Governing Body Spotlight

Spotlight on Krishna Talabathula

Governing Body Member of the Washington, DC CISO Community

Krishna Talabathula

CSO & CISO

Bank Fund Staff Federal Credit Union

Krishna Talabathula is VP & Chief Information Security Officer at Bank Fund Staff Federal Credit Union (BFSFCU), where he leads the cybersecurity program for a financial institution serving the World Bank Group and IMF communities. Before stepping into the CISO role, he spent 15 years at Marriott International in application delivery, giving him a builder's perspective on security.

Fun fact: he once developed a business plan for a luxury electric-vehicle rideshare startup targeting Hyderabad, India — proof that his passion for innovation extends well beyond the security operations center.

Learn more about the Washington, DC CISO community here.
 

Give us a brief overview of the path that led to your current role.

My path was unconventional — I spent 15 years at Marriott International delivering enterprise applications before moving into security leadership. Building systems taught me how they break, and that engineering mindset shaped how I approach cyber risk today. At BFSFCU, I've had the opportunity to lead a Zero Trust transformation, modernize identity and access management, and build a security program that treats regulators, members, and the business as partners rather than obstacles.
 

What is one of your guiding leadership principles?

Technology leadership done well is an act of service. My job isn't to say "no" — it's to enable the business to move fast, safely. That means translating cyber risk into business language, empowering my team to own their domains, and measuring our success by the trust we earn from members, examiners, and the board.
 

What is the greatest challenge CISOs face today, and how are you addressing it?

The velocity of AI adoption is outpacing governance. Every vendor is embedding AI into their products, employees want to use it, and the risk surface is evolving faster than traditional control frameworks. We're addressing it by building an AI security and governance framework aligned to NIST AI RMF, embedding AI evaluation criteria into our architecture review process, and treating AI as something to govern and harness — not fear. The institutions that win will be the ones that enable AI responsibly, not the ones that block it.
 

What is the key to success for someone just starting out as a CISO?

Learn the business before you try to secure it. Early credibility comes from listening — understanding what the CEO worries about, what the board asks, and where revenue actually comes from. Then translate everything you do into that language. Technical excellence gets you into the room; business fluency keeps you there.
 

How do you measure success as a leader?

Two ways: outcomes and people. Outcomes means measurable risk reduction — value-based KPIs the board can understand, not activity metrics. People means whether my team is growing: are they taking on bigger problems, presenting to leadership, and building careers? If my team can run the program without me in the room, I've done my job.
 

What is the value of being a member of Gartner C-level Communities?

The peer network is the value. Cybersecurity leaders face the same threats but rarely compare notes candidly. Gartner C-level Communities creates a trusted space to pressure-test strategies, learn from others' successes and mistakes, and stay ahead of what's coming — which is invaluable when the threat landscape and technology landscape are both moving this fast.

 


Governing Body members share their insights and leadership perspectives to shape the agendas and topics that address the top priorities impacting business leaders today.