Intelligent CIO Europe Issue 17 | Page 77

////////////////////////////////////////////////////////////////////////////////// /////////////////////////////////////////////////// t cht lk TECH TALK BEYONDTRUST EXPERT ON WHY BIOMETRIC DATA POSES UNIQUE SECURITY RISK Morey Haber, CTO at BeyondTrust, explores the potential security risks associated with biometric data and provides some basic recommendations that consumers should consider before handing over biometric data to organisations. W e live in sensitive times. One ‘sensitive’, under-discussed topic that we need to directly confront and have an open conversation about is around the sensitivity of data. Yes, that’s right, what do people today consider ‘sensitive’ data? The definition of Personally Identifiable Information (PII) often includes your name, email addresses, usernames, passwords, birthdate, address, social security number, credit card information, medical history, etc. I would stipulate that most people can agree that these are all sensitive data sets. www.intelligentcio.com But there is an entire classification of sensitive data in the world that we do not discuss and is going to be a problem in the very near future. The sensitive data we are failing to adequately address is the linkage of our physical, carbon-based human bodies to all the biometric data being stored by IoT devices and services in the cloud. If you think this sounds far-fetched, ask yourself if you or any of your loved ones participated in an ancestry DNA kit or received a new notebook, mobile device, or smartwatch that stores health or login data via fingerprints or facial recognition PII. I am willing to bet that either you, or someone close to you, has. “ THE BIGGEST PROBLEM WITH BIOMETRIC DATA IS NOT THE STORAGE OR AUTHENTICATION TECHNOLOGY USED, RATHER IT IS THE STATIC NATURE OF BIOMETRIC DATA ITSELF. INTELLIGENTCIO 77