Dynamic Tensions Revisited: Privacy, Security, and Identity Eleven Years Later

The technologies have changed dramatically since 2015. The fundamental tension has not.

By Tim Godlove, Ph.D.

In 2015, I published Dynamic Tensions: Essays on Balancing Privacy, Security & Identity in the 21st Century. The book brought together several years of writing and research around a problem that was becoming increasingly important as society moved deeper into the digital age: individuals, organizations, and governments were becoming increasingly dependent upon information while simultaneously struggling to determine how much personal information should be collected, who should control it, how it should be protected, and how identity could be reliably established in cyberspace.

The title Dynamic Tensions reflected what I believed was the central problem. Privacy, security, and identity were never independent objectives. They existed in tension because strengthening one could easily affect the others. Establishing a person's identity, for example, can improve security while requiring the collection of additional personal information. Expanding surveillance may help identify threats, yet it can also diminish privacy. Greater anonymity may protect legitimate personal freedom while making fraud and malicious activity more difficult to detect. The challenge, then and now, is not to eliminate these tensions but to manage them responsibly. The original book explicitly described this balance, arguing that too little information can make identification and authentication difficult, while too much can threaten individual privacy.

Eleven years later, the technologies at issue in this argument have changed dramatically. Cloud computing has become a foundation of modern information technology. Smartphones have become extensions of personal and professional identity. Biometric authentication has moved into everyday life. Telework and hybrid work have weakened the traditional connection between employees and organizational facilities. Digital identities mediate access to banking, healthcare, government services, employment systems, social networks, and countless commercial services. Most significantly, artificial intelligence can now analyze, correlate, infer, generate, imitate, and act upon information at a scale that would have been difficult to imagine when Dynamic Tensions was published. Yet the underlying tension among privacy, security, and identity has not disappeared. If anything, it has become more consequential.

The Question Was Never Just About Cybersecurity

One of the central arguments underlying Dynamic Tensions was that cybersecurity could not be considered separately from privacy and identity. As organizations accumulated greater quantities of medical, financial, employment, government, and other personal information, protecting databases and networks was only part of the problem. We also had to consider what information should be collected, how it should be used, who should be able to access it, and how individuals could establish their identities in an increasingly interconnected environment. The book consequently addressed subjects ranging from privacy and anonymity to healthcare information, data protection, telework, identity, and patient identification, as related parts of a larger digital transformation.

At the center of that transformation was a deceptively simple question: Who can be trusted in cyberspace? Before an organization grants someone access to a bank account, medical record, government benefit, corporate network, or information system, it must establish reasonable confidence that the individual is actually who they claim to be. Doing that requires information, whether through passwords, devices, credentials, behavioral characteristics, biometrics, or combinations of authentication factors. Yet every additional piece of information collected to establish identity creates another piece of information that must be protected and another potential source of privacy risk.

This relationship creates one of the most persistent dynamic tensions in the digital environment. Organizations need sufficient information to establish trust, prevent fraud, control access, and protect systems, but collecting increasingly detailed information about individuals can itself create risk. The question is therefore not simply how much information technology can collect. It is the amount of information an organization actually needs to accomplish a legitimate purpose while respecting the privacy of the individual.

Identity Has Become Part of the Security Boundary

In 2015, much of cybersecurity was still discussed in terms of protecting organizational networks and systems. Firewalls separated trusted environments from untrusted environments, employees authenticated into corporate systems, and security organizations devoted considerable attention to protecting the organizational perimeter. That model was already changing, but the transformation accelerated considerably over the following decade.

Today, cloud computing distributes applications and information across infrastructure that organizations may not physically own. Telework enables employees to work from home, hotels, airports, customer sites, and other locations. Mobile computing distributes organizational access across smartphones, tablets, laptops, and other devices. Contractors, business partners, suppliers, customers, and increasingly automated systems routinely interact with organizational resources from networks and devices outside the traditional enterprise boundary. As a result, physical location alone cannot provide a meaningful basis for establishing trust.

Identity has therefore become an increasingly important part of the modern security boundary. Organizations must determine not only whether a connection is technically permitted, but also who or what is making the connection, how strongly that identity has been authenticated, which device is being used, which resources the identity is authorized to access, and whether the requested activity is consistent with expected behavior. This represents a fundamental shift from a security model centered largely on where someone is located to one increasingly centered on who or what is requesting access and whether that request should be trusted.

The change reinforces one of the original arguments of Dynamic Tensions. Identity and security cannot be separated, but neither can identity and privacy. Establishing a stronger digital identity may improve security, but the mechanisms used to establish that identity may require additional information about individuals. The modern challenge is therefore to develop identity systems that provide sufficient assurance without turning authentication into unnecessary surveillance.

Biometrics Went From the Future to Everyday Life

Biometrics played an especially important role in the identity discussion because they appeared to offer a powerful solution to one of cybersecurity's oldest problems: determining whether the person presenting a credential is actually the authorized user. Fingerprints, facial characteristics, retinal or iris patterns, voice characteristics, and other biological attributes offered possibilities that passwords alone could not provide.

Eleven years later, biometric authentication has moved from a comparatively specialized security technology into everyday life. Millions of people routinely unlock smartphones with their faces or fingerprints, authorize financial transactions through biometric authentication, and encounter facial recognition technologies across travel, government, commercial, and security environments. What once appeared to be an emerging technology is increasingly an ordinary part of digital identity.

The privacy implications, however, remain substantial. A password can be changed after it is compromised. A fingerprint cannot. A person's face cannot simply be replaced following a data breach. Biometric information therefore requires a different level of consideration because it is inherently connected to the individual. The risk becomes even greater when biometric information is combined with other data, because the resulting collection can reveal much more about an individual than any single piece of information would on its own.

The pattern is familiar by now: stronger authentication and greater privacy exposure grow from the same root. What differs with biometrics is the stakes involved. Information collected unnecessarily, retained indefinitely, shared beyond its original purpose, or used for surveillance cannot simply be reissued the way a compromised password can. The question is no longer whether biometrics will become part of digital identity. They already have. The more important question is how biometric information should be governed, protected, retained, and used.

Privacy Has Become a Data-Governance Problem

The privacy argument in Dynamic Tensions was not simply about secrecy. It reflected broader questions concerning the collection, use, accuracy, protection, and control of information about individuals. Those questions have become considerably more difficult because a person's digital identity is no longer contained within a single organization or database. Instead, fragments of an individual's identity are distributed across a vast digital ecosystem.

Financial institutions know certain things about us, healthcare organizations know others, and government agencies possess still different information. Employers, retailers, social networks, mobile applications, automobiles, websites, connected devices, and online services continually add to our digital lives. A single piece of information may reveal relatively little. When many pieces are combined, however, they can create an extraordinarily detailed representation of an individual.

Privacy therefore cannot be reduced to whether an organization successfully prevents a cybersecurity breach. An organization could theoretically protect every database from unauthorized access and still create a serious privacy problem by collecting excessive information, retaining it indefinitely, combining it in unexpected ways, or using it for purposes that individuals never reasonably anticipated. Security and privacy overlap, but they ask different questions. Security asks whether information is adequately protected from unauthorized access, alteration, theft, or loss. Privacy also asks whether the information should have been collected, whether the individual understood how it would be used, whether it is being retained longer than necessary, and whether its use remains consistent with the purpose for which it was originally obtained.

This distinction is increasingly important because data itself has become an organizational asset. The temptation is to collect information because storage is inexpensive and future uses cannot always be anticipated. Yet responsible data governance requires a different question: not simply, can we collect this information? but should we collect it, and what responsibilities do we assume if we do?

Artificial Intelligence Changes the Scale of the Problem

Artificial intelligence represents perhaps the most consequential technological development affecting the privacy-security-identity relationship since Dynamic Tensions was published. The digital economy had already generated enormous amounts of information, but AI dramatically increases the ability to derive value, patterns, relationships, predictions, and new insights from that data.

Modern AI systems can analyze large datasets, correlate information from multiple sources, identify patterns that humans might overlook, generate predictions, summarize enormous collections of documents, and infer characteristics that an individual may never have explicitly disclosed. This changes the privacy equation because protecting the individual pieces of information may no longer be sufficient. AI can sometimes derive sensitive conclusions from combinations of otherwise ordinary data.

Generative AI introduces another dimension to the identity problem. Historically, digital identity systems primarily sought to determine whether someone presenting a credential was the legitimate owner of it. Increasingly, organizations must also determine whether the digital evidence associated with a person is authentic. The apparent sender may not have written a convincing email. A voice may be synthesized. A photograph may be generated or altered. Video can be manipulated. Documents can be convincingly fabricated, and automated agents can interact with information systems without a human being directly participating in every transaction.

The identity question is therefore evolving. Eleven years ago, we were principally concerned with the question: How do I prove that I am me? Increasingly, we must ask a more complicated question: How does a digital system know that I am me, that the evidence representing me is authentic, and that the entity interacting with the system is actually authorized to act on my behalf? As artificial intelligence becomes more capable and AI agents begin performing activities independently, distinguishing between human identity, machine identity, delegated authority, and synthetic representations of identity will become increasingly important.

Anonymity Has Not Disappeared—It Has Become More Complicated

Dynamic Tensions also examined the relationship between identity and anonymity, as anonymity can simultaneously serve legitimate privacy interests and pose security challenges. Whistleblowers may require anonymity. Political dissidents may depend upon it. Individuals seeking sensitive medical, financial, or personal information may reasonably desire privacy. Ordinary citizens may believe that legitimate activities should not automatically become permanent records associated with their identities.

At the same time, anonymity can benefit fraudsters, cybercriminals, hostile intelligence services, and others attempting to conceal malicious activity. This creates an understandable temptation to conclude that stronger identification is always the answer. Yet a digital environment in which every action requires permanent identification would solve some security problems while potentially creating profound privacy and civil-liberty concerns.

A more sophisticated approach recognizes that different transactions require different levels of identity assurance. Sometimes an organization genuinely needs to know exactly who an individual is. In other circumstances, the organization may only need to establish that the person possesses a particular attribute—that the individual is authorized, eligible, licensed, an employee, above a required age, or entitled to receive a particular service. Good digital identity architecture should distinguish between proving identity and proving eligibility, rather than automatically collecting as much personal information as possible.

The Human Problem Remains

Perhaps one of the most enduring lessons from the original work is that technology alone cannot resolve the tension among privacy, security, and identity. Even the most sophisticated identity architecture ultimately depends on the people who operate it, a point my earlier research bears out. Although organizations can implement extensive technical controls, the security of information ultimately depends in part on whether people understand and follow them. My dissertation found that personal attitude, social pressure, and sense of control provided a weak-to-moderate model for explaining teleworkers' willingness to follow organizational information-security guidelines.

That human dimension remains relevant even as the technologies have become considerably more sophisticated. Organizations can deploy encryption, multifactor authentication, identity management platforms, biometric systems, Zero Trust architectures, data loss prevention technologies, AI monitoring, and increasingly sophisticated cybersecurity tools. People still click links, approve authentication requests, disclose credentials, circumvent inconvenient controls, decide what information to collect, determine how long information should be retained, configure systems, grant permissions, and establish organizational priorities.

The same principle now applies to artificial intelligence. AI can assist with cybersecurity, detect anomalies, automate analysis, and help organizations manage enormous volumes of data, but people still determine the objectives, rules, access permissions, training data, acceptable risks, and governance structures for those systems. Technology may change the mechanisms by which decisions are implemented, but responsibility for those decisions cannot be simply delegated to technology.

From Privacy by Design to Trust by Design

Looking back at Dynamic Tensions from 2026 suggests that we may need to think beyond treating privacy, security, and identity as separate technical or compliance disciplines. A more useful concept may be trust by design. Privacy should not be considered only after a system has been developed. Security should not be strengthened only after an incident occurs. Identity should not become important only when authentication fails, and AI governance should not begin only after an automated system produces an unacceptable result.

These considerations increasingly need to be designed together. Organizations developing digital systems should ask from the beginning what information is truly necessary, why it is being collected, how identity will be established, how access will be authorized, how information will be protected, how long it will be retained, whether individuals understand how it will be used, and what happens when the technology makes a mistake. Artificial intelligence adds further questions about what information AI systems can access, what they can infer, what decisions they can make, and whether automated agents should be permitted to act independently.

Trust by design does not mean eliminating risk. That is impossible. It means recognizing that privacy, security, identity, usability, accountability, and increasingly artificial intelligence are interconnected elements of the same digital environment. Decisions made in one area inevitably influence the others.

Trust by design is admittedly an aspirational standard. Organizations profit from collecting and retaining data, and design philosophy alone rarely overcomes that incentive; historically, it has been regulation and enforcement, not voluntary design principles, that have most reliably forced restraint. Trust by design is therefore best understood not as a substitute for accountability mechanisms but as a framework for how organizations should think even where external requirements are minimal or absent.

The Long View

When I wrote Dynamic Tensions in 2015, the central challenge was how to balance privacy, security, and identity in a society becoming increasingly dependent upon digital information. Eleven years later, I would not fundamentally change that premise. What has changed is the scale of the environment in which the tension must be managed. We have more data, more connected devices, more remote access, more biometric identification, more dependence upon digital services, and now artificial intelligence capable of analyzing and generating information at unprecedented scale.

Artificial intelligence makes this responsibility even more important. AI will make information more powerful, digital identity more consequential, authentication more difficult, and the distinction between human and machine activity less obvious. At the same time, organizations will possess greater capability to assemble, analyze, and infer information about individuals. Those capabilities can create tremendous social and economic value, but they also make thoughtful governance essential.

Eleven years later, privacy, security, and identity therefore remain inseparable elements of the digital environment. Each matters independently, but the concept connecting all three is trust. Individuals must be able to trust that organizations will collect only the information they legitimately need, protect it appropriately, use it responsibly, and establish identity without creating unnecessary surveillance. Organizations, in turn, must be able to trust that the people, devices, systems, and increasingly artificial agents interacting with their information are authentic and appropriately authorized.

The technologies surrounding this problem will continue to change, just as they have during the eleven years since Dynamic Tensions was published. The deeper issue has endured. Technology can give us increasingly powerful tools for identifying people, protecting information, analyzing behavior, and making decisions. Still, it cannot decide for us what kind of digital society we want to create. That responsibility remains ours—and that may be the most important dynamic tension of all.

Previous
Previous

How Do We Learn in the Digital and AI Era?

Next
Next

Small Hotels, Big Consequences: Why Hospitality Cybersecurity Is a National Security Issue