Skip to Content

IAPP Privacy. Security. Risk. + AI Governance Global 2026

Seattle

6-9 October

Conference

8-9 Oct.

Training

6-7 Oct.

Workshops

7 Oct.

Back to conference agenda

Cute Policy, But Who Defends the Door? Why Security Legal Is the True Enterprise Shield

Thursday, 8 Oct.

11:30 - 12:30 PDT

Room 612, Level 6

Intermediate level

BREAKOUT SESSIONCYBERSECURITY LAWDATA SECURITYINCIDENT MANAGEMENTLAW AND REGULATIONRISK MANAGEMENTSTRATEGY AND GOVERNANCETECHNOLOGY

Cybersecurity, privacy, physical security and AI governance are increasingly part of the same enterprise risk conversation. Decisions that begin in the security operations center can quickly reach the boardroom, the workplace, the data center, or the public, and they often require legal, security, engineering, human resources and business leaders to make tradeoffs before all the facts are known.

This session examines how companies move beyond siloed compliance checklists to manage converged risk in practice. Through real-world scenarios involving insider threat, supply-chain exposure, incident response, law-enforcement engagement and agentic AI, the panel will explore how teams balance regulatory obligations, operational resilience, privacy, speed and accountability.

The discussion will also consider the evolving role of security legal: when to engage law enforcement, how to preserve privilege while coordinating response, how to build defensible third-party and AI-governance processes, and how to navigate increasingly complex reporting and enforcement expectations. The session closes with a practical framework for building a security legal function that is embedded early, aligned to the company’s risk tolerance, and equipped to support decisive action under pressure.

What you will learn:

  • How cyber, privacy, physical security, insider risk and AI governance combine to create one enterprise risk surface.
  • How to make defensible decisions when legal compliance, operational resilience, privacy and speed pull in different directions.
  • How legal, security, engineering, HR and business teams can clarify roles before and during an incident.
  • How law-enforcement engagement, intelligence sharing, third-party risk and AI agents are changing security-legal practice.
  • How to build the governance, frameworks and resourcing model needed for an effective security legal function.

Featured in this session

headshot of Andrew Scott

Andrew Scott

CIPP/E, CIPP/US, CIPM

Senior Privacy and Security Counsel

Roblox

headshot of Laura Newton

Laura Newton

CIPP/US

Global Security Counsel

TikTok

generic profile silhouette

Stacy Shelhorse

Cybersecurity Counsel

F5

headshot of Bunny Smith

Bunny Smith

Global Cybersecurity Counsel

Yahoo