As the world becomes ever more connected and the Internet of Things grows, the potential risks of large, devastating cyberattacks will raise the stakes in the privacy–security dispute. For example, attacks on supervisory control and data acquisition networks, such as the 2010 Stuxnet attack on Iranian nuclear-enrichment facilities8 and the attack on the Ukrainian power grid in 2015,9 threaten to cripple entire critical infrastructures