{"content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "modules": [{"id": "m01", "slug": "why-cios-and-cisos-arent-normal-either", "title": "Why CIOs and CISOs Aren't Normal Either", "unit": "I. The Technology Executive's Mind", "big_idea": "Technology leaders are selected for a different temperament than CEOs — and the CISO is selected for a temperament the CEO's own optimism will fight.", "effectiveness_equation_term": "Traits", "learning_objectives": ["Contrast the CEO temperament (optimism, risk tolerance, agency) with the dispositions the CIO and CISO roles select and reward.", "Explain why the CISO's structural role creates a built-in tension with the CEO's optimism, and how mature technology executives manage it with the Risk Corollary.", "Distinguish 'CISOs tend to be X' from 'X makes a good CISO', and say plainly where the evidence on technology executives' temperament is thin.", "Describe the selection filters — self-selection, promotion out of engineering, executive appointment, breach survival — that make the CIO/CISO population unrepresentative."], "sections": {"core_lesson": "The CEO edition opened with an uncomfortable fact: the people who become CEOs are a filtered population, and the filters select for temperament — optimism, risk tolerance, a strong sense that one's own actions decide outcomes — long before they select for results. This module makes the same argument about CIOs and CISOs, with one twist: the technology executive is filtered by different sieves, toward a different temperament, and then placed in a room with the CEO the first set of sieves produced.\n\nThree claims follow. First, the CIO and CISO populations are as unrepresentative of capable adults as the CEO population, but in a different direction — the CISO in particular is selected for a disposition we call, descriptively, **enablement with institutional paranoia**. Second, the tension between a CEO paid to believe and a CISO paid to imagine failure is structural, not personal; it exists whoever holds either chair, and the mature technology executive manages it with the Risk Corollary. Third, the evidence on technology executives' temperament is thin — no psychometric study of CIOs or CISOs exists in our library — so most of what this module says about disposition is labeled hypothesis, and anyone who tells you otherwise is selling something.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on the **Traits** term: what the typical technology executive's profile looks like, how it got that way, and why the base rate is a description of who survived, not a prescription for who to become.", "big_idea": "**The CEO is selected to believe; the CISO is selected to doubt; the CIO is selected to build — and the same company needs all three to be right at once.**\n\nA CEO's optimism is not a flaw to be corrected by the security function, and a CISO's skepticism is not a personality problem to be managed by the CEO. They are the outputs of different filters, installed in the same building because the company needs both a reason to move and a reason to check. The combined CIO/CISO — the normal case below a billion dollars of revenue — has to hold the builder's belief and the risk officer's doubt in one head, which is why this edition exists.", "research": "### The CEO base rate, from the CEO library\n\n**RESEARCH FINDING.** Graham, Harvey and Puri (2013, from the CEO library) administered validated psychometric instruments to a large survey of CEOs and CFOs of public and private firms. CEOs scored markedly more risk-tolerant and more optimistic than population norms; roughly 80% of US CEOs were classified \"very optimistic,\" against roughly 65% of CFOs, and those traits were associated with more acquisitions and more short-term debt. What it supports: the person a CISO reports to, directly or at one remove, is very probably drawn from a population unusually inclined to believe things will work out. What it cannot: anything about CIOs or CISOs, who were not surveyed, or any causal claim — the design is cross-sectional and self-reported.\n\n### What the CISO literature actually contains\n\n**RESEARCH FINDING.** Ashenden and Sasse (2013) conducted five in-depth interviews with CISOs, who described their obstacles as \"a perceived lack of power, confusion about their role identity, and their inability to engage effectively with employees\"; the authors argued CISOs must build credibility through communication and engagement so that security becomes \"business as usual\" rather than a specialist function. Five interviews, UK, 2013: illustration, not measurement — but the role's influence problem described from inside it.\n\n**RESEARCH FINDING.** Maynard, Onibere and Ahmad (2018), in a systematic literature review, concluded that \"there has been little emphasis on understanding the role of the CISO as a strategist\" and proposed a competency set for the CISO as strategist. A framework-level contribution; nobody has tested whether those competencies improve outcomes. Peer-reviewed research has also examined CISO appointments and reporting positions in relation to breach events (Karanja, 2017); our bibliography could not retrieve the abstract, so no finding from it is cited here.\n\n**RESEARCH FINDING (Tier 3, practitioner survey).** IANS Research and Artico Search (2026) surveyed more than 600 security leaders: 47% of CISOs held EVP/SVP-level titles; 64% reported to IT leaders (CIO or CTO) and 36% to non-IT leaders such as the CEO, COO, general counsel or chief risk officer; 52% said their responsibilities were \"not manageable given current resources\"; 69% were \"open to changing jobs within the next year.\" A self-selected survey from vendors with a commercial interest in the CISO market, without response-rate information. Base rates only.\n\n### Why context bounds the technology executive\n\n**RESEARCH FINDING.** Peppard (2010), from interviews with CIOs, executives and commentators, argued that CIO performance is largely a function of organizational context — above all \"the IT savviness of the CEO and the leadership team\" — and that blaming CIOs for disappointing IT returns misplaces accountability. Interview-based, no outcome data; cite it for the framing.\n\n**RESEARCH FINDING.** Preston, Leidner and Chen (2008), the practitioner-facing companion to Preston, Chen and Leidner (2008), crossed a CIO's strategic decision-making authority with strategic leadership capability to define four profiles — IT Orchestrator (high/high), IT Advisor (low authority, high capability), IT Mechanic (high authority, low capability) and IT Laggard — and reported that IT's contribution to firm performance varied with the profile. Survey-based, cross-sectional, perceptual. What it supports: effectiveness depends on the match between granted authority and brought capability; capability without authority is a recognized under-performing profile.\n\n**RESEARCH FINDING.** Haislip, Lim and Pinsker (2021), using reported breaches from 2005 to 2017, found that CEOs with IT expertise were associated with fewer reported data security breaches, that a CIO on the top management team was \"significantly associated with reduced DSBs of all types examined,\" and that CFOs with IT expertise were less likely to report breaches. Reported breaches only; associations. No single appointment is shown to cause fewer breaches, and the CFO finding warns that \"fewer reported breaches\" can mean fewer reports.\n\n### Personality × Power, from the CEO library\n\n**RESEARCH FINDING.** Hambrick and Finkelstein (1987, from the CEO library) introduced managerial discretion — the latitude of action available to an executive — as the variable that decides how much an executive's characteristics matter; Hambrick (2007) added that heavy job demands increase reliance on heuristics and dispositions. Li and Tang (2010), surveying 2,790 Chinese manufacturing CEOs, found hubris associated with more firm risk taking, markedly more so where discretion was greater. What it supports: traits become visible in outcomes in proportion to the power the holder has — for the CISO usually low, and in an incident suddenly high.\n\n### Where the evidence is weak\n\nAlmost everywhere. There is no psychometric study of CIOs or CISOs in this library; the closest CEO-library evidence, Kaplan and Sorensen's (2021) 2,603 assessments of candidates for CEO, CFO, COO and other top roles, shows the C-suite is not one population but does not break out technology roles. The CISO literature is a five-person interview study, a literature review, a paper whose abstract we could not retrieve, and a vendor survey; the CIO literature is stronger on structure than on disposition. Every statement here about the temperament the roles select is therefore a **HYPOTHESIS** built from the filters and from the CEO evidence by analogy. What the evidence does establish is negative and important: the CEO population is unusually optimistic and risk-tolerant, and the technology executive works for it.", "explanation": "### Start with the CEO base rate, because it is the CISO's problem\n\n**INTERPRETATION.** You are not the CEO. You work for one, and the CEO you work for is, on the best evidence available, more likely than four out of five ordinary people to believe the plan will work (Graham, Harvey & Puri, 2013). That disposition was selected for; it is why there is a company for you to secure; and it is the single most important feature of your operating environment, because your job — half of it, if you hold both — is to say what could go wrong to a person constitutionally inclined not to hear it.\n\nNothing about that is personal. A CISO who experiences the CEO's optimism as a character flaw has misread a base rate as a biography; a CEO who experiences the CISO's doubt as obstruction has done the same in reverse.\n\n### The filters that produce a technology executive\n\n**FRAMEWORK.** The CEO edition described three stacked filters — who wants the job, who gets promoted toward it, who the board picks. The technology executive passes through four, and each prefers a temperament.\n\nThe first is self-selection into technology. **HYPOTHESIS.** People who spend their twenties with systems tend to like problems that have answers and prefer being right to being liked; security adds people who enjoy thinking about how things break, a specific and slightly unusual pleasure. The second is promotion out of engineering: the best engineer gets the team-lead job, and at each step the organization selects on technical performance while the job it is filling requires something else — the Player → Coach transition, where many technology careers mature or stall.\n\nThe third is executive appointment, where the paths diverge. **INTERPRETATION.** A CIO is usually appointed to build something and chosen for the builder's disposition: agency, optimism, comfort with capital. A CISO is often appointed in response to something — a near-miss, a regulator's letter, a peer's breach. Peer-reviewed research has examined CISO appointments in relation to breach events (Karanja, 2017); we cannot quote its findings, but a role created under threat and staffed for vigilance selects a different temperament than a role created to ship.\n\nThe fourth is survival. In a practitioner sample, 69% of CISOs were open to changing jobs within the year and 52% called the job unmanageable with current resources (IANS, 2026 — Tier 3). Churn is a filter: what remains is the temperament that can tolerate being responsible for outcomes it does not fully control.\n\n### The temperament the roles select — a hypothesis, labeled\n\n**HYPOTHESIS.** For the CIO: high agency, high uncertainty tolerance, a systems view, optimism about what technology can do, and a builder's impatience — closer to the CEO temperament than any other C-suite role except perhaps the COO. For the CISO: vigilance, a default toward skepticism, comfort with being the least popular person in the room, tolerance for ambiguous evidence (was that alert nothing, or the first thing?), and a conscientiousness that borders on the compulsive. The combined CIO/CISO — the normal case below a billion dollars of revenue and the universal case in the MSP and vCISO world — is asked to have both.\n\n**FRAMEWORK.** On the Trait Dial these are defaults, not settings: the CIO default sits toward optimism, aggression and urgency; the CISO default toward skepticism, caution, inquiry and operational discipline, and on this edition's overlay dials toward control and prevention. Module 6 is about turning the dials; this module is about knowing where they start.\n\nThe CISO disposition has a name in this course: **enablement with institutional paranoia** — the counterpart to the bank CEO's \"ambition with institutional paranoia\" in the CEO edition, and like it a description, not a diagnosis. Enablement is the half that says yes; institutional paranoia assumes the adversary is already inside and the control that worked last quarter is the one being probed now. A CISO with only the second half is a control. A CISO with only the first is a liability.\n\n### The built-in tension, and the tool for it\n\n**INTERPRETATION.** Put the selected CEO and the selected CISO in a budget meeting. The CEO asks, with the sincerity of a person for whom things have generally worked out, why the new client cannot go live next week; the CISO explains, with the sincerity of a person who has read the incident reports, why it cannot. Neither is wrong about their own job. The meeting fails because each treats the other's disposition as a position to be argued out of.\n\n**FRAMEWORK.** The Risk Corollary is the way out and the closing device of every module in this edition. A mature technology executive can say both: \"Yes — and here is the risk we are accepting, priced.\" And: \"No — and here is what would change my answer.\" The first converts the CEO's optimism into an informed bet with a named owner. The second converts the CISO's skepticism from a wall into a door with a price on it. Both require a priced view of risk (Module 3) and the standing to state it (Module 10). Neither requires the CISO to become an optimist or the CEO a pessimist. The tension stays; it becomes productive.\n\n### Personality × Power for the technology executive\n\n**INTERPRETATION.** Traits need power to be visible: a disposition shapes outcomes in proportion to the discretion the situation grants (Hambrick & Finkelstein, 1987). A CEO's discretion is broad by default. A CIO's or CISO's is set by someone else — the reporting line, the budget process, the board's committee structure, the regulator. Ashenden and Sasse's (2013) CISOs named \"a perceived lack of power\" as their first obstacle; Preston, Leidner and Chen (2008) named the mismatch: the IT Advisor, capable without authority. Hence the extra term in this edition's Fit Equation. **FRAMEWORK.** Industry × Scale × Lifecycle × Strategy × Governance × Problem × **Reporting Line** = CIO/CISO Fit. Two executives with identical temperament and capability produce different outcomes depending on whether the reporting line lets their judgment reach the decision.\n\nDiscretion spikes at two moments: the incident, when for the hours a breach is live the CISO has more real authority than anyone in the building — and Li and Tang's (2010) finding that hubris expresses itself most where discretion is greatest belongs in the war room (Module 4); and the budget cycle after a peer's breach, when the CEO briefly becomes a pessimist. Hambrick (2007) adds that heavy job demands push executives toward heuristics and dispositions: if half of CISOs call the job unmanageable, half are operating in exactly the conditions under which default settings run the show.\n\n### \"CISOs tend to be X\" versus \"X makes a good CISO\"\n\n**INTERPRETATION.** Everything above describes who survives the filters. None of it is evidence that the surviving temperament produces better security. \"CISOs tend to be skeptical\" is a base rate; \"skepticism makes a good CISO\" is a causal claim with no study behind it. The closest the library gets — a CIO on the top team is associated with fewer reported breaches (Haislip, Lim & Pinsker, 2021) — is a finding about structure, not disposition, and about reported breaches, which the same paper's CFO result shows can fall because reporting falls.\n\nVisibility compounds the confusion. The CISOs the public knows are almost without exception the ones whose companies were breached in the press; the CIOs the public knows ran famous transformations. **Visibility ≠ prevalence; visibility ≠ effectiveness.** The quiet operator who priced risk correctly for fifteen years is invisible by construction. Do not build your model of a good technology executive from the ones you have heard of.\n\n### What to do with the base rate\n\n**FRAMEWORK.** Locate yourself on the Maturity Model — Temperament → Capability → Maturity → Fit — honestly at level one. Temperament is what the filters left you with, it is mostly not trainable, and it is the source of every rung on the Overuse Ladder you will climb: institutional paranoia climbs skepticism → cynicism and caution → paralysis; the builder's optimism climbs optimism → delusion and urgency → recklessness. Judge yourself against the filtered population: a CISO who is \"cautious\" relative to the people who become CISOs is very cautious indeed. And notice which job you are in. In the MSP and SMB world the technology executive is a Player by necessity, and the dominant danger is not overuse of a trait but insufficient action and no second opinion — in an environment where, in the 2025 DBIR sample, ransomware was present in 88% of SMB breaches (Verizon, 2025 — Tier 3, non-random contributor sample).", "example": "*Fictional composite.* Harbor Line Business Services is a business-process and managed-services firm in Stamford, Connecticut: founded in 2019, $16 million in revenue, 120 employees, about 85 clients across registered investment advisers and small broker-dealers, medical and dental groups, law and accounting firms, and regional retailers in Connecticut, Massachusetts and the Hudson Valley. Roughly 40 clients buy a fractional CISO service on top of managed IT. The founder and CEO, Rob Castellano, came up in enterprise software sales and is, by his own cheerful description, \"a yes person.\" The CIO and CISO is one person, Elena Marsh, a former network engineer and service-delivery lead who joined in 2021 as the firm's first technology executive.\n\nIn March, Castellano signs the firm's largest healthcare client to date: a nine-location orthopedic group with 340 staff, a vendor-hosted electronic health record, and a departing IT contractor who has given three weeks' notice. Castellano has told the group's CEO that Harbor Line will \"take over on the first of the month\" — in nineteen days.\n\nMarsh's onboarding baseline takes six weeks: identity audit, MFA enforcement, endpoint agents, backup verification, and a review of every vendor with access to patient data. A nineteen-day takeover means Harbor Line inherits administrative credentials it has not reviewed, on devices it has not seen, under a business associate agreement that puts Harbor Line's name second on any breach.\n\nThe conversation that follows is the module in miniature. Castellano's position is sincere: the client is bleeding, the contractor is leaving, and a firm that cannot start when a client needs it is not a firm he wants to run. He is not being reckless. He is being a CEO. Marsh's first instinct — she notices it, which matters — is to say it cannot be done, in a tone that ends the meeting. That is the CISO default: skepticism, caution, and the comfort of being the person who said no.\n\nShe does something else. She takes two hours, prices it, and comes back with both sentences.\n\n\"Yes — we can take over on the first, and here is the risk we're accepting. For four weeks we'll be operating on credentials and devices we haven't verified, at a HIPAA-covered entity, on a stack whose last owner is leaving. What goes wrong in that window is an inherited admin account being used, or a backup that doesn't restore. I'd put the chance of a material incident in those four weeks at something like one in twelve, against roughly one in fifty once the baseline is done. The cost if it lands is the group's notification obligations and ours, and probably the contract. I need the client's CEO to sign that acceptance in writing, in those words.\"\n\n\"And here is what would change my answer to a clean yes: three things before the first. Reset every administrative credential the day the contractor leaves, enforce MFA on the EHR and email that week, and test-restore one server before we touch anything else. Five working days, and I need the contractor's cooperation for the first one.\"\n\nCastellano takes the second version to the client. The client's CEO, who had never been told what a takeover involves, signs the acceptance, funds the five days, and — because Marsh's numbers were ranges rather than a wall — asks what it would cost to have the whole baseline done in three weeks. The answer becomes a paid accelerated-onboarding tier that Harbor Line now sells.\n\n**INTERPRETATION.** Nothing about Marsh's temperament changed. Her skepticism reached the decision as a price rather than a refusal, and the CEO's optimism reached the client as a bet with a named owner rather than a promise. The filters produced two people who would always disagree about the first of the month; the Risk Corollary let them disagree usefully.", "ceo_contrast": "Put three archetypes in Marsh's chair, facing the same nineteen days.\n\n**The Technical CISO** says no, and says it well. Six weeks is what the work takes; a takeover on unverified credentials at a covered entity is not a risk to be priced but a mistake to be prevented. The gain is real: if the inherited environment is as bad as most are, the Technical CISO has kept Harbor Line's name off a breach notification. The cost is that the decision never reaches the client as a choice, Castellano hears a wall rather than a price, and next time he asks the account manager instead. Ashenden and Sasse's (2013) \"perceived lack of power\" is often self-inflicted this way: power only ever used to refuse is power the organization learns to route around.\n\n**The Business-Risk CISO** says yes and prices it — but the temptation is to price it to the CEO's liking, with ranges becoming point estimates that land where the deal closes. The gain is the deal and a CEO who thinks of security as an enabler. The cost is that \"yes as identity\" slowly under-prices every risk, and the day the inherited admin account is used, the acceptance turns out to have been priced by someone who wanted to be liked. Enablement without institutional paranoia is a liability with good manners.\n\n**The Enterprise CIO**, dropped into a 120-person MSP, reaches for governance: a steering committee, an onboarding policy with an exception process, a risk register the client's board can review. Each instrument is right at 5,000 people and wrong at 120, where the exception process is a conversation and the risk register is Marsh's notebook. The gain is the mechanism Harbor Line will need at 500 people; the cost is that the nineteen days pass while it is designed. This is Module 8's \"enterprise CIO in a 40-person company\" mismatch, seen from the client's side.\n\nMarsh's path — priced yes, conditional no, both in writing — is available to all three. None of their defaults lands there without effort.", "failure_mode": "The technology executive's temperament fails in two opposite directions, and the Overuse Ladder describes both.\n\n**INTERPRETATION.** The CISO side climbs **skepticism → cynicism** and **caution → paralysis**. Skepticism, the trait that finds the misconfiguration everyone else missed, becomes a reflexive assumption that every request is a threat. Caution, the trait that insists on the test restore, becomes the CISO who is never breached because nothing is ever deployed. Rigor climbs to bureaucracy — the security review that ships nothing — and \"no\" stops being an answer and becomes an identity. The organization adapts: it stops asking. Projects route around the security function, the CEO finds an account manager who will say yes, and the CISO, now consulted on nothing, experiences the isolation Ashenden and Sasse (2013) describe and blames the organization's immaturity rather than the wall.\n\nThe CIO side climbs **optimism → delusion** and **urgency → recklessness**. The builder's belief that the platform will work becomes an inability to hear that it is not; the migration date announced to the board becomes a fact the engineers must not contradict; and the combined CIO/CISO finds the builder's half quietly overruling the risk officer's half in every meeting, because the builder's half is the one the CEO rewards.\n\n**HYPOTHESIS.** The combined role has a failure mode of its own: alternation. Under pressure the CIO/CISO does not integrate the two arguments but switches between them — a builder on Monday, a risk officer on Thursday — and the organization learns that the technology executive's answer depends on their mood.\n\nEarly warning signs, for the executive or the CEO watching them:\n\n- The security function's answer can be predicted before the question is asked, and the prediction is \"no.\"\n- Requests for exceptions have stopped arriving — not because the controls are accepted but because people have learned where to go instead.\n- The technology executive has not accepted a priced risk in writing in two quarters; every yes was unconditional or every no was.\n- The CEO describes the CIO/CISO as \"great, but you have to manage them,\" and the CIO/CISO describes the CEO as someone who \"doesn't get it.\"\n- Reported security incidents are falling, and nobody has asked whether reporting is falling with them.\n\nThe correction is not a different temperament. It is the recognition that the temperament is a default, that the default is where the filters left you, and that the job from here on is learning to move it."}, "research_refs": ["res.graham2013", "res.kaplan2021", "res.ashenden2013", "res.maynard2018", "res.karanja2017", "res.ians2026", "res.peppard2010", "res.preston2008", "res.haislip2021", "res.hambrick1987", "res.hambrick2007", "res.li2010", "res.verizon2025"], "reflection": ["Which of the four filters shaped you most: choosing technology, being promoted out of engineering, being appointed to build or to prevent, or surviving an incident? What did each reward in you, and what did it let you avoid learning?", "Describe the CEO you work for (or the client CEOs you serve) in base-rate terms. Are they more or less optimistic than the roughly four-in-five figure for US CEOs? How has your own default adjusted to theirs — and in which direction?", "Write down the last three times you said no to a business request. For each: did you say what would change your answer? If not, what did the requester do next?", "Write down the last three times you said yes. For each: did you price the risk being accepted, and did someone other than you sign for it?", "Which rung — skepticism → cynicism, caution → paralysis, optimism → delusion, urgency → recklessness — is closest to your reflex under pressure? What is the evidence from the last year?", "If you hold both jobs: in the last month, which half of you won more arguments inside your own head, the builder or the risk officer? Was that the right half for the month you were having?"], "simulation_ref": "sim.m01-founders-mfa", "knowledge_check": [{"id": "m01-kc1", "type": "multiple_choice", "question": "Graham, Harvey and Puri (2013), from the CEO library, found which of the following?", "answer": "B", "explanation": "The study surveyed CEOs and CFOs, not technology executives; it found associations, not causes; and it is the base-rate reason the CISO's disposition will meet resistance.", "options": [{"key": "A", "text": "CISOs are more risk-averse than the general population"}, {"key": "B", "text": "Roughly 80% of US CEOs were classified \"very optimistic,\" against roughly 65% of CFOs, and CEOs were markedly more risk-tolerant than population norms"}, {"key": "C", "text": "Optimistic CEOs cause their firms to be breached more often"}, {"key": "D", "text": "CEOs and CIOs have similar psychometric profiles"}]}, {"id": "m01-kc2", "type": "multiple_choice", "question": "\"CISOs tend to be skeptical\" is best described in this course as:", "answer": "B", "explanation": "There is no psychometric study of CISOs in the library; the profile is inferred from the filters, and selection is not prescription.", "options": [{"key": "A", "text": "A research finding that skepticism improves security outcomes"}, {"key": "B", "text": "A hypothesis about who survives the role's selection filters, which says nothing about whether skepticism makes a good CISO"}, {"key": "C", "text": "A fact established by psychometric studies of CISOs"}, {"key": "D", "text": "A diagnosis that boards should screen for"}]}, {"id": "m01-kc3", "type": "short_answer", "question": "In one or two sentences, explain why the tension between a CEO and a CISO is structural rather than personal, and name the tool this course gives the CISO for managing it.", "answer": "The CEO is drawn from a population selected for optimism and risk tolerance and the CISO from one selected for vigilance and doubt, so the disagreement exists whoever holds either chair; the Risk Corollary — \"Yes, and here is the risk we're accepting, priced\" / \"No, and here is what would change my answer\" — turns it into a priced decision rather than an argument about temperament.", "explanation": "Reading a base rate as a biography is the error the module is built to prevent, in both directions."}, {"id": "m01-kc4", "type": "multiple_choice", "question": "The IANS and Artico Search (2026) figures — 64% of CISOs reporting to IT leaders, 52% describing the role as not manageable — may be used in this course as:", "answer": "B", "explanation": "A self-selected survey by firms with a commercial interest describes prevalence and nothing else.", "options": [{"key": "A", "text": "Evidence that reporting to the CIO causes CISO burnout"}, {"key": "B", "text": "Descriptive base rates from a Tier 3 practitioner survey, with no causal claims attached"}, {"key": "C", "text": "Proof that the CISO should report to the CEO"}, {"key": "D", "text": "A peer-reviewed finding about CISO tenure"}]}], "takeaways": ["The CEO population is unusually optimistic and risk-tolerant on the best available evidence, and the technology executive works for it; the CISO's disagreement with the CEO is structural, not personal.", "CIOs and CISOs pass through four filters — choosing technology, promotion out of engineering, appointment to build or to prevent, surviving incidents — that select for a builder's temperament in the CIO and \"enablement with institutional paranoia\" in the CISO. This is a hypothesis; no psychometric study of technology executives exists in our library.", "\"CISOs tend to be X\" is a base rate; \"X makes a good CISO\" is an unsupported causal claim. Visibility ≠ prevalence; visibility ≠ effectiveness.", "The technology executive's discretion is granted, not assumed — hence the Fit Equation's Reporting Line term — and it spikes in incidents and post-breach budget cycles, exactly when dispositions run unsupervised.", "The Risk Corollary — \"Yes, and here is the risk we're accepting, priced\" / \"No, and here is what would change my answer\" — is how a selected skeptic and a selected optimist disagree usefully. Know your default; the rest of the course is about moving it."], "videos": ["vid.00-selection-is-not-prescription-reading-th", "vid.00-the-ceo-s-optimism-and-the-ciso-s-parano", "vid.00-why-cios-and-cisos-aren-t-normal-either"], "glossary_terms": ["term.selection-filter", "term.base-rate", "term.enablement-with-institutional-paranoia", "term.risk-corollary", "term.structural-position", "term.managerial-discretion", "term.vciso", "term.trait-dial"], "tags": {"dials": ["aggression_caution", "decisiveness_inquiry", "optimism_skepticism", "unilateral_consensus"], "archetypes": ["arch.business-risk-ciso", "arch.enterprise-cio", "arch.smb-msp-technology-leader", "arch.technical-ciso", "arch.transformation-cio"], "stages": ["mature", "scale_up", "startup"], "learn_categories": ["ceo_fundamentals", "personality"]}, "estimated_minutes": 75, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/01-why-cios-and-cisos-arent-normal-either.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m02", "slug": "two-jobs-one-chair", "title": "Two Jobs, One Chair — Builder and Risk Officer", "unit": "I. The Technology Executive's Mind", "big_idea": "The CIO is paid to build capability; the CISO is paid to preserve it. When one person holds both, the job is to keep the two arguments alive inside one head.", "effectiveness_equation_term": "Organizational Context", "learning_objectives": ["Describe the builder/enabler mandate and the risk-officer mandate, and name the five places where they reliably conflict.", "Explain what the evidence says about CIO reporting lines and strategic positioning, and what it can and cannot support.", "Explain the CISO reporting-line debate — CIO versus CEO versus general counsel or risk — without pretending research settles it.", "Design decision rights that let the same person hold both jobs honestly in an SMB, MSP or mid-market company."], "sections": {"core_lesson": "This module is about the structural fact that distinguishes the technology executive from every other C-suite role: two mandates that pull in opposite directions, and — in most companies below a billion dollars of revenue — one person paid to hold both.\n\nThe builder mandate is the CIO's: deliver capability, ship the platform, migrate the ERP, make the business faster than it was. The risk-officer mandate is the CISO's: preserve capability, keep the platform from becoming the breach, make the business slower than it wants to be in the specific places where speed is how companies die. In a large enterprise these are two people with a reporting line between them, and the reporting line is a design decision with evidence behind it. In an SMB, an MSP or a mid-market company they are one person, and the \"reporting line\" runs through that person's own head.\n\nThree things are taught here. What the research says about where the CIO should report — more than most people think, and conditional on strategy. What it says about where the CISO should report — much less than the conference circuit implies, and we will not pretend otherwise. And how to design decision rights so that the combined CIO/CISO can be honest with themselves: which means keeping the argument they are not currently making alive, in writing, where someone else can see it.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module changes the **Organizational Context** term. The reporting line and the decision-rights design are context, and for the technology executive, context is a term of the equation rather than a footnote.", "big_idea": "**The builder and the risk officer are not two personalities; they are two arguments, and the company needs the loser of each argument to be recorded.**\n\nA CIO who builds without a risk officer's argument ships the breach. A CISO who preserves without a builder's argument preserves a company that stops growing. Separate people with separate reporting lines keep both arguments alive by structure; the combined CIO/CISO has to keep them alive by discipline, and the discipline is mechanical — written cases, owned risk acceptances, a standing second opinion — because nobody wins an argument with themselves fairly under deadline.", "research": "### Where the CIO reports, and why it depends\n\n**RESEARCH FINDING.** Banker, Hu, Pavlou and Luftman (2011) argued and showed, on longitudinal firm-level data covering 1990–1993 and 2006, that a firm's strategic positioning should be the primary determinant of where the CIO reports. Firms pursuing differentiation performed better when the CIO reported to the CEO; firms pursuing cost leadership performed better when the CIO reported to the CFO. The authors state this alignment should hold \"independent of whether IT plays a key strategic role in the firm.\" What it supports: the \"right\" reporting line is conditional on the problem the company is solving — evidence that structure should follow strategy, not a universal rule. What it cannot: a cloud-era prescription (the data predate today's CIO), or causation — endogeneity of the reporting choice was addressed statistically, not experimentally.\n\n**RESEARCH FINDING.** Chatterjee, Richardson and Zmud (2001) ran an event study on announcements of newly created CIO positions and found that \"for firms competing in industries undergoing IT-driven transformation, announcements of newly created CIO positions do indeed provoke positive reactions from the marketplace.\" A market reaction measures investor belief, not subsequent performance, and the effect is conditional on industry context. What it supports: creating the role sends a signal that investors read as value in the right context — not that the role delivered it.\n\n**RESEARCH FINDING.** Peppard (2010), from interviews, argued that CIO performance is largely a function of organizational context — especially \"the IT savviness of the CEO and the leadership team\" — and that blaming CIOs for disappointing IT returns misplaces accountability. Qualitative, no outcome data. It is the contextual account of CIO performance this module builds on.\n\n### The CIO–top-team relationship as mechanism\n\n**RESEARCH FINDING.** Preston and Karahanna (2009), using 243 matched CIO–top-management-team pairs, found that shared understanding between the CIO and the top team about the role of IS was a significant antecedent of IS strategic alignment, and that shared language, shared domain knowledge and formal \"systems of knowing\" influenced shared understanding — while informal social interaction and CIO–TMT experiential similarity did *not* significantly affect it. Cross-sectional, self-reported, US, alignment rather than performance as the outcome. What it supports: formal mechanisms and shared knowledge, not socializing, are associated with the understanding that alignment rests on.\n\n**RESEARCH FINDING.** Karahanna and Preston (2013), with matched responses at 81 US hospitals, found that the structural, cognitive and relational dimensions of CIO–TMT social capital facilitated knowledge exchange; cognitive and relational social capital directly influenced alignment; and \"IS alignment significantly influences the firm's financial performance and mediates the relationship between CIO–TMT social capital and performance.\" One sector, 81 organizations, partly perceptual performance, correlational with alignment as mediator. What it supports: relationship quality as a mechanism, measured in one industry.\n\n**RESEARCH FINDING.** Gerow, Grover, Thatcher and Roth (2014) meta-analyzed the IT–business alignment literature and found \"all mean corrected correlations between dimensions of alignment and dependent variables were positive,\" concluding \"there is not much of an alignment paradox.\" The underlying studies are largely cross-sectional surveys; corrected correlations are modest and heterogeneous. What it supports: pooled across the literature, alignment is positively associated with performance on every dimension examined.\n\n### Governance as decision rights\n\n**RESEARCH FINDING (Tier 3).** Weill and Ross (2004), in a research-based practitioner book from MIT's Center for Information Systems Research studying about 250 enterprises, defined IT governance as the framework of decision rights and accountabilities for IT decisions and reported that \"firms with superior IT governance have more than 25% higher profits than firms with poor governance given the same strategic objectives.\" Not peer-reviewed; the \">25%\" figure is a descriptive comparison with the authors' own selection of top performers; the book's taxonomy of decision domains and governance archetypes is a framework, not a finding. What it supports: governance framed as a design choice about who decides what — useful language, not proof that governance causes profit.\n\n**FACT.** Since February 2024 the NIST Cybersecurity Framework 2.0 has included a **Govern** function alongside Identify, Protect, Detect, Respond and Recover, treating executive and board accountability for cyber risk as co-equal with the technical functions (NIST, 2024). The framework is voluntary and outcome-focused; it does not prescribe a reporting line and is not evidence of effectiveness.\n\n### What the CISO literature adds — and does not\n\n**RESEARCH FINDING.** Maynard, Onibere and Ahmad (2018) found through systematic review that the CISO's strategic role is under-theorized and proposed a competency set for the CISO as strategist; no outcome test. Peer-reviewed research has examined CISO appointments and reporting positions in relation to breach events (Karanja, 2017), but the abstract could not be retrieved and no finding is cited. **RESEARCH FINDING (Tier 3).** In the IANS and Artico Search (2026) survey of more than 600 security leaders, 64% of CISOs reported to IT leaders (CIO or CTO) and 36% to non-IT leaders (CEO, COO, general counsel or chief risk officer), and executive-level CISOs were about twice as likely as VP-level CISOs to report to business leaders. Self-selected, commercially interested; a base rate.\n\n**RESEARCH FINDING.** Two archival studies are adjacent rather than direct. Haislip, Lim and Pinsker (2021) found the presence of a CIO on the top management team \"significantly associated with reduced DSBs of all types examined\" over 2005–2017; Higgs, Pinsker, Smith and Young (2016) found that over 2005–2014 firms with board-level technology committees were more likely to have *reported* breaches, and that the committee's presence mitigated negative abnormal returns from external breaches. Both use reported breaches, which conflate occurrence, detection and disclosure; both are associations. What they support: where technology sits in the top team and the board is associated with breach outcomes and with how breaches are reported and priced.\n\n### Where the evidence is weak\n\nThe CIO reporting-line evidence is real but old and conditional; the mechanism evidence is cross-sectional and, in the strongest study, single-sector. For the CISO reporting line there is no peer-reviewed outcome study in this library — no paper that compares CISO-to-CIO with CISO-to-CEO or CISO-to-general-counsel on breach outcomes, cost or anything else. The IANS figures describe prevalence, and the archival studies describe the top team and the board, not the CISO's box on the chart. Everything this module says about where the CISO should report is therefore **INTERPRETATION**, reasoned from the CIO evidence and from the logic of whose argument reaches the decision.", "explanation": "### Two mandates, five collisions\n\n**FRAMEWORK.** The builder mandate is to increase what the business can do: capability, speed, reach, margin. The risk-officer mandate is to protect what the business can do from the ways it can be lost: breach, outage, regulatory penalty, the loss of a client's trust. Both are legitimate; both are measured; and they collide at five predictable points.\n\nThe go-live. The platform is ready, the pen-test remediation is not, and the date has been announced. The builder says ship and patch; the risk officer says the findings are the reason not to. The access decision. The sales team wants the CRM open from any device; least privilege says no. The vendor decision. The fast vendor has not completed the security questionnaire; the compliant one is three months slower. The budget. Every dollar on controls is a dollar not on features, and the CEO can see the features. The incident. The engineers know what happened; legal wants to wait; the builder half wants the platform back up before the risk-officer half has finished scoping.\n\nIn a large enterprise, each collision is a meeting between two executives. Below that scale it is a conversation the combined CIO/CISO has with themselves, usually at 11pm, usually under a date. The problem is not that one argument is wrong. It is that under deadline the argument with the CEO behind it wins by default, and the other one is never written down.\n\n### What the evidence says about the CIO's reporting line\n\n**INTERPRETATION.** The CIO evidence is more useful than it looks, because it is conditional. Banker, Hu, Pavlou and Luftman (2011) found that differentiation-strategy firms did better with the CIO reporting to the CEO and cost-leadership firms with the CIO reporting to the CFO. Read as a rule, that is a curiosity from the 1990s. Read as a principle — structure follows the problem — it is the whole module. A company whose competitive problem is building something new needs the builder's argument in the room where strategy is set; a company whose competitive problem is cost needs the builder's argument disciplined by the person who owns cost. Neither is \"right.\" Each is right for a problem.\n\nThe mechanism studies say how the reporting line does its work. Preston and Karahanna (2009) found that formal systems of knowing and shared domain knowledge — not informal socializing — were associated with the shared understanding that alignment rests on; Karahanna and Preston (2013) traced social capital through alignment to performance in 81 hospitals; Gerow et al. (2014) found alignment positively associated with performance across the literature. **INTERPRETATION.** The reporting line matters because it is the primary formal mechanism by which the technology executive's argument reaches the decision — and Peppard (2010) adds the limit: a CEO who does not understand technology bounds what any CIO can do, wherever the CIO reports.\n\n### The CISO reporting-line debate, honestly\n\nHere the evidence stops and the arguing starts. There are three positions, and each is held by intelligent people.\n\n**INTERPRETATION.** *CISO reports to the CIO.* The majority case (64% in IANS, 2026 — a base rate, not a recommendation). The argument for: security is mostly implemented in technology, and a CISO inside the technology organization has the access, the budget line and the engineers. The argument against: the builder is grading the builder's homework. When the go-live collision arrives, the risk-officer argument reaches the decision through the person who most wants to ship.\n\n*CISO reports to the CEO.* The argument for: the risk argument reaches the decision unfiltered, and the CISO has the standing Ashenden and Sasse's (2013) interviewees said they lacked. The argument against: the CEO already has too many direct reports, most CEOs are not equipped to arbitrate technical risk, and a CISO with a seat at the table but no engineers is the IT Advisor profile — capability without authority (Preston, Leidner & Chen, 2008) — in a different chair.\n\n*CISO reports to the general counsel or chief risk officer.* The argument for: security becomes an enterprise risk like any other, priced alongside legal and financial risk, with disclosure decisions where disclosure expertise lives. The argument against: the CISO drifts into a compliance function, measured on audit findings rather than on whether the company is actually hard to attack, and loses the engineers entirely.\n\n**What the research can say.** That structure should follow the problem (Banker et al., 2011). That formal mechanisms carry the argument (Preston & Karahanna, 2009). That top-team and board placement of technology is associated with breach outcomes and reporting (Haislip et al., 2021; Higgs et al., 2016). That governance is a design of decision rights (Weill & Ross, 2004 — Tier 3) and that a national framework now names it a function (NIST, 2024 — FACT). **What it cannot say:** which CISO reporting line produces fewer breaches, lower cost or better decisions. No such study is in our library. Anyone who tells you the CISO \"must\" report to the CEO is stating a preference.\n\n**INTERPRETATION.** The honest conclusion is a test rather than a rule. The reporting line is right if the risk-officer argument reaches the person who decides without passing through the person who most wants to overrule it — and if the overruling, when it happens, is written down by the person who did it. That is the Reporting Line term of the extended Fit Equation: Industry × Scale × Lifecycle × Strategy × Governance × Problem × **Reporting Line** = CIO/CISO Fit. A company in a post-breach turnaround, under a consent order, or selling into regulated clients may need the CISO's argument to reach the board directly; a 200-person software company building fast may be fine with the CISO inside technology, provided the exception log is real. Personality × Power applies: the same CISO is a different executive on each line, because discretion is granted by structure (Hambrick & Finkelstein, 1987).\n\n### Decision rights for the combined chair\n\nNow the case that matters most for this course's first learners: one person, both jobs, an SMB or MSP or mid-market company where \"reporting line\" is a metaphor.\n\n**FRAMEWORK.** The design goal is to reproduce by mechanism what the enterprise reproduces by structure: two arguments, both recorded, the loser visible. Six decision rights do it.\n\n1. *Both cases in writing before any collision decision.* A one-page build case and a one-page risk case, each written as if by an advocate. The combined CIO/CISO writes both. The discipline is not the document; it is having to argue the side you are about to overrule.\n2. *Risk acceptance owned by the business, not the technologist.* When the risk case loses, the executive who chose the build — CEO, client principal, PE operating partner — signs the acceptance in the risk case's own words. The technology executive never accepts a risk on the business's behalf. This is the first sentence of the Risk Corollary made into paper.\n3. *A standing second opinion.* Somebody outside your head — a peer vCISO on retainer, an external auditor, the MDR provider's lead, a board member with security experience — who sees the risk case before the decision and can say the technologist has under-priced it. The SMB/MSP Player's dominant danger is the absence of exactly this.\n4. *Separation of duties at the three points where it matters.* Who approves control exceptions; who can disable a control; who can declare an incident closed. The combined CIO/CISO should hold at most one of the three alone.\n5. *An escalation path that skips you.* Engineers and account managers must be able to raise a risk to the CEO or the client without going through the person who owns both the build and the control.\n6. *A quarterly reading of the exception log by someone who did not write it.* The log of accepted risks is the company's true security posture. If nobody reads it, the second decision right was theater.\n\n**INTERPRETATION.** This is Weill and Ross's (2004) idea — governance as decision rights and accountabilities — scaled down to a company where the \"IT steering committee\" is three people and a client. It is also what NIST's Govern function asks for at the outcome level (NIST, 2024). And it is where the Maturity Model's third level lives for the technology executive: letting the business own its risk. A Player-stage CIO/CISO who cannot let the business sign for a risk is not being careful; they are keeping a decision that is not theirs.\n\n### The dials, and the two jobs at each scale\n\n**FRAMEWORK.** The builder default runs aggression, urgency and innovation; the risk-officer default runs caution, patience and operational discipline. Holding both jobs is not averaging the dials — an average ships nothing and secures nothing. It is moving them by decision: aggression on the migration architecture, caution on the cutover weekend; urgency on the MFA rollout, patience on the vendor's questionnaire. The Overuse Ladder's two rungs for this chair are rigor → bureaucracy (the security review that ships nothing) and urgency → recklessness (the go-live that becomes the breach), and the combined role can climb both in the same quarter.\n\nPlayer → Coach → Architect changes what \"both jobs\" means. The Player holds both hands-on and needs the six decision rights as scaffolding. The Coach has hired a security lead and a platform lead and needs the two of them to argue in front of the Coach rather than to the Coach separately. The Architect has two organizations and a reporting line to design, and the evidence above is finally about them.", "example": "*Fictional composite.* Brightwater Foods is a specialty food distributor in Rochester, New York: $420 million in revenue, 1,100 employees, eleven warehouses, owned by a mid-market private equity fund since 2022. Marcus Bell has been CIO since 2020 and added the CISO title in 2023 when the fund's operating partner asked who owned security and found the honest answer was \"nobody, exactly.\" He has 34 people, a managed detection provider, and a cloud ERP migration that is eight months in and two weeks from cutover.\n\nThe pen test came back in week thirty. Three high findings: an API gateway that accepts a legacy authentication path, a warehouse-management integration that runs with a shared service account, and a backup configuration that has not been restore-tested since the migration began. Remediation is estimated at five weeks. Cutover is scheduled for the Columbus Day weekend, when order volume is lowest; the next comparable window is Presidents' Day, four months out. The fund's value-creation plan has ERP go-live in the third quarter, and the operating partner has mentioned it on two board calls.\n\nBell notices the argument forming in his head and notices which side is winning: the builder's. The findings are \"manageable,\" the legacy path is \"rarely used,\" the service account \"has been there for years.\" Every phrase is true and every phrase is the CIO overruling the CISO in private. So he writes both cases, one page each, as advocates.\n\nThe build case: a four-month delay costs roughly $600,000 in parallel-running licenses and contractor retention, defers $2 million of planned working-capital benefit, and breaks a commitment made to the board. The risk case: the three findings are precisely the mechanisms by which distributors get ransomed — an unauthenticated path into the order system, a shared credential into the warehouse, and backups nobody has proven. Bell prices it: perhaps one chance in ten of a material incident in the four-month exposure window if they ship now, against one in fifty after remediation, with a plausible cost of $3–8 million and eleven warehouses idle for a week. He shows both pages to the MDR provider's lead engineer, who reads the risk case and says the one-in-ten is optimistic.\n\nThen he takes both pages to the CEO and the operating partner and says both sentences. \"Yes — we can cut over on Columbus Day, and here is the risk we're accepting, priced; if we do it, I need one of you to sign this page.\" And: \"No — I'd recommend not, and here is what would change my answer: the API path closed and the service account replaced before cutover, which is eleven days of the five weeks, and the restore test done the weekend before. The backup finding I can carry for a month with daily manual verification.\"\n\nThe operating partner asks the question the module exists to produce: \"What does the eleven days cost?\" A cutover slipped from Columbus Day to the following weekend, one extra week of parallel running, and a board note. Brightwater cuts over eight days late with two of three findings closed and the third under a written acceptance the CEO signed. **INTERPRETATION.** The combined chair did not become two people. It produced two documents, let someone outside Bell's head read one of them, and made the person who wanted the build sign for the risk of it.", "ceo_contrast": "Same pen test, same weekend, four archetypes in Bell's chair.\n\n**The Technical CISO** stops the cutover. Three high findings is three high findings; the migration waits for remediation and the next window is Presidents' Day. The gain is a clean go-live and no exposure window. The cost is $600,000, a broken board commitment, and — more expensive — a fund that now regards its CIO/CISO as the reason the value-creation plan slipped. The Technical CISO has not lost the argument; they have declined to have it, and the operating partner will hire someone to have it for them.\n\n**The Business-Risk CISO** ships on schedule with a risk acceptance and compensating monitoring. The gain is the date and a reputation for enablement. The cost depends entirely on whether the acceptance was priced honestly or priced to fit the weekend; if the one-in-ten was written as one-in-a-hundred to make the signature easy, the Business-Risk CISO has converted the risk case into a formality. The second opinion in decision right three exists to catch exactly this.\n\n**The Transformation CIO** was hired by the fund to deliver the migration and sees the findings as noise in the last mile. The gain is momentum and a board that gets the date it was promised. The cost is that the Transformation CIO's discretion is high and short-lived, the findings are the ransomware playbook, and nobody in the room is being paid to say so. This is the archetype for whom the six decision rights are least natural and most necessary.\n\n**The Regulated-Industry CIO/CISO**, imagine Brightwater were a broker-dealer or a hospital, would have had the pen test findings on the audit committee's agenda before the cutover question arose, because in those industries the risk argument has a structural path to the board. The gain is that the decision is never made at 11pm. The cost is that the same structure makes the four-month delay the default and the operating partner's question — what does the eleven days cost — is never asked. Institutional paranoia as job description works until the job is to ship.", "failure_mode": "The two-jobs chair fails when one argument stops being made, and the Overuse Ladder describes each direction.\n\n**INTERPRETATION.** When the builder swallows the risk officer, the rungs are **urgency → recklessness** and **optimism → delusion**. The go-live ships with the findings open, the exception log fills with acceptances the technologist signed for the business, and the company learns that \"we'll fix it after cutover\" is a category of work that never starts. When the risk officer swallows the builder, the rungs are **rigor → bureaucracy** and **caution → paralysis**: the security review that ships nothing, the vendor questionnaire that outlasts the vendor, the CISO who is never breached because nothing is ever deployed.\n\nThe reporting line has failure modes of its own. A CISO under the CIO whose overrulings are never written down is a control the builder can switch off silently. A CISO under the general counsel who is measured on audit findings becomes a compliance function that is compliant on the day it is breached. A CISO reporting to the CEO without engineers is an advisor whose advice arrives after the build.\n\n**HYPOTHESIS.** The subtlest failure for the combined chair is that the two arguments merge into one voice that sounds balanced and is not. The CIO/CISO who says \"it's a manageable risk\" about everything has stopped writing the risk case; the one who says \"we need to be careful\" about everything has stopped writing the build case. Balance is not a tone. It is two documents.\n\nEarly warning signs, for the executive or the CEO watching:\n\n- The exception log has not been read by anyone except its author in two quarters, or every acceptance in it is signed by the technology executive.\n- Remediation items deferred at go-live are still open at the next go-live.\n- The security lead and the platform lead never disagree in front of the CIO; they disagree to the CIO separately, and the CIO decides in private.\n- Nobody can name the last time the risk argument won a collision — or the last time the build argument did.\n- The CEO cannot say who is allowed to overrule the CISO and what they have to write down when they do."}, "research_refs": ["res.banker2011", "res.chatterjee2001", "res.peppard2010", "res.maynard2018", "res.weill2004", "res.ians2026", "res.preston2008", "res.preston2009", "res.karahanna2013", "res.gerow2014", "res.haislip2021", "res.higgs2016", "res.karanja2017", "res.nist2024", "res.hambrick1987"], "reflection": ["Take your last go-live, vendor selection or access decision. Write the build case and the risk case now, one paragraph each, as advocates. Which was easier to write? Which one did you actually make at the time?", "Who signed the last risk you accepted? If it was you, whose risk was it?", "Name the person outside your head who sees your risk cases before decisions. If there is nobody, what is the decision-rights design you are relying on instead?", "Where does the risk argument in your company reach the decision — through you, past you, or not at all? Who can overrule it, and do they have to write it down?", "If you report to a CIO: when did they last overrule you in writing? If you are the CIO with a CISO under you: when did you last lose an argument to them, and does anyone else know?", "At your scale, are you a Player holding both jobs, a Coach with two leads, or an Architect with two organizations? Which set of decision rights are you actually running, and which set does your scale need?"], "simulation_ref": "sim.m02-tidewater-reporting-line", "knowledge_check": [{"id": "m02-kc1", "type": "multiple_choice", "question": "Banker, Hu, Pavlou and Luftman (2011) found that:", "answer": "B", "explanation": "The finding is conditional on strategy — structure should follow the problem — and says nothing about CISOs; the data cover 1990–1993 and 2006.", "options": [{"key": "A", "text": "The CIO should always report to the CEO"}, {"key": "B", "text": "Differentiation-strategy firms performed better with the CIO reporting to the CEO, and cost-leadership firms with the CIO reporting to the CFO"}, {"key": "C", "text": "CIO reporting structure had no association with performance"}, {"key": "D", "text": "CISOs who report to the CIO experience more breaches"}]}, {"id": "m02-kc2", "type": "multiple_choice", "question": "Which statement about the CISO reporting-line debate is consistent with this module?", "answer": "C", "explanation": "The research is conditional for CIOs and absent for CISO reporting lines; IANS is a base rate; NIST does not prescribe a reporting line.", "options": [{"key": "A", "text": "Peer-reviewed research shows CISOs reporting to the CEO have fewer breaches"}, {"key": "B", "text": "The IANS (2026) figure of 64% reporting to IT leaders establishes the best practice"}, {"key": "C", "text": "No outcome study in the library compares CISO reporting lines; the module offers a test — does the risk argument reach the decision unfiltered, and are overrulings written down — rather than a rule"}, {"key": "D", "text": "The NIST CSF 2.0 Govern function requires the CISO to report to the board"}]}, {"id": "m02-kc3", "type": "short_answer", "question": "Name three of the six decision rights the module proposes for a combined CIO/CISO in an SMB or MSP, and say what each protects against.", "answer": "Any three of: both cases in writing (protects against the losing argument never being made); risk acceptance signed by the business (against the technologist accepting risk on the business's behalf); a standing second opinion (against the absence of anyone outside the executive's head); separation of duties on exceptions, disabling controls and closing incidents (against one person holding all three); an escalation path that skips the CIO/CISO (against filtered bad news); a quarterly reading of the exception log by someone else (against the acceptance process becoming theater).", "explanation": "The design reproduces by mechanism what the enterprise reproduces by structure: two arguments, both recorded, the loser visible."}, {"id": "m02-kc4", "type": "multiple_choice", "question": "Preston and Karahanna (2009), in 243 matched CIO–top-team pairs, found that shared understanding about the role of IS was influenced by:", "answer": "C", "explanation": "The result is why the module treats the reporting line and decision rights as formal mechanisms rather than relationships to be managed over lunch.", "options": [{"key": "A", "text": "Informal social interaction between the CIO and the top team"}, {"key": "B", "text": "The CIO's experiential similarity to the top team"}, {"key": "C", "text": "Shared language, shared domain knowledge and formal \"systems of knowing\" — while informal socializing and experiential similarity did not significantly matter"}, {"key": "D", "text": "The CIO's reporting line to the CFO"}]}], "takeaways": ["The builder mandate and the risk-officer mandate collide at five predictable points — go-live, access, vendor, budget, incident — and under deadline the argument with the CEO behind it wins by default unless the other is written down.", "For the CIO, the evidence says structure should follow strategy: CIO-to-CEO was associated with better performance in differentiation firms and CIO-to-CFO in cost-leadership firms (Banker et al., 2011); formal mechanisms, not socializing, carry the argument (Preston & Karahanna, 2009); alignment is associated with performance across the literature (Gerow et al., 2014).", "For the CISO, no outcome study in the library compares reporting lines. Use the test, not a rule: does the risk argument reach the decision without passing through the person who most wants to overrule it, and are overrulings recorded?", "The combined CIO/CISO keeps both arguments alive by mechanism — both cases in writing, risk accepted by the business, a standing second opinion, separation of duties at three points, an escalation path that skips you, and an exception log someone else reads.", "Holding both jobs is not averaging the dials; it is moving them by decision, and the loser of every collision should be visible to someone other than you."], "videos": ["vid.00-decision-rights-for-the-one-person-cio-c", "vid.00-two-jobs-one-chair", "vid.00-where-should-the-ciso-report-what-the-ev"], "glossary_terms": ["term.builder-mandate", "term.risk-officer-mandate", "term.reporting-line", "term.decision-rights", "term.risk-acceptance", "term.it-governance", "term.strategic-alignment", "term.second-opinion"], "tags": {"dials": ["aggression_caution", "centralization_decentralization", "unilateral_consensus", "urgency_patience"], "archetypes": ["arch.business-risk-ciso", "arch.mid-market-cio", "arch.regulated-industry-cio-ciso", "arch.smb-msp-technology-leader", "arch.technical-ciso"], "stages": ["mature", "regulatory_reputation_crisis", "scale_up"], "learn_categories": ["ceo_fundamentals", "organizational_design"]}, "estimated_minutes": 75, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/02-two-jobs-one-chair.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m03", "slug": "pricing-risk", "title": "Pricing Risk — The Economics of Security Leadership", "unit": "I. The Technology Executive's Mind", "big_idea": "Security is a spending decision under uncertainty, and the executive who can say what a control is worth is worth more than the one who can only say it is necessary.", "effectiveness_equation_term": "Behaviors", "learning_objectives": ["Explain the Gordon–Loeb logic — security spending as a function of expected loss — and state its limits before quoting its bound.", "Summarize what breach-cost research does and does not show, and why a market reaction is not your invoice.", "Distinguish proactive from reactive investment and symbolic from substantive adoption, and treat both as multipliers on the same dollar.", "Run a budget conversation as risk pricing rather than fear, using the Risk Corollary, and price a single control in numbers a non-technical CEO can argue with."], "sections": {"core_lesson": "Most security budget conversations fail the same way. The technology executive arrives with a threat, a headline and a number; the CEO hears a request to buy peace of mind at an unspecified price. The executive reads the resulting cut as the business not taking security seriously. The business reads the ask as an unpriced demand from a function that has never once said \"that one isn't worth buying.\"\n\nThis module teaches the alternative: treating security as a spending decision under uncertainty, which is what it is. The economics of information security investment is nearly a quarter-century old, and its central result is uncomfortable for both sides of that meeting — the optimal spend is well above zero and well below everything, and it depends on numbers you can only estimate. The evidence on what breaches cost says less than it is usually claimed to. And *when* you spend, and how deeply you integrate what you buy, matter more than the amount.\n\nThe payoff is an instrument — the Risk Corollary, used as the structure of a budget conversation rather than as a slogan — and a worked example: one control, priced so a non-technical CEO can argue with it. In the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module changes the **Behaviors** term. Pricing is a behavior, and it is learnable.", "big_idea": "**A control you cannot price is a control you cannot defend — and a risk you cannot price is a risk you are accepting by accident.**\n\nYour authority does not come from being right about threats; everyone in the room believes threats are real. It comes from being the only person who can say what a control buys, what it costs, and what happens if it is not bought — in the units the CFO already uses. The moment you can also say \"this one isn't worth it,\" the other three asks become credible.", "research": "### How much is rational to spend\n\n**RESEARCH FINDING.** Gordon and Loeb (2002) built an economic model in which optimal security investment for a given information set depends on its value, its vulnerability, and the productivity of security spending. For the breach-probability functions they assume, optimal investment \"does not exceed 37% of the expected loss from a breach\" — the 1/e bound — and it can be rational to invest *less* in the most vulnerable assets, because the marginal dollar buys less there. What it supports: spending as a function of expected loss, and a formal argument that \"spend until safe\" is not a coherent target. What it cannot support: a budget. This is an analytical model, not an empirical study; the bound holds only for the two classes of breach functions the authors assume, and later papers show other functions can justify 50% or more.\n\n### What breaches cost — and what the studies measure\n\n**RESEARCH FINDING.** Campbell, Gordon, Loeb and Zhou (2003), in an event study of newspaper-reported breaches at US public firms, found \"limited evidence of an overall negative stock market reaction,\" but \"a highly significant negative market reaction for information security breaches involving unauthorized access to confidential data\" and \"no significant reaction when the breach does not involve confidential information.\" Pre-2003 newspaper sample, short windows, the authors' own classification of \"confidential.\" Investors price the *type* of breach, not the fact of one. **RESEARCH FINDING.** Cavusoglu, Mishra and Raghunathan (2004) put an average on it — about 2.1% of market value, or \"$1.65 billion per breach,\" over two days — while security vendors gained (1.36%, about $1.06 billion). Those dollar figures reflect a pre-2004 large-cap sample and do not generalize.\n\n**RESEARCH FINDING.** Kamiya, Kang, Kim, Milidonis and Stulz (2021) tested a model of optimal cyber-risk exposure on successful attacks against US firms. Attacks involving loss of personal financial information caused \"significant shareholder wealth loss, which is much larger than the attack's out-of-pocket costs,\" consistent with reputational damage; losses spilled over to industry peers; firms whose boards had attended to risk management *before* the attack suffered smaller excess losses. Archival, disclosed attacks only, board attention proxied, associations. Kashmiri, Nicol and Hsu (2017) found the same neighbourhood effect at 168 US retailers around the December 2013 Target breach.\n\n**RESEARCH FINDING.** Amir, Levi and Livne (2018) compared attacks firms disclosed with attacks they withheld that outsiders later revealed: \"withheld cyber-attacks are associated with a decline of approximately 3.6% in equity values in the month the attack is discovered, and disclosed attacks with a substantially lower decline of 0.7%.\" Attacks never discovered are unobservable by construction, and the period predates the SEC rules. Concealment is priced when discovered — a cost line, not a moral aside.\n\n### When you spend, and how deeply you adopt\n\n**RESEARCH FINDING.** Kwon and Johnson (2014), using a Cox proportional-hazard model on US healthcare organizations, found \"proactive security investments are associated with lower security failure rates,\" that proactive investment was more cost-effective than reactive, and that \"external pressure decreases the effect of proactive investments on security performance.\" One sector, disclosed breaches, associations. The same dollar buys more before the failure than after — and regulatory pressure can crowd out the benefit of getting ahead.\n\n**RESEARCH FINDING.** Angst, Block, D'Arcy and Kelley (2017), in a matched panel of over 5,000 US hospitals and 938 breaches from 2005 to 2013, classified hospitals as symbolic or substantive adopters and found \"symbolic adoption diminishes the effectiveness of IT security investments, resulting in an increased likelihood of breach,\" while deeper integration of security into IT routines was associated with fewer breaches. Adoption depth was inferred from an institutional profile rather than observed; reported breaches only. This is the most important qualifier on any security budget number.\n\n### Practitioner base rates — Tier 3, descriptive only\n\n**RESEARCH FINDING (Tier 3).** The Verizon 2025 Data Breach Investigations Report analyzed 22,052 incidents, of which 12,195 were confirmed breaches, and reports third-party involvement in 30% of breaches (up from 15%), ransomware in 44% and in 88% of SMB breaches, credential abuse as the most common initial vector at 22%, the human element in roughly 60%, and a median ransom payment of $115,000 with 64% of victims not paying. **RESEARCH FINDING (Tier 3).** IBM and the Ponemon Institute (2025), from about 600 breached organizations, put the global average breach cost at $4.44 million, down 9% from $4.88 million, with mean time to identify and contain at 241 days. Neither is peer-reviewed. The DBIR is a non-random contributor sample whose visibility depends on regional disclosure laws; IBM's figures come from self-selected participants, use estimated rather than audited costs, and are published by a company that sells security products. Use them for orders of magnitude. **Never use them causally** — no line in either establishes that any control reduced any cost.\n\n### Where the evidence is weak\n\nNearly all of it concerns large public companies, and the breach-cost studies price investor expectations rather than cash out the door. Nothing here gives an SMB, MSP or private mid-market firm a defensible loss distribution — the population that most needs one is the least studied. And no study in this library shows that a particular control, framework or spending level reduces breaches at your company. Everything the module says about *how* to price is **FRAMEWORK**; the worked example's numbers are fictional.", "explanation": "### What Gordon–Loeb actually gives you\n\n**FRAMEWORK.** Strip the mathematics and the model says three things a CEO accepts immediately. Spending should be a function of what you would lose, not of what a threat report says exists. The return on the marginal dollar falls as you spend, so there is a level beyond which more spending destroys value. And the most vulnerable asset is not automatically the one deserving the most money, because where protection is very hard the marginal dollar buys less.\n\n**INTERPRETATION.** Use the 37% bound as a sanity check, never an allowance: if you are asking for more than roughly a third of what the thing is worth losing, either your loss estimate is too low or your proposal is wrong. Anyone quoting it without its assumptions is quoting a number they have not read.\n\n### What breach-cost research does not show\n\nTwo misuses get technology executives caught in front of a CFO. The first is treating someone else's average as your cost. Campbell et al. (2003) and Cavusoglu et al. (2004) measure abnormal returns over days — investor expectations, re-priced — in pre-2004 samples of very large firms, and the IBM/Ponemon $4.44 million is a mean across self-selected organizations of wildly different sizes. Quote either to a private mid-market CFO as their exposure and you have handed the room a reason to distrust every other number you brought.\n\nThe second is ignoring type: the significant reactions in both Campbell et al. and Kamiya et al. concentrate in breaches of confidential and personal financial data. **INTERPRETATION.** The question is never \"what does a breach cost\" but \"what does *this* breach, of *this* data, at *this* firm cost\" — which your business can help answer and a threat report cannot.\n\n### The two multipliers on every dollar\n\n**INTERPRETATION.** *Timing* (Kwon & Johnson, 2014): the same control is a different purchase before and after an incident. Bought before, it is a priced choice; bought after, it is bought at the worst price, under duress, alongside a public-relations budget nobody planned.\n\n*Depth* (Angst et al., 2017): bring this to the meeting where the CFO offers to fund the tool but not the engineers who would operate it. Half a control is not half a benefit; it may be no benefit and a line item. If you cannot integrate it this year, do not buy it this year — and say so, because saying it is what makes your other asks credible.\n\n### Enablement with institutional paranoia, as a budget behavior\n\n**FRAMEWORK.** \"Enablement with institutional paranoia\" is a description of a disposition, not a diagnosis. In a budget conversation it takes one form: you arrive as someone trying to make the business's plan work, carrying a quantified, unsentimental view of how that plan could kill the company.\n\nThe instrument is the Risk Corollary. **\"Yes — and here is the risk we are accepting, priced\"** is what makes you an executive rather than a control. It requires a loss estimate, a probability estimate, and a named person who signs the acceptance; a \"yes\" without those three is abdication with a pleasant tone. **\"No — and here is what would change my answer\"** stops \"no\" from becoming your identity. The second clause is not politeness but a trade the business can execute: \"No, unless the vendor completes SOC 2 Type II or we scope them to a segregated tenant\" is a decision; \"No, it's too risky\" is a mood.\n\nBoth require a price, which is why pricing precedes influence — and it gives you something to do with the pressure the role carries. In the IANS and Artico Search (2026) survey of more than 600 security leaders, 52% said their responsibilities were \"not manageable given current resources\" (self-selected; base rate only). An unmanageable mandate is easier to renegotiate with a priced list than with an appeal.\n\n### Pricing one control, in numbers a CEO will follow\n\n*Illustrative and fictional; the arithmetic is real, the inputs are estimates.* A 300-person managed-services firm administers 190 client environments through a remote-administration path. The proposal: phishing-resistant multi-factor authentication plus a privileged-access broker on every administrative session.\n\n**1. What are we protecting?** Not \"the network.\" The administrative path into 190 client environments — the mechanism by which one compromised technician becomes 190 compromised clients.\n\n**2. How likely per year, without the control?** Call it 8%, about one year in twelve, from three years of the firm's own attempted-intrusion logs plus the fact that credential abuse is the most common initial vector in the DBIR's 2025 sample at 22% (Tier 3, non-random). This is the weakest number in the model.\n\n**3. If it happens, what does it cost?** A range, not a point. Response, forensics and counsel $250,000–$600,000; client credits, remediation and re-attestation $400,000–$1.5 million; two or three lost clients at roughly $250,000 of recurring revenue each. Central estimate **$3.4 million**; high case above $9 million if several regulated clients are hit at once. Expected annual loss today: 8% × $3.4 million = **$272,000**.\n\n**4. What does the control cost?** Year one $95,000 ($38,000 licences, $22,000 implementation, $35,000 internal engineering). Steady state **$46,000 a year**.\n\n**5. What does it do to the probability?** It does not remove the risk; it removes a class of it. Estimate 8% down to 2%. Expected annual loss falls from $272,000 to $68,000 — **$204,000 avoided for $46,000**, about $4.40 per dollar spent.\n\n**6. The sentence the CEO can argue with.** \"This pays for itself if it moves the annual probability of a credential-driven client compromise by more than about 1.4 percentage points\" — $46,000 divided by $3.4 million is 1.35 points. A non-technical CEO can contest that without knowing what a security key is, and contesting it is the point.\n\n**7. The Gordon–Loeb sanity check.** Expected loss $272,000; 37% is about $100,000. Year-one spend of $95,000 sits just under, steady state well under. Had the proposal been $400,000 against the same exposure, the model says it is wrong even though the threat is real.\n\n**8. The honesty clause.** Say which numbers are quotes and which are guesses: the 8% is a guess informed by logs, the $3.4 million a modeled range, the 2% an engineering judgment, only the $46,000 a quote. **INTERPRETATION.** Executives lose credibility by presenting all four with equal confidence, not by admitting three are soft.\n\n**FRAMEWORK.** Pricing moves the aggression↔caution and optimism↔skepticism dials by decision rather than temperament. Graham, Harvey and Puri (2013, from the CEO library) found CEOs scored substantially more risk-tolerant and optimistic than the general population — self-reported, associations only. That is the room you price into: your estimates read as pessimistic by default, which argues for showing arithmetic rather than conclusions.", "example": "*Fictional composite.* Charter Oak Business Services is a business-process and managed-services firm in Hartford, Connecticut: $41 million in revenue, 310 employees, 190 clients across registered investment advisers and broker-dealers, two hospital-affiliated physician groups, several law firms and a regional specialty retailer. Ruth Alvarez has been VP of Technology and Security for three years and holds both mandates. Security spend last year was $780,000; her ask for the coming year is $1.14 million.\n\nThe CEO, a former operations partner who reads a P&L faster than anyone in the building, asks the question the module exists for: \"What does this buy us?\"\n\nShe has brought three asks, priced, ranked by expected loss avoided per dollar.\n\n*Privileged access and phishing-resistant MFA on the administrative path* — the control priced above. $95,000 in year one, roughly $4.40 avoided per dollar, break-even at 1.4 percentage points. She names the 8% as the soft number before anyone asks.\n\n*Two security engineers to operate the detection stack bought eighteen months ago* — $340,000 fully loaded, framed with Angst et al. (2017): across 5,000-plus hospitals, the same investment was associated with fewer breaches only where adoption was substantive. \"We already spend $210,000 a year on a tool nobody is paid to tune. That is a symbolic adoption. The engineers are not an addition to the tool; they are what makes it a control instead of a receipt.\"\n\n*A deception and honeypot platform* — $180,000. Here Alvarez does the thing that makes the meeting work. She withdraws it. \"I asked for this two months ago and I still cannot price it. I cannot tell you what it moves. The others I can. Take it out.\"\n\nThe CFO offers the predictable compromise: renew the tool, defer the engineers, add one contractor. Alvarez says no, and says the second half. \"No — one contractor gets tuning but not on-call coverage, and we would still pay $210,000 a year for an untuned control. What would change my answer is a second contractor, or a co-managed detection contract at about $190,000 that comes with coverage.\"\n\nThen the first sentence. \"Yes — we can run one more year without the engineers, and here is the risk we are accepting, priced. Our mean time to notice an intrusion in a client environment is measured in weeks. If it happens, my central estimate is $3.4 million. If we accept that, I need you or the CEO to sign the acceptance in my words, not yours.