Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityCyber Tactics ColumnSecurity Enterprise ServicesSecurity Leadership and ManagementLogical Security

Tap into connection points between security and privacy

A proactive and collaborative approach to security is crucial to forging a secure and privacy-conscious digital future.

By Pam Nigro, Contributing Writer
Data privacy and information security

da-kuk / E+ via Getty Images

March 14, 2024

Data privacy and information security are both critical components of building customer trust for organizations. Privacy protects our personal data and empowers us to control its use, while security shields information against unauthorized access and threats. Balancing these needs is key, like finding the sweet spot between convenience and robust protection.

In the face of challenges posed by emerging technologies, evolving regulations and the escalating volume of data, privacy and security teams often find themselves stretched thin. To address these issues effectively, enterprise leaders can better leverage the intersections between privacy and security disciplines. By doing so, they not only enhance performance in both areas but also strengthen their overall approach to safeguarding sensitive information. It is crucial for leaders to actively seek connection points between these disciplines, fostering collaboration and ensuring a holistic approach to data protection.

Transparency and trust are vital foundations; organizations must be clear about data practices, while individuals can strengthen their defenses through safe online habits. The connection between security and privacy are evident in ISACA’s recently released Privacy in Practice 2024 survey. According to the survey, data breaches rank among the top three privacy program failures alongside inadequate training and lack of privacy by design. Failing to secure customer data can lead to severe consequences that may lead to privacy violations for affected customers. This in turn, may also expose organizations to regulatory peril and possible long-lasting reputational damage.

Still, the distinctions between privacy and security can often be muddled. Vice Vicente addressed the distinctions well in an AuditBoard blog post, writing “privacy-relevant information usually ties back to a human being. Meanwhile, under security, you might have sensitive data that has to do with a company’s metrics or strategy. Although company information is sensitive, it does not necessarily have an impact on the privacy of the individual, their identity, or their data.”


❝

While there are distinctions between security and privacy, fostering initiative-taking, intentional collaboration between the teams can yield better results for both disciplines.”


Information security encompasses additional imperatives, including data recovery and managing incident response repercussions. In contrast, privacy teams spend substantial time addressing legal and compliance mandates, especially in the context of evolving privacy regulations.

While there are distinctions between security and privacy, fostering initiative-taking, intentional collaboration between the teams can yield better results for both disciplines. Sharing a detailed data inventory is one example. Providing a clear understanding of what data is collected and maintained by the enterprise is crucial for both privacy and security functions, particularly in handling personally identifiable information. There also are technical areas in which security teams can leverage sound privacy protocols. According to the ISACA Privacy in Practice survey, for those whose organizations embrace privacy by design, half or more use more privacy controls than are legally required, leading to cryptographic protection (59%), data minimization and retention controls (54 percent) and improved data quality and integrity (50%). These methods can make the job of security professionals more straightforward and achievable.

Ongoing collaboration between privacy and security professionals is especially key in executing enterprise projects and initiatives. That is why both functions should be represented on a cross-functional taskforce (for enterprises large enough to have dedicated security and privacy functions). By having representatives from privacy, security and related digital trust fields represented, the organization can drive toward holistic approaches to leveraging technology effectively, responsibly and ethically, while also keeping key compliance considerations top-of-mind for all stakeholders. Cross-functional taskforces play a pivotal role ensuring that security and privacy are considerations are integrated from the outset of projects and product development, minimizing the risk of costly recalibrations or remediations in later stages.

Although cybersecurity has been a hot-button issue and dominated discussions among enterprise leaders for nearly a decade, the imperative to prioritize data privacy has gained momentum in recent years, particularly with the introduction of regulations like GDPR and similar regulatory requirements taking root across the globe. While security and privacy interests share some overlap on the Venn diagram, there are distinctions that call for practitioners with specialized expertise. Collaboration between security and privacy professionals can significantly enhance the impact of their work by fostering a connection between functions and moving away from siloed approaches. Joining forces on comprehensive data inventories, developing a shared understanding of necessary actions needed to protect critical data and committing to an ongoing knowledge exchange will allow security and privacy professionals to navigate their increasingly challenging roles with greater efficiency and effectiveness.

Ultimately, a proactive and collaborative approach, involving everyone from security to privacy to IT teams to users, is crucial to forging a secure and privacy-conscious digital future.

KEYWORDS: cyber security data privacy data protection information security security strategy

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Nigro headshot

Pam Nigro is the Vice President of Security and Security Officer at Medecision. She also is an ISACA Board Director and was the 2022-23 ISACA Board Chair. Image courtesy of Nigro

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • iPhone

    Find the balance between security and privacy in a BYOD world

    See More
  • cybersecurity and privacy

    The Privacy–Security Partnership: How We Bend Risk in a Resource Crunch

    See More
  • cyber

    4 reasons ERP data security and privacy should factor into your 2021 security budget

    See More

Related Products

See More Products
  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

  • 9780367667887.jpg

    Surveillance, Privacy and Security

  • s and the law.jpg

    Surveillance and the Law: Language, Power and Privacy

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing