The role of a Chief Information Security Officer (CISO) has expanded significantly to encompass areas such as fraud, resilience, third-party risk, and AI governance, according to Ann Barron-DiCamillo, EVP and CISO at U.S. Bank. She notes that while this consolidation can make security leaders more effective by addressing interconnected risks, no single individual can realistically own every aspect of these disciplines at scale. Instead, success increasingly relies on building strong partnerships across technology, risk, legal, fraud, compliance, and business teams.
Barron-DiCamillo emphasizes that the CISO's function is evolving from direct control to convening stakeholders, aligning priorities, and ensuring risk decisions are made with a comprehensive understanding of their broader implications. She states that "cyber knows no borders," illustrating how issues like a third-party outage can become a resilience problem, AI adoption raises governance questions, and fraud techniques evolve alongside general threat activity.
Regarding incident reporting, Barron-DiCamillo acknowledges regulators' push for shorter deadlines to facilitate early awareness and assist affected organizations. However, she points out the inherent tension between speed and certainty during the initial hours of an incident, when information is incomplete and teams are focused on containment and investigation rather than drafting reports. While timely communication is important, she stresses that it should be grounded in facts to avoid confusion and maintain confidence, advocating for a balance that allows for timely information sharing without imposing excessive administrative burdens during critical response phases.
When discussing security investments, Barron-DiCamillo suggests that many organizations over-invest in compliance activities that merely demonstrate security rather than actively reducing risk. She argues that financial institutions, which often possess mature control frameworks and understand their risks, should prioritize capabilities that reduce exposure before human intervention is required. This includes greater investment in automation, asset visibility, identity management, vulnerability management, and secure-by-design engineering practices, measuring success by risk reduction and resiliency rather than the number of controls implemented.
Concerning the duplication of effort when a widely used vendor is compromised, Barron-DiCamillo believes some parallel assessment is inevitable and appropriate due to varying technology stacks, dependencies, and risk tolerances across institutions. However, she also highlights the strength of the financial sector's information sharing through organizations like FS-ISAC and FSSCC. She advocates for more effective sharing of threat intelligence, technical indicators, and mitigation approaches to allow institutions to focus on their unique risks rather than independently recreating the same situational picture.
Drawing from her experience teaching cybersecurity risk management at American University, Barron-DiCamillo notes that many students initially perceive cybersecurity as primarily a technology problem. She corrects this by emphasizing that the most challenging issues often involve people, processes, and decision-making. Furthermore, she stresses that cybersecurity is a shared responsibility, with security teams providing expertise and guidance, but lasting risk reduction achieved through collaborative efforts across technology, business, risk, and security teams.