\"\n\nCharter Oak funds the access control and the co-managed contract; the deception platform never returns, and the signed acceptance goes into an exception log that someone other than its author reads in April. When the board's audit chair asks about the withdrawn item, the CEO gives the module's thesis in one line: \"She took one off the list herself. That's why I believed the other two.\"", "ceo_contrast": "Same three asks, same CEO, four archetypes in Alvarez's chair.\n\n**The Technical CISO** brings the threat, not the price. The presentation is excellent on mechanism and silent on worth. Asked \"what does this buy us,\" the honest internal answer is \"safety,\" which converts in the CEO's head to \"an unbounded ask.\" The cost is that the budget is then set by whoever *can* price — the CFO — whose model of security value is the invoice. This archetype's dominant risk, \"no\" as identity, starts here: unable to say what a control is worth, and therefore never able to say one is not worth buying.\n\n**The Business-Risk CISO** prices all three and wins all three, because the pricing was built to win. The 8% becomes 15%, the high case becomes the central case, and the deception platform acquires a story. The gain is a funded program; the cost arrives in eighteen months when nothing has happened, the CFO recalculates, and every future number carries a discount. **INTERPRETATION.** The failure is not dishonesty; it is a pricing model with no downside case, built by someone unaware they are advocating.\n\n**The SMB / MSP Technology Leader (Player)** gets no budget meeting — just a conversation with an owner about whether $95,000 is affordable this quarter. The arithmetic is scale-free and still works; the estimates are thinner and nobody checks them. The danger is a loss estimate produced by the same person who wants the control. The mitigation is cheap: send the one-page pricing to the insurance broker, the outside accountant or a peer vCISO first, and ask only \"which of these four numbers would you argue with?\"\n\n**The Regulated-Industry CIO/CISO**, imagine Charter Oak as a broker-dealer rather than its service provider, has an easier meeting and a subtler problem. Regulatory expectation carries the ask across the line without pricing, which is faster and worse: Kwon and Johnson (2014) found external pressure *decreased* the effect of proactive investment on security performance. **INTERPRETATION.** When the regulator is the argument, nobody learns what anything is worth. Price it anyway, in private, and notice which items survive only because an examiner will ask.", "failure_mode": "Pricing has two opposite overuse paths and one that pretends to be neither.\n\n**INTERPRETATION.** The first is **rigor → bureaucracy**. Pricing becomes a program: a quantification workstream, a consultant, a model with sixty inputs, and decisions due in March still open in September. The tell is that the model's outputs never change anyone's mind, because the decision was made by default while it was being built. Treat any model that cannot produce a recommendation in a week as a control that failed its own cost-benefit test.\n\nThe second is **confidence → arrogance**, wearing a spreadsheet. False precision is more dangerous than admitted ignorance, because a number invites a decision. Present the 8% as confidently as the $46,000 quote and a guess has been laundered into a fact — and the first time the guess is visibly wrong, the method is discredited with it.\n\nThe third looks like neither: **optimism → delusion** in the direction of the business. This is the executive who prices everything to the answer the CEO wants, calls it enablement, and signs the risk acceptances themselves. Every \"yes\" is priced, none honestly, and the business never learns what it is carrying.\n\nEarly warning signs, for the executive or the CEO watching:\n\n- The security function has never once said \"that control isn't worth buying,\" in any budget cycle.\n- Every ask is justified by a threat report or a peer's breach, none by a loss estimate for this company.\n- Loss estimates always land just above the cost of the thing requested, and nobody can say which number is weakest.\n- A tool bought last year still has no named operator, and this year's ask is a different tool."}, "research_refs": ["res.gordon2002", "res.campbell2003", "res.cavusoglu2004", "res.kamiya2021", "res.kashmiri2017", "res.amir2018", "res.kwon2014", "res.angst2017", "res.verizon2025", "res.ibm2025", "res.weill2004", "res.ians2026", "res.graham2013"], "reflection": ["Take the largest control in your stack. Write four lines: what it protects, the annual probability it addresses, the loss if that event happens, its annual cost. Which is a quote and which is a guess?", "When did you last recommend *against* buying a control you had asked for? If never, what does your CEO conclude from that?", "What is the highest-value asset you are deliberately under-protecting because the marginal dollar buys more elsewhere? Can you defend that in Gordon–Loeb terms, or have you simply not looked?", "Name one purchase from the last two years that is a symbolic adoption — funded, installed, untouched by any routine. What would substantive adoption cost, and is it worth more than the next new thing on your list?", "Write both Risk Corollary sentences for the biggest open decision on your desk. If the second clause of the \"No\" sentence is empty, what does that tell you?", "Who signed your last risk acceptance? If the honest answer is that you did, whose risk was it — and what would it have cost to ask for the signature?"], "simulation_ref": "sim.m03-harrowgate-budget", "knowledge_check": [{"id": "m03-kc1", "type": "multiple_choice", "question": "The Gordon–Loeb (2002) result that optimal security investment \"does not exceed 37% of the expected loss from a breach\" should be presented as:", "answer": "C", "explanation": "A model result, not an empirical or regulatory one; the bound is conditional on assumptions that must be stated whenever it is quoted.", "options": [{"key": "A", "text": "An empirical finding about how much firms spend"}, {"key": "B", "text": "A universal ceiling on security budgets"}, {"key": "C", "text": "An analytical-model result holding only for the breach-probability functions the authors assume, with later work showing other functions can justify 50% or more"}, {"key": "D", "text": "A regulatory expectation under the NIST Cybersecurity Framework"}]}, {"id": "m03-kc2", "type": "multiple_choice", "question": "Angst, Block, D'Arcy and Kelley (2017), across more than 5,000 US hospitals and 938 breaches, found that:", "answer": "B", "explanation": "The same dollar bought protection only where adoption was substantive — the reason \"fund the tool but not the operator\" is not half a control.", "options": [{"key": "A", "text": "Higher spending was associated with fewer breaches regardless of implementation"}, {"key": "B", "text": "Symbolic adoption diminished the effectiveness of IT security investments, increasing breach likelihood, while deeper integration into IT routines was associated with fewer breaches"}, {"key": "C", "text": "Hospitals that bought more tools reported fewer breaches"}, {"key": "D", "text": "Board technology committees reduced breach costs"}]}, {"id": "m03-kc3", "type": "multiple_choice", "question": "Which use of the Verizon DBIR (2025) or the IBM/Ponemon report (2025) fits this curriculum's evidence rules?", "answer": "C", "explanation": "Both are Tier 3 and self-selected: usable for base rates, never causally or as a firm's loss forecast.", "options": [{"key": "A", "text": "\"Ransomware is in 44% of breaches, so this control cuts our risk by 44%\""}, {"key": "B", "text": "\"The average breach costs $4.44 million, so that is our exposure\""}, {"key": "C", "text": "\"In a non-random sample of 12,195 confirmed breaches, credential abuse was the most common initial vector at 22% — a base rate that informs, but does not set, our probability estimate\""}, {"key": "D", "text": "\"IBM's report shows firms with AI governance policies have fewer breaches\""}]}, {"id": "m03-kc4", "type": "multiple_choice", "question": "Kwon and Johnson (2014), studying US healthcare organizations, found that:", "answer": "B", "explanation": "Timing is a multiplier on the same dollar, and the external-pressure result warns against spending that exists to satisfy an examiner.", "options": [{"key": "A", "text": "Reactive investment after a breach was more cost-effective than proactive investment"}, {"key": "B", "text": "Proactive investments were associated with lower failure rates and were more cost-effective than reactive ones, and external pressure decreased the effect of proactive investment"}, {"key": "C", "text": "Regulatory pressure strengthened the benefit of proactive investment"}, {"key": "D", "text": "Security investment had no association with failure rates"}]}, {"id": "m03-kc5", "type": "short_answer", "question": "A CEO asks what a proposed $46,000-a-year control buys. Name the four inputs the method needs and the sentence you should end on.", "answer": "The specific asset or path being protected; the annual probability without the control; the loss if it happens, as a range with a central estimate; and the control's effect on that probability. End on a break-even claim — \"this pays for itself if it moves the annual probability by more than X percentage points\" — and say which numbers are quotes and which are guesses.", "explanation": "Expected loss before minus after, against cost; the break-even framing turns an unfalsifiable ask into a claim the business can contest."}], "takeaways": ["Security is a spending decision under uncertainty. Gordon and Loeb (2002) give the discipline — spending as a function of expected loss, with falling marginal returns and a bound conditional on the model's assumptions — not a budget.", "Breach-cost research prices investor expectations at large public firms, and prices the *type* of breach rather than the fact of one (Campbell et al., 2003; Cavusoglu et al., 2004; Kamiya et al., 2021). It is not your invoice.", "Two multipliers sit on every dollar: timing (Kwon & Johnson, 2014) and depth (Angst et al., 2017). Funding a tool without its operator is not half a control; it may be no control and a line item.", "Practitioner reports — DBIR 2025, IBM/Ponemon 2025 — are Tier 3, non-random and vendor-adjacent. Use them for base rates; never causally, never as your firm's exposure.", "The Risk Corollary is the budget instrument: \"Yes — and here is the risk, priced,\" with a named signatory, and \"No — and here is what would change my answer,\" with a trade the business can execute. Both require arithmetic — and the ask you withdraw is what makes the rest credible."], "videos": ["vid.00-pricing-risk-the-economics-of-security-l", "vid.00-the-37-bound-and-what-it-does-not-mean", "vid.00-yes-and-no-unless-the-budget-conversatio"], "glossary_terms": ["term.expected-loss", "term.gordonloeb-model", "term.risk-corollary", "term.proactive-investment", "term.symbolic-adoption", "term.substantive-adoption", "term.risk-acceptance", "term.enablement-with-institutional-paranoia"], "tags": {"dials": ["aggression_caution", "innovation_operational_discipline", "optimism_skepticism", "urgency_patience"], "archetypes": ["arch.business-risk-ciso", "arch.mid-market-cio", "arch.regulated-industry-cio-ciso", "arch.smb-msp-technology-leader", "arch.technical-ciso"], "stages": ["mature", "regulatory_reputation_crisis", "scale_up"], "learn_categories": ["risk", "decision_making"]}, "estimated_minutes": 80, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/03-pricing-risk.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m04", "slug": "confidence-overconfidence-and-the-breach", "title": "Confidence, Overconfidence, and the Breach", "unit": "I. The Technology Executive's Mind", "big_idea": "Breaches do not fire technology executives; the response to breaches does — and the same overconfidence that builds a program can conceal its failure.", "effectiveness_equation_term": "Behaviors", "learning_objectives": ["State precisely what Banker and Feng (2019) found about CIO turnover after breaches, why breach type matters, and what the study does not cover.", "Describe the SEC's 2023 cybersecurity disclosure regime as FACT, and the materiality determination inside it as judgment.", "Distinguish productive conviction from epistemic arrogance in a live incident, using observable behaviors rather than tone.", "Apply the Two-Sentence Test and the Risk Corollary under time pressure, as scheduled mechanisms rather than dispositions."], "sections": {"core_lesson": "Anyone who has been in the room during a serious incident knows the two failure modes, and both are made of confidence. The first is the leader who will not commit: every hypothesis provisional, every decision waiting for more telemetry, the organization drifting because nobody said \"we are treating this as X until 6pm.\" The second is the leader who commits and then stops listening: the first theory becomes the only theory, contradicting evidence becomes noise, and the room gets smaller.\n\nThis module is about the ridge between them, and about what happens afterwards. The evidence on executive turnover after breaches is more specific than the folklore — it concerns CIOs, not CISOs, and only one category of breach is charged to them. The disclosure regime is a legal fact with a four-business-day clock, and the judgment inside it is yours. And the psychology of overconfidence, borrowed from the CEO literature, names a dangerous pattern: discounting the unpleasant objective feedback your program generates while amplifying on the pleasant social feedback your role attracts. Productive conviction and epistemic arrogance look identical from outside for about an hour; after that they diverge in observable ways, and the divergence can be designed rather than hoped for.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module changes the **Current Moment** term. An incident is the moment; how you hold confidence inside it is the variable.", "big_idea": "**Not every breach is charged to the same executive — accountability follows the perceived scope of your duties, and the response you run is part of what decides which kind of breach yours becomes.**\n\nThe first half is a research finding, stated carefully below. The second is an interpretation, and the reason this module exists: attribution happens in descriptions written after the fact, and what you can show you knew, priced and escalated beforehand is most of what those descriptions have to work with.", "research": "### Who loses their job, and for which breach\n\n**RESEARCH FINDING.** Banker and Feng (2019) matched disclosed breaches to executive changes and found that breaches attributed to **system deficiency** \"increase CIO turnover likelihood by 72 percent,\" while breaches caused by **criminal fraud or human error** showed **no significant association** with CIO turnover. The pattern differs by seat: CEO turnover increased after both system-deficiency and human-error breaches, and CFO turnover showed no relationship at all. The authors frame it as \"negative labor market consequences for executives who fail to meet performance expectations within the scope of their duties.\"\n\nThree qualifications, none optional. This is a study of **CIO** turnover; there is no CISO turnover study in this library, and anyone quoting \"72%\" about CISOs is quoting something that was not measured. Breach-cause classification relies on public descriptions, so the study measures how breaches were *characterized*, not their underlying physics. And turnover is not always dismissal; these are associations.\n\n**RESEARCH FINDING.** Haislip, Lim and Pinsker (2021), using reported breaches from 2005 to 2017, found \"CEOs with IT expertise are associated with fewer DSBs,\" that CFOs with IT expertise were less likely to report breaches, and that \"the presence of a CIO as part of the TMT is significantly associated with reduced DSBs of all types examined.\" Expertise was coded from biographies; only reported breaches are observable; the CFO result may reflect reporting behavior. Associations, not a causal case for any appointment.\n\n**RESEARCH FINDING.** Higgs, Pinsker, Smith and Young (2016) found that over 2005–2014 \"firms with technology committees are more likely to have reported breaches in a given year than are firms without the committee,\" and that \"the presence of a technology committee mitigates the negative abnormal stock returns arising from external breaches.\" Reported breaches conflate occurrence, detection and disclosure; committee formation is endogenous. Visible board oversight changes both what gets reported and how it is priced.\n\n### Disclosure: the rule, and the concealment premium\n\n**FACT.** The SEC adopted its cybersecurity disclosure rules on 26 July 2023. Form 8-K Item 1.05 requires disclosure of a material cybersecurity incident — nature, scope, timing and material impact — **within four business days after the registrant determines the incident is material**. Regulation S-K Item 106, which appears as Item 1C in Form 10-K, requires annual disclosure of the processes for assessing, identifying and managing material cyber risks, the material effects of risks and prior incidents, the board's oversight of cyber risk, and \"management's role and expertise in assessing and managing material risks.\" Comparable requirements apply to foreign private issuers on Forms 6-K and 20-F. Annual disclosure began with fiscal years ending on or after 15 December 2023 and incident disclosure from 18 December 2023, with smaller reporting companies given 180 additional days. The rule is a legal requirement, not a finding.\n\n**RESEARCH FINDING.** Amir, Levi and Livne (2018) compared attacks firms disclosed with attacks they withheld that outsiders later revealed: \"withheld cyber-attacks are associated with a decline of approximately 3.6% in equity values in the month the attack is discovered, and disclosed attacks with a substantially lower decline of 0.7%.\" The authors estimate managers disclose when investors already suspect about a 40% likelihood of an attack. Attacks never discovered are unobservable by construction, and the period predates the SEC rules. **RESEARCH FINDING.** Campbell et al. (2003) add the type condition — the significant market reaction appeared for breaches involving unauthorized access to confidential data and not otherwise — and Kamiya et al. (2021) found firms whose boards had attended to risk management *before* an attack suffered smaller excess losses. The response is priced, and so is the preparation.\n\n### Overconfidence, and how leaders respond to feedback\n\n**RESEARCH FINDING.** Malmendier and Tate (2008, from the CEO library) found that CEOs classified as overconfident — by an option-holding **proxy** (failing to diversify personal exposure to their own firm) and a press-portrayal proxy — were about 65% more likely to make an acquisition, and that the market reacted more negatively to their deals (about −90 basis points against −12 for other CEOs). Both measures are proxies, the panel predates 1995, and alternative explanations were addressed but not eliminated. Overconfidence is a measurable tendency to over-weight one's own judgment, with visible costs.\n\n**RESEARCH FINDING.** Chatterjee and Hambrick (2011, from the CEO library) introduced \"capability cues\" — contextual signals about one's current ability — and found CEO risk-taking generally rose after positive cues and fell after negative ones, but that highly narcissistic CEOs were much *less* responsive to objective performance feedback and considerably *more* responsive to social praise such as media coverage and awards. Archival panels (capital outlays 1992–2006; acquisition premiums 2001–2008), an unobtrusive index, associations.\n\n**RESEARCH FINDING.** Edmondson (1996) studied eight nursing units across two hospitals (146 respondents) and found units with stronger team climates and more active manager coaching showed *higher* detected error rates (r = .74 for coaching) — because error rates come from reporting systems that climate itself affects. Owens and Hekman (2012, from the CEO library) identified three observable humble-leader behaviors and found humility appears *less* effective under extreme threat or time pressure.\n\n### Where the evidence is weak\n\nThere is no study here of CISO turnover, of executives under the SEC rules, or of whether any response behavior changes how a breach is later attributed. Banker and Feng (2019) is the closest finding on executive accountability, and it concerns CIOs and public characterizations. The overconfidence literature is about CEOs, uses proxies, and transfers to the technology executive only by argument. Everything this module says about conviction inside an incident is **FRAMEWORK** and **INTERPRETATION**.", "explanation": "### The asymmetry, and what it implies\n\n**RESEARCH FINDING.** Start from the finding, exactly: system-deficiency breaches were associated with a 72% higher likelihood of CIO turnover; fraud and human-error breaches were not. The CEO's exposure was broader — turnover rose after system-deficiency *and* human-error breaches — and the CFO's was nil.\n\n**INTERPRETATION.