ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

Preparing for the departure of an information security officer

It can become an opportunity to bolster security governance and refine cybersecurity practices.

April 25, 2024
Reading Time: 5 mins read
Preparing for the departure of an information security officer

By Zach Duke

Financial institutions face a pressing issue in terms of employee retention, especially when it comes to their information security officers. ISOs are in high demand leading to challenges in keeping cybersecurity talent amid high turnover rates. Banks and other institutions once only had to compete against the local business community for talent, but in today’s post-pandemic environment, where it is not uncommon for ISOs to work remotely, this challenge has been exasperated due to the expanded competition created from remote work.

Banks must understand what is causing the challenges of ISO retention, the critical steps to take when one departs, and the succession planning that can be implemented today to reduce risk and exposure.

ISOs are the linchpin of banks’ information security program governance. But holding onto these team members is becoming increasingly difficult. The allure of the job market, coupled with the high-stress nature of the position, often leads to burnout. Dealing with examiners and the over-reliance on manual, labor-intensive tasks only add to the strain.

Loss of an ISO can weaken a bank’s defensive stance and compliance framework, potentially exposing it to cyber threats and regulatory scrutiny. The American Bankers Association Banking Risk and Compliance Management 2023 Outlook Survey found that cybersecurity remains the top risk priority for community banks, with a significant 74 percent of responding institutions identifying it as such. Having a gap in that critical role can lead to catastrophic consequences.

When an ISO departs

To ease the stress of losing such a critical role, many financial institutions are turning to automated tools and solutions that are designed to streamline and simplify the compliance process and help banks navigate the complex landscape of information security and compliance.

With these tools in place banks experience:

  • Enhanced information security. Banks significantly improve their information security posture and meet compliance requirements.
  • Peace of mind. Bank executives can focus on strategic leadership with the confidence that information security governance is in capable hands.
  • Automated risk assessment. With automated risk assessment processes, manual effort is reduced, and a more comprehensive evaluation of risks is ensured.
  • Efficient oversight. Automated solutions empower banks to efficiently manage vendor relationships and assess controls.

When Franklin, West Virginia-based Pendleton Community Bank’s ISO left, the bank faced a significant void in its oversight capabilities. The bank realized it needed to establish an effective process for information security governance and cybersecurity oversight to ensure compliance and peace of mind.

The bank turned to an automated governance platform that gave it a proven blueprint for information security. With this solution, the bank is able to identify, assess and mitigate risks effectively.

“With this solution in place I can focus on leading the bank, secure in the knowledge that our cybersecurity and information security governance are being handled professionally,” said Bill Loving, CEO of Pendleton Community Bank.

Succession planning to implement today

There are certain issues banks should be thinking about proactively and processes they should implement in their institutions to ensure they are prepared for ISO departures:

  • Review the security tasks and policies from the last 12 months. Was anything missed? Do you have the approved documents and assessments centrally located?
  • Audit schedule. Note the dates of forthcoming audits and regulatory exams to ensure readiness. How soon are the dates? Information security is not a series of one-and-done events, but rather a consistent plan and process. By using the next exam or audit, you can create a plan to address challenges in a phased approach.
  • Innovate processes. Use this transition as a chance to improve or automate laborious, manual security tasks. What can be done more efficiently? It is not uncommon for innovation to be found with technology platforms and tools that streamline, innovate and empower your team.
  • Review documentation. Who are your vendors and what systems are implemented? How comprehensive and up to date is the data? Confirm that system maps and vendor information are current and accurate, as a large portion of information Security Governance is related to systems and vendor management.
  • Revoke access. Ensure that all accounts, credentials, and system access privileges associated with the former ISO are revoked or transferred to prevent unauthorized access.
  • Evaluate IT controls. Assess the documentation of implemented IT security controls. What controls haven’t been implemented? Are there documentation gaps where proof of how controls are implemented may be missing?
  • Cyber insurance coverage. Cyber insurance companies protect their financial exposure by leveraging the questionnaires for coverage. By reviewing the previous questionnaire, the institution can highlight gaps in answers that may put the institution at risk for coverage in the event of a breach.
  • Vendor communication. Notify relevant vendors and service providers of your personnel change, especially if the former ISO was the main point of contact. Request a complete briefing on ongoing security projects to ensure they are handed over without interruption.
  • Look for help. Information security for banking is specialized, but there are solutions with expertise, processes, and platforms that can help streamline and simplify the governance process.
  • Governance reporting. Scrutinize the executive and committee reporting for gaps or areas needing enhancement. What do the executive team and committee members think about the IT governance status reporting they receive? Is there an opportunity to make the reporting more actionable?

