Cybersecurity leaders are being asked to coordinate more than traditional security work—but one CISO cannot personally own every related risk. In a Help Net Security interview published October 6, 2026, U.S. Bank EVP and CISO Ann Barron-DiCamillo described the role as a convener across technology, business operations, risk management and resilience. Her answer to whether consolidation makes the job more effective or unmanageable: “both.”
Why the CISO role keeps expanding
Cyber risk rarely stays within the security department. A third-party outage can become a resilience problem; AI adoption raises governance questions; and fraud techniques evolve alongside other threats. Barron-DiCamillo said those overlaps are drawing related responsibilities into the CISO’s orbit.
That does not mean a CISO should try to become the organization’s expert in every discipline. “The most effective CISOs are not trying to become experts in everything,” she said. Instead, she described effective security leaders as conveners who build partnerships across the functions that share exposure to cyber risk. These are her views from the interview, not a universal job description for every organization.
What shared responsibility looks like
Security teams contribute expertise, visibility and guidance, but durable risk reduction depends on cooperation among security, technology, business and risk teams. Legal, fraud, compliance and business-line partners may also be needed when a particular risk crosses their responsibilities.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Barron-DiCamillo drew on her teaching of cybersecurity risk management and governance at American University: some students initially saw cybersecurity mainly as a technology problem or assumed security teams alone managed cyber risk. Her answer was that “cybersecurity is a shared responsibility.” In practice, shared responsibility means security can help identify and explain risk, while the relevant teams work together on decisions and lasting changes.
How to judge security investment
Counting controls alone does not show whether an organization is safer. Barron-DiCamillo said investment should be judged by whether it reduces exposure and delivers resilience. She named these capability areas as useful ways to reduce risk before people have to intervene:
- Automation: reduce reliance on manual intervention for repeatable security work.
- Asset visibility: improve understanding of what the organization needs to protect.
- Identity management: manage access as a core part of exposure reduction.
- Vulnerability management: find and address weaknesses.
- Secure-by-design engineering: account for security during system design and development.
These are capability categories she recommended in an interview, not a comparative evaluation of technologies or proof that one approach fits every organization. The practical test is whether a proposed investment addresses the organization’s actual exposure and improves its ability to withstand or recover from disruption.
Incident reporting: speed versus reliable facts
Early incident awareness can help government and industry partners recognize a broader campaign and assist affected organizations. But the first account of an incident may be incomplete: responders still need to contain the threat, investigate what happened and establish facts. Barron-DiCamillo acknowledged both needs and emphasized factual regulator communications.
The operational tension is between sharing useful information promptly and avoiding claims that later evidence may change. An organization can prioritize containment and investigation while ensuring its communications are grounded in what is known, rather than treating an early report as a final explanation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What banks gain from sharing—and what they cannot delegate
Financial institutions can share threat intelligence, technical indicators and mitigations through groups such as FS-ISAC and FSSCC, as well as through public-private partnerships. Sharing can help establish a common operating picture sooner and reduce the work of recreating analysis other organizations have already done.
Rank #4
It cannot replace an institution’s own assessment. Banks have different technology stacks, dependencies and risk tolerances, so each still needs to understand its own exposure and recovery needs. Barron-DiCamillo’s distinction is between using shared information to move faster and retaining independent judgment about local risk—not choosing one in place of the other.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →

