About

Oritse J. Uku

Three employers over 25 years. I led the cyber threat management team for North America at Citigroup, carried enterprise security for two regulated Northwestern Mutual subsidiaries, and served eight years as an Army intelligence officer in Korea, Germany, and Afghanistan. Between the Army and the cyber work I spent five years on Citi’s rates desk selling interest rate derivatives to institutional clients.

Oritse J. Uku
2022 – 2026

Northwestern Mutual subsidiaries

Security accountability for a federally chartered savings association and a registered broker-dealer. Board-appointed Chief Information Security Officer of both, 2025.

2022 – 2026

Northwestern Mutual

Vice President, Business Information Security Office & IT Governance, Risk, and Compliance

2017 – 2022

Citigroup

Cyber threat management for North America. Wrote the bank’s major incident-response runbook and third-party incident-response playbook.

2011 – 2016

Citigroup

Institutional rates sales

2001 – 2009

U.S. Army

Military intelligence officer

The record

What I have run

2022
Northwestern Mutual2022 – 2026

CISO of two regulated subsidiaries, and enterprise business information security

The security responsibilities for two regulated subsidiaries, a federally chartered savings association and a registered broker-dealer, were on my plate from the day I joined Northwestern Mutual in 2022. In 2025 the boards of both companies formally appointed me their CISO. In both seats I was accountable for enterprise security, resilience, and regulatory engagement. I also ran business information security for the enterprise and, from 2023, IT governance, risk, and compliance.

2017
Citigroup2017 – 2022

Cyber threat management, incident-response doctrine, and the bank’s first cloud responders

Much of the team’s work was threat-informed defense. Prioritized patching was one application of it. CVSS rates a vulnerability in isolation, so we ranked ours across the estate by what adversaries were exploiting in the wild.

In 2019 I was one of two people asked to write the cloud security brief the CISO took to the board. I then led the eighteen-month effort that trained the bank’s first cadre of cloud incident responders, more than three dozen of them. They sat in teams across the bank, trained to a common standard. I wrote the third-party incident-response playbook and the major incident-response runbook. Incident response covered the bank’s footprint of about 160 countries. I planned for nation-state denial-of-service campaigns anticipated in response to US government actions. When Russia invaded Ukraine in 2022, Citi had offices in both countries. The exposure ran wider than cyber, covering a western bank’s people, premises, and data in both places, and I worked the information security side of the response.

2001
U.S. Army2001 – 2009

Military intelligence, in Korea, Germany, and Afghanistan

The work was predictive analysis: building the adversary’s most likely course of action from their own doctrine, history, and worldview, filtered through the sources reporting on them, and tailored to the decision a specific commander actually had to make. In South Korea I was the intelligence officer for an attack helicopter squadron, a strategic asset in a potential conflict with the North, and I spent that year on North Korea. In Germany I was executive officer of a counterintelligence and human intelligence company.

Recalled from business school to deploy to Afghanistan, I spent most of the tour as the intelligence officer for the Army command advising Afghan army and police units across the western region, on the Iranian border. The shop I ran was staffed by Army, Navy, and Air Force intelligence personnel. I briefed the commander, coordinated with the Spanish and Italian contingents, and was the channel between allied teams that did not deal with each other directly. I kept a truck and crew so my shop was out among the Afghan army, the police, and the people in the areas we covered. For the last six weeks I was attached as intelligence officer to an Embedded Training Team with an Afghan National Army battalion, there so it won its fights with the Taliban.

Prioritizing patches on what adversaries are actually exploiting is that same course-of-action work, run against a different adversary set.

Credentials

2025CISO Executive Education Certificate
Carnegie Mellon University, Heinz College
2011Master of International Affairs
Columbia University
2008 / 2001MBA, and BA in history
Boston College
CertificationsCISSP, GCIH, GCTI, GDAT

I speak conversational German and basic Spanish, and am learning Korean.

Markets

On the desk

I came to the desk from Columbia, where my regional specialization was East Central Europe, and from Roubini Global Economics, where I interned as an Eastern European economic analyst and published on the region. I covered government bonds and interest rate derivatives across G10 currencies for about fifteen institutional clients. After Russia annexed Crimea in 2014, I wrote my read of it to clients over Bloomberg. My call was that Russia would stay. The Black Sea Fleet had been based at Sevastopol since 1783, and Crimea mattered more to Russia than keeping Russia out of it mattered to the United States.

The desk’s daily work was pricing: what a position costs, what it costs if the world moves, and what somebody will pay today to be protected from that move.

Arguments

Two instruments

Both came out of operating practice, which is also the limit of what they claim.

The Resilience Operating Discipline →

How I run resilience: six operations, in order, that keep a critical service inside its stated tolerance. They produce the evidence during normal operation, so the record is in hand when the service is tested and a board can read it. I wrote it from the two subsidiary seats. It is mapped against the operational-resilience regimes of five jurisdictions: DORA, PRA SS1/21, APRA CPS 230, OSFI E-21, and the MAS Business Continuity Management Guidelines. It also answers SEC Regulation S-K Item 106, which governs disclosure rather than resilience.

The Pipeline Paradox →

The same arithmetic applied to staffing. Agentic AI is absorbing the entry tier of cybersecurity. The automation is correct and the cost is unpriced, because that tier was the profession’s apprenticeship, and the shortfall arrives late, across the whole industry at once, and cannot be surged. I serve on the CISO Advisory Program at 7AI, an agentic security company in the category this argument examines. 7AI sees what I publish when everyone else does. Full disclosures.

The gap · 2016 to 2017

After Dodd-Frank pushed rates onto electronic execution, I kept asking whether anyone else noticed our jobs being automated.

I formed PetDr in June 2015 and left Citi in March 2016 to work on it full time. It did not work out. I moved into cybersecurity on the same reading of where technology was heading, and on 11 September 2017 I returned to Citi, into its Cyber Security Fusion Center.

Writing

Elsewhere

Two newsletters and one book, described in full on the writing page.

Becoming Cyber

Becoming Cyber · Entering and remaining in the profession as agentic AI absorbs the entry tier. Read it →

CyberFuture

CyberFuture · The governance and board oversight of security. Read it →

Taking the Boy Scouts to War is my memoir of the Afghanistan tour.

Connect

Conversations, not consulting.

I welcome conversations with security leaders, executive teams, and boards. I do not accept consulting engagements.

LinkedIn · Press and speaking: media@oritseuku.com · Media and speaking