When specifying a system, security and privacy need to be addressed as early as possible, yet stakeholders find doing so difficult in the face of conflicting priorities. When these concerns are addressed, we discover how intrinsically difficult specifying usable security and privacy can be towards meeting business and developmental needs, and the subsequent blurred distinction between requirements and security and privacy concepts.
The theme of this year's Evolving Security and Privacy Requirements Engineering (ESPRE) 2026 workshop continues to align with the main theme of this year’s RE conference - Sustainability and workforce transformation in the era of generative AI: How to prepare for a future in collaboration with AI tools and assistants.
The growing pervasiveness of generative AI systems is profoundly reshaping both sustainability concerns and workforce transformation, making it essential to rethink how requirements are engineered. From a security and privacy perspective, generative AI introduces new opportunities that improve elicitation, consistency, traceability, and compliance checking, unfortunately it also raises novel risks related to data protection, model misuse, accountability, and human–AI responsibility sharing.
At the same time, sustainability becomes a first-class concern, encompassing not only energy consumption and environmental impact of AI-driven solutions, but also long-term social sustainability, skills evolution and trust in AI-supported work practices. These challenges call for new paradigms on security and privacy requirements that explicitly consider human–AI collaboration and its impact on both technical systems and people.
The ESPRE workshop provides a multi-disciplinary one-day workshop, bringing together practitioners and researchers from across the world interested in evolving security and privacy requirements engineering practice.
The workshop will include an invited keynote talk, paper presentations and discussions, and a facilitated roadmap discussion session towards future Security and Privacy Requirements Engineering activities.
We look forward to seeing you in Montréal.
Abstract: 'Secure by Design' is an approach ensuring security is designed into any project delivering capabilities or services, such that security is considered from the outset and through life. It has been mandated not only by UK MOD, and the UK government more generally, but by our international partners around the world. In this talk, I will discuss what Secure by Design means to UK Defence, and several problems that make its adoption particularly challenging. I will then talk about some of the work we're doing to address these challenges, and propose some directions where the ESPRE community could help. © Crown Copyright (2026), Dstl. This material is licensed under the terms of the Open Government Licence
Bio: Dr Shamal Faily is a Senior Principal Scientist at Dstl, and a Chartered Engineer. Much of his current work delivers the Science and Technology underpinning Secure by Design within the UK Ministry of Defence (MOD). He previously held a range of academic posts at Robert Gordon University, Bournemouth University, UCL, and University of Oxford. Prior to his work in Higher Education, Shamal was a software engineer at Logica UK’s Space & Defence division for nearly a decade. Shamal has long established interests in the design of secure and usable systems. He has published over 100 peer-reviewed publications in Software Engineering, Cyber Security, HCI, and Computer Science Education.
Security Analysis of IRC Server Design: Mapping Protocol Features to Attack Vectors Using MITRE ATT&CK, Melisa Sarıtaş, Yusuf Tahir Kaya, Malek Malkawi and Reda Alhajj. (Istanbul Medipol University, Turkey, and University of Calgary, Canada)
PCSRF: A Personalized CSRF Simulation Framework for Security Education and Attack Delivery Analysis, Ahmet Cemal Ozturk and Malek Malkawi. (Istanbul Medipol University, Turkey)
A Systematic Mapping Study on Security Requirements, Vulnerabilities, and Technological Architectures in E-Voting, Max Christian Sørensen, Ahmed Najem Khalaf and Elda Paja. (IT University of Copenhagen, Denmark)
A Stage-Aware Requirements-to-Evidence Framework for Secure CI/CD Pipelines, Sabbir M. Saleh, Nazim Madhavji and John Steinbacher. (University of Western Ontario and IBM Canada Lab, Canada)
Towards Productive Cyber Resilience and Safety Analysis in Model-Based Systems Engineering: A Quantitative Framework and Prototype Tool, Serdar Akar, Huseyin Dogan, Shamal Faily and Duncan Ki-Aries. (Bournemouth University and Dstl, UK)
See the schedule below for other details
Due by 23:59:59 AoE, (Extended to) Monday, 01 June 2026
Submissions to EasyChair
(8 Pages, plus 2 pages for references)
From Monday, 22 June 2026
For more information, see the RE26 website about how to register to attend the event
Due by 23:59:59 AoE, Thursday, 02 July 2026
Submission link to be supplied
Monday, 17 August 2026
Throughout the day, the workshop organisers will note potential research challenges that form the basis of a roadmap for evolving security and privacy requirements engineering. Following the final session, we will close the workshop with a wrap-up session, in which these challenges and a potential roadmap for addressing them will be proposed.
| 13:45 - 13:55 | Workshop OpeningWelcome and Opening Remarks - Dr. Mattia Salnitri, Workshop Co-Chair. (Università degli studi di Bergamo, Italy) |
| 13:55 - 14:35 | Invited TalkBy Dr. Shamal Faily (Defence Science Technology Laboratories (Dstl), UK) |
| 14:35 - 15:15 | Presentations
|
| 15:15 - 15:45 | Coffee Break - E-2010 and E-2011 |
| 15:45 - 16:45 | Presentations
|
| 16:45 - 17:00 | Conclusion and recap of ESPRE 2026, discussion on next year's theme. |
| 17:00 | Workshop Close |
If you would like to be considered towards joining the Programme Committee, do contact us for more information.
ESPRE is now celebrating it's 13th year. Although the ESPRE workshop has been co-located with RE since 2014, it builds on the success of earlier workshops in security requirements engineering and secure software engineering.
For example, the Security and Privacy Requirements Engineering (SPREE) Workshop in 2011, the International Workshop for Software Engineering for Secure Systems (SESS) series, and the Requirements for High Assurance Systems (RHAS) workshop series.
During 2020-2022 (the pandemic), workshop and conference sessions were mostly held online, then in 2023 we retunred to in-person sessions in Hannover, Germany, followed by Reykjavik, Iceland in 2024, then Valencia, Spain in 2025.