IAPP Privacy. Security. Risk. + AI Governance Global 2026
Seattle
6-9 October
Conference
8-9 Oct.
Training
6-7 Oct.
Workshops
7 Oct.
Cute Policy, But Who Defends the Door? Why Security Legal Is the True Enterprise Shield
Thursday, 8 Oct.
11:30 - 12:30 PDT
Room 612, Level 6
Intermediate level
Cybersecurity, privacy, physical security and AI governance are increasingly part of the same enterprise risk conversation. Decisions that begin in the security operations center can quickly reach the boardroom, the workplace, the data center, or the public, and they often require legal, security, engineering, human resources and business leaders to make tradeoffs before all the facts are known.
This session examines how companies move beyond siloed compliance checklists to manage converged risk in practice. Through real-world scenarios involving insider threat, supply-chain exposure, incident response, law-enforcement engagement and agentic AI, the panel will explore how teams balance regulatory obligations, operational resilience, privacy, speed and accountability.
The discussion will also consider the evolving role of security legal: when to engage law enforcement, how to preserve privilege while coordinating response, how to build defensible third-party and AI-governance processes, and how to navigate increasingly complex reporting and enforcement expectations. The session closes with a practical framework for building a security legal function that is embedded early, aligned to the company’s risk tolerance, and equipped to support decisive action under pressure.
What you will learn:
- How cyber, privacy, physical security, insider risk and AI governance combine to create one enterprise risk surface.
- How to make defensible decisions when legal compliance, operational resilience, privacy and speed pull in different directions.
- How legal, security, engineering, HR and business teams can clarify roles before and during an incident.
- How law-enforcement engagement, intelligence sharing, third-party risk and AI agents are changing security-legal practice.
- How to build the governance, frameworks and resourcing model needed for an effective security legal function.
Featured in this session

Andrew Scott
CIPP/E, CIPP/US, CIPM
Senior Privacy and Security Counsel
Roblox

Laura Newton
CIPP/US
Global Security Counsel
TikTok

Stacy Shelhorse
Cybersecurity Counsel
F5

Bunny Smith
Global Cybersecurity Counsel
Yahoo