Log in

CISO of the Year Award


And...Here are the 2023 Nominees and Winners!!!

                                                                                                  ENTERPRISE                                                                                  MIDCAP


                                                                                    Darin Hurd, CISO, Guaranteed Rate                                             Neil Witek, CISO, Oak Street Health

Visit the New CISO of the Year Website for More Information and Pictures


Brad Skibitzki, CISO - Zebra Technologies
Dan Manley, CISO - CME Group  2023 Runner-up
Matt Morton, CISO - University of Chicago
Kenneth Townsend, CISO - Ingredion
Brian Palmer, Director of Security & Infrastructure - Ventas
Darin Hurd, CISO - Guaranteed Rate  2023 CISO of the Year Award - ENTERPRISE


Phil Kane, VP Director of IT Infrastructure & Information Security - The Inland Real Estate Group, LLC
Fred Kwong, CISO - DeVry    2023 Runner-up - MID-CAP
Neil Witek, CISO - Oak Street Health  2023 CISO of the Year Award - MID-CAP

Please send them a note of congratulations!

Click Here to view the 2023 Awards Press Release

2023 CISO of the Year Program Overview

The CISO of the Year Committee and the Chicago Chapters of AITP, ChicagoFIRST, InfraGard, ISACA, ISSA and SIM invite you to submit exceptional cybersecurity leaders for the Chicago Area CISO of the Year Award.

All of our events will be in person this year.  We will continue to follow all federal, state and local pandemic guidelines should another Covid surge occur.


The current business climate has seen an unprecedented number of cybersecurity related headlines. Hackers to Nation State actors have been shown to be constantly probing organizations defenses with the intent to break in, disrupt operations, monetize information, and steal intellectual property. Between these threats and the increasing regulatory climate, never has the Chief Information Security Officer (CISO) been asked to navigate more difficult terrain.

Originally patterned after the Chief Information Officer (CIO) of the Year Award sponsored by the Association of Information Technology Professionals (AITP Chicago), SIM-Chicago and the Executives' Club of Chicago, this program seeks to recognize outstanding CISOs for the contributions they make to their organizations, the Information Security profession and the local community. The award process is overseen by the Chicago CISO of the Year Program, which is a not-for-profit affiliated with AITP Chicago and managed by local area security leader volunteers.


Starting in 2022 two different awards will be presented – “ENTERPRISE” for CISO’s from organizations with more than $4B USD in revenue and “MID-CAP” for those from organizations with less than $4B in revenue. If a CISO does not have company-wide responsibilities, the combined revenue of the business units under their remit will be used to determine the award for which they’ll be considered. 


Nomination is an open process that can be initiated by anyone with direct experience working with the nominee. Submitted nominations are reviewed by the Head of the Judges Committee to ensure that the nominee meets the requirements laid out in the Nomination Form. Nominees demonstrate their competency and achievements through a multi-staged process that includes a detailed written questionnaire, and a series of formal and informal interviews with a panel of industry peer-level judges. The program spans over five months and culminates with a final interview and selection process completed by a panel of local area CEOs. The CISO of the Year winner is announced at an Awards Ceremony held in October of the same year.


  1. Nominees are submitted to the program by the community.
  2. Anyone who has a direct working relationship with a CISO can nominate that individual for the CISO of the Year Program.
  3. Participation in the program requires the explicit agreement from the nominee.
  4. Nominee fills out a multi-page application covering multiple topic areas relevant to the Information Security profession and community.
  5. Each nominee will be assigned at least two judges to conduct a 60-90 minute interview. These interviews are strongly preferred, but not required, to be in person.
  6. Judges evaluate both the written and verbal submissions as compared to other nominees.
  7. Scores of all nominees will be evaluated, discussed, and calibrated by the Judges Committee (JC). The JC consists of all volunteer CISO peer group judges.
  8. The Head of the Judges Committee (HJC) will facilitate the calibration sessions with a focus being on the four nominees with the highest scores.
  9. The HJC does not submit scores for any nominees.
  10. If two nominees have the same score, the tiebreaker is decided by the HJC and is determined by the nominee’s participation in the program (quantity and engagement level).
  11. The two nominees with the top scores in each category will advance to the CEO evaluation round where the winner is selected.
  12. CEOs will interview the two finalists in each category and select the winner.
  13. Tie-Breaker Rule: If the CEOs deadlock, the finalist with the highest score wins. If both finalists have the same score, the HJC will select the winner.


