Skip to content

CruiseCon AI & Privacy 2026: Ship's Log

Bill Brenner posts regular updates from abourd the Mariner of the Seas cruise ship, where he is covering the proceedings during CruiseCon 2026

Ship's Log, Sunday, Oct. 4, 2026:

I'll be honest: A cruise was never on my bucket list. I love the sea and riding on it in boats big and small. I did grow up on the North Shore of Massachusetts, after all. But the carnival atmosphere of a cruise never appealed to me.

But I go where the job takes me, and this time it was aboard the Mariner of the Seas, a Royal Caribbean ship that left the Port of Galveston, Texas yesterday, on a course to the eastern coast of Mexico.

Like any journey destined for a special place in the heart, this one has been illuminating so far. Not because of the ship, though it's not bad at all. The sunset yesterday and sunrise this morning were quite spectacular, lighting up the clouds in a way you imagine Heaven looking like.

But what is truly making this cruise special are the people joining me for CruiseCon AI and Privacy 2026.

There are a few old friends, and many new ones who are already making me feel smarter than I was before coming aboard. Some Sunday highlights:

Mental health data raises the stakes for cybersecurity

One of the conversations I was especially interested in having aboard CruiseCon was with the team from TherapyAppointment, a company that provides practice-management software for mental health professionals.

Mental health has been one of my recurring areas of focus throughout my years covering cybersecurity, particularly the burnout and psychological strain facing security professionals. But this conversation approached the intersection from another direction: What does good cybersecurity look like when the information you're protecting may be among the most personal data someone will ever generate?

TherapyAppointment's story goes back decades. Its founder, Bill Whitehead, started writing software for his own therapy practice, initially automating repetitive administrative work. What was conceived as a tool for one office — and later a side business that might someday attract 20 customers — eventually grew to roughly 40,000 customers.

The team – including Serina Isch, Lisa Stephens, Denise Hoyt, Clinton Campbell, and Heather Kuhn Houston – described cybersecurity evolving from something largely handled by the security people into something that increasingly shapes business decisions. HIPAA requirements helped accelerate that evolution, but so have growing customer concerns about privacy and, more recently, questions about AI and how sensitive information might be used.

Security can't belong only to the security team. Developers need to understand it. Support staff need to understand it. Leadership needs to buy into it. And customers need enough education to ask the right questions. That is partly why TherapyAppointment brought its people to CruiseCon: to expose more of the organization to the threats, privacy issues and security thinking shaping the technology they build and support.

When you're entrusted with people's mental health information, that seems like exactly the right mindset. I look forward to writing about them more in the future.

CYBR.SEC.Careers: Sometimes opportunity starts with getting someone into the room

My second conversation brought me back to one of the reasons CYBR.SEC.Careers sponsored CruiseCon in the first place.

I spoke with two young men whose paths into cybersecurity couldn't be more different — and yet their experiences reinforce the same point: Breaking into this industry requires more than certifications, job listings and exhortations to "network."

Sometimes people need someone to actually open a door.

Antonio Talavera is a University of Houston student who is also interning with the USDA as an IT program and resource management analyst. His ambitions are considerably more offensive: He'd eventually like to test the security of nuclear power plants for the federal government — finding weaknesses so defenders can fix them. His connection to CYBR.SEC.Careers began at a much more precarious moment, when he was looking for help funding school and wasn't certain he could afford another semester. That connection led to a scholarship and opportunities that have since included a Capital One internship, CYBR.SEC.CON and now CruiseCon.

Jawad Charafeddine came from acting and education and began an intentional pivot into IT and cybersecurity about a year ago. Faced with the bewildering amount of information confronting newcomers, he gravitated toward CYBR.SEC.Careers' mentorship program. The mentor he met through it remains part of his network today.

What struck me most wasn't another discussion about the "cybersecurity talent gap." We've had plenty of those.

It was hearing them talk about human connections.

They came aboard to meet people, learn from people already doing the work and build relationships that may matter years from now.

That's the talent pipeline CYBR.SEC.Careers is trying to build — not by complaining that we can't find enough qualified people, but by giving promising people access, mentorship and a chance to get into the rooms where careers begin.

More CruiseCon coverage:

CruiseCon 2026: Cybersecurity, AI and Privacy at Sea
CYBR.SEC.Careers sponsors CruiseCon 2026, an Oct. 3–8 cybersecurity conference at sea focused on AI, privacy, identity and leadership.
CruiseCon 2026: AI, Privacy and Security Leadership
CruiseCon 2026 brings CISOs, privacy leaders and security experts together Oct. 3–8 to tackle AI risk, identity, privacy, cyber threats and leadership at sea.

Latest