Three of the people on this list have held their current CISO seats for more than a decade, and one has led the same organization’s security program since 2005. Columbus has a way of keeping its security leaders. It also draws others in from much farther afield: a former Army law enforcement officer, a startup cofounder who once ran incident response out of Cincinnati, and a bank executive who spent part of his career recruiting CISOs before becoming one. Insurance, banking, higher education, state government, retail, and nonprofit research all draw from this capital city’s bench.
Tim Lyons – VP & CISO, Nationwide
Tim Lyons spent most of the 2000s building software before he was put in charge of securing it. At Nationwide Financial, he led a team of more than 350 developers working on internet, call center, data warehousing, and eB2B applications. He later became Vice President of Integrated Application Services, overseeing more than 475 IT associates and an annual budget above $70 million. Along the way, Lyons served as the sales organization’s technology liaison, reporting to the President of Sales, and he co-chaired the NAVA technology committee’s work on straight-through processing in the variable annuity industry. In 2009 he launched the Nationwide Development Center, an internal startup effort to centralize major application development across the enterprise. He became Nationwide’s VP and CISO in October 2012 and has held the role for 14 years.
Navpreet Jatana – EVP & CISO, Huntington National Bank
For about a year in the early 2010s, Navpreet Jatana recruited CIOs and CISOs for a living. As Managing Director of a regional staffing firm in Buffalo, he grew its Technology Search Practice. He then moved into the security leadership pipeline himself as Director of Enterprise Information Security at Highmark Blue Cross Blue Shield of Western New York. From there, Jatana became SVP of Enterprise Information Security and Deputy CISO at Zions Bancorporation in Salt Lake City, leading 14 teams of cybersecurity professionals. He later worked on the vendor side, first as an Advisory CISO at Palo Alto Networks advising executives at the company’s largest financial services and healthcare clients, and then as Principal Advisor at the startup Seemplicity. He became EVP and CISO of Huntington National Bank in 2024, protecting a Columbus-headquartered institution with more than $290 billion in assets and over 1,400 financial centers. Until late 2025, he also coached youth basketball for fifth through eighth graders, a role he describes as “voluntold.”
Rich Nagle – AVP & CISO, The Ohio State University
Rich Nagle was named CISO of the Year at the OhioCISO ORBIE Awards for protecting more than 100,000 students, faculty, researchers, clinicians, patients, and staff across Ohio State’s statewide enterprise. His security career at the university began in identity work. He joined Ohio State in 2015 as Associate Director of Identity and Access Management, leading the Identity Management and Shibboleth teams. In 2018 he became the university’s first Deputy CISO, overseeing security intelligence, endpoint security, and intrusion detection and incident response. He stepped in as interim CISO in February 2021 and took the role permanently that September. Under his leadership, the team created a disaster recovery program for the entire university and launched a new Information Security and Privacy Assessment now used by all 20 Ohio State colleges and administrative functions. Before Ohio State, Nagle spent more than 12 years at JPMorgan Chase in Columbus, moving from Associate to Director.
Kevin Arnold – CISO, Ohio Public Employees Retirement System
Kevin Arnold has led information security at the Ohio Public Employees Retirement System since 2005, a tenure now past 20 years. Before OPERS, he was Global Security Officer at Greif, where he managed the full information security effort for a distributed, multi-billion-dollar worldwide company. He also worked as a Manager in PricewaterhouseCoopers’ Technology Risk Services practice. His technical background covers firewalls, vulnerability management, computer forensics, and mainframe access control through RACF.
James Matheke – CISO, Ohio Department of Developmental Disabilities
An electrical engineer by training, James Matheke holds a master’s degree in the field from The Ohio State University. He has spent more than two decades in Ohio state government. He joined the Ohio Department of Job and Family Services in 2004 as Assistant Section Chief and then worked there as a Security Architect for nearly nine years. In March 2014 he became CISO of the Department of Developmental Disabilities, where he has built the agency’s security governance framework and its incident detection, response, and recovery capability. Matheke holds CISSP, CISM, CRISC, and COBIT 5 certifications.
Brian Klenke – CISO, Bath & Body Works
Brian Klenke began his career as an interaction designer at a software company before moving into network security administration for the Clermont County, Ohio Board of Commissioners. His intelligence work came next. At General Electric, he spent five years as a Cyber Intelligence Lead Analyst on a team focused on intellectual property protection and counter-espionage, followed by a stint as a Senior Cyber Intelligence Analyst at Lockheed Martin. In 2013 he cofounded Morphick in Cincinnati and led the company’s incident response practice. He then joined Booz Allen Hamilton, first as Vice President leading its Managed Threat Services portfolio and then as the firm’s CISO. Klenke became CISO of Columbus-based Bath & Body Works in July 2021.
Anthony Fisic – CISO, Battelle
Anthony Fisic served more than 20 years in the US Army as a law enforcement and cyber officer before entering corporate security in 2014. He managed global information security at HNI Corporation in Iowa and then at Libbey in Toledo, where his scope included governance and compliance. He moved to Columbus in 2017 as Executive Director of Global Security and CISO at OCLC. Since August 2022, Fisic has been CISO of Battelle, the world’s largest nonprofit research and development organization. His portfolio at Battelle covers work in national security, health, energy, and the environment. He co-chairs CDO Magazine’s Columbus Executive Board, sits on the publication’s Global Editorial Board, and serves on Evanta’s CISO Governing Body.
Staying Power in the State Capital
Columbus rewards patience. Lyons has spent more than a quarter century at Nationwide, Arnold has run OPERS security for over two decades, and Matheke has never left Ohio state government. Nagle built his career entirely in Columbus, first at JPMorgan Chase and then at Ohio State, where he rose through identity management into the top job. The newer arrivals took longer routes. Fisic came through two decades of Army service and three Midwestern manufacturers, Klenke through intelligence work and a startup of his own, and Jatana through three states, two vendors, and a recruiting desk. The city holds its homegrown leaders for decades and still manages to attract seasoned ones from elsewhere, and that combination gives its security bench unusual depth.
Discover more CISOs securing their organizations:
- Indy’s CISO Bench: Leaders to Watch
- The Inner Harbor’s CISOs to Watch
- Guarding the Peach State: Atlanta’s Security Leaders to Watch
- Securing the Capital Region: CISOs to Watch in the DMV
- Guarding the Steel City: Pittsburgh’s Security Leaders to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

