The division ISOs are pretty useless many of them were recruited without security backgrounds and I knew some who were demoted into an ISO role or even hired with criminal records.
I understand they're all under Corporate Risk under Mandy Norton doing security planning using a risk based approach. But they're terrible at what they do and the bank should let most of them go to keep the jobs for the Frontline employees in the branches or call centers, it's only right.