The Chief Information Security Officer (CISO) is responsible for leading the enterprise information security strategy and protecting the organization’s systems, data, customer information, and information assets from compromise, unauthorized access, disclosure, or disruption. This role designs, implements, and matures an enterprise-wide information security program aligned to the organization’s size, complexity, risk profile, regulatory obligations, and business strategy.
BOKF’s information security program must also support the risk and regulatory complexity associated with more than $120B in assets under management or administration, two SEC-registered investment advisers, and two FINRA-supervised broker-dealer affiliates/subsidiaries.
The CISO is expected to support SEC and FINRA regulatory readiness by coordinating with affiliate compliance, legal, supervision, and business leaders on cybersecurity examinations, incident escalation and response, customer and client data protection, books-and-records considerations, third-party risk oversight, remediation tracking, and evidence-based demonstration of effective security governance across regulated advisory and broker-dealer affiliates.
The CISO also serves as the organization’s Privacy Officer and is responsible for overseeing the enterprise privacy program, including privacy governance, privacy risk management, regulatory readiness, customer/client information protection, privacy incident response, breach notification coordination, and alignment of privacy controls with cybersecurity, data governance, business, and regulated affiliate requirements.
The CISO partners closely with executive leadership, the Board, Risk, Information Technology, Compliance, Legal, Audit, business leaders, and external partners to identify, assess, monitor, and communicate the organization’s cyber-risk profile. This includes oversight of inherent risk, control effectiveness, residual risk, risk trajectory, security incidents, regulatory expectations, third-party risk, and emerging threats. The role is accountable for ensuring the organization maintains a strong security culture, operates within established risk thresholds, and has the leadership, governance, resources, controls, and response capabilities needed to protect the organization and its customers.