  1. Individual submitting nomination has direct experience working with Nominee.
  2. Goods or services have not been exchanged or promised for nomination.
  3. Nominations must be submitted to no later than July, 30 2023.


  1.  Nominee leads the Information Security program for the organization (CISO or equivalent).
  2. Nominee has been in role for a minimum of 12 months at the time of nomination.
  3. Nominee remains active in role until the end of September of the Award year.
  4. Nominee's organization is based out of or has a significant office presence in the Chicago Area.
  5. Nominee's primary work location is in the Chicago area.


2022  -  ENTERPISE, Mahmood Khan, SVP & CISO, CNA Insurance

2022 -  MID-CAP, Walter Lefmann, CISO, Chicago Trading Corporation

2021 -   Ricardo Lafosse, CISO, Kraft Heinz

2020 – Paige Adams, Global CISO, Zurich Insurance

2019 – Jill Rhodes, CISO, Option Care

2018 – Bradley Schaufenbuel, CISO & VP, Paylocity

2017 – Erik Decker, Chief Security & Privacy Officer, University of Chicago Medicine

2016 – Todd Fitzgerald, CISO, Grant Thornton International Ltd.

2015 – Kevin Novak, CISO and Technology Risk Officer, Northern Trust Bank

2014 – Arlan McMillan, CISO, Department of Innovation and Technology, City of Chicago

2013 – Jason Witty, CISO & SVP, US Bank


2022  - ENTERPRISE, Pat Blandford, Founder, CEO, Green Shield Risk Solutions & Tom Monahan, CEO, DeVry University

2022 - MID-CAP, Wells Hutchinson, CEO, Dental Delta Plans Assoc. & Tom Monahan, CEO, DeVry University

2021 – Bradley Alter, CEO, Certified Health Management and Sunil Cutinho, President, CME Clearing

2020 – Bob McGonigle, CEO, Martin Brower and Michael O'Grady, CEO, Northern Trust

2019 – Doug Kofoid, CEO, DialogTech and Tony Lorenz, CEO, PRA and Jo Ann Rooney, Pres., Loyola Univ.

2018 – Sharon O'Keefe, President, UCMC and John Walden, CEO, FTD

2017 – Anders Gustafsson, CEO, Zebra Technologies and Tom Richards, Executive Chairman, CDW

2016 – David Nelms, Discover Financial and Steve Lieber, CEO, HIMSS

2015 – Artur Fridberg, CEO, eboundhost and Dan Yunker, CEO, MCHC/LLH

2014 – Deborah Gage, CEO, Medecision and Rick Waddell, CEO, Northern Trust

2013 – none


Wayne Johnson, Founder 

Arlan McMillan, Head of Judges Committee and Co-Chair

Sally Martin, Head of Operations and Co-Chair

On behalf of the Program Committee, prior winners, nominees, partners, sponsors and the CISOs of the Chicago region, thank you for your participation in the Program.

Wayne Johnson, Founder



>April 1, 2023 - Nomination Process Opens

> - 5/30/2023 - Mixer #1 :  Florentine at the JW Marriott,  151 W. Adams St. Chicago, 5-8 PM (Tuesday)  Click Here to Register

>  6/20/2023 - Mixer #2: Gibson's Bar & Steakhouse, 5464 N. River Road, Rosemont, IL , 5-8 PM (Tuesday) 

> 7/25/2023 - Mixer #3:  Smith & Wollensky's Steakhouse, 318 N. State St., Chicago, IL 5-8 PM (Tuesday) 

> 7/30/2023 - Final date for Nominees to submit nominee their Application Forms

> 8/22/2023 - Mixer #4 :Raised Bar at Renaissance Hotel , 1 West Upper Wacker Drive, Chicago, IL,  5-8 PM (Tuesday)

> 9/9/2023 - Judges announce the names of the two finalists

>10/10/22 - Award Breakfast Ceremony - Event #5: In Person - Location: Union League Club of Chicago, 65 W. Jackson Blvd, Chicago, IL,  60604 -  Doors open at 7:30 am and the Ceremony begins promptly at 8:00 ends at 10 AM.  Please note that this event happens on Tuesday, the day following Columbus Day. 


It's a pleasure to offer out sponsors the best opportunity to meet Chicago area Chief Information Security Officers (CISOs) and Senior Information Security Practitioners in multiple settings!  As we all realize 2021 was a challenging year, but our plan is to return to all in person events in 2022.  You will meet many of the same CISOs multiple times throughout the course of the 6-month Chicago CISO of the Year Program.  As we all know, relationships build success.  The program is designed for our Sponsors to be able to communicate with CISO’s in great settings and as a way for CISOs to meet their Peers to grow their careers and network.

There are 5 events that make up the program sponsor year.  We have averaged about 100 people per event.  Significantly more people attend the last events in the program. We are limiting the number of sponsor participation to 11 for 2022.  As the year progresses we will be adding a couple more events like baseball games and/or round-tables. 

Please Thank Our 2023 Program Sponsors:




For detailed information on sponsor opportunities, contact:

Wayne Johnson (Founder and Sponsors Contact),


We have a tremendous group of partners in Infragard, AITP, ISSA, SIM, ISACA, WiSys and ChicagoFirst. We are very pleased to announce a new partner was added last year.

Given the circumstances this year, we expect to work much more directly with our partners to cross-promote through virtual events and ongoing chapter communications.  We will rely more than ever on partners to drive nominations and keep our communities collectively engaged.  We are interested in your ideas, so please don’t hesitate to reach out to Wayne Johnson, Arlan McMillan or Sally Martin with any questions or concerns.


While COVID-19 has introduced a world of uncertainty, we on the committee would like to think positively and are  dedicated to conducting an In-Person program this year in a way that our nominees, judges, event attendees, sponsors, and partners can do so safely and healthily. 

Thank you to everyone who makes this program and the Chicago CISO community great!  We look forward to another good year.

About the Program Partners

AITP Chicago

It is the mission of AITP Chicago to provide superior leadership and education in Information Technology.  AITP is dedicated to using synergy of Information Technology partnerships to provide education and benefits to our members and to working with the industry to assist in overall promotion and direction of Information Technology.

Information Systems Security Association (ISSA)

The Information Systems Security Association (ISSA) is a not-for-profit, international organization of information security professionals and practitioners. It provides educational forums, publications, and peer interaction opportunities that enhance the knowledge, skill, and professional growth of its members.


InfraGard is a partnership between the FBI and members of the private sector. The InfraGard program provides a vehicle for seamless public-private collaboration with government that expedites the timely exchange of information and promotes mutual learning opportunities relevant to the protection of Critical Infrastructure. With thousands of vetted members nationally, InfraGard's membership includes business executives, entrepreneurs, military and government officials, computer professionals, academia and state and local law enforcement; each dedicated to contributing industry specific insight and advancing national security.

ISACA Chicago

As an independent, nonprofit, global association, ISACA engages in the development, adoption and use of globally accepted, industry-leading knowledge and practices for information systems. Previously known as the Information Systems Audit and Control Association, ISACA now goes by its acronym only, to reflect the broad range of IT governance professionals it serves.

Society of Information Managers (SIM)

SIM brings together IT leaders to share, network and give back to their communities through the collaboration of local chapters.   SIM Chicago provides a unique opportunity to interact with thought leaders throughout the technology and business fields. SIM Chicago sponsors regular programs for members to network, hosts social and philanthropic events to enhance the community, and acts as a forum for business and technology leaders in partnership with peer executive organizations in Chicago.    


Women in Cybersecurity (WiCyS) is a 501c3 nonprofit organization with global reach dedicated to bringing together women in cybersecurity from academia, research and industry to share knowledge, experience, networking and mentoring.  The WiCyS Chicago Affiliate is Chicago CISO of the Year's newest partner, and we look forward to working together to raise awareness, opportunity and inclusion for women in (or aspiring to) the CISO role.


In 2020, the CotY committee announced a new partnership between ChicagoFIRST and the Chicago CISO of the year awards program. ChicagoFIRST is a nonprofit association that provides critical firms a collaborative forum to address private sector resilience and emergency management planning and response with relevant local, regional, and national public sector agencies. We look forward to collaborating with ChicagoFIRST  in the years to come.


2022 CISO of the Year Results - Click Here for Press Release


Walter Lefmann

CISO, Chicago Trading Corporation

Walter Lefmann is currently Director of Security at CTC Trading Group LLC, a capital markets trading firm. That role has included Information Security, Physical Security and Life Safety, Privacy, and BCP/DR.

He has been practicing cybersecurity with varying focus for his entire professional career. The balance has shifted back and forth over time between technology engineering/operations and security over the years, which has led to a well-balanced business-focused approach to security.

The professional journey to CTC came by way Goldman Sachs, Hull Trading Company, and Motorola, from an early career as an experimental physicist at the Fermi National Accelerator Laboratory. Walter holds a PhD, MPhil, and MA in Physics from Columbia University, and a BS in Physics from Stevens Institute of Technology.

While at Columbia University, Walter also served for five years as a volunteer NYC Auxiliary Police Officer and Sergeant. The experience of working closely with the public sector to serve and improve the community was tremendously rewarding and has shaped a lifelong respect for the dedicated people who face the challenges of that service!

Walter participates in many professional and public/private outreach organizations, including FBI InfraGard (currently serving as a Chicago Chapter board member), US Secret Service Cyber Fraud Task Force, Chicago FIRST, FS-ISAC, the National Technology Security Coalition, and ASIS.  Walter was a nominee for the 2020 Chicago CISO of the Year award program.

Outside of work, Walter is an avid scuba diver (even diving in Lake Michigan … yes, it’s COLD!), sings tenor in the Harper Festival Chorus community group, and dances with his wife whenever he can!


Mahmood Khan

SVP & CISO, CNA Insurance

Mr. Mahmood Khan is Senior Vice President and Global Chief Information Security Officer at CNA Financial (NYSE: CAN), one of the largest commercial property and casualty insurance companies in the U.S. with $10.8 billion in sales and 5,800 employees.

Mahmood joined CNA in 2020 in his current role, in which he oversees CNA’s global cybersecurity team responsible for the firm’s information security strategy, policy and programs. He developed and implemented a strategy to transform the company’s existing information security program, expanding it from 20 employees and a $20 million budget to an organization with more than 90 employees and a $65 million budget. He led all aspects of the recovery, containment and investigation efforts after a catastrophic ransomware cyberattack on the organization that had significantly affected operations. He also oversaw the creation of a next-generation virtual private network to enable and secure remote work operations during the pandemic.

Before joining CNA, Mahmood held the position of Managing Director of Cybersecurity Operations and Deputy Chief Information Security Officer at United Airlines (Nasdaq: UAL) from 2017 to 2020. He led a global team responsible for programs including industrial network visibility and active monitoring, threat intelligence, risk assessment and vulnerability management, application security, forensics, monitoring, incident response and more. In his first 90 days at the company, he created an intelligence-driven, risk-based adaptive three-year roadmap. He also managed a $25 million operating budget and a $40 million project portfolio.

Previously, he spent 10 years at Bank of America (NYSE: BAC), where he held several information security leadership roles from 2007 to 2017, most recently serving as Senior Vice President of Global Information Security. In this role, he led a global team that managed all aspects of enterprise application security and customer protection strategy. He developed and executed a long-term enterprise security strategy that aligned with Bank of America’s corporate strategic imperatives. Prior to this role, he served as Business Information Security Officer, Senior Manager of Enterprise Security Assessment. He joined Bank of America in 2007 as Head of Infrastructure Assessment.

He serves on the steering committee of the U.S. Secret Service’s Chicago Electronic Crime Task Force (C-ECTF) as well as the board of advisors for several security technology companies.

Mahmood holds a bachelor’s degree in Computer Information Systems from DePaul University and a master’s degree in Cybersecurity from Missouri State University.

Click Here for Selected Photos from the Awards Ceremony


2021 CISO of the Year Award

Ricardo LaFosse, CISO, Kraft Heinz Company

Mr. Ricardo Lafosse is the Chief Information Security Officer for Kraft Heinz.  He is responsible for IT risk governance, OT security, incident management, technical disaster recovery, and determining enterprise-wide security policies and procedures.  Ricardo routinely presents on security topics at global conferences, including Defcon, MirCon, ISACA,CACS and Secure World.

Prior to his current role, he was the Chief Information Security Officer for Morningstar, where he was responsible for providing strategic information security leadership, implementation, product security, and governance for the Information Security Program.

Ricardo was the inaugural CISO at Cook County Department of Homeland Security where he was tasked with building an entire security program from the ground up, which was instrumental to the success of the program and continues to be the cornerstone of the security program at Cook County.

Ricardo has more than 18 years of experience in information security for the manufacturing, government, banking, legal, healthcare and education sectors having begun his career in information security consulting in the financial sector. He started through local consulting, securing critical infrastructure at the Army Corp of Engineers, and advancing to his first CISO position for the 2nd largest County in the United States. He holds a Master's in Information Assurance from Iowa State University as well as the Certified Information Security Professional (CISSP) and Certified Information Security Manager (CISM) designations.


Upcoming Events

Visit to access research, communities, councils and philanthropy. 

© 2021 Association of Information Technology Professionals - Chicago Chapter

Terms of Use | Privacy Policy | Report an Issue

Powered by Wild Apricot Membership Software