In an interview with Help Net Security, U.S. Bank CISO Ann Barron-DiCamillo described a role that keeps absorbing adjacent domains—fraud, resilience, third-party risk, and AI governance. She said the expansion makes sense because cyber risk crosses organizational borders, but it also means no single leader can personally own all of it. The most effective CISOs, she argued, act as conveners, building partnerships across technology, risk, legal, fraud, compliance, and business lines rather than trying to master every discipline.

On incident reporting, Barron-DiCamillo acknowledged why regulators have moved to shorter deadlines—early awareness can help the broader industry—but warned of a tension between speed and certainty. In the first hours, facts are incomplete and teams are focused on containment, not drafting reports. She said initial reporting should enable timely sharing without adding administrative burden at the worst moment, and that communications should be grounded in facts rather than assumptions.

She also pushed back on compliance-driven spending, saying many organizations over-invest in activities that provide evidence of security rather than security itself. The real gains, she said, come from automation, asset visibility, identity management, vulnerability management, and secure-by-design engineering. On vendor compromises, she said some duplication in assessments is inevitable because environments differ, but the financial sector should lean on groups like FS-ISAC and FSSCC to share threat intelligence and avoid recreating the same analysis.