** Read that as a map of perceived duty: the CIO owns the systems, the CEO the systems *and* the people, the CFO neither. The corollary is uncomfortable — whether a breach is yours depends less on what happened than on which story fits it. A stolen credential used by a criminal group is a fraud story; a clerk approving a fraudulent invoice is human error; an unpatched edge device with a known exploit is system deficiency. One intrusion can be described all three ways depending on where the account starts.\n\n**HYPOTHESIS.** The most consequential thing a technology executive does before an incident may therefore be documentary. If the exception log shows the edge device was flagged, priced and deferred by a named business signatory — Module 2's second decision right and Module 3's Risk Corollary — the account contains a fact no defensive narrative could supply afterwards. Nothing here tests that; it is the implication of a study showing attribution matters, plus the observation that attribution is built from records. Note what it does *not* license: building a record so blame lands elsewhere is a different activity from building one so decisions are visible, an organization tells them apart within a quarter, and the first destroys the reporting culture Module 5 depends on.\n\n### Overconfidence, translated\n\n**INTERPRETATION.** The CEO overconfidence literature transfers with one substitution. Malmendier and Tate's (2008) proxy is a CEO who declines to diversify away exposure to their own firm — behavior that says \"my judgment about this company beats the market's.\" The security analogue is the executive who declines to expose their own program to independent judgment: no external red team, no third-party assessment, no standing second opinion, no adversarial review of the architecture they designed. **HYPOTHESIS.** Under-diversified assurance is the equivalent, and unlike a personality it is visible in a calendar and a budget.\n\nChatterjee and Hambrick's (2011) capability cues are the sharper tool: risk-taking tracked feedback, but the most narcissistic executives discounted objective performance feedback and responded strongly to social praise. **INTERPRETATION.** Security leadership offers a bad ratio of the two. Objective cues arrive as criticism — pen-test findings, control failures, missed detections, an audit reopening a closed item. Social cues are pleasant and abundant — a board compliment, a conference invitation, an award, a profile after a clean year. An executive who does not deliberately weight the first over the second is calibrated by the wrong signal; Module 12 returns to this as the celebrity problem.\n\n### Productive conviction versus epistemic arrogance, inside an incident\n\n**FRAMEWORK.** Both begin identically: the executive commits early and publicly to a working account, because an incident with no committed hypothesis is one where forty people investigate forty things. The divergence is structural and shows up in five places.\n\n*The claim.* Conviction says \"we are treating this as credential compromise on the build pipeline.\" Arrogance says \"this *is* credential compromise on the build pipeline.\" One is a decision; the other is a fact that has not been earned.\n\n*The kill criteria.* Conviction names in advance what would overturn the hypothesis: \"if egress logs show nothing outbound from that subnet by 4pm, we are wrong.\" Arrogance never specifies what would change its mind, which is what makes contradicting evidence look like noise.\n\n*The clock.* Conviction schedules the review at fixed intervals, with a named person whose job is to argue the alternative. Arrogance revisits when it feels like it, which under stress is never.\n\n*The room.* Conviction gets larger as confidence rises, because a confident hypothesis is cheap to test. Arrogance narrows to the same three names.\n\n*The report upward.* Conviction carries the confidence level and the alternative alongside the hypothesis. Arrogance reports only the hypothesis, because uncertainty feels like weakness — and a CEO who hears only certainty at hour six hears only betrayal at hour thirty.\n\n**INTERPRETATION.** These are mechanisms, not virtues, deliberately. Owens and Hekman (2012, from the CEO library) suggest humility appears less effective under extreme threat or time pressure — exactly the condition an incident creates. Do not rely on being humble at 3am: write the kill criteria into the procedure, put the review on the clock, and name the dissenter in the runbook before you need one.\n\n### The disclosure decision, as judgment inside a fact\n\n**FACT.** The rule's four-business-day clock starts at the materiality determination, not at discovery (SEC, 2023). **INTERPRETATION.** That puts the judgment where the rule cannot reach. The determination is legal, financial and factual at once, which is why the technology executive's job in it is narrow and non-negotiable: give counsel and the CEO an accurate, current, uncertainty-labeled picture, including what is not yet known, and update it when it changes. Deciding materiality is not the CISO's call; corrupting the inputs to it is the CISO's failure. Amir et al. (2018) supply the economics — concealment is priced at discovery, not at the decision.\n\n### A documented case: the decision to conceal\n\n**FACT.** Joseph Sullivan, then Uber's chief security officer and previously Facebook's, was convicted in October 2022 of obstruction and misprision of felony for concealing Uber's 2016 breach, sentenced in 2023, and had the conviction affirmed by the Ninth Circuit on 13 March 2025 (*United States v. Sullivan*, No. 23-927).\n\nAnalyze the decision class, not the man. The course takes no position on his character, motives or the fairness of the outcome, and nothing in this curriculum's sources would support one. What the case establishes is narrower and more useful: **concealing a breach from parties entitled to know it is a decision a security executive can personally be prosecuted for, and an appellate court has affirmed a conviction on those facts.** The exposure is personal and criminal rather than merely corporate, which changes the calculus of any \"we'll handle this internally\" conversation. It predates the SEC rules, so the decision class exists independently of any disclosure regulation. And it is the pattern this module describes in its most consequential form: an executive with standing, inside an incident, deciding alone what other people needed to know.\n\n### The two sentences under time pressure\n\n**FRAMEWORK.** The Two-Sentence Test changes shape under time pressure. \"We're going to do this\" acquires a time box: \"we act on this hypothesis until 4pm.\" \"I was wrong. Change the plan\" becomes an appointment rather than a virtue — the scheduled review is where it gets said on time, by design, instead of at hour thirty when it has become an admission.\n\nThe Risk Corollary runs the same way. **\"Yes — and here is the risk, priced\"**: \"Yes, we can restore the ERP tonight; the risk is reinfection from an image we have not finished validating — one chance in four, five more days down if it happens.\" **\"No — and here is what would change my answer\"**: \"Not tonight; what would change it is a clean differential on the two remaining images, six hours of work I can start now.\" Both require a price under time pressure, which is why Module 3 comes first.", "example": "*Fictional composite.* Merrimack Instrument Corporation is a NASDAQ-listed precision-instruments manufacturer in Lowell, Massachusetts: $640 million in revenue, 2,300 employees. Ellen Barros is CIO; Dev Kapoor is CISO and reports to her. On a Tuesday at 06:40 the managed detection provider flags anomalous authentication against a build server in the firmware pipeline, inside a vendor-managed continuous-integration environment.\n\nBy 08:15 Kapoor has a hypothesis and states it as one: \"We are treating this as a compromised service account in the CI tenant, with no movement into the plant networks. If we are wrong, the tell is outbound traffic from the plant VLANs to anything we cannot name, and we check at 12:00.\" He names the plant network engineer as designated dissenter, whose only job today is to argue the other case.\n\nAt 12:00 the dissenter has something. Not outbound traffic — a firmware build artifact signed nineteen hours *before* the authentication anomaly. The hypothesis is not merely incomplete; its timeline is backwards.\n\nThis is the moment the module is about. Kapoor's credibility is attached to the 08:15 account, the CEO has been briefed on it, and treating the artifact as a logging anomaly would cost nothing today. Instead the review does what it was built for: \"I was wrong about the timeline. We are now treating this as a supply-chain compromise of the build environment, duration unknown. Confidence medium. The alternative I cannot exclude is a mislabeled rebuild, and I will know by 18:00.\"\n\nThen the disclosure question. Counsel opens the materiality file; the CFO models exposure. Kapoor's job is inputs — what is known, what is not, what would change each. He declines to offer an opinion on materiality and says so when the CEO asks, then adds what the CEO actually needs: the four-business-day clock under Form 8-K Item 1.05 begins when the company determines materiality (SEC, 2023), so the pace of that determination is a decision to make deliberately rather than by drift.\n\nThree days later the attribution question arrives as a draft statement. System deficiency, or criminal intrusion? Both descriptions are available. The CI environment had been flagged eight months earlier in an architecture review — no separate signing enclave, shared service credentials, no independent verification of build artifacts. Kapoor priced remediation at $310,000, recommended it, was deferred a quarter on cost, and because Merrimack runs its exception log properly the deferral is signed by the COO in Kapoor's own words.\n\n**INTERPRETATION.** That signature does not protect Kapoor's job and is not meant to. It makes the eventual account accurate in a way no post-incident narrative could: a known weakness, priced, escalated and consciously accepted, followed by an intrusion that exploited it. Merrimack discloses; the COO's deferral practice does not survive the quarter; and the review that gets written is about the decision rather than about who to blame.", "ceo_contrast": "Hour six at Merrimack, four archetypes in Kapoor's chair.\n\n**The Technical CISO** is deepest in the artifacts and slowest to commit. Every hypothesis stays provisional because the evidence genuinely is incomplete — true, and at hour six unhelpful. The gain is that this archetype rarely commits to a wrong account. The cost is that forty people investigate forty things, the CEO gets no usable statement, and the vacuum is filled by whoever is most confident in the room, usually a vendor. The Overuse Ladder rung is **humility → hesitation**, and it costs more in an incident than anywhere else.\n\n**The Business-Risk CISO** commits early, communicates well, and briefs upward with a clean narrative. The gain is an organization that moves. The risk is what Chatterjee and Hambrick (2011, from the CEO library) describe from the other end: responsiveness to the social cue — the CEO's visible relief at a clear story — and slowness to weight the objective cue that contradicts it. The scheduled hypothesis review is the control for this archetype, and it works only if someone other than the CISO owns the calendar entry.\n\n**The Post-Breach CISO (Turnaround)**, brought in after a prior failure, centralizes hard: single bridge, single voice, decisions in hours. Often correct — a program that has just failed usually needs less consultation, not more. But a narrowed room is the shape epistemic arrogance takes, so the archetype most likely to be right about strategy is the most likely to miss the artifact at 12:00. The mitigation is not more consultation; it is a named dissenter and a review on the clock.\n\n**The Regulated-Industry CIO/CISO** has the disclosure machinery built — counsel in the first hour, the materiality file open, the audit committee on a schedule — so nobody improvises the legal question at 3am. The cost is subtler: when the disclosure clock dominates, the incident gets managed toward a defensible filing rather than toward the truth about the environment. **INTERPRETATION.** The tell is the first time someone edits a timeline for how it will read rather than for whether it is right.", "failure_mode": "Confidence becomes destructive on two rungs of the Overuse Ladder, and the incident context accelerates both.\n\n**INTERPRETATION.** **Confidence → arrogance** is the classic path: the hypothesis becomes an identity, the dissenter is reframed as unhelpful, the bridge narrows, and the executive stops distinguishing \"I decided this\" from \"this is true.\" The mechanism is not stupidity — under time pressure a committed hypothesis is enormously efficient, and abandoning it is expensive, visible and personally costly at the moment the executive has least slack.\n\n**Optimism → delusion** is slower and operates between incidents: the executive who reads a quiet quarter as a working program, when Edmondson (1996) shows low reported-error counts can equally mean people stopped reporting. Paired with the capability-cue asymmetry, it produces a leader fed by conference invitations and starved of pen-test findings.\n\n**Decisiveness → impulsiveness** is the third, specific to hour one: declaring the incident contained before the evidence supports it, because closure is what everyone in the building wants from you.\n\nEarly warning signs, for the executive, the CEO or the board:\n\n- Nobody in the last three incidents can name the evidence that would have overturned the leading hypothesis.\n- The incident bridge has fewer people on it at hour twelve than at hour two, and no one decided that.\n- The program has had no external red team, third-party assessment or adversarial architecture review in a year.\n- Reported near-misses and phishing reports are falling, and this is being presented as improvement.\n- Post-incident reviews name people more often than they name decisions."}, "research_refs": ["res.banker2019", "res.haislip2021", "res.higgs2016", "res.sec2023", "res.amir2018", "res.kamiya2021", "res.campbell2003", "res.edmondson1996", "res.malmendier2008", "res.chatterjee2011", "res.owens2012"], "reflection": ["Take your last serious incident. What was your hour-one hypothesis, and what evidence had you named in advance that would overturn it? If none, what were you actually doing when you said you were investigating?", "Who is the designated dissenter in your incident procedure — by name, in the document? If nobody, who plays that role informally, and what has it cost them?", "Over the last twelve months, what exposed your program to independent judgment — red team, third-party assessment, adversarial review? If the answer is thin, is that a budget decision or a preference?", "Of the last five significant pieces of feedback about your program, how many were objective (findings, failures, misses) and how many social (praise, invitations, recognition)? Which set changed a decision?", "If a breach at your company were described three ways — criminal fraud, human error, system deficiency — which would the public record best support, and what did you do this year that determines the answer?", "Write the sentence you would say to your CEO at hour twelve if your hour-one account turned out to be wrong. Say it out loud. Is the discomfort about the company or about you?"], "simulation_ref": "sim.m04-narragansett-notification", "knowledge_check": [{"id": "m04-kc1", "type": "multiple_choice", "question": "Banker and Feng (2019) found that:", "answer": "B", "explanation": "The study is about **CIO** turnover, and only system-deficiency breaches were associated with it; CEO turnover rose after system-deficiency and human-error breaches, and CFO turnover showed no relationship.", "options": [{"key": "A", "text": "CISO turnover was 72% more likely after any disclosed breach"}, {"key": "B", "text": "Breaches attributed to system deficiency increased CIO turnover likelihood by 72 percent, while breaches caused by criminal fraud or human error showed no significant association"}, {"key": "C", "text": "CFO turnover rose after human-error breaches"}, {"key": "D", "text": "All breach types raised CIO turnover equally"}]}, {"id": "m04-kc2", "type": "multiple_choice", "question": "Under the SEC's 2023 rules, the four-business-day Form 8-K Item 1.05 clock begins:", "answer": "C", "explanation": "FACT: disclosure is required within four business days after the materiality determination — which places the judgment, and the pace of making it, inside the company.", "options": [{"key": "A", "text": "When the incident occurs"}, {"key": "B", "text": "When the incident is discovered"}, {"key": "C", "text": "When the registrant determines the incident is material"}, {"key": "D", "text": "When law enforcement authorizes disclosure"}]}, {"id": "m04-kc3", "type": "multiple_choice", "question": "Which behavior best distinguishes productive conviction from epistemic arrogance in an incident?", "answer": "C", "explanation": "Both postures commit early; the difference is falsifiability on a clock — which is a mechanism you can write into a runbook rather than a disposition you hope to have at 3am.", "options": [{"key": "A", "text": "Speaking with less certainty in briefings"}, {"key": "B", "text": "Waiting for complete evidence before committing to a hypothesis"}, {"key": "C", "text": "Naming in advance the evidence that would overturn the hypothesis, and scheduling the review that checks it"}, {"key": "D", "text": "Consulting more people before deciding"}]}, {"id": "m04-kc4", "type": "short_answer", "question": "Your reported phishing clicks and near-misses fell 40% this quarter and the CEO calls it progress. Using Edmondson (1996), what do you say?", "answer": "That the number is ambiguous. Edmondson found units with stronger team climates and more active manager coaching reported *more* detected errors, not fewer (r = .74 for coaching), because reporting depends on climate. A fall could mean fewer events or less reporting; other evidence distinguishes them — simulated-phish detection rates, time-to-report, whether people who reported last quarter had a good experience.", "explanation": "Low counts can signal silence rather than safety; reading them as progress is the optimism→delusion rung between incidents."}], "takeaways": ["Banker and Feng (2019) found breaches attributed to **system deficiency** associated with a **72% higher likelihood of CIO turnover**, with **no significant association** for breaches caused by criminal fraud or human error. CEO turnover rose after system-deficiency and human-error breaches; CFO turnover did not move. It is a CIO study, and it measures how breaches were publicly characterized.", "Because attribution is built from records, what you priced, escalated and got signed *before* the incident is most of what the eventual account has to work with — an implication, not a finding, and not a licence to build a record aimed at blame.", "Overconfidence in this role looks like under-diversified assurance (no red team, no third-party assessment, no standing second opinion) and like weighting social praise over objective findings — the capability-cue asymmetry Chatterjee and Hambrick (2011) describe.", "The SEC's four-business-day clock starts at the materiality determination (SEC, 2023). Deciding materiality is not the security executive's call; supplying accurate, uncertainty-labeled inputs to it is. Concealment is priced at discovery (Amir et al., 2018) and, as the Sullivan case establishes, can be prosecuted personally.", "Productive conviction is a mechanism, not a temperament: a time-boxed hypothesis, named kill criteria, a scheduled review, a designated dissenter, and a briefing that carries the confidence level upward with the conclusion."], "videos": ["vid.00-confidence-overconfidence-and-the-breach", "vid.00-productive-conviction-at-hour-six", "vid.00-what-banker-and-feng-actually-found"], "glossary_terms": ["term.system-deficiency-breach", "term.materiality-determination", "term.productive-conviction", "term.epistemic-arrogance", "term.capability-cue", "term.two-sentence-test", "term.risk-corollary", "term.blameless-review"], "tags": {"dials": ["decisiveness_inquiry", "hands_on_delegation", "optimism_skepticism", "unilateral_consensus"], "archetypes": ["arch.business-risk-ciso", "arch.enterprise-cio", "arch.post-breach-ciso-turnaround", "arch.regulated-industry-cio-ciso", "arch.technical-ciso"], "stages": ["mature", "regulatory_reputation_crisis", "turnaround"], "learn_categories": ["risk", "decision_making", "personality"]}, "estimated_minutes": 80, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/04-confidence-overconfidence-and-the-breach.