Question
What makes working in information security at a regulated insurer or bank different from other industries, and what skills does it demand?
Answer
Regulated sectors face strict supervision, sensitive data, and close proximity to management, so security work blends technical control with consultancy, communication, and resilience under stress.
A practitioner described the field as "demanding and interesting": you need to be curious, stress-resistant, flexible, consequent, open, collaborative, and (in international firms) able to work in English. Relevant differences for regulated sectors (banking, insurance, critical infrastructure) include the regulated environment, processing of sensitive data, a strong security culture, proximity to management, being early adopters of GenAI / new ways of working, and heavy consultancy demands. The job is as much about advising the business as configuring tools.
Note saved — thanks!
Question
How is the security organization structured at a large international insurer like Helvetia Baloise across group and local levels?
Answer
A central Group CISO sets direction, while market-unit and business-unit layers carry the controls down to local CISOs and ISOs near the front line.
* The security org: a Group CISO on top, 2LoD (Risk Management) CISOs per Market and Business Unit, and 1LoD (IT) ISOs running the controls near the front line. *
The structure at Helvetia Baloise (a Swiss insurer present across Europe) layers a Group CISO over 2LoD CISOs for each Market Unit and Business Unit, who in turn oversee 1LoD ISOs (Information Security Officers) at unit level. Group-wide there are roughly 50 security officers for ~22,000 employees, including Group CISO, Group ISOs, Local CISOs, Local ISOs, and a Cyber Defense Team. A separation of 1LoD (IT) and 2LoD (Risk Management) responsibilities was ongoing — meaning operational security ownership is being cleanly split from independent risk oversight.
Tip: "LoD" = Line of Defense; 1LoD owns and runs controls, 2LoD independently oversees risk.
Go deeper:
Chief Information Security Officer — Wikipedia — Rolle, Reporting-Linien und Verantwortlichkeiten des CISO in der Sicherheitsorganisation.
Note saved — thanks!