The Missing Link

The Missing Link: Data Privacy & Information Security – 
A Question for Prof. Dr. Louise Specht-Riemenschneider

Digital transformation is often framed as being in tension with data protection: while organizations aim to use data more efficiently, privacy regulations and security requirements can appear to slow down innovation. In a discussion with Prof. Dr. Louisa Specht-Riemenschneider, a more nuanced perspective emerged—one in which digitalization, data protection, and information security are not opposing forces, but mutually reinforcing elements of modern digital systems.

Information security as an enabler of digital trust

In response to the question of how information security fits into the relationship between digitalization and data protection, Prof. Specht-Riemenschneider emphasized that secure technical infrastructures are a prerequisite for lawful and trustworthy data use.

Information security frameworks—such as ISO standards and Information Security Management Systems (ISMS)—were highlighted as key building blocks in this context. Rather than simply acting as compliance tools, they create structured and controlled environments in which data can be processed safely. This includes mechanisms such as controlled access, secure temporary data aggregation, and strict separation of storage systems.

From this perspective, strong security architecture does not limit data use; instead, it enables organizations to process data in ways that are both legally compliant and ethically responsible. Standardization was also identified as increasingly important, as it helps create transparency, consistency, and trust across different systems and organizations.

Overcoming organizational resistance to security investment

A second central question addressed the common reluctance of companies to invest in robust information security systems. Many organizations tend to assume that their existing IT infrastructure is sufficient—until they experience a serious security incident.

The expert pointed out that awareness often changes only after cyberattacks make risks tangible. To address this gap proactively, two approaches were highlighted:

First, organizations need to be confronted with realistic threat scenarios that make abstract risks more concrete and understandable. Second, information security should not be communicated solely as a regulatory obligation, but as a strategic advantage that benefits the organization as a whole.

Research findings, including studies from Austria, suggest that users place greater trust in systems that demonstrate strong privacy and security protections. When usability is comparable, secure systems are more likely to be preferred. This positions information security not only as risk mitigation, but also as a competitive factor.

Conclusion: Security as a foundation for digital progress

The discussion ultimately reframes information security as a core enabler of digital transformation rather than a barrier to it. Secure systems allow organizations to unlock the benefits of data-driven innovation while maintaining legal and ethical standards.

Key takeaways include the idea that strong security frameworks actively support better data protection practices, that awareness of digital risks often remains low until incidents occur, and that trust is becoming a decisive factor in digital ecosystems. In the long term, robust data protection and security standards may even evolve into a location advantage for businesses and countries competing in the digital economy.

At the same time, the conversation highlights an ongoing challenge: communicating the value of information security in a way that resonates with decision-makers beyond compliance requirements and technical details.

You can watch the full interview here. It is available in German only.

DSRA - Digital Security & Regulatory Advisory © 2026         All rights reserved        Legal & Privacy Notice        Imprint         

Information icon

Wir benötigen Ihre Zustimmung zum Laden der Übersetzungen

Wir nutzen einen Drittanbieter-Service, um den Inhalt der Website zu übersetzen, der möglicherweise Daten über Ihre Aktivitäten sammelt. Bitte überprüfen Sie die Details in der Datenschutzerklärung und akzeptieren Sie den Dienst, um die Übersetzungen zu sehen.