Judging from the results of a survey CSO conducted late last fall, a high percentage of respondents (from among nearly 800 CSOs and other top security executives) may feel more of an allegiance to their former colleagues in law enforcement than they do to their enterprise’s customers. In answer to our questions about their willingness to rat out various stakeholders and under what conditions, 24 percent of respondents said they would give up information about customers to government or law enforcement agencies without a court order. When it came to their trading partners and employees, the percentages were 23 and 37, respectively (or disrespectively, in the case of the poor benighted employees).Upping the ante somewhat, we asked roughly the same question in the context of a national security investigation; in that case, the segment willing to give up customer information without a warrant rose to 41 percent (versus 43 percent who would surrender such data only under court order or subpoena).To me, this says something about the strength of professional affinity. In many cases, CSOs come from law enforcement backgrounds. They trust police and government agencies to operate in good faith and to do the right thing. Sometimes the people who come knocking for information are old friends whose ties go back a long way. One prominent CSO told me he is frequently called by former police colleagues trying to locate people on outstanding criminal warrants. On request, he would search his company’s customer records and, if any matches were found, provide the subjects’ address information to police.We live in a world in which most people don’t have guilty consciences (even those who ought to). In the view of a self-described average citizen, those who have “nothing to hide” should never object to invasions of their privacy. By that rationale, privacy is itself a presumptively suspect condition, making those who would insist upon it appear to be guilty of something. Dan Geer, the CTO of security consultancy @Stake, has opined that privacy is a generational thing and that the expectation of having any is being gradually bred out of the populace (this is of course less true in Europe, which continues to exalt privacy). Some of us of a certain age are outraged by practices that younger citizens may take for granted. My mother, for example, reacted with horror to surveillance video of a woman beating her child in a mall parking lot. Her horror, however, was triggered more by the very existence of the video than by the behavior of the woman. But when it comes to customers, CSOs entreated by police or government agencies to divulge customer information should at least feel the twinge of divided loyalties. They need to ask themselves what, if any, duty they may have to protect the information they get from customers. Must the privacy of customer information always take a backseat to requests from law enforcement? Should such requests be governed by probable cause limitations applied by courts? At a minimum, should customers be fully informed as to the circumstances under which a company will provide information to police?Clearly, an important debate is needed now about privacy in the context of national security. CSOs should stop to consider where their loyalties lie and whether customers would agree that those loyalties are in the right place. For more on CSO’s related survey, visit www.csoonline.com/csoresearch/report49.html. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe