Intro to Privacy for Information Security Professionals

Thursday, April 30, 2026 | 10:30AM–11:15AM PT | California Ballroom D, Second Floor
Session Type: Breakout Session
Delivery Format: Presentation/Panel
Security teams spend a lot of time keeping malicious actors out, but some privacy problems don’t involve the bad guys at all. They often arise from everyday security decisions about how data is used, shared, and retained. This session approaches privacy as more than compliance, offering a perspective that enhances both cybersecurity and privacy perspectives. We will discuss privacy through a cybersecurity lens for technically fluent professionals who already manage security risk, but may not always think about how their decisions affect individual privacy. Using familiar security concepts like least privilege, logging, retention, threat modeling, and incident response, the session connects them to core privacy ideas such as data minimization, purpose limitation, transparency, and privacy by design. Attendees will explore where security and privacy align, where they differ, and why many privacy incidents come from authorized, well-intentioned actions rather than malicious actors. Through short, realistic scenarios drawn from higher education, participants will dig into common decision points and blind spots in security workflows. The session wraps up with practical, institution-agnostic ways to fold privacy thinking into the cybersecurity work you’re already doing, whether or not your institution has a formal privacy office. You’ll leave with a clearer mental model for spotting privacy risks and harms, collaborating more effectively, and protecting people, not just systems.

Presenters

  • Ben Archer

    Associate Director, Technology Privacy and Compliance, Arizona State University