U.S. Bank CISO says the security role keeps growing and no one can own all of it
In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance. She says no single leader can own all of it, so partnerships across technology, risk, legal, and business teams matter most.
Barron-DiCamillo also weighs in on shorter incident reporting deadlines, spending on compliance versus risk reduction, sharing threat intelligence across banks, and what she taught students at American University about cyber risk being a shared responsibility.

The CISO role keeps absorbing adjacent territory: fraud, resilience, third-party risk, AI governance. Is that consolidation making security leaders more effective, or producing a job no single person can hold?
I think the answer is both.
The CISO increasingly serves as a convener across technology, business operations, risk management, and resilience. It makes sense that many of these responsibilities have gravitated toward the CISO because cyber risk rarely stays confined to a single domain. I’ve frequently said, ‘cyber knows no borders’ and this is an extension of that reality into cross-organizational dependencies. A third-party outage becomes a resilience issue. AI adoption creates governance questions. Fraud techniques evolve alongside threat activity.
At the same time, no one leader can personally own every aspect of those disciplines at scale. The most effective CISOs are not trying to become experts in everything. They build strong partnerships across technology, risk, legal, fraud, compliance, and the business lines. The role is becoming less about direct control and more about convening the right stakeholders, aligning priorities, and ensuring risk decisions are made with a full understanding of broader implications.
Success in this space is less about expanding authority and more about building trusted partnerships and creating operating models that enable organizations to manage risk collectively.
Reporting deadlines for incidents have grown shorter in recent years. From where you sit, does that help defenders or mostly generate paperwork during the hours when teams can least spare it?
I understand why regulators have moved toward shorter reporting timelines. Early awareness can help government and industry partners identify broader campaigns and potentially assist affected organizations.
That said, there is always tension between speed and certainty. In the first hours of an incident, organizations are working with incomplete information. The facts are evolving, the scope may be unclear, and priorities are rightly focused on containment, investigation, and understanding what happened, not drafting reports.
Timely communication with regulators is important and will remain a priority. But it is equally important that those communications are grounded in facts rather than assumptions. Early assessments often change as investigations progress, and repeated revisions can create confusion and erode confidence at a time when clear communication matters most.
The key is finding the right balance. Initial reporting should enable timely information sharing without creating unnecessary administrative burden at the exact moment responders are trying to investigate and recover. Most practitioners support transparency. The challenge is ensuring reporting requirements strengthen collective defense while still allowing organizations sufficient time to develop an accurate understanding of the event before drawing conclusions.
Which control that the industry treats as table stakes do you think earns less than its cost, and what deserves the money instead?
Rather than pointing to a specific control, I would argue that many organizations still over-invest in compliance activities that provide evidence of security rather than security itself.
Most financial institutions have mature control frameworks. Most financial institutions understand where their risks are. The real work is reducing those risks consistently and at scale. That’s where automation, asset visibility, identity management, vulnerability management, and secure-by-design engineering practices can have a much larger impact.
If I had to choose where additional investment should go, it would be in capabilities that reduce exposure before human intervention is needed. The threat environment moves too quickly for organizations to rely solely on manual processes. Security spending should be measured by risk reduction and resiliency delivery, not the number of controls added.
When a widely used vendor is compromised, every affected bank runs its own assessment in parallel. Is duplicated effort the price of independent judgment, or a coordination failure the sector should have solved by now?
I think some duplication is inevitable and appropriate because our environments differ. Every institution has a different technology stack, different dependencies, and different risk tolerances. No organization can outsource its responsibility to understand its own exposure.
At the same time, we should not all be building the same situational picture independently. One of the strengths of the financial sector is its willingness to share information through organizations like FS-ISAC, FSSCC, and our public-private partnerships. The more effectively we share threat intelligence, technical indicators, and mitigation approaches, the more time institutions can spend assessing their unique risks rather than recreating the same analysis.
Recent industry response to widely adopted technology vulnerabilities demonstrated the strength of this coordination. The speed of information sharing between financial institutions, industry groups, government partners, and technology providers helped organizations make more informed decision in a rapidly evolving environment.
We’ll always need independent judgment, but the faster we can establish a common operating picture during major cyber events, the more time organizations can spend managing risk and recovery rather than chasing the same information in parallel.
You taught cybersecurity risk management and governance at American University. What do graduates tend to believe on arrival that gets corrected in their first year on a security team?
Many of my students arrived believing cybersecurity is primarily a technology problem. They quickly learned that the most difficult issues usually involve people, processes, and decision-making.
They also often believe security teams are solely responsible for managing cyber risk. What I emphasized is cybersecurity is a shared responsibility. Security’s role is to provide expertise, visibility, and guidance, but lasting risk reduction happens when technology, business, risk, and security teams work together.

Read more:
- National Life Group CISO expects more vulnerabilities in six months than in thirty years
- Airbus CSO on supply chain blind spots, space threats, and the limits of AI red-teaming
- Marathon Petroleum’s CISO on OT security automation, supply chain risk