In Depth

Sharon O'Bryan: Called to Account

Some security executives see protecting their company's assets as a way to earn a living. ABN Amro's Sharon O'Bryan sees it as her mission.

By Simone Kaplan

February 01, 2003CSO — You're in good hands with Sharon O'Bryan.

That may sound like an advertising slogan or a political promise, but O'Bryan isn't campaigning for anything. She's the senior vice president and chief information security officer for Dutch banking giant ABN Amro's North American division, and she loves her job. To her, protecting her clients' cash and sensitive information is much more than a way to earn a paycheck. It's a calling.

"Security is so intrinsic to what we do for our clients," she says, her voice filled with conviction. "This is people's livelihood that I'm protecting. It's their ability to send their children to college, to pay for their daughters' weddings. It's a very big deal."

O'Bryan is passionate about security. She is also very honest about the challenges of being a CISO. Professionally, like many of her peers, O'Bryan faces a continually changing landscape that requires deft strategic planning and a nimble mind. On a larger scale, she must navigate the heavily regulated waters of the financial services industry, in which every action, every goal must be documented for corporate and federal auditors. She frequently visits Washington, D.C., where she represents her company on the financial services branch of Presidential Cybersecurity Adviser Richard Clarke's Critical Infrastructure Protection Board and is a major player in Bits, the technology arm of the Financial Services Roundtable, an industry lobbying group. "Staying on top of security technology and the nature of security threats, which change constantly, isn't easy," she admits. "But then, you know the saying, the only thing that's constant is change."

Considering how much she has going on, it's amazing that O'Bryan has time to talk at all. Since she joined ABN Amro four years ago (after several years as an IT auditor for two Big Five accounting consultancies), she's revamped the security architecture of her company's technology risk management group and helped her staff adjust to a global corporate reorganization. Not only that, but ABN Amro, which has 3,400 branches in 60 countries, is so active on the mergers and acquisitions front that O'Bryan is continually applying security standards to systems newly integrated into the company's network. Sometimes she feels like the company's landscape changes on a daily basis. As CISO, she's not in charge of the company's physical security arena, but she still has to make sure the two groups don't duplicate efforts in their common goal of protecting the business.

To top it all off, the CEO and the CIO of ABN Amro's North American division are both retiring, and O'Bryan doesn't know to whom she'll be reporting in the long run. Fortunately, she likes that kind of pressure.

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

Configuration Assessment: Choosing the Right Solution

IS/IT Project Mgt. Credentials From Villanova - 100% Online

Revolutionizing Endpoint Security with a Single Agent

Envision Identity-Based Access Control for the Datacenter

Rolling the dice with your security? Take the Self-Assessment Test now

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

Digital Identity Protection and Data Security Get Personal

Solving Online Credit Fraud Using Device Reputation

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

Using Likewise to Comply with PCI Data Security Standard

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Data Protection: Challenges for the Traveling User

Key strategies for C-level executives and security staff

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Envision Identity-Based Access Control for the Datacenter

The Case for Business Software Assurance ~ Securing Your Applications

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Diebold: Frost & Sullivan Global Physical Security Systems Integrator of the Year

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage