Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

First Bank
Marc Ashworth, Chief Information Security Officer
Translating Tech for Business: CISO's Role in Communication and Risk Management


Marc is a highly esteemed expert with over 30 years of experience in various areas, including cyber and physical security, virtualization, risk management, IT and security architecture, budgeting, project management and board governance. He is a strategic thinker who can effectively assess departmental or organizational requirements and create feasible plans to accomplish those goals.
Please tell us about the journey that you've had so far and your roles and responsibilities at First Bank.
I have over 30 years of experience in the industry. I've handled everything from development to systems and network architecture, administration, and operations. I've built and rebuilt departments, consulted for small businesses to Fortune 100 companies, advising them on various technology and security needs. I've served on many advisory boards and currently I’m on the Webster University cyber advisory board and recently started the Missouri Banking Association technology committee. I’ve also been a board member and officer for nonprofits, including the St. Louis InfraGard Chapter, where I helped co-found the State of Cyber conference. .
In my current role, spanning nearly seven years, I oversee four teams responsible for networking, security, physical security, and financial crimes. Each team addresses distinct aspects of technology and security, collaborating effectively while requiring tailored strategies to meet their unique demands. .
You have a diverse background in system/network design and application development. How has this technical foundation influenced your approach as a CISO?
It allows me to communicate effectively with various technology teams and act as a translator to bridge the gap between technical details and management. Drawing from my past experience, I address management's inquiries about different technology components and help them understand the interconnectedness of technology and business, as well as how to manage risks to safeguard the bank while also advancing business goals. My earlier experience in the hotel industry before and during college also instilled a strong focus on customer service, which continues to influence my approach. .
Combining this background with my consulting expertise in technology solutions helps me be a good leader as a CISO to bridge the gap between business goals and cybersecurity. Rather than simply identifying risks, I focus on finding secure solutions that enable the business to operate effectively and safely. This ensures that we meet organizational objectives while maintaining robust security measures. .
How do you develop and implement a business and departmental strategy that addresses both cyber and physical security needs?
The physical side can affect the cyber side and vice versa. We actively monitor cyber threat intelligence to anticipate trends linked to physical events. For instance, before the Ukraine invasion, we saw a drop in cyber activity from Russia. Similarly, natural disasters like hurricanes often trigger a surge in email scams and fraud attempts. By integrating these physical events into our strategy, we can better prepare and prioritize our cyber defenses. This involves conducting thorough gap analyses of our environment, comparing them with threat intelligence, and weighing those gaps to conduct risk analyses to prioritize and mitigate vulnerabilities effectively. .
On the physical security side, we evaluate environmental gaps and risks to enhance protection measures and support law enforcement when needed. While we can deter physical threats, our goal is to maximize safety and provide evidence for legal action when necessary. .
You've managed budgets for security initiatives. How do you determine which areas require the most investment?
When managing budgets for security initiatives, the key is to conduct a thorough risk analysis. This involves evaluating the risks, identifying necessary mitigations, and prioritizing them to determine which risks need to be mitigated in advance, considering the associated costs and budget impact. This may involve purchasing new solutions or simply reallocating existing resources. By assessing overall risks and setting priorities, we can decide which items require market solutions to effectively mitigate these risks, thereby shaping our strategy for the upcoming budget. .
Your technical expertise is complemented by sales and customer service experience. How has this unique blend helped you communicate effectively with both technical teams and non-technical stakeholders?
I believe CISO should include ‘translator’ in the title as it involves translating technical information into business terms for better communication with management. This expertise allows for effective presentation of information in a way that is easily understandable by all parties involved
When I reflect on my sales and customer service experience, I realize it allows me to be more empathetic to those who struggle with understanding technology and enables me to act as a translator. I believe CISO should include ‘translator’ in the title as it involves translating technical information into business terms for better communication with management. My expertise in this area helps me effectively communicate and present information in a way that is easily understood by management. This includes explaining our needs, assessing risks, and outlining the steps needed to mitigate those risks. .
How do you see the cybersecurity industry evolving in the next 18 to 24 months?
There is a constant buzz surrounding the impact of AI and its potential influence on various aspects, and I truly believe that it will play a significant role in shaping the future. In the next six to 12 months, the political landscape in the U.S. will be an important factor in dictating the cybersecurity landscape. Other nations and cyber groups may attempt to exploit this environment by launching various BECs and phishing campaigns to steal data and gauge the response of the incoming administration to cyber threats. Historically, the period following elections tends to be a testing ground across both digital and physical realms, underscoring the need for robust cyber defenses. .
What advice would you give to your fellow peers or aspiring CISOs who are looking to build a career in cybersecurity?
For those interested in entering cybersecurity, it's crucial to emphasize continuous learning and a deep passion for both technology and understanding its vulnerabilities. It's about viewing technology not through rose-colored glasses but with a critical eye to identify potential weaknesses and understand how they could be exploited. The excitement lies in piecing together these puzzle pieces of risk assessment, patiently uncovering where vulnerabilities exist and how they could impact systems. Constantly learning and being able to troubleshoot quickly are essential skills in this fast-paced technology career. .
When it comes to a management or CISO position, having the skill to communicate in business terms is essential in translating technology concepts. It is crucial to understand the direction of the business and effectively align security risks with technological enhancements within the organization. .

