Meet the new Citrix Field CTOs for financial services and insurance
Financial services and insurance (FSI) institutions face an unprecedented trifecta: evolving regulatory requirements, rising cloud and infrastructure costs, and pressure to innovate securely. Navigating this complex landscape requires more than just vendor tools—it demands strategic guidance from seasoned FSI leaders.
To help FSI leaders meet these challenges, Citrix is introducing Rush Blevins and Nathan O'Reilly as Field Chief Technology Officers for financial services and insurance.
Rush, our Americas-based Field CTO, brings over 25 years of experience in consumer finance, including IT and security transformations at Santander Consumer USA and Flagship Credit Acceptance.
Nathan, our Europe-based Field CTO, brings over 30 years of experience leading global desktop transformation, end-user computing collaboration, and digital programs at global institutions including HSBC and Citigroup.
In this conversation, Rush and Nathan discuss how FSI technology leaders can strengthen operational resilience, improve productivity, and reduce operating costs to fund innovation.
Strengthening operational resilience and regulatory compliance in modern banking
Q: Splunk’s 2024 research put the annual cost of downtime for financial services companies at $151M. How should FSI technology leaders approach operational resilience?
Rush Blevins: Traditional disaster recovery plans are often more of a compliance checkbox for auditors than a pragmatic solution for today’s rapidly expanding failure points. My approach is to identify vulnerabilities across the technology stack, start with the highest-risk areas, and build resilience that matches the institution’s risk tolerance.
Endpoint recovery is an important part of that plan. A failed OS update or cyber incident can leave employees unable to use their laptops. A modern resiliency strategy addresses this directly using solutions like Citrix UniconOS—an immutable, read-only Linux-based OS that runs natively or alongside Windows. If the primary OS is corrupted, employees can instantly boot into Citrix UniconOS, launch a secure browser for SaaS apps, or access virtual desktops to maintain continuous operations.
Q: Global institutions operate across multiple jurisdictions with complex compliance landscapes. How can leaders streamline regulatory posture without adding friction to daily operations?
Nathan O'Reilly: Having led enterprise-wide digitization and compliance programs at Citi and HSBC, I found that consistent global standards are essential. Centralized management and session recording can help provide evidence for audits while maintaining operational efficiency.
However, satisfying modern mandates like the Digital Operational Resilience Act (DORA) or the NIS2 cybersecurity directive requires granular, real-time visibility across the entire workspace ecosystem. This is where Citrix Experience Insights becomes critical and delivers deep telemetry, actionable analytics, and compliance-centric reporting that satisfies strict auditor requirements. But visibility alone isn't enough; it must translate into active policy enforcement.
Combining observability with policy controls on a unified platform can help FSI institutions reduce the number of tools they manage and support consistent compliance processes. Clear processes and trusted tools matter whether the environment is on-premises, hybrid, or in the cloud.
Reducing operating costs to fund AI and innovation
AI investment, public cloud costs, and day-to-day IT support put pressure on FSI budgets. Leaders need to make room for innovation while managing the cost of running the business.
Q: How can FSI institutions fund AI and digital initiatives while controlling operating costs and maintaining the capabilities they need?
Nathan O'Reilly: Start with vendor consolidation and centralized application management. By replacing fragmented point solutions, you can avoid complexity, reduce support desk ticket volume, and redirect capital toward AI governance and innovation. For example, when I spearheaded Citi's Robotic Process Automation (RPA) deployment for retail customer support, it delivered massive operational expenditure reductions and significantly enhanced the user experience.
Q: How does hybrid cloud modernization factor into cost containment and infrastructure agility?
Rush Blevins: In my experience migrating core infrastructure at Flagship Credit Acceptance, hybrid cloud modernization requires balancing operational agility with Total Cost of Ownership (TCO). While certain workloads remain materially cheaper on-premises, cloud hosting can win on overall TCO when you factor in reduced support costs, streamlined licensing, and consumption models. It gives IT the agility to scale instantly without the long runways traditional infrastructure demands.
To accurately predict the cost impact, a critical step is a granular workload analysis before making a move. For end-user environments, observability tools can give us exact telemetry into persona behavior—revealing whether an employee is purely browser-based or running heavy processing software, like a developer. When you pair this deep visibility with Citrix DaaS Flex—where you only pay for what you actually consume—institutions can eliminate massive compute and licensing waste to free up capital for high-value innovation.
Improving productivity and security in FSI
Persistent latency and application lags across fragmented back-end systems degrade productivity and drive-up support desk tickets. Simultaneously, endpoint proliferation and API sprawl are continuously expanding the attack surface, increasing both security and regulatory risks in FSI.
Q: Security and end-user experience often seem to be in tension. How can FSI security teams achieve top-tier security standards without frustrating employees or worsening latency?
Rush Blevins: As a CIO, I focused on strengthening security while improving the employee experience. We had no cyber incidents and earned top ratings from our cyber insurance brokers while maintaining monthly IT support satisfaction between 98% and 100%. I recommend solutions that use zero trust principles and device and browser context to evaluate access and enforce data loss prevention policies in the browser, with less friction for employees.
Centralization is equally crucial; every CIO and EUC leader should aim to minimize the time spent touching physical endpoints. Reducing the number of failure points across endpoints directly slashes support effort, minimizes downtime, and accelerates recovery. By pairing Citrix SecurAccess ZTNA and enterprise browser capabilities with other Citrix solutions like Citrix deviceTRUST, Citrix UniconOS, and application delivery technology from Numecent, institutions can create a more low-touch, highly secure workspace environment.
Q: From retail branch staff to wealth advisors and contact center agents, FSI personas have distinct needs. How did desktop transformation at scale impact workplace productivity and security in your past roles?Nathan O'Reilly: When I led HSBC’s global desktop transformation, we leveraged cloud, automation, and virtualized desktops to modernize the workspace for tens of thousands of users. Standardized, low-latency workspaces consistently accelerate task completion for branch staff, insurance claims processors, and third-party contractors while maintaining strict data loss prevention (DLP).
With Citrix Platform Flex, you can match workspaces to employees’ needs and use observability and control to support that choice. A better employee experience can also help reduce support requests and the cost of managing workspaces.
For instance, at Citi, we sold a development wing, but our staff still needed to provide a critical function. When we met the app and data needs of the staff in a safe, user-friendly and compliant way, it had a very positive impact on staff morale and productivity.
Today, complex scenarios like this can be managed entirely in policy. By using the right automation solutions and policy controls, you can provide a restricted, controlled workspace environment that hides anything the user doesn't need to see.
Practical advice for FSI technology leaders
Rush and Nathan recommend three priorities for FSI technology leaders:
- Shift from reactive recovery to continuous operations: FSI leaders must now treat operational resilience as an ongoing architecture parameter rather than a traditional off-site backup plan.
- Consolidate to innovate: Streamline tool sprawl across NetOps, EUC, and SecOps to unlock the capital needed to fund critical AI and digital banking initiatives.
- Seamless productivity and governed security: Streamline application and workspace delivery across fragmented FSI legacy systems to eliminate performance lags while maintaining tight, governed security controls over endpoints and APIs.
Connect with Rush and Nathan
Ready to strengthen resilience, improve security, and make room for innovation?
Connect with Rush and Nathan on LinkedIn to discuss your priorities and arrange a one-on-one strategy session.
Explore Citrix solutions for financial services and insurance.