I spent a year at the Defense Intelligence Agency before Citi. At the time I thought it was a detour. Seventeen years later, it was the education that made everything else make sense.
Three things the intelligence community gets right about risk that I have never seen a bank board fully apply.
Principle 1: Distinguish Between The Absence Of Evidence And The Evidence Of Absence.
When no threat signal is visible, the untrained analyst concludes there is no threat. The trained analyst asks a different question: are we not seeing it because it does not exist, or because our collection systems are not positioned to detect it?
Banks apply this backwards. When no failure is visible, most boards conclude the risk posture is sound. They are measuring the absence of detected failure — not the same thing. At Citizens Bank, the most valuable work we did rationalizing our 49-platform ecosystem was not finding the risks showing up. It was asking which risks our monitoring was structurally incapable of seeing. We found several. They were not small.
Principle 2: Assume The Adversary Is Already Inside. Design Accordingly.
The intelligence community does not build security postures around preventing penetration. It assumes penetration has occurred or will occur — and designs to detect, contain, and respond rather than block.
Banking still builds around perimeter defense. Shifting our cloud architecture at Citizens Bank from perimeter-first to zero-trust on AWS and Azure was not a compliance exercise. It was this mindset applied to financial services. Institutions that have not made this shift are not more secure. They are less aware of their exposure.
Principle 3: Separate The Signal From The Noise Before You Act — Not After.
Intelligence analysis operates under constant pressure to act on incomplete information. The discipline is not to act faster. It is to triage ruthlessly: which signals carry genuine predictive value, and which will consume attention without improving the decision?
At Citi, the discipline was distinguishing regulatory findings that required operating model change from findings that required documentation improvement. They are not the same. Treating them identically is what happens when an organization has not learned to triage.
The intelligence community closes every risk review with a question I have never heard in a bank board meeting:
WHAT WOULD HAVE TO BE TRUE FOR EVERYTHING WE BELIEVE ABOUT OUR RISK POSTURE TO BE WRONG?
That is not pessimism. It is the most rigorous form of risk discipline available — deliberate inversion of your own assumptions to find gaps your framework is designed to miss.
Most bank boards review technology risk to confirm what they already believe. The intelligence community reviews it to find what it cannot yet see.
That difference in posture is worth more than any technology investment on its own.
What would change in your risk conversation if your board asked that question every quarter?
