Banking, Leadership, Risk & Compliance, Talent

The CISO Conversation: When You Need One, What to Look For, and How to Structure the Role

At most community banks, cybersecurity sits with an IT manager who already owns hardware, software, vendor risk, and board reporting. AI agents are now exploiting the same access control and segmentation gaps the industry has known about for twenty years, and that job has outgrown one desk. Amber Buker, Chief Research Officer at Travillian, sits down with Chris Bedel, Founder, President and CEO of Bedel Security, and Cyrene Wilke, COO of Verve, a Credit Union, to work through what security leadership needs to look like inside a $1 to $10 billion institution, and how to tell whether yours needs a full-time CISO, a fractional partner, or something else.

Listen here: Spotify | Apple Podcasts

Episode Breakdown: Security Leadership at a Community Bank

01:24 – Why Security Can’t Live on the Corner of a Desk

Amber opens on the setup most $1 to $10 billion institutions are running: security handled alongside IT and operations by one person wearing a second hat. Chris answers with two words — Hugging Face — and notes the agent got in through vulnerabilities, network monitoring gaps, weak access controls, and missing segmentation, all controls the industry has had for decades. Treating the CISO function as a secondary hat “just isn’t going to cut it any longer.”

02:15 – What Happened at Hugging Face

Hugging Face built an application to test whether an AI agent could hack into a system. The agent decided it was easier to break out of its container and go get the answer key than to take the test legitimately, so it found Hugging Face and broke in. Chris’s point: OpenAI’s agent did this by accident, and criminals will have the same tooling pointed at community banks soon, if they don’t already.

04:06 – What Doesn’t Get Done When IT Also Owns Security

Cyrene answers from the operator’s seat. Smaller institutions ask one team to run IT in an industry entirely dependent on technology, then stack a governance and administrative load on top that looks nothing like IT management fifteen years ago. Expecting an IT manager to keep pace with a full information security program isn’t a realistic expectation, and she points to application whitelisting as an exposure nobody in community banking was discussing a few years ago.

05:33 – No Silver Bullet Is Coming

Chris quotes an executive at a recent conference: the industry will “just have to wait until we get an AI tool that can battle the AI tools.” He agrees that belongs in a larger strategy but warns against letting it substitute for the work. Governance beats technology — tools keep changing, good governance doesn’t, and a bank with a real program can absorb each new tool as it arrives.

06:54 – The Questions to Ask Before You Sign

Amber asks how Verve keeps controls tight without wrecking the member experience. The work happens upstream: third-party risk management starts during budget and strategic planning, long before a contract is in front of anyone. Cyrene’s team asks vendors hard questions early, including about full language capabilities and PowerShell requirements, and completes a risk assessment before signing.

08:08 – One Microsoft Outage, Several Vendors Down

Cyrene raises fourth-party risk with a concrete example: in one recent week, three or four Verve software programs went down from a single outage inside the Microsoft ecosystem. The response has been operational — a modern IT service desk pulling RSS feeds from fintech partners, and a dedicated staffer whose only job is vendor risk, contracts, and service level agreements. When something breaks, the team runs root cause analysis and an after-action report.

09:49 – The Tabletop Scenarios That Weren’t on the List Five Years Ago

Chris starts with deepfakes and wire fraud, tested not as user education but as a check on whether internal process would catch it and what verification exists beyond “the CFO said so.” AI-powered attacks belong in incident response testing, as does shadow AI: what happens when an employee uploads NPI to a platform nobody authorized. He also sets the bar — a test you score an A+ on probably wasn’t a good test, because the valuable ones send you home with action items.

12:02 – Where Board Reporting Breaks Down

Amber names three failure modes — too technical, too compliance-focused, not tied to business impact — and Chris sees all three, most often the first. He traces it to a hiring question: is the CISO role defined as technical or business-minded? Boards think in risk at a high level, and when the CISO can’t bridge that, neither side gets much from the exercise.

13:01 – What Separates a Strong CISO from a Security Manager

Cyrene’s answer is translation. Technologists speak in jargon that means little to the room, and the differentiator is converting it into something stakeholders can act on, often through storytelling. Travillian sees the same pattern in executive placements, particularly CIO searches: candidates who can keep the lights on but can’t hold a room.

14:23 – Full-Time, Fractional, or Outsourced

Cyrene lays out the spectrum, from banks heavily dependent on their core provider to institutions running their own DevOps. Low third-party dependency, no open APIs, and managed services across the board mean a lighter risk profile, and the decision should be risk-assessment based rather than benchmarked against peers. Chris adds the line that reframes the question: generally it’s not the size of the institution, it’s the complexity. Amber ties it to Travillian’s compensation study on innovative banks, where two $2 billion Midwest institutions can run entirely different programs and hire entirely differently.

16:03 – One Change to Make Before Year End

Cyrene recommends board composition: if nobody on your board has background in this space, fill that gap, because the support matters when making the case for investment in controls. Chris stays in the same vein — cyber is a specialized risk facing the whole organization, and it needs focused leadership, whether that’s a full-time hire or a fractional partnership. Cyrene adds culture, where encryption and multi-factor authentication come up in everyday conversation at Verve and the standard is “tech savvy, cyber smart team members.”

18:55 – Continuous Testing and the End of the 30-Day Patch Window

Cyrene points to continuous penetration testing and partnerships that monitor which vulnerabilities are exploitable so those move to the top of the queue. Thirty days used to be acceptable; vulnerabilities now need patching nearly immediately once discovered. Chris flags the part the industry isn’t discussing — that pace is resource intensive and will cost money most institutions haven’t budgeted for.

20:11 – The Microsoft Environment Nobody Is Hardening

Cyrene’s second practice is benchmarking security scores in the Microsoft environment and moving continuously toward a hardened configuration, treated as discipline rather than an optional tool. Chris calls it an under-looked vulnerability: institutions assume being on Microsoft covers them, when it comes down to how it’s configured. People build entire careers on configuration in that environment because of how complicated it has become.

22:05 – The Closing Note

Cyrene Wilke is at Verve, a credit union headquartered in Oshkosh, Wisconsin, with 20 locations across metro Chicago, western Wisconsin, and the Fox Valley. Chris Bedel is at Bedel Security, which provides fractional CISO services to financial institutions nationwide; LinkedIn is the best place to reach him.

Tags: Banking, Leadership, Risk & Compliance, Talent

Author

Must Read

You May Also Like

How CNB Bank Built a New Growth Engine by Listening to Women Entrepreneurs: Mary Kate Loftus, President, Impressia Connect, CNB Bank