Leading at the Edge of Digital Risk: Inside the Evolving Role of Today’s CISO

In today’s digital era, cybersecurity is no longer merely a technical necessity, it is the backbone of trust, resilience, and sustainable growth, particularly in the financial services sector. The role of the Chief Information Security Officer has transformed dramatically, evolving from a technical guardian to a strategic leader who shapes organizational culture, drives enterprise-wide awareness, and anticipates emerging threats. Upendra Sugathadasa, CISO at Singer Finance (Lanka) PLC, exemplifies this evolution, combining technical mastery with strategic vision and inspiring leadership to redefine what it means to protect a modern financial institution.

For Upendra, cultivating a security-first mindset within an organization begins with awareness. “Staff need to see the threats, understand the trends, and appreciate the consequences of their actions,” he says. He refers to this as building a “human firewall,” where every employee, regardless of role, takes responsibility for safeguarding data. For example, developers are shown real-world breaches resulting from coding errors, while board members are presented with the financial and reputational costs of lapses in security. By creating relevance, all individuals across an organization will begin to internalize the importance of cybersecurity. But awareness alone is not enough. Upendra emphasizes that security must be seen as a shared responsibility: “Everyone who handles data, is responsible for its security. Culture has to be built with that in mind.”

This cultural foundation is complemented by rigorous preparation and structured processes, which allow organizations to respond with confidence under pressure. Cybersecurity incidents are often high-stakes and time-sensitive, and the ability to act decisively is critical. Upendra begins by identifying the organization’s most valuable assets, its “crown jewels”, mapping the risks they face, and recognizing gaps in current controls. From there, incident management frameworks and detailed playbooks are developed and rehearsed. “Multiple roles must work together, each playing a part in responding effectively. My goal as a CISO is to guide and drive this collective effort towards success,” he explains. By combining preparation, rehearsal, and collaboration, he ensures that his teams are ready to face even the most complex scenarios with clarity and composure.

Building a future-ready cybersecurity team, according to Upendra, requires nurturing both technical expertise and strategic thinking. He exposes his teams to business discussions, corporate management, and even board-level conversations, helping them understand how decisions are made and what leaders expect at the top. This exposure encourages strategic thinking, allowing cybersecurity professionals to align technical operations with organizational goals. At the same time, he insists on technical rigor. “Cybersecurity never stands still. Controls evolve, threats evolve, therefore so must we. You can’t slack off in this field.” Foundational practices such as vulnerability assessments, patching, and basic controls remain critical, providing a stable base upon which more advanced security measures are built. By instilling a mindset of curiosity, continuous learning, and respect for fundamentals, he ensures his teams are equipped to adapt and thrive in a constantly shifting landscape.

Looking ahead, the threat landscape in financial services is expected to accelerate dramatically, driven largely by artificial intelligence. Cybercriminals are already leveraging AI to automate attacks, uncover vulnerabilities faster, and develop sophisticated malware that is more difficult to detect. At the same time, Ransomware continues to evolve, with new, advanced variants appearing with alarming frequency. Meanwhile, the expansion of digital ecosystems through APIs, mobile applications, fintech partnerships, and cloud adoption creates additional attack surfaces. To stay ahead, financial institutions must adopt a proactive, intelligence-led approach. This includes leveraging threat intelligence services for early detection, implementing zero-trust frameworks, and strengthening third-party risk management to cover the entire supply chain. Continuous staff awareness remains a critical component, ensuring that the human firewall is as robust as any technological defense. As Upendra notes, “To protect the organization, we must move from traditional defense to proactive intelligence, combining technology, process, and people in harmony.”

Balancing operational agility with robust security is another challenge that financial institutions face as they embrace cloud platforms and digital channels. A strong security framework should enable growth and innovation without creating blind spots or hindering progress. Technologies such as Data Loss Prevention (DLP), Security Information and Event Management (SIEM), and Extended Detection and Response (EDR) form the core of this foundation, but their value depends on how effectively they are configured, managed, and integrated into business operations. Automation reduces human error, meaningful insights drive decision-making, and careful configuration ensures that security supports rather than obstructs organizational objectives. When these elements align, security becomes an enabler, allowing institutions to scale confidently while remaining protected.

What emerges from Upendra’s approach is a vision of cybersecurity that is not reactive, but anticipatory, not isolated, but woven into the fabric of the organization. His leadership demonstrates that the role of the modern CISO extends far beyond safeguarding systems, it involves shaping culture, mentoring teams, guiding strategic decision-making, and preparing the enterprise to confront the unknown with confidence. It is an inspiring reminder that leadership in cybersecurity, much like leadership in business, requires a blend of technical excellence, strategic foresight, and the ability to motivate people to rise to a shared purpose.

In reflecting on the challenges and responsibilities of his role, Upendra offers a compelling insight: “Stay curious, stay current, and never overlook the fundamentals. That mindset is what will carry you through even the most unpredictable landscapes.” This philosophy, rooted in both rigor and resilience, exemplifies the qualities that define next-generation cybersecurity leadership, qualities that will become increasingly essential as financial institutions navigate an era of rapid technological change and escalating cyber threats.

As organizations continue to expand their digital footprints and embrace AI-driven transformation, leaders like Upendra Sugathadasa illuminate the path forward. By combining awareness, preparation, technical mastery, and strategic vision, they ensure that cybersecurity is not merely a line of defense but a platform for innovation, trust, and sustainable growth. In a world where the pace of change is accelerating, his example demonstrates that with the right mindset, tools, and leadership, financial institutions can not only withstand emerging threats but thrive in spite of them.

Total
0
Shares