Phishing is a disgusting scam that is discussed in Chapter 17. The FBI's
2017 internet crime report identified over $675 million in losses from
this type of cybercrime.
I hope most institutions have beefed up their security against these emails since the days when I used to regularly report emails to IT that my colleagues apparently ignored. My sense also is that my students were not very careful. Perhaps they were even gullible, especially to the "something for nothing" offers.
Whether you approach this subject from a personal perspective or from a business one, it is important. I think the updated information in this new post will be helpful. You could even use the Google test in class as an engagement device.
There seems to be little doubt that the security and privacy of their personal data is important to Americans, and it is becoming more so every day (or maybe every data breach!). This has been an important subject in the textbook from the beginning and these are important findings that look forward to the future of the topic and build on content in Chapter 17.
Is Data Privacy the Top Concern?
Americans' concern about privacy has been tracked from the early days of the internet. EPIC has a page Public Opinion on Privacy that chronicles studies back as far as 1990 and has links to the most important ones from the present back to 2011. It's a tremendous resource. But what is the status of the concern at present?
http://bit.ly/2AYwZyg
The Harris Poll has conducted two surveys recently, the first for IBM and the second with Finn Partners. The April 2018 study found a big gap between what customers want from the firms they do business with and what those firms actually provide as shown in the graphic. Specifically, the respondents replied as follows:
75 percent will not buy a product from a company – no matter how
great the products are – if they don't trust the company to protect
their data;
73 percent think businesses are focused on profits over addressing consumers' security needs;
73 percent indicated it is extremely important that companies quickly take proper actions to stop a data breach; and
60 percent are more concerned about cybersecurity than a potential war.
Harris conducted a second study with Finn Partners in conjunction with the introduction of their Societal ROI Index. That's an interesting subject that should resonate with students; more about the Index later.
http://bit.ly/2SXhsWy
The global study extracted the American data to confirm that data privacy was once again the most important societal concern for the US respondents, as the graphic shows. However, privacy ranked only 6th on the list of concern on which businesses are having a positive impact.
Access to healthcare was second on the list of concerns. Respondents ranked healthcare 4th on the list of positive business impact.
They ranked job creation first in terms of where business was having a positive societal impact. Job creation was 5th on their list of concerns.
Are Businesses Losing the Battle for Trust?
The third graphic doesn't answer that question directly, but the data on 2017 data breaches provide a strong implication. If data privacy is most important to customers and the war on data breaches is being lost, the trend is clearly in the wrong direction. Consider the number and growing magnitude of these data breaches in 2017.
The survey confirmed that there is a
rising national sentiment of anxiety as relatively few consumers trust
that their data is secured by the organizations that manage it.
Specifically, the survey revealed that 78 percent of U.S. respondents
say a company’s ability to keep their data private is extremely
important but only 20 percent completely trust organizations they
interact with to maintain the privacy of their data.
The online survey of 10,000 global consumers also found that:
69 percent said it is extremely important that companies are accessible in the wake of a data breach;
73 percent indicated it is extremely important companies quickly take proper actions to stop a data breach;
75 percent
will not buy a product from a company – no matter how great the
products are – if they don’t trust the company to protect their data;
73 percent think businesses are focused on profits over addressing consumers’ security needs
The Freedom House report on the status of internet freedom in 2018 has a great deal more important data and I'll also return to that later.
The Important Take-Aways
There are many important things going on here, but these are the two top takeaways:
The tsunami of data breaches goes on and, in spite of corporate efforts, it hasn't yet shown any evidence of abating. The breached data leads to identity theft. Even more broadly, it leads to fear of identity theft among the general public. If brands are letting their identities be stolen, how can customers trust them?
Another issue with great potential long-term impact is emerging--the
expectation held by many consumers, especially younger ones, that
corporations will act in the best interests of society, not just in their own best interests.
