Bernice Russell-Bond, the North Carolina CISO, said she’s looking for the most impactful cyber tools while also maintaining fiscal responsibility.
Bernice Russell-Bond asks a simple question of her North Carolina cybersecurity team every time someone wants to add a new tool to the mix.
The state chief information security officer doesn’t ask about the technology or the vendor, but breaks it down more simply: “What problem are we trying to solve?”
Russell-Bond said North Carolina is improving the management of its cyber architecture by following some basic guiding principles.
Bernice Russell-Bond is the chief information security officer for North Carolina.“What are the tools we’re using for each of those cyber areas? What are the tools we’re using for on-premise? What are the tools we’re using for cloud applications? We want to see what we have and what was the purpose of it, and then really look at what are the capabilities of those tools because vendors are including more all the time,” Russell-Bond said on Ask the CIO. “It’s important to challenge my team and peers to say, ‘what is the problem we’re trying to solve? What are we trying to solve short term and long term?’ That can impact the product you go with. A number of times people look at a problem and think they just need to fix something so they buy one tool to fix something. But if you look at solutioning as a process or a problem, you may go to a different solution.”
At the same time, Russell-Bond is asking the opposite question about current capabilities her team isn’t use or don’t need anymore.
“It’s looking to say, what don’t we need? What is causing friction in our environment and making those choices, whether we want to continue with those or not. I’m a firm believer that should be an annual process to look to see if we are mitigating risk, if we are improving the user experience with the way a tool works, and based off those answers, narrow down the tools that are making the impact and reducing the risk on authorized access, the risk of having data loss, and so forth,” she said. “It’s really holding some accountability with our vendors because I firmly also believe that’s the difference between a vendor and a partner. We need to understand what’s coming with new additions to their product, and say, ‘hey, does that work for us? Does that help us to reduce our footprint somewhere else?’ Those are the exercises we go through.”
AI to help fill gapsOf course, North Carolina found a few “surprises” in its cyber inventory, including tools and capabilities they turned on that helped them avoid some planned purchases.
Russell-Bond said these “little jewels” helped fill some cybersecurity gaps.
Those cyber gaps are only getting more challenging to fill with the expansion of artificial intelligence both on the offensive and defensive side.
North Carolina is taking a collaborative approach in ensuring AI tools are secure
Russell-Bond said she is having constant conversations with agency-level chief security officers around how to continuously secure these capabilities.
“Understanding the risk posture because then that risk posture, which takes into consideration the data, takes into consideration the audience and your end user and a number of things, lets you start asking what type of security should it have,” she said. “I think the other important piece is, though, to be very intentional about having security by design. That’s making sure that our developers understand that you have to build a system, an application with security in it, not try to fit it in afterwards, because that’s when you have your gaps. It’s educating those process owners by ensuring that my team is there to provide help, guidance, consultation, that governance, toolkits, baseline requirements and continuous monitoring.”
Part of this process is also working closely with vendor partners. Russell-Bond said this is especially important as contractors integrate AI tools into their products at a quicker rate.
Fast moving technologyShe said North Carolina is discussing with some of the frontier model providers how the state can use some of their additional functionality.
“Can they help us identify vulnerabilities? Can they look to our end-to-end processes and where we can automate responses or where things have to make sure we have that human in the loop?” Russell-Bond said. “It’s a continuous process as this technology gets smarter and smarter. It’s important that the better we know our end-to-end process, the more impactful and the more intentional we are with where we place AI in our processes to bring the biggest benefits back to the security program.”
While North Carolina still is early in applying AI tools to protect their systems, Russell-Bond said she recognizes how fast the technology is moving.
“There are some foundational things that had to be in place so we understand where in our processes that we’re using AI to make the biggest impact. I’ll say quickly that one of the pitfalls I see sometimes with the implementation of AI is that that people aren’t understanding the return on investment,” she said. “Some things are not worth the additional lift because the return is not that great. I go back to trying to be financially responsible. We can’t do everything everywhere, so we’re trying to make sure that we are doing automation and using emerging technology where it will give us the biggest impact for the state. That takes a little time, and so we’re not always going to be the quickest, but we’re trying to be the most impactful.”
Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | CMS moving beyond compliance-based cybersecurity | 0 | 20.25 | 03-08-2026 |
| 2 | DC3 making better sense of its cyber data | 0 | 11.04 | 16-04-2026 |
| 3 | State CISOs facing new set of challenges as role expands, survey finds | 0 | 6.32 | 03-08-2026 |
| 4 | ‘I love solving puzzles and this industry is full of them,’ says this cyber CISO | 0 | 5.05 | 12-08-2026 |
| 5 | AI incidents bolster push for federal cyber improvements | 0 | 8.62 | 24-07-2026 |
| 6 | Government use of personal data is changing. How to ensure responsibility? | 0 | 7.66 | 14-04-2026 |
| 7 | Orbia CISO Miranda Ritchie on building security into sustainable infrastructure | 0 | 7 | 08-07-2026 |
| 8 | Наталья Касперская: нужно ввести уголовную ответственность за утечки данных | 0 | 0 | 27-06-2023 |
| 9 | ЦБ выразил беспокойство по вопросу необоснованных блокировок средств граждан | 0 | 0 | 12-09-2025 |
| 10 | В ЦБ заявили, что при цифровизации личными данными должен распоряжаться человек | 0 | 0 | 06-04-2023 |