Christina Alexandropoulou-Alexander, Co-Chair, ISRM Mediterranean Chapter and Security & Market Safety Manager at Philip Morris International, discusses why privacy must be embedded into organisational security
As returns from taking the stage at Intersec in Dubai and simultaneously celebrates being named a finalist for the Trailblazer in Security Award, Christina Alexandropoulou-Alexander remains focused on the themes that have shaped her 25-year career. Privacy, security, ethics, and human behaviour continue to converge in ways that define organisational resilience, and these themes also sit at the heart of her keynote on Privacy and Data Protection at the EU Conference.
For her, privacy is no longer an isolated compliance requirement but a living practice that determines how organisations behave, communicate, and respond under pressure. In this interview, Christina expands on why privacy must be woven into the fabric of modern security strategy, and why its future sits firmly in the hands of people, not just systems.
Why do you believe privacy has become a strategic imperative for modern organisations?
Privacy today is far more than a regulatory obligation. It has become an essential part of organisational resilience and responsible security practice. After decades working across Security, Safety, Crisis Management, Investigations and Market Safety, I have learnt that genuine protection begins much earlier than the technologies we often focus on first.
It begins with ethics, behaviour, and human-centred decision-making.
If we think about Aristotle’s principle, “We are what we repeatedly do. Excellence, then, is not an act but a habit”, privacy excellence follows this logic. It does not emerge because we have a policy written on a page. It emerges because behaviours and leadership decisions reinforce it every single day. When privacy becomes a habitual practice rather than an administrative task, organisations gain not only compliance, but trust.
How do privacy and security intersect in the real operations of a business?
Although people often try to categorise privacy as legal and security as operational, in practice they are inseparable. A privacy breach is a security breach. A poorly managed investigation becomes a data protection failure. A lack of coordination between functions exposes gaps that directly put organisations at risk.
Security teams sit at the centre of this intersection. We understand how data flows across an organisation, how people behave under pressure, and where weak points in a process may sit. That position gives us a unique responsibility: to ensure that privacy becomes a lived operational habit, not an abstract compliance requirement.
You emphasise the human element. Why is this still the root of most privacy failures?
Because most incidents do not begin with malicious actors. They begin with people navigating unclear responsibilities, rushed decisions, inadequate training, fragmented communication, or outdated processes. Humans act based on comfort, pressure and practicality. Not regulation.
This is especially visible in sensitive environments such as investigations, employee relations or crisis response, where people are making decisions quickly and sometimes emotionally. If privacy is not embedded into the human layer of an organisation, then even the strongest technical system cannot compensate. When people understand the why, not just the how, privacy becomes culture, not compliance.
How does Aristotle’s framework of Ethos, Pathos and Logos apply to organisational privacy today?
It is surprisingly relevant. Aristotle created a model for persuasion, but it is also a model for leadership.
Ethos, the foundation of credibility, requires security professionals to demonstrate integrity when handling sensitive information. If people trust the process, they behave honestly. If they fear mishandling, risk escalates.
Pathos, the dimension of empathy, reminds us that privacy is fundamentally about protecting people: their dignity, their identity and their personal stories. In investigations, crisis communication or delicate interpersonal matters, empathy reduces harm and improves outcomes.
Logos, the rational component, reinforces the need for structured governance, clear escalation pathways, and processes that are consistently followed. Scenario-based learning also plays a role, because it gives people the confidence to act correctly under pressure.
Together, these elements create a holistic, human-centred framework for privacy that transcends legal obligation.
How should organisations embed privacy within their wider risk management frameworks?
Modern threats are hybrid. They sit across technology, behaviour, reputation and regulation. As Co-Chair of the ISRM Mediterranean Chapter, I see daily that privacy cannot sit outside the risk ecosystem. When organisations integrate privacy into risk assessment and operational planning, they gain the ability to:
- Anticipate vulnerabilities before they escalate
- Improve the integrity and proportionality of investigations
- Support leadership decisions with accurate, ethically sourced information
- Strengthen crisis coordination and communication
- Reduce legal and reputational exposure
- Build trust with regulators, employees and partners
Privacy, when fully embedded, becomes a strategic advantage.
You describe security as a guardian of trust. What does that mean in practice?
Security professionals today are responsible for much more than physical assets. We protect people, data integrity, organisational credibility and ethical conduct. In investigations we must uphold dignity and proportionality. In communication we must balance transparency with confidentiality.
Trust takes years to build and seconds to lose. Privacy is one of the clearest indicators of organisational character. If a company treats personal information with respect, people notice. If it does not, the damage is immediate and long-lasting.