A straight lift from the bank next door
ANZ confirmed on August 26 that Sandro Bucchianeri will become its Chief Information Security Officer, arriving November 11 from National Australia Bank, where he has held the Group Chief Security Officer title since NAB recruited him from Absa Group in 2021. ANZ Group Chief Information Officer Donald Patra called him an outstanding and globally respected security leader with a proven track record of uplifting cyber maturity across large, complex organisations. That framing is accurate, and it also states plainly what happened here: ANZ went shopping at a direct competitor for a finished executive rather than developing one internally, and it agreed to wait almost three months to get him.
The two banks sit across the same regulatory table, answer to the same prudential regulator, and compete for the same retail and business banking customers every day. Handing your rival's chief security officer the same job, with the same mandate and largely the same threat landscape, is a specific kind of statement. It tells the market that ANZ's board decided the fastest way to raise its security ceiling was to buy a proven operator rather than accelerate a deputy, and it tells NAB's remaining security staff that the person who set their current strategy is walking straight to the competition.
Eleven weeks of acting cover is the real story
The gap between announcement and start date is the detail worth sitting with. Shane Ripley will run ANZ's security function as Acting CISO from now until mid-November, which means the bank is operating without a permanent security leader for the better part of a quarter. That is not unusual for a hire of this seniority, since notice periods and garden leave clauses are standard when an executive is moving between direct competitors, but it is still a long window for an organization that presumably considers cyber risk a board-level priority every other week of the year.
The honest read is that ANZ needed a name it could announce, not a bench it could promote from immediately. If Ripley were a credible permanent candidate, this would likely have been framed as an internal promotion with Bucchianeri as a later addition, not the other way around. Instead ANZ chose to be public about who is running security on an interim basis while the person everyone will actually remember spends eleven weeks finishing commitments at a rival bank.
A career built on hopping every few years
Bucchianeri's resume reads like a tour of global banking and telecom security: Absa Group, National Bank of Abu Dhabi, Investec, AT&T, and now a fifth stop at NAB before this sixth move to ANZ, spanning more than 30 years and multiple continents. Each stint runs long enough to stand up a security program, prove it against real incidents, and build a reputation, then hand it off to a successor while moving to the next institution willing to pay for that proof. This is not a criticism of Bucchianeri specifically. It is a description of how the market for elite bank security leadership actually works now.
The pattern matters because it concentrates institutional knowledge in a small number of people who move between competitors on a predictable cadence. A rotating cast of star CISOs effectively transfers structural knowledge, vendor relationships, and playbook design across rival banks every few years, even when no confidential data ever changes hands. Boards that treat a marquee security hire as a permanent fix should recognize they are renting expertise on the same cycle every competitor is renting it, and plan succession accordingly rather than treating the next departure as a surprise.
What that hopping costs an organization in between
Every handoff carries a tax. The incoming executive spends the first several months relearning an environment that the outgoing one already understood cold, re-litigating architecture decisions, and rebuilding trust with a team that just watched its leader leave for a competitor. ANZ's own security staff will spend the next quarter reporting to an acting leader who may or may not stay once Bucchianeri arrives, then adjusting again to a new permanent boss with his own priorities. None of that shows up in a press release, but it shows up in delayed roadmaps and diverted attention exactly when threat activity does not pause to accommodate a leadership transition.
The alternative, building security leadership internally on a deliberate multi-year timeline, is harder to announce and slower to show results, which is precisely why fewer banks choose it. ANZ's move is rational given the market it operates in, but it is worth naming clearly: this is a bank buying finished expertise because it judged its own bench insufficiently ready. External hiring can be the right call in a given year, and a mature security organization still treats every such hire as evidence that its own development pipeline needs another look, not as proof the pipeline was unnecessary in the first place.
Threat-led risk is now a specific ask, not a platitude
Patra's announcement leaned on precise language, describing Bucchianeri's mandate as driving a threat-led, risk-informed approach across the enterprise and working closely with teams across the bank to manage risk and uplift cyber maturity and capability. That phrasing tracks Australian prudential expectations under APRA's CPS 234 standard, which pushes regulated financial institutions toward security programs built around live threat models rather than static compliance checklists. ANZ timing a high-profile CISO hire to that vocabulary reads as a bank positioning itself for its next regulatory review as much as for its next incident.
Every CISO outside Australian banking should expect the same vocabulary to show up in board and audit committee conversations soon, regardless of jurisdiction. The label matters less than whether your organization can point to a current, specific threat model tied to actual attack paths against your own infrastructure, rather than a generic framework mapped to a compliance standard. If a board asks for evidence of a threat-led approach and the honest answer is a policy document, that gap is the one to close before the next audit cycle, not after.
What this means if you run security for a mid-market enterprise
Few companies outside the top tier of global banking can pay for a 30-year, six-employer security veteran, and most should not try to copy this move directly. The lesson worth taking is structural: ANZ's eleven-week acting-CISO period is a live demonstration of what happens when a security leader departs and no internal successor is fully ready. Run that scenario against your own organization today. If your answer requires an external search of unknown length before anyone is accountable for the seat, that is the gap to close now, while it is a planning exercise rather than an active crisis.
The cheaper fix is naming and empowering a real deputy well before you need one, the way ANZ named Ripley publicly rather than leaving the CISO seat visibly empty during its search. A credible acting leader, announced with confidence rather than treated as an embarrassment, reduces regulatory and reputational risk during any transition. Build that bench now, because the market for experienced security executives is only getting more competitive, and you may not get eleven weeks of notice the next time someone on your team gets the call from a rival.



