# The Surge in Chief Information Security Officer Appointments Across Industries in 2026
The first half of 2026 has seen an remarkable wave of chief information security officer appointments spanning virtually every sector of the economy — from financial services and healthcare to retail, government, and emerging frontier technology companies. This unprecedented pace of cybersecurity leadership hiring reflects a growing recognition among organizations that robust security leadership is no longer optional but foundational to business strategy.
## A Cross-Section of Industries Reinforces Security Leadership
### Fashion and Retail
Ralph Lauren elevated John Opala to the role of chief information security officer, where he will spearhead the company’s global cybersecurity strategy. Opala previously spent significant time at HanesBrands collaborating with international leadership teams to bolster cybersecurity capabilities and drive enterprise-wide transformation. His appointment underscores how even consumer-facing luxury brands are investing heavily in digital resilience.
### Financial Services and Banking
The financial sector has been particularly active in its security hiring. United States Bank named Ann Barron-DiCamillo as executive vice president and global CISO, bringing more than 25 years of experience from Citi, American Express, and her role as director of the U.S. Computer Emergency Readiness Team. Western Alliance Bank elevated Stephen McMaster to CISO, drawing on two decades at Wells Fargo where he led cloud security, data loss prevention, and third-party risk programs. SMBC Americas appointed Donna Hart as CISO, leveraging over 30 years of experience from Ally Financial, Wells Fargo, and Wachovia. In Pakistan, Hugobank named Zeeshan Manzoor CISO, who previously held the same role at the Pakistan Stock Exchange. Nubank also brought on John Walton to lead its information security strategy for the digital financial platform.
### Technology and Software Companies
Tech firms continue to compete for top security talent. GitLab hired Chaim Mazal as CISO, a move that followed his tenure as chief AI and security officer at Gigamon and years as a GitLab customer. Infoblox named former Amazon executive Henrik Smith as CISO, who previously headed security for devices and systems at the e-commerce giant and served as vice president of security at Salesforce. Entrust appointed Adam Dimopoulos as CISO, a former Synchrony executive who also held advisory positions at Microsoft and Gartner. LogicGate brought on Edwin Ng to the role, and Tanium named Paul Black as chief information security officer with a specific mandate around AI-related security priorities.
### Healthcare and Life Sciences
Healthcare organizations are placing security at the center of their operations. Novant Health promoted Srini Uppugonduri to senior vice president and CISO, where his expertise in cyber engineering, threat intelligence, and resilience efforts will support the company’s complex healthcare environment. Cook Children’s Health Care System named Kathy Jobes as CISO, bringing over 25 years of healthcare cybersecurity experience with a focus on data governance and a human-centric approach. Omnicell promoted Michael McNeil to senior vice president and CISO, where he will expand responsibilities around global cybersecurity and cloud security strategy.
### Government and Public Sector
Government agencies are making significant investments in cyber leadership. The U.S. Department of Homeland Security named Supriya Ahuja as acting deputy CISO, drawing on nearly two decades of experience across both government and private-sector cybersecurity. The U.S. Department of Defense appointed James “Aaron” Bishop as deputy CIO and CISO, tasked with providing department-wide policy and technical oversight of cybersecurity matters. Pennsylvania named Andy Ritter as state CISO, where he will lead statewide cyber resilience and enterprise risk management. Texas appointed Chad Holmes as CISO for the Office of the Attorney General, leveraging over 25 years of private-sector security experience. The National Motor Freight Transportation Association promoted Ben Wilkens to director of cybersecurity, where he will guide the transportation sector’s cybersecurity strategy.
### Emerging and Specialized Companies
New and niche organizations are also prioritizing security leadership. Starburst, an enterprise intelligence platform, hired Paras Malhotra as CISO after his time at Datadog and Amazon Web Services. Socure, an identity infrastructure provider, brought on Mark Carter, a former CISO at Navan, Tesla, and Vimeo. SolarWinds named Justin Henkel as CISO, whose background includes 25 years as an intelligence officer in the U.S. Air Force and a deputy CISO role at OneTrust. Fable Security appointed Jacob Berry, who brings 18 years of experience in incident response and cyber operations. Fintech newcomer iCounter named Ali Waezzadah CISO, while 1Kosmos brought on Roger Hale and BreachRx appointed Stephen Garcia to lead their security functions.
### Education and Media
Discovery Education made headlines by naming Kara Schlageter as its first-ever CISO, bringing over 25 years of cybersecurity and enterprise risk expertise to the education technology sector. Green Impact Exchange, a stock exchange operator, hired John Visneski as CISO, who previously served in the same capacity at MGM Studios and began his career in the U.S. Air Force.
## What This Trend Signals
The sheer volume and breadth of these appointments paint a clear picture: organizations across all verticals now understand that cybersecurity is a boardroom-level concern. Companies are not simply filling vacancies — they are strategically elevating security leadership to drive digital transformation with resilience built in from the start. Many of these new CISOs carry dual expertise in areas like artificial intelligence governance, cloud security, and risk management, reflecting the evolving complexity of the modern threat landscape.
The diversity of backgrounds among these appointees is also noteworthy. Military intelligence, financial services, healthcare, cloud computing, and consulting are all represented, illustrating that organizations are drawing from a wide talent pool to address multifaceted security challenges.
—
## Frequently Asked Questions
**Q: What does a Chief Information Security Officer (CISO) do?**
A CISO is responsible for overseeing an organization’s entire information security posture. This includes developing and implementing cybersecurity strategy, managing risk, leading incident response teams, ensuring regulatory compliance, and often collaborating with other C-suite executives to align security goals with business objectives.
**Q: Why are there so many CISO appointments happening in 2026?**
The volume of appointments reflects a convergence of factors: rising cyber threats including ransomware and AI-driven attacks, stricter regulatory requirements across industries, and the increasing digitalization of business operations. Companies now view CISOs as essential strategic leaders rather than purely technical roles.
**Q: What industries are hiring the most CISOs?**
Financial services, healthcare, technology, and government agencies have been particularly active. However, CISO appointments are now appearing across virtually every sector, including retail, education, transportation, and entertainment.
**Q: How do organizations choose a CISO?**
Organizations typically look for candidates with a combination of technical cybersecurity expertise, leadership experience, industry-specific knowledge, and the ability to communicate risk to non-technical stakeholders. Many recent appointments highlight prior experience in related domains such as cloud security, AI governance, or enterprise risk management.
**Q: Is the CISO role the same as the CIO role?**
No. While both are senior technology leadership positions, the CIO focuses primarily on technology strategy and IT operations, while the CISO concentrates specifically on protecting the organization’s information assets, managing cybersecurity risk, and ensuring compliance with security standards and regulations. In some organizations, these roles are combined, while others keep them separate.
**Q: What qualifications are common among new CISOs?**
Many CISOs hold advanced degrees in computer science, information technology, or related fields. Certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), and CCSP (Certified Cloud Security Professional) are frequently seen among these leaders.
—
## Conclusion
The remarkable pace of CISO appointments throughout 2026 signals a pivotal moment in how organizations approach cybersecurity. From global fashion brands to government agencies, from healthcare systems to emerging AI companies, the message is consistent: cybersecurity leadership belongs at the highest levels of organizational strategy. As cyber threats continue to grow in sophistication and frequency, the demand for experienced, forward-thinking security leaders will only intensify. Organizations that invest in strong CISO appointments today are positioning themselves to navigate tomorrow’s digital challenges with confidence and resilience.
Thank you for reading



