Models and Simulations to Evaluate the Impact and Necessity of Protecting Sensitive Personally Identifiable Information at the Source
Open Access DepositedOver the past two decades, the race to secure sensitive data and prevent data breaches saw substantial changes as cybercriminals and security experts advanced their capabilities. With the expanded use of the public internet, a substantial focus of cybercrime was targeting sensitive credit card information to meet financial objectives. As regulatory scrutiny increased for protecting payment card information (PCI), organizations that processed payment card data adapted to better data protection technologies, including tokenization of credit card data at the source with a digital wallet like Google or Apple Pay. Cybercriminals have focused more on stealing personally identifiable information (PII) that is not as well protected and threaten to leak details of stolen data unless an organization pays a ransom or target individuals themselves. This Praxis makes the case that government identities, such as social security numbers, should be treated like credit card numbers and be tokenized at the source. The Praxis presents a comprehensive risk analysis approach organizations can use to evaluate the impacts of data breaches on individuals using both qualitative and quantitative models. The analysis techniques include quantifying historical data breach impacts, machine learning, Monte Carlo Simulation, and exploratory data analysis to evaluate the significance of government identities compromised in data breaches. The Monte Carlo simulation resulted in 164 billion trials of crime occurrences mapped to sensitive and non-sensitive data types for a sample population of 8.4 million real-world data breach victims. The Praxis results indicate that the impact significance of tokenizing sensitive government identities was 23% and 32% across the evaluations of the two target variables. The results also indicate a need for additional data protection of other types of information identifying a person and their sensitive login information. These types of information had significance scores over 75% in some models.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.