Topic
Privacy Intersections: Cybersecurity, GRC and Audit
When: Monday, 31 Aug 2026, 12:00 pm – 1:00 pm (NZST)
Format: Virtual Only
Topic Abstract
Privacy and cybersecurity programs operate in parallel, creating unclear ownership, duplicated effort and gaps that GRC and Internal Audit professionals must identify. This session examines where privacy, cybersecurity, risk management and assurance intersect and where privacy requires distinct oversight. Attendees will learn how to evaluate sensitive data inventories, data retention, unstructured data, data minimization, access controls, third party risk, privacy impact assessments, AI bias, incident response and privacy metrics. The presentation also addresses emerging privacy exposures, including incomplete processing maps, purpose drift, weak consent and preference management, excessive data collection, AI-related data use and unclear governance. Participants will leave with practical methods to clarify control ownership, assess program maturity, identify audit evidence, prioritize remediation and build a roadmap for establishing or strengthening a privacy risk management program.
Why Attend
Gideon Rasmussen is a cybersecurity leader with more than 20 years of experience. He has served as a Chief Information Security Officer, leading information security programs, including PCI payment card security, third-party risk management, application security and information risk management. His experience spans banking, startups, insurance, pharmaceuticals, DoD/USAF, aerospace and defense, state government, advertising and talent management.
Gideon is a sought-after speaker at conferences, universities and corporate events. He is the #1 bestselling author of Program Architecture: Fight the Good Fight and has written more than 30 articles on cybersecurity and operational risk. A United States Air Force veteran, Gideon has completed the Bataan Memorial Death March four times.
Please register via the ISACA Auckland Chapter Engage site.