About this program
How Exceptional Technology and Security Executives Think, Decide, Lead, Adapt, and Build.
The thesis
The CEO thesis holds: there is a recognizable executive temperament and no universally successful personality; effectiveness is multiplicative — Traits × Behaviors × Organizational Context × Current Moment. Three things change for the technology and security executive:
- Structural position is a term of the equation, not a footnote. A CEO's discretion is broad by default; a CIO's or CISO's is set by someone else — the reporting line, the budget process, the board's committee structure, the regulator. RESEARCH FINDING CIO reporting structure is associated with firm performance conditional on strategy (Banker, Hu, Pavlou & Luftman, 2011); CIO decision-making authority depends on structural power and the CIO–top-team relationship (Preston, Chen & Leidner, 2008; Karahanna & Preston, 2013). The Fit Equation becomes: Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line = CIO/CISO Fit.
- The job is to price risk, not to eliminate it. The elite CISO is not simply risk-averse — the same logic as the bank CEO in the CEO course. Security spending has an economically optimal level well below "everything" (Gordon & Loeb, 2002); breaches have measurable but bounded market costs that depend on type and context (Campbell et al., 2003; Cavusoglu et al., 2004; Kamiya et al., 2021). The signature disposition is "enablement with institutional paranoia" — a description, not a diagnosis.
- The information environment is the asset. A CEO fears being told what they want to hear; a CISO's entire function depends on people reporting the click, the misconfiguration, the near-miss. Security culture research and Edmondson's error-reporting work make psychological safety a control, not a nicety.
A mature technology executive can say both "We're going to do this." and "I was wrong. Change the plan." The CISO edition adds the Risk Corollary — two sentences every security leader must be able to say to a CEO:
- "Yes — and here is the risk we are accepting, priced."
- "No — and here is what would change my answer."
A CISO who can only say "no" is a control; a CISO who can only say "yes" is a liability. Both sentences require a priced view of risk and the standing to state it.
How to read this program
Every consequential claim carries one of five epistemic labels, rendered as tags. The rule for authors: no statistic without a citation; no citation without an entry in the Research Library; no “studies show” without naming the study.
Archetypes are educational lenses, not categories. The assessment reports tendencies you currently display, never a type. The simulator has no correct answers. All companies in examples and simulations are fictional composites — the five leaders and four cases in the Leaders section are the exception, and every fact about them is cited on the page.