Episode 20

Security by Design or Disaster?

Professor Lee Bygrave, Director of the Norwegian Research Centre for Computers and Law in the University of Oslo, joins Johanna in the studio to discuss security by design.

The pair discuss the importance and challenges of translating “by design” mantras from legal concepts to engineering concepts and vice versa. In the context of the Optus and Medibank hacks, they canvas the proposal for new penalties for privacy breaches in Australia, privacy reform, the EU’s proposed Cyber Resilience Act and much more.

Relevant links:

Professor Bygraves’ Paper: Security by Design: Aspirations and Realities in a Regulatory Context: https://www.idunn.no/doi/10.18261/olr.8.3.2#sec-5

Professor Bygraves’ Paper: Data Protection by Design and Default: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3944535

Australian Securities and Investments Commission v RI Advice Group Pty Ltd: https://www.judgments.fedcourt.gov.au/judgments/Judgments/fca/single/2022/2022fca0496

Proposed EU Cyber Resilience Act: https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act

GDPR Text, Article 25: https://gdpr-text.com/read/article-25/

‘Good privacy reform rests on well-resourced tech regulators’ by Sarah O’Connor: https://www.innovationaus.com/good-privacy-reform-rest-on-well-resourced-tech-regulators/

‘Privacy is hard and Seven Other Myths’ by Jaap-Henk Hoepman: https://mitpress.mit.edu/9780262045827/privacy-is-hard-and-seven-other-myths/

‘Ethical IT innovation, a value based system design approach’ by Sara Spiekerman: https://www.taylorfrancis.com/books/mono/10.1201/b19060/ethical-innovation-sarah-spiekermann

Follow:

Tech Policy Design Centre on Twitter: @TPDesignCentre