Author: OWASP Foundation - Bewertung: 0x - Views:0
Integrating privacy into development cycles often feels like forcing a square peg into a sprint-shaped hole—too slow, too complex, too disconnected from the team’s real-world pace. This talk demystifies privacy threat modeling and shows how it can be adapted for Agile teams without creating friction.
Drawing from real-world implementations across regulated industries (healthcare, finance, insurance), we’ll explore practical methods to identify privacy risks using streamlined artifacts—like sprint-aligned privacy prompts, backlog risk markers and minimalist data flow nudges.
We’ll also look at how frameworks like LINDDUN and OWASP Privacy Threat Modeling cheat sheets can be adapted for sprint rituals like backlog grooming, daily standups and retrospectives.
By the end, attendees will walk away with a blueprint to make privacy a by-design reality—even in two-week sprints—and improve alignment between development, security and compliance.
Adarsh Nair
adarshnair.com
x.com/svnairadarsh
facebook.com/adarshsvnair
linkedin.com/in/adarshsvnair
instagram.com/toadarshnair
Adarsh Nair is the Dir & Global Head of Info Sec Compliance at UST, where he leads the organization's efforts to maintain and enhance information security and business continuity across global operations. In this role, he ensures compliance with industry standards and regulatory requirements, driving a culture of security and resilience throughout the organization. In addition to being an information security strategist, he is an author and keynote speaker. Adarsh is recognized as a Fellow of Information Privacy (FIP) recognized by the International Association of Privacy Professionals (IAPP). He has received several accolades, including the CyberSecGlobal (CSG) Award for Emerging CISO and an Excellence Medal from the Hon’ble Chief Minister of Kerala for his contributions to Kerala Police Cyberdome.
Adarsh holds a Bachelor’s degree in Computer Science & Engineering and a Master’s degree in Information Security. He is currently advancing his expertise by pursuing a Doctoral Degree in Information Security. With over a decade of experience, he has developed expertise in Information Security Governance, Risk and Compliance, Business Continuity, Data Privacy, and Ethical Hacking. He continues to learn and grow through various certifications, including CCISO, CISSP, FIP, CIPM, CIPP/E, OSCP, ECSA, CHFI, CEH, ISO 27001:2022 Lead Auditor, ISO 22301:2019 Lead Auditor, ISO 27701:2019 Lead Implementer, ISO 31000:2018 Lead Implementer, PGCCL and so on.
In his spare time, Adarsh volunteers as Commander at the Kerala Police Cyberdome, an honorary position. He is also a Co-Leader of the Open Worldwide Application Security Project (OWASP) Kerala chapter and serves on advisory boards for the EC-Council. Additionally, he is part of the Industry Institute Interaction Cell at Kerala Digital University and also the syllabus-revision committee member at Kerala Technological University (KTU).
Adarsh has spoken on Information Security topics at various conferences, sharing his knowledge on Ethical Hacking, Social Engineering, Financial Frauds, Ransomware, Dark Web, and Data Privacy. He has authored three books: “Mastering Information Security Compliance Management,” “The Infodemic,” and “Dark Web Demystified,”. He has published articles in various national and local newspapers, magazines and in journals such as IEEE and ACM.
Greeshma Nair
Tsaaro
Sr. Data Protection Consultant
She is a certified privacy and security professional with a strong foundation in GDPR, DPDPA, and global data protection frameworks. She is CIPP/E certified, an ISO 27701 Lead Implementer, and has completed Data Protection Officer (DPO) training. Her credentials are further reinforced by multiple OneTrust certifications, including Privacy Management, PIA & DPIA Automation, Consent & Preferences Management, Responsible AI, and Data Mapping Automation.
With a background spanning knowledge management, data analysis, and software testing, Greeshma’s transition into the privacy domain is anchored by her ISO 27001 Lead Auditor certification and a deep understanding of compliance-driven security practices. She has worked on building privacy control frameworks, conducting PIAs, designing workflows for RoPA, LIA, and PbD assessments, and aligning privacy programs with evolving regulatory requirements.
An accomplished author, Greeshma co-authored Mastering Information Security Compliance Management (Packt) and self-published The Infodemic and Dark Web Demystified. She has spoken at national and international platforms including OWASP AppSec and c0c0n, sharing insights on privacy trends, digital hygiene, and emerging tech risks.
Passionate about continuous learning and community engagement, she is committed to advancing responsible data practices and supporting organizations in embedding privacy into agile development and security-by-design frameworks.
linkedin.com/in/greeshmamr
Managed by the OWASP® Foundation
SOCIAL SHARE CARD GENERATOR