Collective defense: the security you don't build alone
by Claudiu Hulea · IT Management Consultant
One of the healthiest ideas I have read about security lately comes from an interview with Ann Barron-DiCamillo, CISO at U.S. Bank: security cannot be owned by one person. Neither inside the organization, nor against attackers. It is a simple observation, but it changes how you build your defense. Below, three things worth taking from it, translated into the context of organizations in Romania.
The opinions attributed belong to the interviewee; the rest is our reading, informational, not advice.
The security you don’t build alone, not even internally
The CISO role has ballooned: today it covers fraud, resilience, third-party risk, AI governance. Her point is that no single leader can personally own every piece at scale. Success does not come from giving the CISO more authority, but from trusted partnerships between teams: technology, risk, legal, fraud, compliance, business. A risk decision needs the context of the whole organization, not just the technical one.
In Romania, this ties directly to a requirement DORA and NIS2 make explicit: accountability rises to the top. Article 20 of NIS2 puts the management bodies in charge of approving and overseeing the risk measures. In other words, the law itself says security is not a technical silo, but a distributed responsibility with accountability at the top.
Collective defense, beyond the organization
The second idea is that a single organization only sees its own slice. Attackers, by contrast, reuse the same infrastructure and the same techniques against multiple targets. Hence the value of sharing: indicators, techniques and remediation approaches, pooled together, build a better operational picture than anyone can build alone. Barron-DiCamillo points to sector mechanisms of the ISAC type and to public-private partnerships.
Translated to our context, this means taking part in the information sharing coordinated by DNSC and in sectoral communities, banking and beyond. Some duplication between organizations is inevitable and even appropriate, because environments differ, but mutual early warning is worth more than the cost of the overlap. Market competition does not mean competition in defense: attackers cooperate, so defenders must too.
Compliance that looks good is not the one that reduces risk
Here is the sharpest observation, and the one that rhymes with what we keep saying. Many organizations over-invest in activities that demonstrate security, instead of those that produce it. The money should move toward automation, asset visibility, identity and vulnerability management, and secure-by-design engineering.
Mind the nuance, so it is not misread: compliance is not the enemy. A DORA or NIS2 inspection asks you to prove the measures work. The problem is compliance for show, the document that ticks a requirement with no real control behind it. A control you cannot demonstrate does not exist, but neither is a document that covers no real control worth anything. We wrote at length about that difference in the control that passes the test.
Speed or accuracy in incident reporting
The fourth observation is about a tension everyone under DORA and NIS2 feels: reporting deadlines have shortened, but at the start of an incident the information is incomplete and changes from one hour to the next. The right balance is neither silence nor the premature reporting of “facts” that turn out false, but a process that communicates transparently and, at the same time, leaves room for an accurate understanding of the event.
In practice, this means having ready, in advance, who decides, what goes into the first notification, and how it is updated as the facts clear up. The process is prepared in peacetime, not in the first hours of an incident.
What we take from this
For an organization in Romania, especially a regulated one, the lessons translate simply:
- security is a shared responsibility, with real partnerships between teams and accountability at the management level;
- take part in threat-information sharing, do not defend only with what you can see;
- spend on what reduces risk, not on what demonstrates it, and require every control to be provable;
- prepare the reporting process before you need it.
None of these is spectacular. All of them are about maturity, not a new tool.
Want to see where your organization stands on these four dimensions and what to strengthen first? Contact us and we start from an assessment.
Sources
Frequently asked questions
What does "collective defense" mean in security?
That no organization defends itself successfully alone. Internally, security is a shared responsibility of the technology, risk, legal, fraud, compliance and business teams. Externally, sharing threat information gives everyone a better common picture than any one of them could build alone.
Why would companies share information if they compete?
Because attackers do not compete with each other, they cooperate. A threat that hits one bank usually hits the others too. Sharing indicators and techniques is not an advantage given to the competition, it is mutual early warning. Some overlap is normal and useful, because environments differ.
Is compliance not already a form of security?
Only if it proves real controls. Organizations often over-invest in activities that "show" security (documents, box-ticking reports) and under-invest in what actually reduces risk: automation, asset visibility, identity and vulnerability management, secure-by-design engineering. Good compliance proves controls that work, it does not fill binders.