When examiners, auditors, or the Board ask who is responsible for information security, the answer should not simply be “IT.” For many financial institutions, IT and Information Security work closely together, and in some cases the same individual may support both areas. But while the functions are connected, they are not the same.
A simple way to think about the distinction is: IT operates the technology and Information Security manages the risk.
Understanding this distinction is important because financial institutions are responsible for protecting customer information, managing technology and cybersecurity risks, and maintaining an effective information security program. Additionally, federal guidance specifically emphasizes board oversight, defined responsibility, risk assessment, and appropriate independence for information security functions.
At its core, IT is focused on operating and supporting technology so the institution can conduct business effectively.
Depending on the size and structure of the institution, IT responsibilities may include:
Information Security takes a broader, risk-based view.
Rather than focusing primarily on whether technology is working, Information Security focuses on whether the institution is adequately protecting its information and managing the risks associated with its technology environment.
Information Security responsibilities may include:
The question Information Security should continually ask is: "What could go wrong, how significant is the risk, and are we doing enough to manage it?"
That is different from asking whether a particular system is operational.
The distinction does not mean that IT and Information Security should operate independently from one another. In fact, it is recommended they work closely together.
Consider multifactor authentication (MFA).
IT may be responsible for implementing MFA, configuring the technology, troubleshooting authentication issues, and ensuring employees can access the systems they need.
Information Security, however, may evaluate whether MFA is appropriately implemented across critical systems, identify gaps, assess the associated risk, establish expectations, and report significant deficiencies to management.
One of the most important distinctions between IT and Information Security is independence.
The FFIEC Information Security booklet states that an institution should designate an information security officer who is responsible and accountable for implementing and monitoring the information security program. It also states that the information security officer should have sufficient authority, stature, knowledge, and independence to perform the role and, for appropriate segregation of duties, should be independent of IT operations staff and not report to IT operations management.
Why does that matter?
If the same person or group is responsible for implementing a control and independently determining whether that control is adequate, there can be a natural conflict.
This does not mean that IT personnel cannot perform security-related responsibilities. It means the institution should have appropriate separation between operating controls and independently overseeing the effectiveness and risk associated with those controls.
Federal guidance recognizes that institutions differ in size, complexity, risk profile, and structure. The agencies have historically stated that an institution does not necessarily need to create a new position with a specific title, provided it has adequate staffing and clearly defined lines of authority and responsibility for its information security program.
What regulators do expect is an effective information security program with appropriate accountability and oversight. In other words, the regulatory expectation is not simply:
"Have an Information Security Officer."
It is closer to:
"Have an effective information security program, clearly defined responsibility, appropriate oversight, and sufficient independence to manage the associated risks."
This deserves careful consideration.
A managed IT provider can be an important part of an institution's overall information security program. However, simply adding the title "Information Security Officer" to an IT services agreement does not automatically create independent Information Security oversight.
The institution should consider:
The answers to these questions are more important than the title on an organizational chart.
For some institutions, the right solution may be an internal Information Security Officer who works closely with an outsourced IT provider.
For others, an outsourced vCISO may provide the independence and expertise needed to oversee the Information Security Program while the IT provider continues to manage day-to-day technology operations.
A vCISO can serve as the bridge between technology operations, executive management, and the Board.
The role can assist with governance, risk management, oversight, regulatory support, board reporting and strategic guidance.
The objective of a vCISO is not to replace IT; it is to provide independent information security leadership and oversight.
The strongest institutions do not view IT and Information Security as competing functions. They recognize that each has a different responsibility.
IT and Information Security are closely related, but they serve different purposes.
Having both functions working together can provide a stronger foundation for cybersecurity, operational resilience, and regulatory compliance.
The goal is to establish clear responsibilities and ensure that someone has the authority and independence to look across the institution's technology environment, identify information security risks, challenge assumptions, and provide meaningful oversight to management and the Board.
For institutions that do not have the resources to build that capability internally, an outsourced vCISO can provide experienced Information Security leadership while allowing the bank's IT personnel or managed service provider to continue focusing on technology operations.
If your institution is looking for experienced Information Security leadership without the cost of building a full internal security department, Bedel Security's vCISO services can help strengthen governance, manage cyber risk, provide independent oversight, and support your institution's regulatory expectations. Contact us to get the conversation started.