In an interview with The Digital Banker, Álvaro Garrido, COO for Technology and Operations and CIO for Information Security and Data at Standard Chartered, explains why cybersecurity depends as much on culture and leadership as on technology.
Cyber threats, AI-enabled attacks, and complex supply chains test every bank’s defences — and no system alone can withstand them; security cannot rest on systems alone.
For Álvaro Garrido, resilience is as much about people as technology — about how teams think, act, and work together. “At Standard Chartered, embedding a true security culture means making protection seamless,” he says. “Controls must be simple, intuitive, and woven into daily workflows, so employees encounter minimal friction.”
Culture as the first line of defence
For Garrido, technology alone cannot secure the bank. Human behaviour shapes the effectiveness of every control. Complicated procedures are bypassed; intuitive, embedded safeguards are followed instinctively. “If security becomes overly complex, it will be bypassed; if it is designed to be effortless, it becomes second nature,” he notes.
This human-centred approach is reinforced through training and governance, but more importantly through design. Processes are automated where possible, feedback is timely, and the secure path is made the default. Culture itself acts as a firewall — a principle Garrido insists is non-negotiable in cybersecurity strategy.
This focus extends to leadership. Having led technology and security teams across Europe, Latin America, and Asia, Garrido stresses the importance of respecting local context. “Risk appetite, regulatory expectations, and technology maturity differ across regions; imposing uniform approaches without adaptation leads to resistance and fragility,” he says.
True leadership, in his view, lies in balance. “Transformation requires both rigour and empathy: rigour to maintain resilience, and empathy to build alignment,” he explains. “This balance has shaped my approach—ensuring consistency of purpose, while enabling the flexibility and agility to transform an organisation and achieve sustainable growth.”
Embedding security into innovation
Standard Chartered’s global network — spanning Asia, Africa, the Middle East, Europe and the Americas — exposes it to diverse regulatory and operational environments. Balancing consistency and flexibility requires both central discipline and local autonomy.
“We adopt a hybrid model: strict standards and testing are set centrally to ensure a consistent baseline of resilience and data protection, while local markets retain the flexibility to adapt where additional regulations require it,” he says.
“By combining rigorous central oversight with local adaptability, we create a model that is both resilient and responsive.”
Security, he argues, must be embedded into every development pipeline rather than applied as a brake after the fact.
“Controls must be integrated into the innovation lifecycle from the outset,” he says. “Security-by-design allows teams to innovate at speed without subsequent remediation cycles.”
Controls aligned to business value become enablers, not obstacles, he adds.
AI’s dual edge and human oversight
Like many technology leaders, Garrido sees immense opportunity in artificial intelligence (AI) — but also an equal measure of caution. “AI’s near-term value lies in augmenting existing teams,” he says. “It allows us to process vast data volumes, automate responses to common attacks and elevate analyst productivity.”
Yet the same tools that strengthen defences can also empower attackers. “Attackers are also weaponising AI, using it to craft more sophisticated attacks and scale operations,” he warns. The greater risk, he adds, lies in “blind reliance on AI without human oversight,” which can create false confidence and hidden vulnerabilities.
For Garrido, responsible AI integration must strengthen judgement, not replace it. The lesson extends beyond technology to the wider organisational mindset — one where governance, clarity of purpose, and accountability remain intact. “Responsible monetisation of data starts with governance and purpose clarity,” he says. “Privacy, security, and regulatory alignment are not constraints but prerequisites for trust.”
Building resilience in a complex digital era
Resilience, for Garrido, is neither a checklist nor a technology outcome. It is a discipline — demanding foresight, cultural alignment, and a willingness to confront weakness before it surfaces in crisis.
“The hardest lesson is that resilience only emerges when we are willing to push systems to the point of failure.” – Alvaro Garrido
Standard Chartered has redefined its testing, disaster recovery, and operational processes around this principle. Scenario testing is deliberately designed to fail, exposing weaknesses and strengthening the bank’s ability to respond swiftly.
Cyber risk, he notes, cannot be viewed purely through a technical lens.
“The most underestimated risks include the convergence of geopolitics, emerging technologies, and third-party exposure,” he says. These dynamics demand resilience in technology, strategy, and operating model alike.
For Standard Chartered, cybersecurity is as much about people and culture as it is about technology. By embedding intuitive controls, fostering responsible AI use, and respecting local contexts, Garrido argues the bank is building an organisation where security is instinctive and innovation sustainable. “Every challenge has strengthened our ability to respond and recover quickly,” he reflects. “Cybersecurity isn’t built in reaction to disruption; it’s engineered into how we work every day.”