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m05", "slug": "humility-and-the-reporting-culture", "title": "Humility and the Reporting Culture — Why People Don't Report the Click", "unit": "II. The Signature Frameworks, Adapted", "big_idea": "A security program is only as good as the worst thing someone was willing to tell you; humility is how you find out sooner.", "effectiveness_equation_term": "Behaviors", "learning_objectives": ["Define executive humility for the technology leader — accurate self-assessment, openness to corrective information, acknowledging expertise in others — and state what it is not.", "Explain, with evidence, why blame-oriented security cultures reduce reporting and why a low incident count can signal silence rather than safety.", "Install the five mechanisms of the Information-Environment Stack: near-miss reporting, blameless review, red-team standing, engineer direct lines, and the quarterly 'what we got wrong.'", "Connect the compliance research to leadership behavior: why the levers a security leader controls most directly are the ones that matter least."], "sections": {"core_lesson": "This module adapts the CEO course's humility module to the one executive whose entire function runs on other people's willingness to confess. A CEO who is not told the truth makes worse strategy. A CISO who is not told the truth has no detection layer, because the first sensor in most incidents is a human being who clicked, misconfigured, or noticed something odd and decided whether to say so.\n\n**FRAMEWORK.** Executive humility, for the technology leader, is three things a colleague could observe: accurate self-assessment of what you and your program actually know; openness to corrective information, especially the kind that embarrasses your own architecture; and acknowledgment of expertise in others — the claims processor who knows how the fraud emails really look, the engineer who knows which control is theater. It is not deference on risk, not saying yes to the business, and not a softer tone of voice.\n\nThe module explains why blame reduces reporting, why the compliance research says the levers you control most directly matter least, and how to build the Information-Environment Stack — five mechanisms that make bad news travel faster.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module changes the **Behaviors** term. The reporting culture you produce is a set of behaviors people copy. The Two-Sentence Test and the Risk Corollary depend on it: you cannot say \"I was wrong about that risk\" if nobody told you the control failed.", "big_idea": "**A security program is only as good as the worst thing someone was willing to tell you; humility is how you find out sooner.**\n\nEvery control you buy sits behind a human decision to report. The click, the shared password, the firewall rule that opened a port — each is known to someone before it is known to you, and the interval between those two moments is where breaches become expensive. Humility, in the operating sense defined here, is the executive behavior that shortens the interval.", "research": "**RESEARCH FINDING.** The anchor study is Edmondson (1996), and it is counterintuitive on purpose. In eight nursing units across two hospitals, with 146 respondents, units with stronger team climates and more active nurse-manager coaching showed *higher* detected drug-error rates — the correlation between manager coaching and detected errors was r = .74, and with intercepted errors r = .71. Edmondson's interpretation is that the better-led units were not more dangerous; they were more willing to report and discuss errors. The study is small, correlational, in healthcare rather than security, and the error rates come from reporting systems that are themselves shaped by climate — which is the paper's point. What it supports: a low incident count is ambiguous, and a security leader must read reporting numbers with the reporting climate in mind. What it cannot support: any specific ratio, or that coaching causes reporting.\n\n**RESEARCH FINDING.** Edmondson (1999, from the CEO library) formalized the construct. In 51 teams at one US office-furniture manufacturer, with surveys of 427 team members and 135 external observers, team psychological safety — a shared belief that the team is safe for interpersonal risk taking — was associated with learning behavior (seeking feedback, discussing errors, experimenting), which predicted team performance; leader coaching was an antecedent. Single company, cross-sectional, and the author says causality cannot be established. But it names the mechanism a CISO needs: people discuss errors when it is safe to.\n\n**RESEARCH FINDING.** Two CEO-library studies describe what happens when it is not safe. Milliken, Morrison and Hewlin (2003) interviewed 40 employees across industries: 85% recalled at least one occasion on which they felt unable to raise an important issue with a superior; the dominant reasons were fear of being labeled negatively and of damaging relationships, then perceived futility and fear of retaliation; and 74% of those who stayed silent said colleagues who knew of the same issue also stayed silent. Detert and Edmondson (2011), across four studies — 190 interviews at a high-tech firm, 185 executive-education participants, 265 online and MBA respondents, and a three-wave study of 116 executive MBAs — identified five \"implicit voice theories\": the boss will take it personally; you need solid data or a solution first; don't bypass the boss; don't embarrass the boss in public; speaking up damages careers. These beliefs predicted silence over and above personality and context, and persisted even where the environment was objectively safe. **INTERPRETATION.** Map the five theories onto a phishing click and you have the reporting problem in full: \"I need to be sure it was malicious before I bother the SOC\"; \"reporting my own click makes me look careless\"; \"my manager will hear.\" The employee who clicked has every reason to wait.\n\n**RESEARCH FINDING.** Cram, D'Arcy and Proudfoot (2019) is the largest synthesis of what predicts security-policy compliance: a meta-analysis of 95 papers across 17 antecedent categories. The strongest predictors were value-oriented — attitude, personal norms and ethics, and normative beliefs. Punishment and rewards, the levers management controls most directly, were among the weakest; training and perceived usefulness fell in the middle. The underlying studies are largely survey-based, measure intention more often than behavior, and yield correlational effect sizes. What it supports: sanctions are a weak instrument, and a punitive phishing program spends on the lever the evidence rates lowest. What it cannot support: that removing sanctions raises compliance, or anything about reporting specifically, which the meta-analysis did not measure.\n\n**RESEARCH FINDING.** Ashenden and Sasse (2013) interviewed five CISOs in depth. The CISOs described their own obstacles as \"a perceived lack of power, confusion about their role identity, and their inability to engage effectively with employees.\" Five UK interviews — illustrative, not generalizable. What it supports: the reporting problem is partly a relationship the CISO has failed to build, in the CISOs' own account.\n\n**RESEARCH FINDING.** The humility evidence is from the CEO library. Ou, Tsui, Kinicki, Waldman, Xiao and Song (2014, from the CEO library), in 63 private Chinese companies with data from 328 top-team members and 645 middle managers, defined CEO humility as self-awareness, openness to feedback, appreciation of others, low self-focus and self-transcendent pursuit, and found it associated with empowering leadership and top-team integration. Ou, Waldman and Peterson (2018) found in 105 US software and hardware SMEs that CEOs rated more humble by their teams had more integrated teams, associated with more ambidextrous strategy and better performance. Owens and Hekman (2012), from 55 leader interviews, induced three observable behaviors — admitting limits and mistakes, spotlighting others' strengths, modeling teachability — with two contingencies: humility works only from a leader perceived as competent and sincere, and it appears less effective under extreme threat or time pressure. Owens and Hekman (2016), across 607 participants in 161 teams, showed leader humility spreads by contagion. All correlational or team-level except the 2016 program; none is about security leaders.\n\n**RESEARCH FINDING.** Two archival studies show reporting behavior is observable and priced at the firm level. Higgs, Pinsker, Smith and Young (2016) found over 2005–2014 that firms with board-level technology committees were more likely to report breaches, plausibly because they detect and disclose more. Amir, Levi and Livne (2018) found that attacks firms withheld and that were later exposed were associated with an equity decline of approximately 3.6% in the month of discovery, against 0.7% for firm-disclosed attacks. **INTERPRETATION.** The same logic runs inside the firm: the click withheld and discovered later costs more than the click reported.\n\n### Where the evidence is weak\n\nNothing here measures the reporting climate inside a security function directly. Edmondson (1996) is about drug errors in eight units; the silence literature is not security-specific; the humility studies are about CEOs and teams; Cram et al. (2019) measures compliance intention, not reporting. The Information-Environment Stack is a **FRAMEWORK** no study tests. That a humble technology leader gets bad news faster is an inference the evidence supports strongly and no study has tested at CISO level.", "explanation": "### Humility, defined for someone whose job is to say no\n\nNobody hires a CISO to be modest. **FRAMEWORK.** Executive humility, for the technology leader, is three behaviors.\n\nAccurate self-assessment — of the program, not just the person. What does your detection actually cover? Which controls on the board slide are substantive and which are symbolic? A CISO who says \"we have MFA everywhere\" when they mean \"on the systems we know about\" has failed the first test, and the failure is not modesty but arithmetic.\n\nOpenness to corrective information — wanting to hear the thing that contradicts your architecture, from the people least likely to bring it. The engineer who says the EDR agent is not on the finance file server. The claims supervisor who says her team shares a login because the workflow tool times out. The pen-tester who found what your own review missed.\n\nAcknowledging expertise in others — treating the people closest to the work as sensors rather than as risks. The Ashenden and Sasse (2013) CISOs described themselves as unable to engage with employees; this behavior is the correction.\n\n### What it is not\n\n**INTERPRETATION.** Humility is not deference on risk. A humble CISO still says \"No — and here is what would change my answer\"; humility is about the accuracy of the price, not the softness of the delivery. It is not saying yes: the vCISO who grants the client's owner an MFA exception because the owner was insistent is conflict-avoidant, which is the Overuse Ladder's empathy rung. And it is not lack of confidence. The Owens and Hekman (2012) contingency cuts both ways: a visibly weak program cannot buy credibility with candor, and a strong one cannot keep it without candor.\n\n### Why blame reduces reporting\n\n**INTERPRETATION.** Put the silence research and the compliance research together and the mechanism is clear.\n\nEvery employee who clicks has, by Detert and Edmondson (2011), a set of learned rules about whether to say so, mostly learned somewhere else. A phishing simulation that publishes department results, a three-strikes policy, a manager told which of their people failed — each confirms the rules. The employee has a private fact (I clicked) and a public choice (do I tell?), and the organization has just made the public choice expensive.\n\nThen add the executive's contribution, which Tourish and Robson (2006, from the CEO library) describe conceptually: the more committed a leader is to a course of action — \"our awareness program works,\" \"our architecture is sound\" — the more they classify contrary information as noise. Employees read the signal. The result is an information environment both sides built and neither can see from inside.\n\nThe consequence is the Edmondson (1996) inversion applied to security. Your reported-click count falls. Your dashboard turns green. And your actual detection has moved from \"a human tells us within minutes\" to \"the gateway logs it and someone eventually looks\" — a change invisible in the metric that just improved.\n\n### The reported-to-detected ratio\n\n**FRAMEWORK.** The most useful number this module offers is the ratio of incidents reported by people to incidents detected by telemetry, tracked over time. If the gateway sees forty clicks on a lure in a month and eight are reported, the ratio is 0.2. If a policy change drives reported clicks to two while the gateway still sees forty, the ratio has fallen to 0.05 and your program has gotten worse while its headline number improved. Edmondson (1996) is the evidence that the count alone misleads; the ratio reads it correctly. Its denominator covers only what your telemetry sees — one more reason to want the numerator.\n\n### Why the levers you control matter least\n\n**INTERPRETATION.** Cram et al. (2019) is uncomfortable reading for anyone with a sanctions policy. The technology leader controls sanctions directly and norms only indirectly, through behavior — so the reporting culture is shaped less by the policy you write than by what people watched happen to the last person who reported. One punished messenger costs years. One visibly thanked messenger, in front of their manager, does more than a quarter of training modules. This is where humility stops being a nicety and becomes a control: the three behaviors above are the executive actions that move norms.\n\n### The Information-Environment Stack\n\n**FRAMEWORK.** Humility as a disposition is unreliable under pressure, and Owens and Hekman (2012) warn it is less effective in crisis — which is when a security function most needs it. So install it as mechanism. Five layers, built in order, each depending on the one below.\n\n**Near-miss reporting.** A channel — one click, one message, no form — for \"I think I did something\" and \"I noticed something,\" with an explicit statement that near-misses are wanted and a visible response to every one within a day. The near-miss is the cheapest information a program receives: the event happened, nothing was lost, the pattern is now known. Expect the count to rise; a rising near-miss count is the Edmondson (1996) signal of a healthier climate.\n\n**Blameless review.** Every incident and near-miss reviewed for what the system allowed, not who failed. The rule is not \"nobody is accountable\"; it is \"the reporter is not the subject of the review.\" Reckless or repeated conduct is handled separately, by management, and the boundary is stated in advance so that \"blameless\" does not become \"consequence-free.\" The output is a change to a control or a default — and the reporter sees it.\n\n**Red-team standing.** A person or contracted function whose job is to find what the program missed, with standing to present it to you unsoftened and, on a schedule, to your CEO or audit committee. The test is what happens when the findings embarrass your own architecture. If the answer is a smaller engagement next year, you do not have red-team standing; you have a vendor.\n\n**Engineer direct lines.** Skip-level channels from the people who run the systems to the executive who owns the risk, with no agenda beyond \"what would you fix, and what have you stopped mentioning?\" — followed by visible action on something raised. Milliken et al. (2003) found the most-withheld issues concern competence and process failures. Those die in the layer between an engineer and a manager who owns the control.\n\n**The quarterly \"what we got wrong.\"** A short written account, from you, of the quarter's misses: the near-miss that should have been caught earlier, the control on the slide and not on the server, the risk you priced wrong. Sent to your CEO and, where the business allows, to the people whose reports made it possible. This is the top of the stack because it is the executive behaving the way the stack asks everyone else to behave — modeling how to grow, in Owens and Hekman's (2012) phrase. The engineer who watches the CISO write \"I was wrong about that risk\" learns what reporting costs here.\n\n**HYPOTHESIS.** A program with all five layers detects human-originated incidents earlier than an otherwise identical program without them, visibly in the reported-to-detected ratio within two quarters. Untested.\n\n### The fractional version\n\n**INTERPRETATION.** The vCISO or MSP leader has a harder version: the reporting culture belongs to the client, whose owner may be the person least willing to hear bad news. The stack still applies, scaled down — a near-miss channel to the MSP, a blameless review with the client's manager present, an annual pen-test reported to the owner in writing, a quarterly note on what the MSP got wrong. The last is commercially frightening and, in practice, valuable: a client told the truth about a miss trusts the next green dashboard more, not less.", "example": "*Fictional composite.* Harbor Point Business Services is a business-process and managed-services firm in Providence, Rhode Island, with $34M in revenue, 210 employees, and about 160 clients across the Northeast — registered investment advisers, two small broker-dealers, physician groups, law and accounting firms, a few regional retailers. Daniel Okafor is its CIO and CISO, a former network engineer who built the multi-tenant stack the firm runs its clients on and who leads a vCISO practice for around 40 of them.\n\nTwo years earlier, a tier-2 engineer had mis-scoped a firewall change on a client tenant, exposing a remote-desktop gateway for about three days before a routine scan caught it. The engineer received a written warning; the account manager told the client it was \"a vendor-side configuration issue\"; the engineer left within four months. The organization learned two things: configuration mistakes are career events, and clients are told a version. Near-miss reports afterward ran at two or three a quarter across 40 engineers making hundreds of changes a week. The dashboards were green.\n\nThen, on a Thursday in March, Luis Ferreira, a tier-2 engineer nineteen months into the job, pushed a rule change on the tenant of Bramhall Securities, a 38-person broker-dealer and FINRA member. Forty-one hours later, reviewing logs for a different ticket, he saw brute-force attempts against a remote-desktop port that should not have been reachable. His change had opened it. He had, by his own account, about ten minutes of wanting to close the port quietly and say nothing. He closed the port, and then he messaged Daniel directly.\n\nWhat Daniel did in the next 48 hours is the point. He thanked Luis in the message, then again at the next morning's stand-up in front of Luis's manager, and said why: forty-one hours of exposure with a report is a near-miss; forty-one hours with no report is a breach nobody knows about. He ran the review that afternoon with Luis present and with the rule that the subject was the change process, not the engineer. The review found no post-change external scan in the template, peer review skipped on \"minor\" rules with no definition of minor, and thirty days of client log retention — enough to see the attempts, not enough to be sure about the previous quarter. Three controls changed within two weeks. He then called Bramhall's managing principal and told him exactly what had happened, including the forty-one hours. The principal was angry for about ten minutes and then asked whether the same review would apply to his own staff. It did.\n\nOver two quarters Daniel built the rest of the stack: a one-line near-miss channel in the engineering chat; blameless reviews with a stated boundary; an annual external pen-test whose lead presented to Harbor Point's CEO without Daniel in the room; monthly skip-levels with engineers; and a quarterly note to the CEO, later to the vCISO clients, titled \"What we got wrong,\" which the sales team asked him not to send.\n\nNear-miss reports went from three a quarter to nineteen. Reported phishing clicks doubled while detected clicks stayed flat — the ratio moved from roughly 0.2 to roughly 0.5. Two changes that would have exposed client data were caught by their own authors within an hour. One client questioned the quarterly note hard and stayed; two prospects cited it when they signed. Daniel's own read is that the program did not get more secure in those two quarters. It got more honest, which turned out to be the same thing measured later.", "ceo_contrast": "Take Harbor Point at the moment Luis Ferreira's message arrives.\n\n**The Technical CISO** sees a configuration failure and fixes the configuration — thoroughly, quickly, personally. The change template gets a post-change scan by the end of the day. What the Technical CISO is less likely to do is the public thanks, the review with the engineer present, and the call that says forty-one hours out loud. The gain is a tighter control within hours. The cost is that the floor watches the CISO take the problem away from the person who reported it, and learns that reporting means losing ownership. The stack's bottom layer is never built because the leader is too capable to need it.