According to USA Today: Americans believe that companies should have a mission that goes beyond the money—one that has a positive impact on world hunger, job creation and education, according to the latest Harris Poll data. . . "When it comes down to it, people want companies to address the issues
that they struggle with every day like safety, security and health,"
said Amy Terpeluk, a senior partner at Finn Partners. "Companies that
address these needs can build their reputation and in turn strengthen
their business." These are profound shifts in the business landscape and students need to think about the ways in which they will prepare to deal with them. Related Updates
Changes in privacy expectations, US and UK
Our two digital textbooks have only one mention of the deep web--a brief mention of "dark social" in Chapter 10 of Social Media Marketing. While the deep web is not a priority topic for most marketers, instructors and students should be aware of its existence. Instructors should have a definition handy if anyone asks. My guess is that students are more likely to be aware of the concept than most instructors. They are also likely to be badly informed and susceptible to the many dangers that lurk there.
This post has the limited goal of making the instructor aware and providing correct definitions. If the reader in interested in more information on the subject, please read the corresponding post on my new blog, Protecting Yourself in Cyberspace. The target audience of that blog is the layperson who uses the web, not professionals. It probably is not going to contain much information that is useful in the marketing classroom. However, you might like to follow it as an individual, maybe even as a researcher, and you might want to recommend that your students follow it for their own safety.
What is the Deep Web?
The web is generally stratified into three levels as shown in the graphic. The top two levels are:
The Surface Web. The surface web is the portion of the web that is indexed in search engines. It includes platforms large and small and is easily accessible to the user. Students should be aware of the dangers that are present even on the surface web when they have completed Chapter 17, the social and regulatory chapter. That chapter is, as it should be, devoted to the discussion of issues that affect the safety of business data on the web and resultant brand trust on the part of customers. The thoughtful student should realize that many of these same issues affect individual users, but I have always found that students can benefit from frequent reminders about the safety of their own personal data.
Sources indicate that there are currently about 4.49 billion indexed pages on the web. You often see the estimate that only 1% of the pages on the web are actually indexed.
The Deep Web. It's easy to guess, then, that the deep web is the portion of the web than cannot be indexed by search engines.It is huge; perhaps 400 to 500 times the size of the surface web. Again, that's a figure you see often.
The deep web consists of content that has intentionally been hidden. That includes things like our social media profiles, employee websites, email--anything that requires a password for access. That means that most of the content on the deep web is innocuous. It's just things we want to keep private.
How is the Dark Web Different from the Deep Web?
The dark web is the portion of the deep web where the bad guys hang out. Sites on the dark web are encrypted and cannot be accessed by search engines. It requires a special browser to access the dark web. The Tor browser is the most famous. The browser itself is not dangerous. It was initially funded by the US government and is used by people like whistle blowers to mask their identities. The dark web is however, full of stolen passwords and illegal drugs. It is also said to be full of malware that will follow a visitor back to his normal haunts.
I have scoured the web to make sure these definitions are correct, and they are. What I have found in the process is that many people who, according to their credentials, should know better are careless. Beware!
Should Marketers Care About the Dark Web?
While they probably shouldn't loose sleep over it, marketers should be aware. They should keep an eye on it to see if there's anything that could affect their brand reputation. There is not much authoritative content specifically for marketers, but this publication on the AMA website is good. Unfortunately it doesn't have a publication date, but it could be 2016. That's not terribly recent, but in this case of this type of content it's ok.
Should Users Care About the Deep Web and the Dark Web?
We use the deep web all the time, and it is not a problem. We should care about the dark web, although, since everything is encrypted, it is pretty difficult to stumble onto it. I just suggest that it's useful for students to be warned about the potential dangers, especially malware, of intentionally venturing onto the dark web.
There's an interesting and useful way to demonstrate what can go on there and still stay safe. This site lets the user look to see if her passwords are for sale on the dark web. I've searched it occasionally over the past year or so and see passwords from three sites that were hacked some time ago. I'm not exactly sure how to interpret that, although I have been more careful lately. And yes, I have changed the stolen passwords.
The "word" pwned means to totally obliterate an opponent, as in a video game. Wonder how many of your students know that.
This makes for a good classroom exercise. I usually use my own email address for something like this, having first tested it at home. One warning is that it's a free site and you may find yourself closed out if you use it often. You could ask for a brave student to volunteer theirs--and hope it won't turn up something embarrassing!
