In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance.
The CISO role keeps absorbing adjacent territory: fraud, resilience, third-party risk, AI governance.
It makes sense that many of these responsibilities have gravitated toward the CISO because cyber risk rarely stays confined to a single domain.
They also often believe security teams are solely responsible for managing cyber risk.
Security’s role is to provide expertise, visibility, and guidance, but lasting risk reduction happens when technology, business, risk, and security teams work together.