A day in the life of a CISO extends well beyond security controls, covering business relationships, risk judgement, governance and organisational change.

At the 13th Security Edge, David Gee, Author, CISO and ADAPT Advisor, joined Maryam Bechtel, CISO at TAL Australia, and Keith Howard, CISO at Suncorp Group, to explore how security leaders can establish trust, focus investment on material risks and adapt governance as AI changes the operating environment.

 

Key takeaways:

  • Build relationships before making major changes. Strong connections across technology, risk, finance, legal and the wider business give CISOs a clearer view of the organisation and stronger support during crises.
  • Prioritise material risk over isolated compliance measures. Security investment should address risks that could genuinely affect the organisation rather than allowing procedural issues or maturity scores to drive priorities.
  • Design AI governance for accountability and recovery. Define boundaries, observability, human oversight and recovery paths early, then keep testing as technology and organisational capability develop.

New CISOs need an independent view before changing the organisation

Understanding the organisation should come before major decisions about its security posture.

Keith recommends testing cultural fit and establishing relationships before the first day, including with the CIO, CRO, auditors and line-two risk teams.

Maryam extends that network across finance, legal, crisis management, communications and the wider business.

Those relationships provide critical support during incidents and help security leaders secure investment for risk reduction.

Independent reviews can then establish a more objective baseline.

Keith and Maryam advocate for a detailed assessment for practitioners alongside a clear, outcome-focused view for the board.

This gives leaders evidence about the organisation’s current position before major judgements or changes are made.

Material risk should guide security investment

Compliance, security and business enablement are connected responsibilities, but each serves a different purpose.

Keith distinguishes compliance from actual security posture.

Meeting a requirement does not remove the need to understand which threats could cause material harm to the organisation.

Maryam adds business enablement to the CISO mandate.

Some investments may have limited direct impact on compliance or risk reduction while still supporting the organisation’s ability to operate and innovate.

Materiality provides the prioritisation test.

Resources should concentrate on risks with meaningful organisational consequences rather than small procedural issues or a single maturity score.

AI governance needs accountability, recovery and continuous learning

Autonomous systems require clear boundaries around what they can do, how their actions are observed and who remains accountable.

Maryam’s framework centres on accountability, observability, boundaries, recoverability, and continuous testing and learning.

Keith reinforces the need to build those controls into the design, including recovery paths and human oversight before deployment.

People capability has to develop alongside those controls.

Teams need curiosity, resilience, comfort with ambiguity and a willingness to learn as the operating model changes.

Keith advocates practical workshops, time during working hours and collaboration with AI specialists to build confidence progressively.

Strong CISO leadership creates the relationships, feedback loops and learning practices that help the organisation make better decisions as conditions change.

Contributors
Maryam Bechtel CISO at TAL Australia
Maryam Bechtel is the General Manager of Cyber Security at TAL Australia, where she leads TAL’s cyber protection strategy and security operations.... More

Maryam Bechtel is the General Manager of Cyber Security at TAL Australia, where she leads TAL’s cyber protection strategy and security operations. With more than 19 years of experience in the Cyber Security sector, she has worked across multiple continents and held senior roles with organisations including Deutsche Telekom, Deloitte, and AGL.

Ms Bechtel also serves as a board member of the Australian Women in Security Network and is a committed advocate for advancing the participation of women in the
security industry. She holds a Master’s degree in Information Security from Stockholm and a Bachelor of Software Engineering.

Less
Keith Howard CISO at Suncorp Group
Keith Howard was appointed Executive General Manager, Cyber Security & Risk in February 2024, leading the Cyber Security and Risk team for... More

Keith Howard was appointed Executive General Manager, Cyber Security & Risk in February 2024, leading the Cyber Security and Risk team for the Group, and is responsible for keeping the Group and its customer information safe and secure.

Prior to joining Suncorp, Keith held key senior roles at Commonwealth Bank, including Group CISO, CIO Product & Marketing, General Manager Customer Engagement Platform, where he led large cross-functional teams delivering transformational change, such as the successful SAP upgrade, and delivering powerful customer experiences using machine learning.

Keith has also delivered technology transformation programmes and managed global teams across multiple industries including petroleum, transport, and software, having lived in both the UK and Asia prior to moving to Australia.

Less
David Gee CIO, CISO, Risk Executive & Author
David is a former CIO and CISO with over 20 years of global leadership experience across financial services, insurance, and technology risk.... More

David is a former CIO and CISO with over 20 years of global leadership experience across financial services, insurance, and technology risk. His roles at Macquarie Group, HSBC, MetLife Japan, and in advisory positions within fintech and cybersecurity ecosystems have shaped his deep expertise in cyber resilience, digital transformation, IT risk management and value realisation.

  • Global Head Tech, Cyber & Data/AI Risk at Macquarie Group.​
  • Former CISO for HSBC Asia Pacific, overseeing 19 critical markets.​
  • Led digital transformation as CIO of MetLife Japan, managing US$300M+ annual IT spend.​
  • Past CIO of Credit Union Australia and Information Officer for Lilly USA.​
  • Board and venture adviser across cybersecurity, fintech, and innovation sectors.​
  • Best Selling Author and Writer, regular contributor to ITnews, CIO Magazine, CSO, ​
    and Computerworld with 100+ published articles.​
  • Experienced in international assignments across Asia and the US, ​
    with a strong background in financial services and insurance.​
Less
security compliance leadership