How First Hawaiian Bank Cut Detection Time From Four Hours to Seven Seconds While Saving $1.5 Million

6 min read
(June 9, 2026)

At Gartner's Security and Risk Management Summit in National Harbor, one of the most memorable presentations did not focus on the latest security platform, the newest AI capability, or a vendor success story. Instead, Adam Palmer, CISO of First Hawaiian Bank, delivered something many security leaders rarely hear at industry conferences: a candid discussion about outcomes, leadership, governance, and the mistakes that can derail transformation efforts.

Palmer's story resonated because it addressed the realities most CISOs face. Boards want measurable risk reduction, CFOs want cost discipline, regulators want accountability and transparency, security teams want fewer manual tasks and better operational efficiency. The challenge is delivering all of those outcomes simultaneously.

At First Hawaiian Bank, Palmer and his team achieved remarkable results. Mean time to detect dropped from four hours to seven seconds. Mean time to resolve fell from four days to less than ten minutes. Seven security analysts were reassigned from manual operational work to higher-value activities. The bank consolidated multiple security tools and reduced operating expenses by approximately $1.5 million over three years. Yet Palmer repeatedly emphasized that those metrics are only meaningful because they improved business outcomes.


Building Around Outcomes Instead of Technology

One of the central themes of Palmer's presentation was that security transformation should begin with outcomes rather than technology.

Many organizations recognize tool sprawl, operational inefficiencies, or alert fatigue and immediately launch technology replacement initiatives. Palmer argued that this approach often produces disappointing results because it treats symptoms rather than root causes.

At First Hawaiian Bank, the transformation effort started by identifying what the business needed from security. Leadership wanted improved confidence in the security program, business units wanted security to support their objectives without creating unnecessary friction and the board wanted clearer visibility into risk and resilience.

Only after those outcomes were defined did the bank begin evaluating operational and technology changes. This approach ensured every investment could be connected directly to a business objective rather than justified solely through technical capabilities.

For CISOs, the lesson is important, technology decisions should follow strategic outcomes, not define them.

image0

Complexity Was the Real Risk

Palmer described an environment that will sound familiar to many CISOs. Over time, First Hawaiian Bank had accumulated a growing collection of security technologies. New risks generated new purchases, new requirements introduced additional vendors, different teams implemented solutions independently and the result was a fragmented environment with overlapping capabilities, increasing costs, and operational inefficiencies.

The challenge was not that any individual tool was necessarily ineffective, the problem was cumulative complexity. Security analysts were forced to navigate multiple dashboards and workflows, processes lacked consistency and visibility was fragmented. The security program had become increasingly difficult to manage as technologies accumulated over time. Reducing complexity therefore became a strategic priority.

image1

Palmer did not frame simplification as a cost-cutting initiative. The objective was operational effectiveness and cost savings followed because the organization became more efficient, not because efficiency was the primary goal. This distinction matters because the strongest security transformations are typically driven by business outcomes, with financial benefits emerging as a secondary result.

 

You Cannot Automate Chaos

Perhaps the most memorable phrase from the session was Palmer's warning that organizations should never automate chaos. Before introducing extensive automation and AI-driven workflows, the bank focused on foundational governance. Risk ownership was clarified, roles and responsibilities were defined, success criteria were documented and business stakeholders were engaged.

Palmer noted that when organizations introduce automation without addressing underlying organizational issues, they simply accelerate existing dysfunction. Poorly defined processes become faster poorly defined processes and unclear ownership becomes automated confusion. Technology magnifies weaknesses that already exist.

This insight is particularly relevant as organizations race to adopt AI-driven security capabilities. The temptation is to deploy automation quickly and sort out governance later. Palmer's experience suggests the opposite approach. Governance, accountability, and operational maturity should come first and automation should reinforce those foundations rather than compensate for their absence.

AI Proposes and Humans Decide

Although AI played a significant role in First Hawaiian Bank's transformation, Palmer rejected the idea that automation should replace human judgment. The bank adopted a simple operating principle: AI proposes and humans decide.

Automation accelerated investigation, triage, and response workflows. Activities that once required hours of analyst effort could be completed in minutes; however, human oversight remained central to decision making, particularly for higher-risk scenarios. This approach helped build trust among regulators, auditors, and internal governance teams. It also helped security analysts develop confidence in the new operating model.

Not every member of the security team initially embraced automation. Palmer openly discussed resistance from staff members who were uncomfortable with highly automated workflows. Training, communication, and change management became critical components of the transformation effort. Successful AI adoption is often more about people than technology.

Board Confidence Became the Ultimate Metric

One of the most interesting outcomes involved executive and board reporting. Prior to the transformation, security reporting relied heavily on technical metrics. Alert counts, tool performance indicators, and operational measurements dominated conversations with leadership. As the program matured, Palmer shifted the focus toward risk reduction, business resilience, and measurable outcomes. Operational metrics remained available, but they no longer served as the primary narrative.

The change produced tangible results which led to board members requesting fewer deep-dive reviews. Discussions increasingly centered on business decisions and organizational resilience and executive confidence in the security program increased.

For Palmer, this represented one of the clearest indicators of success. A security program ultimately exists to reduce business risk; reporting should therefore focus on demonstrating that outcome rather than showcasing technical activity.

The Role of Cyber Risk Quantification

One other element of the transformation was the adoption of cyber risk quantification. Palmer spoke enthusiastically about the value of discussing cybersecurity in financial terms rather than relying exclusively on qualitative assessments, the bank increasingly used quantitative measures to evaluate investment decisions and communicate risk.

This approach changed conversations with executives and finance leaders. Discussions became less about proving a security problem existed and more about evaluating how investments could reduce measurable business risk.

For CISOs attempting to secure funding for modernization initiatives, this may be one of the most valuable lessons from the presentation. Executive teams naturally understand financial language, quantifying cyber risk helps align security conversations with broader business decision-making processes.

image2What Did Not Work

One of the reasons Palmer's presentation stood out was his willingness to discuss failures. The organization initially approached the challenge as a technology problem. Leadership quickly discovered that the underlying issues were organizational and cultural rather than technical.

The bank also encountered challenges with staffing and adoption. Not everyone was comfortable with increased automation resulting in additional training and communication being required to build trust in the new model.

Vendor selection created another obstacle, some solutions operated as black boxes and could not provide sufficient transparency regarding how AI-driven decisions were made. For a regulated financial institution, that lack of visibility was unacceptable. Palmer's willingness to discuss these setbacks made the success story more credible.

image3Leadership Was the Differentiator

The headline metrics are impressive:

  • Detection times improved from four hours to seven seconds.
  • Resolution times fell from four days to less than ten minutes.
  • Seven analysts were reassigned to more strategic work.
  • Operating expenses declined by $1.5 million.

Yet those numbers are not the most important takeaway. The real lesson from First Hawaiian Bank's experience is that successful security transformation begins with leadership. Palmer's team succeeded because they focused on outcomes, clarified accountability, strengthened governance, communicated effectively with stakeholders, and maintained transparency throughout the process. Technology played an important role, but it was not the driver.

As security leaders face growing pressure to modernize operations and demonstrate business value, Palmer's framework offers a useful reminder. Start small. Scale smart. Govern carefully.

The organizations that succeed will not necessarily be those with the most advanced tools, they will be the ones that align people, processes, governance, and technology around clearly defined outcomes.

 

Slides Attributed to Adam Palmer