Be proactive

By leveraging the lessons learned, banks can be proactive in succession management before they lose an information security officer. Start with reviewing your existing team. What would happen if your ISO received a job offer for a significant pay raise? How prepared is your team to answer the questions above if your ISO were to leave suddenly, or is the ISO the only one who knows the answers? Think about the manual and labor-intensive tasks that may push your ISO to be open to talking with recruiters when they call.

Having a long-term, stable ISO is a blessing, yet one of the foundational challenges in compliance is that if you don’t have documentation to prove what you did, you don’t get credit for the work. If yours is one of the fortunate banks not affected by an ISO departure, think about documenting answers to these questions. Then create a write-up for your next technology steering committee meeting titled An Exercise in Succession Planning for Our ISO. Working through and documenting the process ensures you get appropriate credit with the examiners.

The departure of an information security officer can be a moment of vulnerability for a financial institution. However, it also presents a unique opportunity to bolster information security governance and refine cybersecurity practices. By embracing a proactive approach, leveraging expertise and integrating innovative solutions, banks can not only fill the immediate gap but also enhance their long-term resilience against cyber threats.

Zach Duke is CEO and Founder of Finosec.

Tags: CybersecurityData securityHuman resources
ShareTweetPin

Related Posts

FHFA to create affordable housing advisory committee

HUD proposes to remove disparate impact from Fair Housing Act rule

Compliance and Risk
January 14, 2026

The Department of Housing and Urban Development is proposing to rescind three rules allowing the use of disparate impact in determining Fair Housing Act violations.

AI romance, ‘machine-to-machine’ scams among top 2026 fraud trends

AI romance, ‘machine-to-machine’ scams among top 2026 fraud trends

Compliance and Risk
January 14, 2026

Romance scams carried out by artificial intelligence and computers scamming other computers are among the top five fraud trends to watch out for in 2026, according to a new report by credit reporting agency Experian.

FinCEN proposes applying BSA requirements to investment advisers

G7 expert group releases cybersecurity ‘roadmap’ for post-quantum cryptography

Compliance and Risk
January 13, 2026

The G7 Cyber Expert Group released a “roadmap” to help the financial sector take steps to secure computer systems from cybersecurity risks arising from quantum computing.

Banking agencies: Shared National Credit quality remains moderate

Banking agencies release Shared National Credit Program report

Compliance and Risk
January 12, 2026

Credit risk associated with large, syndicated bank loans remains moderate, with credit risk trends reflecting the effects of borrowers' ability to manage higher interest expenses and other macroeconomic factors, three banking agencies said in their most recent Shared...

ABA urges FinCEN to reevaluate BOI collection burden on banks

Treasury issues order, alert to Minnesota institutions on alleged fraud rings

Compliance and Risk
January 9, 2026

FinCEN issued an alert urging financial institutions to identify and report fraud associated with federal child nutrition programs in Minnesota, and it released a geographic targeting order directing banks and money transmitters in two Minnesota counties to report...

ABA Data Bank: Immigration boom adds to labor force

CFPB, DOJ to withdraw warning on using immigration status to determine creditworthiness

Compliance and Risk
January 9, 2026

The CFPB and Department of Justice plan to withdraw 2023 guidance warning financial institutions that they risk violating federal protections against discrimination if they rely on immigration status to determine a consumer’s creditworthiness.

NEWSBYTES

Senate Banking Committee postpones vote on crypto market structure bill

January 14, 2026

HUD proposes to remove disparate impact from Fair Housing Act rule

January 14, 2026

Business inventories rose in October

January 14, 2026

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: The incredible shrinking penny (circulation)

January 8, 2026

Podcast: Cybersecurity in a mobile-first banking landscape

December 18, 2025

Podcast: The 2026 outlook for bank M&A

December 11, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.