logo
Data privacy is failing. Here's what encryption and MFA can (and can't) do

Data privacy is failing. Here's what encryption and MFA can (and can't) do

Fast Company10-07-2025
Cybersecurity and data privacy are constantly in the news. Governments are passing new cybersecurity laws. Companies are investing in cybersecurity controls such as firewalls, encryption, and awareness training at record levels.
And yet, people are losing ground on data privacy.
In 2024, the Identity Theft Resource Center reported that companies sent out 1.3 billion notifications to the victims of data breaches. That's more than triple the notices sent out the year before. It's clear that despite growing efforts, personal data breaches are not only continuing, but accelerating.
What can you do about this situation? Many people think of the cybersecurity issue as a technical problem. They're right: Technical controls are an important part of protecting personal information, but they are not enough.
As a professor of information technology, analytics, and operations at the University of Notre Dame, I study ways to protect personal privacy.
Solid personal privacy protection is made up of three pillars: accessible technical controls, public awareness of the need for privacy, and public policies that prioritize personal privacy. Each plays a crucial role in protecting personal privacy. A weakness in any one puts the entire system at risk.
The first line of defense
Technology is the first line of defense, guarding access to computers that store data and encrypting information as it travels between computers to keep intruders from gaining access. But even the best security tools can fail when misused, misconfigured, or ignored.
Two technical controls are especially important: encryption and multifactor authentication (MFA). These are the backbone of digital privacy—and they work best when widely adopted and properly implemented.
Encryption uses complex math to put sensitive data in an unreadable format that can only be unlocked with the right key. For example, your web browser uses HTTPS encryption to protect your information when you visit a secure webpage. This prevents anyone on your network—or any network between you and the website—from eavesdropping on your communications. Today, nearly all web traffic is encrypted in this way.
But if we're so good at encrypting data on networks, why are we still suffering all of these data breaches? The reality is that encrypting data in transit is only part of the challenge.
Securing stored data
We also need to protect data wherever it's stored—on phones, laptops, and the servers that make up cloud storage. Unfortunately, this is where security often falls short. Encrypting stored data, or data at rest, isn't as widespread as encrypting data that is moving from one place to another.
While modern smartphones typically encrypt files by default, the same can't be said for cloud storage or company databases. Only 10% of organizations report that at least 80% of the information they have stored in the cloud is encrypted, according to a 2024 industry survey. This leaves a huge amount of unencrypted personal information potentially exposed if attackers manage to break in. Without encryption, breaking into a database is like opening an unlocked filing cabinet—everything inside is accessible to the attacker.
Multifactor authentication is a security measure that requires you to provide more than one form of verification before accessing sensitive information. This type of authentication is more difficult to crack than a password alone because it requires a combination of different types of information. It often combines something you know, such as a password, with something you have, such as a smartphone app that can generate a verification code or with something that's part of what you are, like a fingerprint. Proper use of multifactor authentication reduces the risk of compromise by 99.22%.
While 83% of organizations require that their employees use multifactor authentication, according to another industry survey, this still leaves millions of accounts protected by nothing more than a password. As attackers grow more sophisticated and credential theft remains rampant, closing that 17% gap isn't just a best practice—it's a necessity.
Multifactor authentication is one of the simplest, most effective steps organizations can take to prevent data breaches, but it remains underused. Expanding its adoption could dramatically reduce the number of successful attacks each year.
Awareness gives people the knowledge they need
Even the best technology falls short when people make mistakes. Human error played a role in 68% of 2024 data breaches, according to a Verizon report. Organizations can mitigate this risk through employee training, data minimization—meaning collecting only the information necessary for a task, then deleting it when it's no longer needed—and strict access controls.
Policies, audits, and incident response plans can help organizations prepare for a possible data breach so they can stem the damage, see who is responsible and learn from the experience. It's also important to guard against insider threats and physical intrusion using physical safeguards such as locking down server rooms.
Public policy holds organizations accountable
Legal protections help hold organizations accountable in keeping data protected and giving people control over their data. The European Union's General Data Protection Regulation is one of the most comprehensive privacy laws in the world. It mandates strong data protection practices and gives people the right to access, correct, and delete their personal data. And the General Data Protection Regulation has teeth: In 2023, Meta was fined €1.2 billion (US$1.4 billion) when Facebook was found in violation.
Despite years of discussion, the U.S. still has no comprehensive federal privacy law. Several proposals have been introduced in Congress, but none have made it across the finish line. In its place, a mix of state regulations and industry-specific rules—such as the Health Insurance Portability and Accountability Act for health data and the Gramm-Leach-Bliley Act for financial institutions —fill the gaps.
Some states have passed their own privacy laws, but this patchwork leaves Americans with uneven protections and creates compliance headaches for businesses operating across jurisdictions.
The tools, policies, and knowledge to protect personal data exist—but people's and institutions' use of them still falls short. Stronger encryption, more widespread use of multifactor authentication, better training, and clearer legal standards could prevent many breaches. It's clear that these tools work. What's needed now is the collective will—and a unified federal mandate—to put those protections in place.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Radcom Ltd (RDCM) Q2 2025 Earnings Call Highlights: Record Revenue and Strategic Partnerships ...
Radcom Ltd (RDCM) Q2 2025 Earnings Call Highlights: Record Revenue and Strategic Partnerships ...

