific Aluminium's lightning fast service desk refresh, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Domino's Pizza [The Benchmark Awards]
Judges notes: Domino's Pizza [The Benchmark Awards]
iTnews' panel of judges discuss Domino's Pizza's shift to hosted services, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: McDonald's Australia [The Benchmark Awards]
Judges notes: McDonald's Australia [The Benchmark Awards]
iTnews' panel of judges discuss McDonald's Australia's new self-service portal for employees, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: ING Direct [The Benchmark Awards]
Judges notes: ING Direct [The Benchmark Awards]
iTnews' panel of judges discuss ING Direct's 'Bank in a Box', one of three shortlisted finalists for the banking and finance category of the CIO Benchmark Awards.
Judges notes: Yarra Valley Water [The Benchmark Awards]
Judges notes: Yarra Valley Water [The Benchmark Awards]
iTnews' panel of judges discuss Yarra Valley Water's insourcing project, one of three shortlisted finalists for the Utilities category of the CIO Benchmark Awards.
Latest Comments
Polls
Do you prefer the Coalition's NBN policy?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 1696

Vote