enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Xapo Bank

Protecting Digital Assets in a Regulated Banking Environment

Andrew Mannoukas

Regulated Security Orchestrator

Andrew Mannoukas brings deep experience in cybersecurity architecture within the digital asset sector. As chief information security officer at Xapo Bank, he leads security for Bitcoin custody through advanced cryptographic systems and resilient architecture. He focuses on balancing innovation, regulation and trust in a rapidly evolving landscape. His work in cryptonative banking security has positioned him among Europe’s top CISOs.

Protecting the Assets that Matter Most

My responsibility is to protect Xapo Bank’s most critical assets, the crown jewels of the organisation. These include customer funds, private keys, personally identifiable information and the systems that safeguard them.

My focus sits across three priorities. First is securing Bitcoin custody infrastructure at scale, while ensuring cryptographic systems remain ahead of emerging threats, including quantum computing.

Second is balancing the speed of a technology organisation with the rigor of a regulated bank, embedding security into product development from the beginning.

Third, building a culture where the protection of customer assets is shared across the organisation.

The defining discipline in this role is prioritisation. The challenge is not identifying risk. It is deciding where to apply deep control and where proportionate safeguards are sufficient.

Security Investment Trade-Offs

Every security decision is a resource allocation. In a cryptonative bank under regulation, threats include nation-state actors, financial fraud and dual regulatory scrutiny. The principle that guides my decisions is simple: can we recover if this fails? If failure can be detected, contained and recovered without permanent loss, we apply proportionate controls. If it leads to irreversible loss, risk tolerance is zero, and we invest heavily in layered defences.

When we migrated to multi-party computation for transaction signing (a process that took over a year to complete safely), we invested deeply because it directly protects what cannot be lost. Internal systems receive baseline controls since failure is reversible. The challenge is communicating these trade-offs as strategy, not neglect.

Aligning Security with Business Outcomes

Security is a growth enabler in a regulated environment.

Alignment starts with translating security into business impact. The discussion focuses on what is being protected, the consequences of failure and how controls support safe expansion.

Transparency is equally critical. Leadership needs a clear view of control strength, residual risk and trade-offs. Risk is framed in financial, regulatory and reputational terms. That aligns security with how decisions are made at the executive level.

When that clarity exists, ownership extends beyond the security function. Protection of critical assets becomes embedded in how the organisation operates.

Security Architecture in a Demanding Environment

Xapo operates in a demanding environment, managing Bitcoin custody across jurisdictions. Achieving security, agility and resilience requires a different architectural approach. Strong security does not come from treating all systems equally or aiming for full coverage. That increases complexity and weakens resilience. Protection must instead be risk-based.

Agility depends on early collaboration between security and engineering, not end-stage reviews. When engineers understand rationale, they build stronger solutions faster.

Regulation sets the minimum standard, but compliance alone is not security. Real protection comes from designing defences around threats. Resilience means no organisation is fully immune; the key is detection, containment and recovery speed.

Together, these principles make security a foundation for innovation rather than a constraint.

The Mechanics of Trust in Banking Systems

Trust in crypto banking requires proving security, especially for customers used to self-custody who expect strong evidence.

Our custody model ensures that even with multiple system compromises, transactions cannot be authorised without independent parties coordinating across separate secure environments. Our assets are protected by more than just code. We combine advanced multi-party computation with extreme physical security, utilising a secret network of nucleargrade bunkers across the Swiss Alps and beyond to withstand any disaster. Organisationally, Xapo is SOC 2 accredited, PCI compliant, and audited by Big Four firms. We're also subject to regular reviews from banking regulators across jurisdictions. These are barriers to entry that most crypto companies can't meet and most banks don't face. Operating at the intersection of both frameworks builds credibility. What sustains trust is transparency about controls, risks and remediation. In a space with technically sophisticated customers and deeply skeptical regulators, that gap between promise and reality is fatal.

Balancing Speed and Risk in High-Stakes Security Decisions

The biggest current test is artificial intelligence. Xapo faces pressure to adopt it quickly as competitors advance, customers expect it, and the business seeks its benefits. My job is enabling speed without unacceptable risk to customer funds or data. AI decisions rely on incomplete information. Unlike traditional controls, AI is probabilistic, continuously retrained and evolves faster than the understanding of its security implications.

For internal productivity and analytics, we move fast with guardrails as risk is bounded and reversible. For systems involving funds, keys or personally identifiable information, we conduct a deeper evaluation of behaviour, adversarial risks and attack vectors before deployment. The key is distinguishing where speed applies and where caution is required.

What Good Security Measurement Looks Like

Most security metrics measure activity, not outcomes. Patching and training show effort, not improved security. I focus on indicators tied to protecting customer funds and data and recovery when things fail, including early detection of anomalous access, response speed to suspected compromise and real recovery time under realistic conditions.

These better reflect security posture than ticket counts.

We run simulated incidents under pressure with incomplete information to expose gaps in communication, escalation and assumptions. Regulators focus on compliance and audits while crypto customers focus on custody strength and track record. The goal is meeting both without replacing real security with compliance.

The most valuable metrics are uncomfortable because they reveal unknown weaknesses. If everything looks perfect, the wrong things are being measured. Security is reflected in protection, response and learning from failures. A security programme that only reports good news isn't security, it's public relations.

Turning Setbacks into Organisational Learning

When things go wrong, many organisations focus on blame and add controls, which often worsen outcomes. Blame drives issues underground and controls without root-cause understanding create fragility.

I separate accountability from blame. Accountability means taking ownership and fixing what's broken. Blame means finding someone to punish. Post-mortems focus on reconstructing events without fault to surface assumptions, missed signals and required changes across architecture, process or capability. These insights shape strategy by revealing blind spots, guiding investment and encouraging early issue reporting.

In crypto-native banking, early warning is critical. Not every failure needs new policies, and overreacting can increase risk. Resilient organisations treat failures as data and learn quickly.

Strategic Focus in Security Leadership

The CISO role is evolving from technical specialist to business enabler. Boards now expect security to support transformation and strategy.

I work across product design, business development and regulatory engagement because security intersects all three. The shift is from preventing every attack to building resilience. Sophisticated adversaries will succeed eventually, what matters is detection and recovery speed.

“Trust in Crypto-Native Banking requires Proving Security is Exceptional, not Just Adequate.”

The most effective CISOs translate risk into business language, build relationships and enable growth. Those who succeed are not necessarily the most technical, but those who align security with business value.

Building Security through Strong Teams

A CISO is only as effective as their team. Strategy and board support mean little without execution. While the CISO is accountable in the boardroom, the team keeps the organisation secure in practice.

Effectiveness is directly tied to people quality, making investment in them essential. Hiring and development are therefore critical. I prioritise judgment, adaptability and communication over pure technical depth. Professionals must think critically under pressure and translate complexity into business language.

Once the team is in place, the focus shifts to enabling them, removing obstacles and ensuring autonomy. Strong security teams act as enablers, not blockers. When the business sees security helping achieve goals safely, trust builds naturally.

Advice for Emerging Cyber Security Leaders

Prioritise what matters.

Identify the assets that carry irreversible risk and protect them with depth. Apply proportionate controls elsewhere and be explicit about those decisions.

Operate with clarity under uncertainty. Decisions are rarely made with complete information. Sound judgment and transparency carry more weight than precision.

Invest early in people. Team capability defines execution. Security becomes effective when it is understood and supported across the organisation.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.