Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
ColumnsCybersecurityCyber Tactics ColumnLogical SecuritySecurity & Business Resilience

Cyber Tactics

The Privacy–Security Partnership: How We Bend Risk in a Resource Crunch

The partnership between cybersecurity and privacy matters now more than ever.

By Pam Nigro, Contributing Writer
cybersecurity and privacy
Shutthiphong Chandaeng / iStock / Getty Images Plus via Getty Images
April 22, 2026

If your team feels thinner, your backlog longer, and your privacy asks louder, you’re not imagining it. The 2026 ISACA State of Privacy study confirms what many of us are living: fewer than half of practitioners feel very/completely confident meeting new privacy laws, only 56% believe their Board has adequately prioritized privacy, and the median privacy staff dropped from 8 to 5 in a year. Stress is up — 71% cite the rapid evolution of technology (up from 63% last year), 62% cite compliance challenges, and 61% cite resource shortages. Yet this is exactly when the partnership between cybersecurity and privacy matters most.

Why Privacy and Security Need Each Other:

  • We cannot hire our way out of this resource gap; we must integrate our way out. The partnership is a two-way street:
  • Security provides the “How”: Identity management, encryption, and DLP are the technical guardrails that make lawful processing and breach prevention a reality.
  • Privacy provides the "Why": Lawful basis, data minimization, and retention rules tell Security what is actually worth protecting — and what is a liability that should be deleted.

We cannot hire our way out of this resource gap; we must integrate our way out. The partnership is a two-way street.

Where the pressure shows up:

The 2026 data highlights a shifting landscape in which technical expertise is the new bottleneck:

Eight Steps for Cybersecurity & Privacy Partners

1. Advocate with Shared Metrics

Stop reporting in silos. Build a Joint KPI Pack that ties privacy to cost avoidance:

  • Efficiency: DSAR (Data Subject Access Request) volume vs. automated fulfillment time
  • Risk Reduction: % of DPIAs completed pre-release and deletion coverage for “dark data” systems
  • ROI: Compare the cost of “re-work” for features shipped without Privacy by Design versus those that integrated it from day one.

Note: A DSAR is a legal request (under GDPR/CPRA) for an individual to access, correct or delete their data. Efficient handling is a primary driver for automation budgets.

2. Embed Privacy by Design into the SDLC

  • Add a Privacy Checkpoint in sprint planning for any feature touching personal data.
  • Use lightweight, automated DPIAs (Data Protection Impact Assessments) linked directly to security tickets.
  • Enforce “Privacy-as-Code” by tagging sensitive data classes in infrastructure-as-code to auto-apply retention jobs.

3. Build a Shared Data Foundation

  • Don't boil the ocean. Stand up a Joint Processing Register for your top 10 systems (Owners, Purpose, Lawful Basis).
  • The 90-Day Challenge: Run a deletion sprint on 2–3 high-volume systems. Track records deleted and the resulting reduction in storage costs and breach surface area.

4. Operationalize DSARs Without Chaos

Define a clear RACI (Responsible, Accountable, Consulted, Informed) for data requests. Pre-build playbooks for your systems of record with validated queries and export templates. Test these quarterly, just like a disaster recovery drill.

5. Prepare for “Privacy Incidents” Together

Traditional breach playbooks often miss non-security privacy incidents (e.g., over-collection or misdirected bulk emails).

  • Run Joint Tabletops including Legal and Comms.
  • Pre-draft notification templates to reduce panic when the clock starts ticking.

6. Manage Third-Party and AI Guardrails

Align Privacy’s Data Processing Agreements (DPAs) with Security’s vendor risk scoring.

  • For AI: Require data minimization and “Human-in-the-loop” for sensitive decisions.
  • Shadow AI: Red-team LLMs for prompt injection and data exfiltration to ensure internal data isn’t leaking into public models.

7. Harmonize Frameworks

Map your program to NIST Privacy Framework or ISO/IEC 27701. Align these with your existing security controls to ensure you aren’t creating “net-new” work for engineering teams. Maintain a Unified Risk Register so the Board sees one clear picture.

8. Build a Joint Culture

Launch a Champions Network. Pair a security engineer with a privacy legal expert for a mentorship exchange: the engineer explains the data flow, and the legal expert explains the “why” behind the regulation.

The ISACA data validates the squeeze, but our partnership determines the results. We don’t have infinite headcount, but we do have control over how we design our systems. By acting as one team — doubling down on Privacy by Design and automating the mundane — we can bend the risk curve even when resources are tight.

KEYWORDS: business continuity planning digital security security culture testing security tools

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Nigro headshot

Pam Nigro is the Vice President of Security and Security Officer at Medecision. She also is an ISACA Board Director and was the 2022-23 ISACA Board Chair. Image courtesy of Nigro

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

Man with covered face

Why Most Workplace Violence Prevention Starts Too Late

SEC 2026 Benchmark Banner

Events

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Safety Check: How Can Colleges Address Risk in a Campus Carry Environment?

    Safety Check: How Can Colleges Address Risk in a Campus Carry Environment?

    See More
  • Software-as-a-Service

    Observing Privilege to Reduce Risk in Software-as-a-Service (SaaS)

    See More
  • cyber security freepik

    The fight against cyber threats requires a public-private partnership. Here’s how to get it done.

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk Analysis and the Security Survey, 4th Edition

  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing