THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Please share your journey so far and your current roles and responsibilities.
Marco Maiurano, Executive Vice President and Chief Information Security Officer, First Citizens Bank
I currently serve as the Chief Information Security Officer at First Citizens Bank. However, I began my journey in cybersecurity in a very unusual manner. When working at The College Board, I uncovered students cheating on the Scholastic Assessment Test (SAT) program. What astonished me in this investigation was that it was not merely the students but also test proctors, guidance counselors, and parents who were involved. This is how I started my career in cybersecurity without even realizing at the time. From there, I worked in numerous other cybersecurity roles, including at Citigroup, where I gained first-hand experience leading work in a Fusion Center. Over time, my exposure to all things cybersecurity grew to include working in threat intelligence, working as an information security officer and managing the Vanguard ISO Program, which involved managing cyber champions and overseeing third-party risk management. I also worked at AIG, where I helped build the Global Cyber Defense Center and engaged in cyber risk quantification, incident response, and other aspects of cybersecurity.
Additionally, I managed compliance as a CISO at Barclays. I ran the joint operation center, encompassing the technology command center, the payment command center, and the security operation center (SOC). In my most recent position at First Citizens Bank, I built out the cyber program and scaled the program across every domain within the bank’s cybersecurity space. The recent Silicon Valley Bank acquisition has seen us rapidly grow into one of the top 20 banks in the United States. From a cyber perspective we are keeping pace with this growth by continually developing our cyber capabilities and engaging with the board of directors, senior leaders and business units.
How do you ensure that your organization stays ahead of cybersecurity threats and maintains a robust security posture?
The foremost action we have taken to keep ourselves ahead of cyber threats is the enhancement of our proactive intelligence capabilities. From a capability perspective, we take a risk-based approach that seeks to identify cyber risks and prioritize the mitigation of those risks. We also partner with peers inside and outside the financial services industry to understand best practices for mitigating risks. We participate in a variety of information-sharing circles, such as the Financial Services Information Sharing and Analysis Center (FSI SAC) and the National Cyber-Forensics and Training Alliance (NCFTA).
What are the key considerations that you keep in mind for building an effective incident response plan? How do you ensure readiness to respond to any cyber incident?
Practice makes us better every day, and this is what I incorporate when responding to any cyber incident. For instance, we regularly operate tabletop exercises with the executive leadership and key senior leaders, who in turn foster a culture of awareness, security, and responsiveness amongst our associates. We share the lessons learned and highlight emerging threats to ensure associates are trained to be on the lookout for the latest techniques used by bad actors. Additionally, we hire talented and experienced cyber experts who understand the mission and the severity of each situation and who respond to potential threats in a timely and appropriate manner. This requires proper training and a lot of practice to make things run smoothly.
"The escalation of cyber threats has made advanced cybersecurity practices essential to safeguarding digital assets for modern businesses. we have developed proactive intelligence capabilities to identify risks before they strike and disrupt business operations"
How do you envision the future of cybersecurity and what are the steps or practices you think organizations should imbibe to prepare for the upcoming challenges or opportunities?
In terms of the future of cybersecurity, we have created a team focused on cyber research and innovation. One of the team’s key focus areas is on artificial intelligence (AI) and its implications for cyber security. My peers and colleagues realize that the barrier to entry has become relatively low with the advancement of AI. Collectively, we understand the need to focus on leveraging technology in the right way. As cybersecurity professionals, we continually look to leverage advancing technologies and digital tools to protect our respective organizations. Additionally, we are exploring ways to synthesize large amounts of information and to make more strategic decisions.
What would be your piece of advice to your fellow peers on how to navigate through this changing space?
Collaboration has become an emerging trend in navigating the technological space and in understanding cyber risks faced by other organizations. Sharing strategies and approaches for mitigating risks, collectively makes us all stronger. Every sector is vulnerable to cybersecurity threats, so communicating and collaborating with peers in other organizations is critical to combating bad actors. In addition to collaborating with peers, maintaining strong relationships with regulators and vendors also helps us stay on top of evolving cyber risks. Lastly, it’s imperative to educate associates so that they are aware of the role they play in managing cyber risk. After all, securing data is not merely the responsibility of the CISO but all associates.