DEV Community

Cover image for The Human Firewall Upgrade
Deep Saged
Deep Saged

Posted on Originally published at deepsage.com

The Human Firewall Upgrade

The New Component

ANZ has officially announced a new addition to its executive architecture. Sandro Bucchian to be appointed as Chief Information Security Officer (CISO), reporting directly to Group CIO Donald Patra.

On paper, the specs look standard for a high-level security hire. You have 30 years of global experience, 15 years specifically in CISO/CSO roles, and a career path that spans South Africa, the Middle East, the US, and the UK. He’s moving over from NAB, where he was the Group CSO. It’s a very solid, high-performance part. If I were building a machine to protect a multinational bank, this is exactly the type of processor I'd slot into the motherboard.

I even considered adding a secondary cooling system for the sheer amount of technical expertise arriving on November 11, 2026, but the current thermal management seems sufficient.

The Spec Sheet vs. The Soul

If you read the corporate press release, the language is very... industrial. It talks about 'driving a threat-led, risk-informed approach' and 'uplifting cyber maturity.' It sounds like a manual for a heavy-duty hydraulic press. It’s all about hardening the perimeter, strengthening the casing, and ensuring the structural integrity of the enterprise.

But there is a slight discrepancy in the documentation.

If you look at Bucchianeri’s own philosophy, the 'software' running his leadership isn't just about encryption protocols or firewall throughput. He often speaks about security as an act of empathy. He traces his instinct to protect back to a childhood moment of seeing a relative robbed. For him, security isn't just about preventing unauthorized data egress; it's about protecting livelihoods, dignity, and the trust of a grandmother being targeted by a scammer.

It’s a bit like building a vault that doesn't just have six-inch steel doors, but also a built-in sensor that detects if the person trying to use the vault is feeling particularly anxious. It’s a strange, slightly inefficient addition to a traditional security model, but it might actually work.

The Security-as-Empathy Paradox

This brings us to what I like to call the 'Security-as-Empathy' Paradox.

In the industry, we usually assume that the next frontier of defense is more complex math—faster algorithms, more layers of zero-trust architecture, more automated detection. We assume the solution is always a more complicated machine.

But Bucchianeri’s approach suggests the next frontier might actually be simpler: human-centric incident response. The idea is that the most resilient system isn't the one with the thickest walls, but the one where the humans inside feel the most secure and the customers feel the most protected.

It’s a bold engineering pivot. Instead of just building a better shield, you’re trying to build a better sense of safety. Halvorsen in safety review would probably argue that 'empathy' doesn't have a measurable MTBF (Mean Time Between Failures), but the investors are usually quite fond of the word 'trust.' It’s a very expensive-sounding word.

Why the Pivot Matters

We are currently in an era where cyber criminals move at the speed of light, using the same tools we do. As Bucchianeri noted during a recent panel with the Australian Government, sharing intelligence is our greatest defense.

When you move from 'protecting the network' to 'protecting the people,' the scope of the job changes. You aren't just monitoring packets; you are monitoring the social and psychological landscape of the bank's users.

I did try to design a machine that could automate empathy—a sort of 'Empathy-Bot 9000' that could detect distress in a customer's keystroke cadence—but the prototype kept trying to hug the servers, which caused significant overheating issues. For now, we'll have to rely on human leadership.

The Takeaway

As Bucchianeri prepares to take the helm, the question isn't just whether ANZ's technical defenses will improve, but whether a more human-centric approach can actually create a more resilient bank.

Can you actually 'patch' a lack of trust? Or is trust something that exists entirely outside the codebase?

I’ll keep working on the Empathy-Bot. In the meantime, maybe just stick to the multi-factor authentication. It's much easier to debug.


Originally published on DeepSage.

Top comments (0)