Why sites ask you to "reset your password"
I suspect that you may have seen a message like this at some point when logging into a website. To me, it is ironic that they typically then make you go through the "forgot my password" method, as if you have done something wrong.
The reality is that the most common reason this happens is because the website has experienced a "security breach" of some sort. In fact the Identity Theft Resource Center reported that, in 2023, there were over 3,205 data breaches reported in the US. This number highlights the prevalence of data breaches today. It emphasizes the need for stronger data protection measures beyond reactive steps like "to improve your security, we ask you to reset your password".
Companies of all sizes falling victim to cyberattacks and unauthorized access to sensitive information. In a data breach, hackers gain unauthorized access to a company's systems or databases, compromising the security and confidentiality of personal or proprietary data. This can include everything from customer names and email addresses to more sensitive information such as credit card numbers, social security numbers, and even medical information.
Forced password resets are a knee-jerk reaction of companies in the aftermath of a data breach. This might seem like a proactive security measure, but in fact it is more complex. First, it is a reactionary response, focused on mitigating the potential fallout from their breach. It does not address the root cause of the security incident. What a password reset does accomplish it that it diminishes the likelihood that other attack vectors can be used to compromise your account - such as if you use the same password on multiple websites, or you use something that can be found in one of the many "dictionaries" of passwords available.
Unfortunately, password resets by themselves are not a good solution. It does not address the underlying weaknesses in the company's infrastructure that allowed the breach to occur in the first place. What truly matters is what else the company does to address the weaknesses the cyber criminals used to access their systems in the first place. This is not what the corporate types like, however, because forensic analysis after a data breach is an expensive and error-prone task. Risk management will want to review the terms and conditions, to ensure that the company's exposure to this and future data breaches are mitigated. They use the usual tools: limits on liability, mandatory arbitration, and other mechanisms that permit them to avoid the financial costs associated with these breaches. Instead, it is their customers that bear the brunt of those expenses. Of course, they still worry about reputational risk. Then again, data security breaches have become so common that we have become desensitized to them, so there is less risk of reputational damage.
Still, there are limits to how much liability can be shed via terms and conditions. Regulators and consumer advocacy groups can become involved, particularly in very sensitive leak situations - such as the recent 23andMe data compromise, where genetic information was leaked.
To effectively safeguard sensitive information and prevent data breaches, companies must adhere to reasonable standards for data protection. These standards go beyond mere compliance with legal requirements and encompass best practices recommended by cybersecurity experts and regulatory bodies.
The National Institute of Standards and Technology (NIST) provides comprehensive guidelines and frameworks for securing sensitive data and mitigating cybersecurity risks. These guidelines serve as a roadmap for organizations seeking to establish robust data protection measures. Key resources from NIST include the Cybersecurity Framework, Special Publication 800-53, and the NIST Risk Management Framework.
Reasonable data protections standards incorporate best practices including data encryption, both at rest and in motion, multi-factor authentication (MFA), regular security audits, and proactive analysis of security. Encryption ensures that sensitive data is rendered unreadable to unauthorized parties, even if it is intercepted during transmission or stored on a compromised system. MFA adds an extra layer of security by requiring users to provide multiple forms of verification before accessing sensitive information, reducing the risk of unauthorized access in the event of a compromised password. Regular security audits help identify and address vulnerabilities in the company's infrastructure before they can be exploited by malicious actors. Proactive analysis of security ensures that actual practices remain current or even ahead of industry standards.
Companies that aim to truly prioritize the security and privacy of their users' data must go above and beyond minimum legal requirements. By embracing a proactive approach to cybersecurity and adhering to recognized industry standards such as those outlined by NIST, organizations can significantly reduce the likelihood of data breaches and demonstrate their commitment to protecting sensitive information.
Understanding and analyzing these complex situations requires a broad set of skills. Explaining it to judges, lawyers, and juries requires not only understanding the technological issues, but also being able to bridge the gap between technical and non-technical audiences. That's a rare set of skills - so make sure when you pick an expert, they're not only knowledgeable about the technology, but also familiar with explaining this to non-technical people.