Digital platform technology choices: Cybersecurity and privacy

Is our platform’s commitment to building trust in the ecosystem adequately supported by its technological choices regarding privacy and cybersecurity?

This article is part of the Digital Platforms hub

Data privacy and cybersecurity choices provision the technical backbone for creating a trusted environment for the ecosystem.

A platform organization needs to clearly articulate and enforce its data privacy policy. To build trust with users and partners, the platform organization must have clearly structured data sharing arrangements and policies governing downstream secondary use of data, particularly around access to third parties, but also including data enrichment and transformation that the platform firm may undertake internally. To ensure that downstream processing is clearly defined and avoids unnecessary limitations, the platform organization should articulate its internal privacy policy as well as external privacy notice to ecosystem stakeholders. Where data moves across ecosystem players, every ecosystem stakeholder’s roles, access rights, ownership rights, and transformation rights with respect to data resources should be clearly specified. Managing data privacy also involves managing the trade-off between achieving the platform’s business goals driven by data and delivering agency to the user regarding control of data acquisition points including cookies, pixels, web beacons etc. To enable appropriate downstream usage, the platform firm should also manage data retention and transformation through effective aggregation and anonymization, to ensure it adequately uses data towards its business goals while also complying with regulation and addressing privacy concerns.

Platform organizations also need to set up the appropriate cybersecurity capabilities and defense to ensure data security and regulatory compliance. However, cybersecurity becomes increasingly challenging in an open ecosystem, where the platform firm is dependent on the security guarantees and policies of its ecosystem partners. As firms increasingly participate in open ecosystems, cybersecurity breaches are likely to increase. The speed with which malware and hacking evolve often outpaces the speed with which adequate responses can be developed and deployed. Moreover, the regulatory landscape to prosecute cybersecurity incidents is increasingly fragmented as every regulatory regime involves different requirements.

A platform firm should include cybersecurity as a core part of the partner due diligence review for potential partners. The risk associated with every ecosystem partner/provider/ consumer connected with the firm should be assessed, scored, and periodically reviewed.

Beyond partner review, the rise of machine-to-machine communication in ecosystems requires that access interfaces and credentials are appropriately architected with a view to securing all communication points. Verification of machine communication, for example, through cryptography, is essential to securely scaling ecosystem interactions.

The platform firm should ensure that its infrastructure and governance avoid attack points and single points of failure. Improvements in artificial intelligence and machine learning also, help analyze security threats and better identify malevolent access patterns.

platform-thinking-labs

Spotify, connected cars, and open banking – Platforms or glorified distributors?

Gaining power in concentrated markets What do Spotify, the connected vehicle data market, open banking…

7 days ago

How AI agents rewire the organization

The unbundling and rebundling of organizations We frequently make the mistake of thinking of AI…

3 weeks ago

AI won’t eat your job, but it will eat your salary

On rebundling jobs and skill premiums The AI augmentation fallacy goes something like this: “AI…

1 month ago

Finding the product in your platform

On the risks of over-emphasizing platform thinking In an age of platform hype, everyone scrambles…

1 month ago

Keyboard-as-a-platform

The untold story of the most under-used real estate on the phone screen Which players…

2 months ago

How stand-up comedy helps Amazon win at e-commerce

How stand-up comedy helps Amazon win at e-commerce On Attention Conglomerates and Internal Attention Markets…

2 months ago