In December 2017 the Federal Communications Commission passed a bill called Restoring Internet Freedom that revokes the net neutrality order that has been in effect since 2015, the Open Internet Order. The titles of the two dueling regulations make it clear that the whole issue is deeply political. However, potential consequences are great--to the internet itself, to companies that rely on the internet for their business and their employees, as well as to all users of the internet. That makes it worthy of discussion in classrooms where various aspects of internet marketing are taught. This post is an attempt to lay out the issues in an objective manner for coverage in the classroom.
While it is by no means objective, the prank video by Burger King on the subject is an easy-to-digest (pun intended) explanation of the effects of ending net neutrality which immediately went viral. The 3-minute video could lead into a class discussion of the subject. It is also worth asking why BK, which is about as far as possible from being a telecommunications company, would make a video on this subject. The answer seems to be in Burger King’s audience objective; its ongoing attempt to attract more Millennials to the brand.
Few articles and posts on the subject are free of ideological bias. Here is one of the relative few that are critical of the Burger King effort. Here is a much more typical explanation of the harm that ending net neutrality could cause.
What Was Net Neutrality?
The so-called net neutrality regulation was intended to ensure that all internet traffic was treated equally. Internet service providers were classified as telecommunications services. That made them common carriers who could not discriminate on the basis of how the broadband services were used. All all types of content as well as all websites and platforms had to be treated equally in terms of both service and fees. The term “open internet” is synonymous.
In practice net neutrality meant that ISPs cannot block or slow certain traffic. It cannot charge more to services like Netflix who want their services delivered faster—so-called ‘fast lanes.’ The practices prohibited by net neutrality are generally described as follows:
No Blocking. Simply put: A broadband provider can't block lawful content, applications, services or non-harmful devices.
No Throttling. The FCC created a separate rule that prohibits broadband providers from slowing down specific applications or services, a practice known as throttling. More to the point, the FCC said providers can't single out Internet traffic based on who sends it, where it's going, what the content happens to be or whether that content competes with the provider's business.
No Paid Prioritization. A broadband provider cannot accept fees for favored treatment. In short, the rules prohibit Internet fast lanes.
Note that the regulation specifically applied to broadband providers.
Who are the Large Internet Services Providers?
To understand the arguments pro and con net neutrality one must understand the market structure. The chart shows clearly the increasing market concentration and the results as of the end of 2017. Comcast slowly but steadily increased share from 2011 to 2017. Charter, on the other hand, shot from an also-ran to second in 2016 with the acquisitions of Time-Warner Cable and Bright House Networks. Concentration was clearly ongoing during the period of net neutrality.
The second salient fact is that many of us have little choice in ISPs. Using 2017 Census data a research firm showed that 50 million of the 118 million US households lack access to the internet at 25 Mps, which is the FCC standard for broadband speed. Using a different metric (census tracts vs. households) the FCC itself found that roughly three-fourths of the US lacks access to high-speed broadband.
One of the FCC arguments for revoking net neutrality is that it stifled innovation and repeal would encourage more competition in that market space. The data in the chart shows that concentration was ongoing, both before and during net neutrality. Is it inevitable? Will the repeal of net neutrality accelerate it? One thing is certain; it’s isn’t easy to establish successful new ISPs. A post on the subject from Ars Technica was subtitled, “Creating an ISP? You'll need millions of dollars, patience, and lots of lawyers.” That pretty much summaries the argument. There is potentially another way, described in the last section of this post.
What Does the End of Net Neutrality Mean?
The rules against blocking, throttling and paid prioritization are now gone. Regulation has been shifted from the FCC to the FTC which has always moved against bad actors, primarily violators of data privacy regulations. Proponents of net neutrality argue that the large telecoms are now free to make any changes to existing practices that they wish, as long as they notify users of what they are doing. Industry leaders and associations have released statements indicating that current practices will continue, but that could change.
Small business owners are especially concerned that a “pay to play” environment will emerge in which small firms cannot compete with the financial power of larger competitors.
ISPs do not have to block websites to make them less popular. They can place them behind paywalls like existing premium cable TV channels. One option would be to “bundle” popular sites like social media platforms into a paid offering. In October Congressman Ro Khanna tweeted an ad that shows packages of various internet services, from social media to music, available for subscription in Portugal. Medium, in a scathing critique of current internet practices, says that nothing prevents US ISPs from doing the same thing, with or without net neutrality.
Another concern is the potential sale of even more subscriber data to third-party data services. Again, that would only expand what is now occurring.
It is also possible that, without regulation, the ISPs could slow certain traffic for whatever reasons they choose. It appears they would have to notify users, but beyond that they can do whatever they like—or whatever the market permits them to do without serious backlash from users. And that’s true of all the actions they might take. That is what makes the concentration of the industry so troubling.
Are Local Networks the Answer?
Local networks have been under construction for a number of years, motivated by a number of factors chief among them network availability and speed. Fast Company has a good non-technical description:
Using affordable, off-the-shelf hardware and open-source software, hundreds of communities around the world are assembling small, independent, nonprofit wireless networks, often organized as so-called “mesh networks” for their weblike, decentralized design, in which each node–a phone, for instance, or a sophisticated wireless router–relays the connection onwards to the next node. This is the same principle used in mesh Wi-Fi routers for homes that are large or otherwise have problems getting signals from conventional routers to all areas of the home.
Fast Company offers a number of examples from the education and arts communities. Localities that lack internet access at acceptable speeds provide another example. Detroit, where an amazing 40% of the population lacks any internet access at all, is undertaking the building of a network as a DIY project. There are a growing number of other communities that own private networks of their own and technical services agencies that supply them. I investigated the map for my own state of Massachusetts and found two, both in the rural western part of the state. One is Holyoke with a population of 40 thousand plus. It is an educational center and a tourist destination that has competing ISP and mobile providers. The average download speed appears to be about 15 Mbs although business plans with higher speeds are listed. The other is Mt. Washington, a community in the Berkshires with a 2010 population of 167. Internet service is available from several ISPs with download speeds that vary from 1 to 7 Mbs.
So if you believe competition is the answer, there is a potential solution.
If you believe that restoring net neutrality is the answer, there are numerous efforts underway.
About the only sure thing is that this argument is not going to go away soon. To know whether the predictions might come true, one must wait and see.
The European Union’s 1995 Privacy Directive had strong protection for the privacy of personal data for EU residents and the movement of data across borders. The directive required all EU nations to establish their own laws under its framework. All companies with businesses that collect EU customer data, wherever they were headquartered, were covered by its provisions. The US and the EU established a Safe Harbor agreement to certify that US member companies were complying with EU regulations. The 1995 directive provided strong privacy regulation for many years but now that is changing.
What is the GDPR?
In 2016 the EU passed the GDPR with an effective date of May 2018. The regulation updates the existing procedures under the 1995 directive. Most important, it is a regulation with the force of law, not a directive that directs member companies to establish laws. Industry group Third Certainty (so named because observers believe that today’s third certainty after the traditional death and taxes is identity theft) describes the regulation as follows:
GDPR isn’t a suggestion that companies institute best practices for customer data privacy; it is a directive that could result in fines of €20 million or up to 4 percent of annual global turnover. Not only will all companies in the EU be required to meet the new regulations, but GDPR also is in effect for all organizations that hold or process the data of customers who live in the EU.
In addition, the GDPR site identifies major changes as:
• The unambiguous inclusion of all companies that process the data of people residing in the EU no matter where the companies are located.
• Consent to be obtained in a clear and accessible way, free of legalese, and the purpose for processing the data must be explained. It must be as easy to withdrawn consent as it is to give it.
• Data breaches to be revealed within 72 hours of the company first being aware of the breach. Data processors are also required to notify of breaches without undue delay when they become aware of the breach.
According to the Information Commissioner’s Office in the UK the rights of individual data subjects are:
• Right to be informed by means of privacy notices
• Right of access to their data and information about how it is being processed
• Right to rectification of inaccurate or incomplete data
• Right to erasure of data where there is no compelling reason for continued processing
• Right to restrict processing of personal data
• Right to data portability, allowing subjects to move, copy or transfer personal data easily from one IT environment to another.
• Right to object to certain types of processing
• Rights related to automated decision making and profiling that protect against potentially damaging decisions made without human intervention.
