

There is, actually, a pretty good chance your organization is right now running three separate programs—privacy, cybersecurity, and AI governance—with three different budgets, three different reporting chains, and three different languages. And there is also a pretty good chance that none of those three programs are working as well as they should.
That is, more or less, the central argument behind the 2026 Fortress Cybersecurity Award in Data Protection, and it is exactly what Amy Worley, Managing Director and Data Protection Officer at BRG (Berkeley Research Group), has spent the last several years trying to solve. Worley is a former Big Law trial attorney who spent 16 years in legal practice before going in-house as Global Chief Privacy Officer for a multinational pharmaceutical company, then joining the consulting world in 2019. She now leads BRG’s Privacy and Information Compliance practice group and is the author of The Confidence Advantage: Optimizing Privacy, Cybersecurity, and AI Governance for Growth—an Amazon #1 bestseller in Computer and Internet Law.
So what does a recovering lawyer see in a corporate data breach that a career IT security professional might miss? Quite a lot, it turns out. And the answer has less to do with technical controls than most people expect.
The Language Problem Nobody Wants to Admit
When Worley talks about why siloed governance programs fail, she actually starts with something that sounds almost too simple: language. Privacy professionals talk about GDPR and HIPAA and FTC enforcement. Cybersecurity professionals talk about attack surfaces and threat actors and vulnerability management. AI governance teams have their own vocabulary entirely. And all of them, simultaneously, are trying to convince the same executive team to give them budget and authority.
The result, Worley says, is essentially a slow-motion dysfunction. Each team is, at a principles level, trying to do the same thing—protect the organization’s data assets, manage risk, maintain the trust of customers and regulators. But because they are speaking different languages, using different systems, and competing for the same limited organizational bandwidth, they tend to be collectively less effective than any one of them could be on its own.
Her solution is Confidence by Design, an 11-principle framework that takes the core governance requirements from privacy law, cybersecurity best practice, and AI risk management and synthesizes them into a single unified architecture. The framework is deliberately legislation-neutral—designed to work regardless of which specific regulations apply to a given organization—and built around the idea that “digital trust” is not a compliance cost. It is a commercial asset.
“Effectively implemented digital trust programs actually grow the bottom line,” Worley says. “It is both risk-reducing and revenue-generating if you get implementation right.”
What Day One Actually Looks Like
For organizations that come to Worley in crisis mode—mid-incident, regulators engaged, boards already asking uncomfortable questions—the first priority is rarely technical. She says the breakdown in cybersecurity incidents is almost never on the technical side. It is almost always about who is deciding what, and who is talking to whom about what.
The incident playbook she uses starts with establishing two things immediately: communication rules and decision-making authority. No gossiping, no guessing. Information flows on a clear schedule, to clearly designated people, in clearly defined formats. That structure, she argues, is what separates organizations that recover cleanly from those that compound the original incident with internal chaos and message inconsistency.
For organizations that engage BRG for proactive program builds—increasingly common in 2025 and 2026 as board mandates around AI governance have accelerated—she starts with something she calls a pre-mortem. Rather than beginning with an assessment of what the organization has, she begins with a hypothetical: assume this project fails. What killed it?
“They always know,” she says. “The client always knows what is going to drive it off the rails.” Usually it is one of two things: the executive team does not really understand what they have asked for, or the internal team does not have the bandwidth to absorb and implement outside help. Starting with that knowledge, rather than arriving at it six months into an engagement, lets BRG build a program around the actual roadblocks rather than the theoretical ideal.
The Principle Everyone Skips
Of Worley’s 11 principles, the one organizations most consistently fail to implement is accountability. Not in the abstract sense of “someone is responsible for this”—most organizations have someone whose title includes the word “compliance”—but in the specific, operational sense of individual decision-ownership.
In an accountability culture, she explains, a decision is made deliberately, by a named person, who owns both the decision and the downstream risk. If it goes wrong, the accountable person does not get blamed. They learn, iterate, and make the next decision. The alternative—a blame culture where nobody wants to own a risk call—produces what she describes as “cover your backside” behavior that is both dysfunctional and, increasingly, a legal liability. Privacy law and AI governance frameworks both have explicit accountability provisions. Organizations that have not built that culture internally are, in a meaningful sense, already out of compliance.
Her practical test for accountability is characteristically direct: “Whose day is ruined if it goes wrong? That’s your accountable person.”
AI Governance Is a Data Problem
Worley’s framing of AI governance is somewhat different from how most organizations currently approach it. She does not see it as a distinct discipline that requires a separate Chief AI Officer or a standalone program. She sees it as an extension of the same data governance principles that should already be running privacy and cybersecurity—specifically, the challenge of getting the right data, to the right people, in the right place, at the right time.
The call she is getting most often in 2026 is not “help us deploy AI responsibly.” It is “we deployed AI, we put policies in place, and now nothing is working because the bottlenecks are everywhere and people are ignoring the process.” The root cause, she says, is almost always the same: organizations are over-evaluating low-risk use cases and creating friction that the business simply routes around.
According to Accenture research on responsible AI adoption, organizations that build structured AI governance programs with clear risk tiers see measurably faster deployment cycles alongside lower compliance exposure—exactly the combination Worley’s agile governance model is designed to produce. A Deloitte study on digital trust similarly found that companies with mature trust frameworks outperform peers on both customer retention and revenue growth, reinforcing the commercial case for treating digital trust as a strategic investment rather than a cost center.
The solution is what she calls an agile governance program—one that tiers use cases by actual risk level, empowers users with genuine AI literacy rather than policy documents, and streamlines the assessment process so that governance moves at the speed of the business. “The business will go whether you’re going with it or not,” she says.
The Commercial Case for Digital Trust
The framing Worley most wants business leaders to internalize is this: a well-implemented digital trust strategy is not a compliance expense. It is a product differentiator. The research—from Forbes, Accenture, Deloitte, and others—consistently shows that organizations with mature digital trust programs outperform on customer loyalty, investor confidence, and revenue growth.
That is the mindset shift she is calling for. Not “how do we avoid getting fined” but “how do we turn the evidence of our governance practices into a commercial advantage.” For Worley, the chief trust officer she envisions—owning cybersecurity, privacy, AI governance, and data governance under one unified accountability structure—is not a compliance hire. It is a strategic one.
Worley’s recognition in the 2026 Fortress Cybersecurity Award in Data Protection reflects exactly that kind of contribution: not just expertise in the technical requirements of data protection, but the ability to translate that expertise into organizational transformation that regulators accept, business partners trust, and boards can actually understand.
Enjoying insights from industry leaders? Subscribe to The Winners’ Circle podcast on your favorite podcast player and never miss an episode. Listen and subscribe at bintelligence.com/podcast.









