Summary
The core message of the provided transcript is that data protection should be redesigned around impact reduction, not only attack prevention, and that privacy-enhancing technology such as polymorphic encryption and pseudonymization can support that shift. Sanne Vonk van Denderen frames the session against a changing threat landscape, referring to warnings heard earlier at the conference and arguing that security strategies fail when they try to predict an unknowable future too precisely. Instead, she says organizations should prepare for impact. She uses DigiNotar as a historical example whose lessons remain relevant fifteen years later: compliance does not equal security, organizations depend heavily on trusted third parties, basic security still matters, and prevention alone is insufficient.
Sanne connects those crisis lessons to current breach examples such as Odido and clinical diagnostics, emphasizing that cyber crisis management is fundamentally about uncertainty and impact after compromise. Her practical reframing is that privacy-enhancing technology should be seen as part of a security strategy because it reduces the harm that follows a successful intrusion. She notes that while encryption at rest and in transit are familiar, seeing polymorphic encryption working successfully in practice was new to her and motivated bringing the PEP success story to a wider audience beyond education and research.
Joep Bos-Coenraad then turns to the technical structure of analyzing sensitive data. He argues that the weakest link is not always encryption itself, but also the way people interact with technology; therefore, technology should be designed to encourage safer behavior. He outlines three broad approaches: sending questions to the source so sensitive data does not leave its original environment, using homomorphic encryption to compute on encrypted data and decrypt only aggregated results, and data sharing, where another environment receives access to unencrypted sensitive data. The rest of the visible excerpt focuses on data sharing, especially when data comes from multiple sources or when data collection and data use are separated in time.
The technical example centers on asynchronous data sharing with pseudonymized collection. Joep describes a study participant, “Bobby Tables,” whose identifying details and highly sensitive genome data should not be unnecessarily available to the same people or systems. A hospital may need to verify identity and contact information, while a sequencing workflow or survey tool often does not need names, email addresses, or phone numbers. By introducing an interface such as PEP, applying access management, allowing intermediaries to derive limited results, and sharing only minimized datasets with researchers, the design reduces harm if any single silo leaks. The key conclusion in the excerpt is that data minimization makes leaked data less harmful because it is harder to connect to identifiable individuals.
Key Topics
5 key topics from Sanne Vonk van Denderen and Joep Bos-Coenraad at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Prepare for breach impact, not only attack prevention.
- Use privacy-enhancing technology as an impact-reduction control.
- Separate identity tasks from sensitive data analysis workflows.
- Apply data minimization before sharing research datasets.
- Design access management around sources, intermediaries, and destinations.
“privacy enhancing technology is actually really interesting for your security strategy because it's an impact reduction control.”
Up Next

Next in agenda
Squaring the Circle: Lawful Access to Encrypted Data while preserving Cyber Security
Otmar Lendl

Also on digital sovereignty
Single Country of Failure is the metric you’re missing



Also on digital sovereignty