Cookie Notice from https://ico.org.uk/
The ICO Guide has more detail on these provisions and a “What’s New” page that highlights ongoing analysis. Notice that this information is being provided for UK organizations post Brexit on a site that has one type of cookie notification. The home page of the Financial Times shows another type of notification that is being used under the provisions of the regulation. Notice that this is the U.S. version of the London-based publication that is showing the same notification that is shown on the U.K. and World editions.
Cookies Notice from https://www.ft.com/world/us
The individual rights under GDPR are based on the Fair Information Practices Principles discussed in Chapter 17. These specific rights update the 1995 directive by being clearer and more specific. How Should U.S. Companies Prepare for the GDPR?
It seems the question should really be, “Are U.S. companies preparing for the GDPR?” A study by NTT Security, quoted by Thompson Reuters, found that many decision makers around the world were unaware of the regulation and how it would affect them. Switzerland had the highest preparedness level at 58% of businesses. The U.S. had the lowest level of awareness of the regulation with only 25% of companies believing the regulation would affect them.
attaches to any data concerning an individual residing or present in the EU. Thus, if data is connected to an individual in the EU, the GDPR applies — regardless of where such data is processed. They add that it requires that, “organizations be able to justify their reasons for holding or processing every piece of data in their possession."
Those are sweeping statements, especially in view of the large fines that can result from non-compliance. Steps that U.S. firms should take to comply are outlined by Information Week:
• Determine whether the firm is a controller, a processor or both. A controller is the entity that determines the purposes and conditions under which personal data will be processed. Since processing includes anything as basic as collecting and storing data, that means that any brand that collects personal data is a controller. That definition is the same as under the 1995 directive. The definition of a processor also does not change; a processor is an entity that processes personal data for a controller. Both controller and processor(s) are responsible for compliance with the GDPR but primary responsibility lies with the controller
• Audit personal data to ensure that there is a single view of each data subject. This is necessary to be able to “forget” a data subject under the regulation.
This can be a huge task, but Steve Forde of Britain’s ITV advocates viewing it as an opportunity. He finds 3 principles of data collection—transparency, control and value exchange—to be essential in creating trust with customers. Preparing for GDPR is a way to instill this philosophy throughout the organization with the result that customer trust should increase.
• Redesign what consent looks like for your customers. They must explicitly consent to each use of their data and pre-checked boxes or opt-out requirements are not adequate. The range of data covered and special issues like collecting data from children have been make tighter and more explicit under the regulation.
• Audit service providers to ensure they meet the requirements for processors. Otherwise the processing they do for a U.S. firm on its data for European subjects will be illegal.
• There are other requirements like choosing a member state as the supervisory authority, appointing a data protection officer and locating data centers that are legal or technical in nature, but marketers need to be sure that all requirements are being met. Failure to do so could result in loss of access to data of European subjects—everything from contact information to CRM data. For many U.S. brands, that could result in a significant loss of business.
What is the Role of Privacy Shield?
Privacy Shield prototype
Under the 1995 directive, the Safe Harbor program certified that U.S. companies were compliant with its provisions. That compliance framework has been superseded by the Privacy Shield program. Developed by the Department of Commerce, the service is open to all organizations that are under the jurisdiction of the FTC or the DOT. The framework allows companies to self-certify that they have met the requirements of the GDPR for both the E.U. and the separate Swiss framework.
Companies that wish to certify must have a Privacy Policy that is compliant with the GDPR. Current privacy policies will not conform to the new requirements, which are essentially the rights of individual data subjects listed above. The company must provide an independent recourse mechanism from an approved list that includes agencies like the Better Business Bureau and TRUSTe. The company must provide for verification of its compliance and designate a contact for the Privacy Shield program. Companies that certify under the Privacy Shield program will automatically be removed from Safe Harbor and must remove all references to it from their privacy policy and website.
U.S. Companies Should Move Quickly to Comply with the GDPR.
If this all sounds like a great deal of work, it is. At the same time, remember the advice of Steve Forde from ITV. Trust is essential to ecommerce businesses and being transparent about the way a brand handles the personal data of its customers helps create that trust.
So the best advice to U.S. companies is to move quickly so they do not lose access to the data of their E.U. customers and to do so in a way that creates trust with their customers all over the world.