Join us for the ISACA Chicago Chapter Meeting - November 2025
Topic: Elevating Security and Risk Functions with CMM & Mitigating AI Risks in Financial Services
Title: Elevating Security and Risk Functions with CMM: Journey from Cyber Liability to Top 10 Most Secure FI in the US
This presentation discusses the application of the 5-Level Capability Maturity Model (CMM) to enhance security and risk functions, particularly in financial services. The CMM provides a structured framework for process improvement, helping organizations evolve from chaotic, reactive processes (Level 1) to optimized, continuously improving operations (Level 5). CMM adoption transforms security and risk functions into strategic enablers, aligning them with business goals. This presentation also illustrates a practical application of CMM and how it was used to transform a financial services corporation from a cyber liability to a top 10 most secure FI in the US.
Michael Wichmann is a seasoned leader with deep expertise in information security, technology, and management consulting within the financial services industry. As Senior Vice President at Wintrust Financial, he plays a critical role in protecting the organization and its customers from increasingly sophisticated cyber threats. His strategic efforts contributed to Wintrust being named by Forbes as a top 10 most cybersecure bank in 2024, demonstrating his dedication to fostering innovation and resilience in the face of evolving challenges. His expertise addresses risks related to AI, identity management, digital transactions, and advanced security frameworks, ensuring organizations remain adaptable and secure.
[Second Session @ 4:00 PM]
Title: Mitigating AI Risks in Financial Services: Strategies for Secure and Responsible Adoption
The rapid adoption of AI applications in the financial industry is driving significant benefits in efficiency and cost reduction, but it also introduces heightened risks related to sensitive data exposure. During cybersecurity risk assessments, the classification and handling of sensitive data are critical factors influencing overall risk ratings and exfiltration scenarios. Common protective measures such as encryption, hashing, and tokenization can mitigate exposure but may impact data analytics capabilities and processing efficiency. Data obfuscation and restricted access to sensitive information are additional controls, though they come with operational trade-offs and challenges in implementation, especially at the application level.
Neeraj Kakrania is a seasoned cybersecurity specialist with over 21 years of experience in the IT industry, currently serving as Principal Cybersecurity Analyst at Discover Financial Services. Neeraj has built a distinguished career focused on protecting organizational assets, developing robust security strategies, and leading teams to address complex security challenges in the financial services sector. His expertise spans a broad range of cybersecurity domains, including risk assessment, data security, policy development, and technical leadership.
2 CPE credits will be earned by participating in this webinar.
Note: ISACA members are requested to register with the same email ID as that in their ISACA profile for direct CPE uploads.
Senior Vice President and Director of Information Security, Corporate Security, Identity, and Fraud | Wintrust Financial
--
Principal Cybersecurity Analyst | Discover Financial Services