DoGood Member Spotlight: Howard Wolfe

Member Spotlight

The security leader other security leaders call first.

July 2026

Howard Wolfe

Howard Wolfe

Director of Information Security  ·  FirstBank

Connect on LinkedIn →

Howard Wolfe is Director of Information Security at FirstBank. Before that, he worked for four different companies without changing jobs: same desk, same title, four different private equity owners across five years at Corizon Healthcare, a correctional facility healthcare provider. Most of the people above him didn't survive the transitions. He ran security through all of them.

Here's what that teaches you.

1. When there's no budget, your existing vendors become the strategy.

Correctional facilities are one of the harder environments to run IT security in. They're mostly brick, which means wireless doesn't penetrate. Cabling means clearing secured areas with corrections staff, scheduling access days in advance, sometimes waiting weeks. Rural locations mean fiber is a project before the project starts. And the contracts are government-issued, lowest bidder, leaving almost nothing for security.

"You're not going to get the best tools and resources applied because the contracts are so tight from a financial perspective."

Howard Wolfe, FirstBank

So you learn to audit what you already have. If the organization has Microsoft licensing, what does it actually cover? How much of what you need is already included? Every vendor relationship becomes a negotiation about scope, not just a renewal. That constraint (no margin, no reserves, no fallback) forced the kind of clarity a bigger budget might never have.

Howard doesn't dress up how hard the four ownership changes actually were. "It was very difficult to keep programs moving forward when the leadership is under constant change and rotation in and out," he says. Four CEOs. Four sets of priorities. A security program either survives that or it doesn't.

The budget problem was one thing. The regulatory problem was worse.

2. "Highly recommended" is not "you must," and the difference is everything.

HIPAA has gray areas. Recommendations without requirements. When a CEO asks whether they have to fund a security initiative, the honest answer under HIPAA is often no, not exactly. That's a hard place to build a program.

Banking is different. FFIEC, FDIC, Federal Reserve. The regulations are "you must." A bank with outstanding deficiencies can't open new branches, can't expand, can't grow. "So you have to maintain all your regulations being good standing." You get funding. You get backing. Because the alternative isn't an option.

Howard made the move. At FirstBank, the regulatory structure gives him something correctional healthcare rarely could.

Right now a lot of those decisions involve AI. Banking regulators are moving carefully: personal productivity, document drafting, and contract review are fine. Actual business decisions are not. A model using zip codes to assess mortgage risk can create fair lending violations without anyone realizing it's happening. "Fully understanding what the AI engine is doing and how it's processing data."

The threat side isn't waiting either. Vulnerabilities that used to sit exploitable for days will get found and used within minutes. Low-severity findings will need to be treated like critical ones, because attackers can stack several small weaknesses into one big breach. And phishing emails written by AI won't have the typos and awkward phrasing that used to give them away. Infosec teams won't be able to hire fast enough to keep up. They'll need AI to fight back. That's not a future Howard is excited about. It's just where the math points.

And when the board calls before he's had time to figure out the answer himself, he's not going to be improvising alone.

3. Build the peer group before you need it.

Not for networking. For the 8am call when the board asks about something they saw in the Wall Street Journal. What are you guys doing? How are we responding?

Howard keeps a standing chat group of other CISOs for exactly that moment. The group may not have an answer sitting around waiting. However, they bring years of experience and expertise that can provide advice, validation and support when needed. Howard had spent ordinary weeks building the group, staying active in it, and being useful to the other CISOs in it.

He built that group before he needed it. Now he's often the one other CISOs and Security Leaders in that group call first.

This has been a DoGood Member Spotlight.

For Tech Leaders

Explore Vendors on Your Terms

Join IT leaders like Howard and discover vetted partnerships without the noise.

Request an Invitation
For Vendors

Reach Buyers Who Want to Hear From You

Connect with leaders like Howard who are actively evaluating solutions in your category.

Become a DoGood Vendor
Next
Next

DoGood Member Spotlight: Deb Cafarella