Yahoo

time14 minutes ago

  • Yahoo

Radcom Ltd (RDCM) Q2 2025 Earnings Call Highlights: Record Revenue and Strategic Partnerships ...

Release Date: August 13, 2025 For the complete transcript of the earnings call, please refer to the full earnings call transcript. Positive Points Radcom Ltd (NASDAQ:RDCM) reported a 19% year-over-year increase in revenue, reaching a new record of $17.7 million for Q2 2025. The company ended the quarter with over $100 million in cash and no debt, indicating strong financial health. Operating income increased by more than 50% compared to Q2 last year, with a non-GAAP operating margin extending to nearly 20% of revenue. Radcom Ltd (NASDAQ:RDCM) is actively expanding strategic partnerships, including collaborations with Nvidia and ServiceNow, to enhance its AI-driven solutions. The company is well-positioned in the growing 5G and AI markets, with significant customer engagement and ongoing market shifts supporting its growth outlook. Negative Points Radcom Ltd (NASDAQ:RDCM) did not receive a grant from the Israel Innovation Authority in Q2 2025, unlike the previous year. The company faces currency exchange risks, as 60% of its operating expenses are in shekels, and it does not currently hedge these expenses. There is uncertainty in the directed device satellite space, with potential opportunities still unclear in terms of capital allocation. The competitive environment remains challenging, with competitors trying to shift out of telcos while Radcom Ltd (NASDAQ:RDCM) continues to invest in innovation. Despite strong performance, the company anticipates a gradual increase in sales and marketing expenses to support a growing pipeline and expand its presence in high-value regions. Q & A Highlights Warning! GuruFocus has detected 1 Warning Sign with RDCM. Q: How is the partnership with service management system vendors like ServiceNow and AWS progressing? A: Benny Epstein, CEO: The partnership is going very well. We are co-developing and interconnecting our platforms. A few connectors are already in place, and we are building agent-to-agent use cases together. Q: With $100 million in cash on the balance sheet, how is Radcom planning to allocate capital? A: Benny Epstein, CEO: Our first priority is potential M&A. We are progressing with a few candidates and will decide on capital allocation based on this progress. Q: What percentage of growth over the next 18 months is expected from existing customer expansion versus new logos? A: Benny Epstein, CEO: We anticipate around two-thirds of growth from existing customers and one-third from new logos. Q: Can you provide insight into the revenue split between 5G and legacy networks? A: Benny Epstein, CEO: While 5G is growing, LTE networks are still operational and will remain for a few more years. 5G is our focus, but LTE will continue to contribute to revenue. Q: Are there any emerging opportunities in the directed device satellite space? A: Benny Epstein, CEO: There is an active opportunity with a certain customer, but their capital allocation is still unclear. We are monitoring their progress and participating in opportunities as they arise. For the complete transcript of the earnings call, please refer to the full earnings call transcript. This article first appeared on GuruFocus. Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

The Acura RSX Is Back—But It's No Sports Car
The Acura RSX Is Back—But It's No Sports Car

Motor 1

time16 minutes ago

  • Motor 1

The Acura RSX Is Back—But It's No Sports Car

Nearly 25 years ago, the Acura RSX debuted as a successor to the Integra, and it very much continued in that car's vein—a fancier version of the Honda Civic. Now, the RSX is back as something completely different, an electric crossover with a fastback roof. Acura is debuting the new RSX Prototype during Monterey Car Week, and it previews a soon-arriving EV. Unlike the ZDX , which uses GM's Ultium electric-car architecture, the RSX is a homegrown effort. This will be the first production car on Honda's new EV platform—which debuted with the Honda 0 Series concepts —and Acura plans to build it on the same Marysville, Ohio, line as the gas-powered Integra. (Side note: Imagine telling someone 20 years ago that the RSX and Integra would exist alongside each other, and that one would be an SUV.) Acura calls this a "prototype," but typically, Honda's prototypes are very close to the eventual production models. So, this is pretty much what the new RSX will look like, though we're not sure if the yellow paint will be an option. Mechanically, the RSX will have dual-motor all-wheel drive, double wishbone front suspension, and Brembo-branded brakes. The prototype sits on 21-inch wheels, and Acura says the wide rear-end is inspired by the second-generation NSX. Photo by: Acura The RSX will also be the first Honda product to run the automaker's new infotainment system, ASIMO OS, named for its beloved humanoid robot. Acura considers this a "software-defined" vehicle, with an OS that learns user preferences, and a system that can handle over-the-air software updates. The RSX will also get a Tesla-style North American Charging Standard (NACS) charging port, and it has vehicle-to-load capabilities, so you can essentially use it as a generator of sorts. Acura was pretty mum on details, though. We don't know what sort of performance the RSX will have, battery size, range, or anything, really. We also don't know what it will cost, but since it's smaller than the ZDX, we have to assume it'll be cheaper. Thankfully, we shouldn't have to wait long, as is typically the case with Honda concepts. 25 Source: Acura More from Monterey Car Week This Might Be Cadillac's Craziest Concept Car Ever The Ultimate Guide to Monterey Car Week 2025 Stay informed with our newsletter every weekday back Sign up For more information, read our Privacy Policy and Terms of Use . Gallery: Acura RSX EV Prototype: First Look 25 Source: Acura Share this Story Facebook X LinkedIn Flipboard Reddit WhatsApp E-Mail Got a tip for us? Email: tips@ Join the conversation ( )

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store