From Coder to Chief: How Standard Chartered's Security Boss Runs Defence at a Global Bank

The bank's top security executive explains how the job has changed, why security leaders must speak business rather than just tech, and what AI means for attackers and defenders alike.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Senior executive at a modern glass conference table overlooking a cityscape, surrounded by security infrastructure diagrams and data analytics displays on the w
Share

Key points

  • Standard Chartered's group CISO (Chief Information Security Officer, the person responsible for protecting an organisation's data and systems) gave a video interview to Dark Reading on how the security leadership role is evolving.
  • The CISO described a shift from purely technical work toward strategic, boardroom-level decision-making.
  • AI is changing both sides: defenders use it to spot threats faster, while criminals use it to craft more convincing attacks.
  • Banking is one of the highest-value targets for cybercriminals worldwide.

What does a bank's top security official actually do?

Most people picture a cybersecurity expert behind screens full of code. The reality at a major international bank looks different.

Standard Chartered's group CISO described a career arc familiar to many senior security leaders: years of hands-on technical work, then a gradual move into strategy and board-level conversations. The tools change. So does the audience. Charles Blauner, who held the top security role at JPMorgan, Citigroup and Deutsche Bank, made the same point when we covered his advice for the next generation of CISOs in late July.

At that level, the job is less about writing code and more about convincing executives to fund the right priorities before something goes wrong. That requires fluency in business risk, not just in firewalls.

Why does business knowledge matter so much now?

Security teams that can only speak in technical terms struggle to win resources. Full stop.

A CISO who frames a request as "we need to patch this server" loses ground to one who explains that an unpatched server puts customer data and the bank's regulatory licence at risk. Boards respond to the second version, and regulators increasingly expect it.

That pressure is real. The US Securities and Exchange Commission's cybersecurity disclosure rules, which took effect for large public companies in December 2023, and the EU's NIS2 Directive, a law requiring essential-service operators to meet minimum security standards that became effective in October 2024, both demand that senior leadership own security decisions formally and publicly, not just the IT department.

How is artificial intelligence changing the threat?

AI cuts both ways, and that's the uncomfortable truth.

Defenders at banks like Standard Chartered use AI tools to sift enormous volumes of alerts, flagging what matters faster than any human team could. Response times shrink. Coverage widens.

Criminals are using the same technology. AI helps them write phishing emails, fake messages designed to trick staff into handing over passwords or clicking dangerous links, that are more convincing and harder to spot than before. It also helps them probe systems for weaknesses at scale.

For ordinary bank customers this is the practical consequence: the fake emails or calls pretending to be from your bank are getting better. Contact your bank through the number on the back of your card if anything feels off.

Common questions

Does this affect my bank account?

Your money isn't directly at risk from a security executive giving an interview, but the pressures they describe are real. Banks invest heavily in these defences because failure carries serious consequences for customers and the institution.

What should I watch for as a customer?

AI-generated phishing messages are now harder to detect by eye. If you receive a message creating urgency around your account, go directly to your bank's official app or website rather than clicking any link in the message.

© 2026 Threat Vectr