\n\n**The Business-Risk CISO** reads the event as a client-relationship and liability problem. The instinct is a well-managed disclosure: a controlled call, a written summary, an offer of a credit. Not wrong — Amir et al. (2018) suggest disclosure is priced better than concealment — but the Business-Risk CISO can run the external conversation well and leave the internal one untouched, treating the engineer's report as an input rather than the most valuable thing that happened that week. The gain is a retained client. The cost is a reporting culture that has not moved.\n\n**The Post-Breach CISO** treats the near-miss as the breach they were hired to prevent. Centralize change approval, require sign-off on every rule, add a second reviewer. In a genuine post-breach turnaround this is right. Here it is the Overuse Ladder's rigor rung — the security review that ships nothing — imposed on a team that just demonstrated it will self-report. The cost is that the next engineer with a ten-minute window of wanting to say nothing does the math on the new process and says nothing.\n\n**The Regulated-Industry CIO/CISO** asks the right first question — is this reportable, and what does the client's written supervisory procedure require? — and builds the review around the record. The gain is a defensible file for a FINRA member. The cost is a review written for an examiner rather than for engineers, in which the language of accountability quietly reintroduces the blame the review was meant to remove. The mature version holds both documents and knows they are different.\n\n**INTERPRETATION.** Daniel Okafor's response drew on all four and added the one thing none reaches for by default: he made the reporter the hero of the story, in front of the people who would decide whether to report next time.", "failure_mode": "**FRAMEWORK.** Humility fails in both directions on the Overuse Ladder, and the technology executive is exposed to both.\n\n**Humility → excessive hesitation.** The CISO who has learned to distrust their own numbers stops being able to state a position. Every board question gets \"it depends\"; every risk gets a range too wide to be a price; \"Yes — and here is the risk, priced\" never arrives. Owens and Hekman (2012) warn humility is less effective under time pressure; an incident is time pressure. The signal: incident calls where the executive asks questions for forty minutes and nobody has been told to isolate anything.\n\n**Empathy → conflict avoidance, dressed as humility.** The leader who confuses openness with agreement. The client owner's MFA exception, the CFO's request to skip the vendor review, the engineering director's flat network — each accepted in the name of \"acknowledging expertise in others.\" Acknowledging expertise is about information, not decision rights. The signal: an exception register that grows every quarter and is never reviewed.\n\n**\"Blameless\" → consequence-free.** The security-specific rung. A blameless review is one in which the reporter is not the subject. It is not an organization where nobody is accountable for anything. Programs that lose this boundary produce a different silence: good engineers stop reporting because they have watched reckless ones report and nothing change. The signal: the same near-miss from the same source three quarters running.\n\n**Optimism → delusion, via the dashboard.** The leader who never installed the stack: reported clicks fall, near-misses are rare, the pen-test is scoped to the systems the CISO trusts, and the board slide is green. Edmondson (1996) is why this is a failure mode rather than a success.\n\n### Early warning signs\n\n- Near-miss reports are rare and stable in a function making hundreds of changes a week.\n- Reported phishing clicks fell sharply after a program change, and nobody checked the telemetry.\n- The last pen-test's scope was set by the executive whose architecture it tested.\n- Engineers, asked what they have stopped mentioning, have an answer.\n- The executive cannot name the last thing the program got wrong, unprompted."}, "research_refs": ["res.edmondson1996", "res.edmondson1999", "res.milliken2003", "res.detert2011", "res.ou2014", "res.ou2018", "res.owens2012", "res.owens2016", "res.cram2019", "res.ashenden2013", "res.tourish2006", "res.higgs2016", "res.amir2018"], "reflection": ["What was the last thing an engineer or employee told you that contradicted your own architecture or program? How long after they knew it did you hear it, and what happened to them afterward?", "Estimate your reported-to-detected ratio for last quarter. If you cannot, which number have you been managing instead?", "Name a control that is on your board slide and, as far as you actually know, not fully on the servers. Who else knows?", "When did you last thank someone publicly for reporting their own mistake? When was someone last disciplined for one? Which story does your organization tell?", "Who has the standing to embarrass your architecture in front of your CEO? If nobody, is that because nobody is capable or because nobody is permitted?", "Write the first three sentences of a \"what we got wrong last quarter\" note to your CEO. What did you leave out, and why? For the vCISO: which client has never been told about a miss, and what are you protecting?"], "simulation_ref": "sim.m05-kessler-leaderboard", "knowledge_check": [{"id": "m05-kc1", "type": "multiple_choice", "question": "Edmondson (1996) found that nursing units with stronger team climates and more manager coaching showed:", "answer": "B", "explanation": "The correlation between manager coaching and detected errors was r = .74; Edmondson read the higher counts as reporting climate, not worse safety — the reason a low incident count is ambiguous.", "options": [{"key": "A", "text": "Lower detected drug-error rates, indicating better safety."}, {"key": "B", "text": "Higher detected drug-error rates, interpreted as greater willingness to report and discuss errors."}, {"key": "C", "text": "No difference in error rates."}, {"key": "D", "text": "Higher error rates caused by manager interference."}]}, {"id": "m05-kc2", "type": "multiple_choice", "question": "In the Cram, D'Arcy and Proudfoot (2019) meta-analysis of 95 papers, which antecedents of security-policy compliance were among the weakest?", "answer": "C", "explanation": "Value-oriented antecedents were strongest; sanctions and rewards were among the weakest, with training and perceived usefulness in the middle.", "options": [{"key": "A", "text": "Attitude and personal norms."}, {"key": "B", "text": "Normative beliefs."}, {"key": "C", "text": "Punishment and rewards."}, {"key": "D", "text": "Perceived usefulness."}]}, {"id": "m05-kc3", "type": "short_answer", "question": "Name the five layers of the Information-Environment Stack in the order they should be built.", "answer": "Near-miss reporting → blameless review → red-team standing → engineer direct lines → the quarterly \"what we got wrong.\"", "explanation": "Each layer depends on the one below; the top layer is the executive modeling the behavior the stack asks of everyone else."}, {"id": "m05-kc4", "type": "multiple_choice", "question": "Detert and Edmondson (2011) found that implicit voice theories — such as \"don't embarrass the boss in public\" — predicted silence:", "answer": "B", "explanation": "The rules were learned elsewhere and carried in, which is why making an environment safe is necessary but not sufficient — the stack has to demonstrate safety repeatedly.", "options": [{"key": "A", "text": "Only in environments that were objectively unsafe."}, {"key": "B", "text": "Over and above personality and context, even where the environment was objectively safe."}, {"key": "C", "text": "Only among junior employees."}, {"key": "D", "text": "Only when the boss was the CEO."}]}], "takeaways": ["Executive humility for the technology leader is three observable behaviors — accurate self-assessment of the program, openness to corrective information, acknowledging expertise in others — and it is not deference on risk, saying yes, or self-deprecation.", "Blame reduces reporting through a known mechanism: learned implicit voice theories (Detert & Edmondson, 2011) confirmed by organizational sanctions, in a culture where most people already withhold important issues (Milliken et al., 2003).", "A low incident count is ambiguous; Edmondson (1996) found the better-led units reported more errors. Read reported clicks against telemetry with the reported-to-detected ratio.", "Sanctions and rewards are among the weakest predictors of compliance (Cram et al., 2019); norms are shaped by what people watch happen to reporters, which makes the leader's own behavior the strongest lever.", "Install humility as mechanism, not mood: near-miss reporting, blameless review with a stated accountability boundary, red-team standing, engineer direct lines, the quarterly \"what we got wrong.\""], "videos": ["vid.00-low-incident-counts-safety-or-silence", "vid.00-the-information-environment-stack", "vid.00-why-people-don-t-report-the-click"], "glossary_terms": ["term.executive-humility", "term.reporting-culture", "term.psychological-safety", "term.near-miss-reporting", "term.blameless-review", "term.red-team-standing", "term.information-environment-stack", "term.reported-to-detected-ratio", "term.implicit-voice-theories"], "tags": {"dials": ["centralization_decentralization", "decisiveness_inquiry", "optimism_skepticism", "unilateral_consensus"], "archetypes": ["arch.business-risk-ciso", "arch.post-breach-ciso-turnaround", "arch.regulated-industry-cio-ciso", "arch.smb-msp-technology-leader-player", "arch.technical-ciso"], "stages": ["mature", "regulatory_reputation_crisis", "scale_up", "turnaround"], "learn_categories": ["leadership", "personality"]}, "estimated_minutes": 85, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/05-humility-and-the-reporting-culture.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m06", "slug": "trait-dial-for-technology-leaders", "title": "The Trait Dial for Technology Leaders — Eight Dials and Two Overlays", "unit": "II. The Signature Frameworks, Adapted", "big_idea": "Mediocre technology leaders run on one setting — usually the one that got them promoted. Exceptional CIOs and CISOs move the dial, and know which two dials the role adds.", "effectiveness_equation_term": "Behaviors", "learning_objectives": ["Apply the eight dials to technology decisions: aggression↔caution on a cloud migration, decisiveness↔inquiry in an incident, hands-on↔delegation for the former engineer, centralization↔decentralization on platform versus product teams.", "Use the two overlay dials — Control↔Enablement and Prevention↔Resilience — as FRAMEWORK, and map each to the eight schema dials.", "Apply the Overuse Ladder with technology-specific rungs, including rigor→bureaucracy as 'the security review that ships nothing' and caution→'never breached because nothing is ever deployed.'", "Read the four contextual signals — threat level, regulatory posture, balance sheet, deal cycle — that should move a dial."], "sections": {"core_lesson": "The CEO course's Trait Dial — eight paired settings, neither pole a virtue, a default on each set by temperament and reinforced by whatever worked last time — transfers to the technology executive unchanged. What changes is the decisions the dials are applied to, and two settings the role adds.\n\n**FRAMEWORK.** The eight dials are aggression↔caution, decisiveness↔inquiry, optimism↔skepticism, hands-on↔delegation, urgency↔patience, unilateral↔consensus, innovation↔operational discipline, and centralization↔decentralization. This module applies them to a cloud migration, an incident, a former engineer's team, and a platform-versus-product-team argument. It then adds two overlay dials — **Control↔Enablement** and **Prevention↔Resilience** — which are not new data but new lenses: each is a combination of two schema dials that technology leaders move together so often that they deserve a name.\n\nThe Overuse Ladder acquires technology-specific rungs. Rigor becomes bureaucracy as the security review that ships nothing; caution becomes the CISO who is never breached because nothing is ever deployed.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on **Behaviors**: the connection between your defaults and the situation. Four contextual signals — threat level, regulatory posture, balance sheet, deal cycle — tell you when to move.", "big_idea": "**Mediocre technology leaders run on one setting — usually the one that got them promoted. Exceptional CIOs and CISOs move the dial, and know which two dials the role adds.**\n\nThe engineer promoted for caution runs caution; the architect promoted for boldness runs boldness; the CISO hired after a breach runs control. Each was right once. The evidence on executive traits keeps finding inverted-U shapes and dualities, not \"more is better,\" and the technology role adds a structural twist: the same person is often paid to build and to preserve, which means running one setting is not just suboptimal but self-contradictory.", "research": "**RESEARCH FINDING.** The shape of the evidence is Zhang and Rajagopalan (2010, from the CEO library). Among 193 US CEOs who departed between 1993 and 1998, the level of strategic change had an inverted-U relationship with firm performance: moderate change was associated with better results, excessive change with worse, and both effects were larger for outside CEOs. Modest sample, archival proxies, accounting performance, observational. What it supports: neither \"change more\" nor \"change less\" is a strategy. **INTERPRETATION.** For the technology executive this is the transformation finding — the Transformation CIO's mandate has a peak, and past it the ERP-plus-cloud-plus-reorg program becomes the thing that fails.\n\n**RESEARCH FINDING.** Herrmann and Nadkarni (2014, from the CEO library) found the duality inside a trait. In 120 Ecuadorian SMEs, CEO conscientiousness hindered the initiation of strategic change but improved the performance of changes that were implemented; extraversion and openness related to initiation only. Small-firm, single-country, cross-sectional survey. **INTERPRETATION.** This is the innovation↔operational discipline dial in one finding, and it is the reason the overlay dial Prevention↔Resilience exists: the discipline that makes patching reliable is the discipline that makes the platform change slow.\n\n**RESEARCH FINDING.** Owens and Hekman (2012, from the CEO library), from 55 leader interviews, found that humility — high inquiry, high consensus — works only from a leader perceived as competent, and appears less effective under extreme threat or time pressure. Qualitative, not CEO- or CISO-specific. What it supports: the decisiveness↔inquiry dial has a context that moves it, and an incident is that context.\n\n**RESEARCH FINDING.** Angst, Block, D'Arcy and Kelley (2017) is the most important security-specific finding for the dial. In a matched panel of over 5,000 US hospitals and 938 breaches from 2005 to 2013, hospitals were classified as \"symbolic\" or \"substantive\" adopters of IT security practices based on institutional factors; symbolic adopters tended to belong to smaller systems and to be older, smaller, for-profit, non-academic, faith-based and less IT-entrepreneurial. Symbolic adoption diminished the effectiveness of security investment and was associated with an increased likelihood of breach; deeper integration of security into IT routines was associated with fewer breaches. One sector, adoption depth inferred from institutional profile rather than observed, reported breaches only. What it supports: a Control setting that produces policy without integration buys nothing. What it cannot support: which hospitals' leaders chose which setting, or why.\n\n**RESEARCH FINDING.** Kwon and Johnson (2014), using a Cox proportional-hazard model on US healthcare organizations, found proactive security investments associated with lower subsequent failure rates and better cost-effectiveness than reactive investments, and — the finding that matters for the contextual signals — that \"external pressure decreases the effect of proactive investments on security performance.\" Archival, one sector, disclosed breaches only. What it supports: the Prevention↔Resilience dial rewards moving before the event; and regulatory pressure, which pushes leaders toward compliance-shaped spending, can weaken the benefit of the spending it forces.\n\n**RESEARCH FINDING.** Kamiya, Kang, Kim, Milidonis and Stulz (2021), in an archival event study of successful cyberattacks on US firms, found that attacks exposing personal financial information were associated with shareholder losses much larger than out-of-pocket costs, that firms whose boards had attended to risk management before the attack suffered smaller excess losses, and that after an attack firms increased risk-management and IT investment and reduced managers' risk-taking incentives. Board attention is proxied; associations. What it supports: the organization's own dial moves after an attack, toward caution and control, whether or not the executive moves it — which is why the post-breach setting is so often over-applied later.\n\n**RESEARCH FINDING.** Three CEO-library findings establish that defaults are sticky and drift. Bertrand and Schoar (2003, from the CEO library) showed managers carry persistent decision \"styles\" across firms. Hambrick and Fukutomi (1991) proposed that tenures pass through seasons ending in convergence and dysfunction — a conceptual model. Chatterjee and Hambrick (2011) found highly narcissistic CEOs, by proxy measures, discounted objective performance feedback and amplified risk after media praise. What these support together: the setting hardens with success, and the technology leader who has just had a clean year is the one whose dial most needs checking.\n\n**RESEARCH FINDING (Tier 3, descriptive).** The Verizon 2025 Data Breach Investigations Report, a practitioner report drawn from a non-random contributor sample of 12,195 confirmed breaches, reports ransomware present in 44% of breaches and in 88% of SMB breaches, third-party involvement in 30%, and the human element in roughly 60%. Base rates only. Gordon and Loeb (2002), an analytical model rather than an empirical study, shows that under the breach-probability functions the authors assume the optimal security investment does not exceed 37% of the expected loss from a breach — a reasoning tool whose assumptions must be stated whenever the figure is used. **INTERPRETATION.** Together they supply the threat-level and balance-sheet signals: the base rate tells you what is likely; the Gordon–Loeb logic tells you that \"spend until safe\" is not a setting.\n\n### Where the evidence is weak\n\nNo study tests the Trait Dial or the overlays; they are frameworks built to organize findings made separately. The inverted-U evidence is about strategic change at CEO level. Angst et al. and Kwon and Johnson are single-sector healthcare studies of investment, not of leaders' settings. The claim that a technology executive who deliberately moves a setting does better than one who does not is the course's working **HYPOTHESIS**, not a demonstrated result.", "explanation": "### How to read a dial\n\n**FRAMEWORK.** Each dial has two poles, neither a virtue; a default, where you sit when not thinking about it; and a range you can reach with effort. Calibration has three parts: know your default from behavior rather than self-description, read the signals that call for a different setting, and recognize the overuse failure at each end so you know when you have gone too far. Dials move in clusters: a CISO who moves toward caution usually moves toward centralization and control at the same time. That cluster is the post-breach profile, and it is right after a breach. The failure is running it three years later.\n\n### The eight dials, applied\n\n**Aggression ↔ Caution — the cloud migration.** Aggression is the seven-month lift-and-shift with hardening afterward; caution is hardening first and accepting the slip. Signals for aggression: a lease that ends, a balance sheet that can absorb a miss. Signals for caution: an active campaign against your sector, thin cash, an identity platform you do not yet trust. Overuse of aggression: risk tolerance → recklessness. Overuse of caution: the CISO who is never breached because nothing is ever deployed.\n\n**Decisiveness ↔ Inquiry — the incident.** At 2 a.m. with a credential-stuffing alert, decisiveness is isolating the segment now; inquiry is thirty more minutes of log review first. Owens and Hekman (2012) supply the rule: under threat and time pressure, inquiry costs more than it buys. Signals for inquiry: an irreversible action (wiping the only evidence), a decision outside your competence (clinical systems), a team that has gone quiet. Overuse of decisiveness: the isolate-everything call that takes the business down harder than the attacker did. Overuse of inquiry: the incident call where nobody has been told to do anything.\n\n**Optimism ↔ Skepticism — the vendor's dashboard.** Optimism is believing the migration partner's timeline and the MDR vendor's coverage claim; skepticism is asking for the evidence. Signals for skepticism: a green dashboard nobody has tested, a control on the slide and not on the server (Module 5), praise arriving faster than results. Overuse of optimism: the symbolic adoption Angst et al. (2017) found buys no protection. Overuse of skepticism: the CISO who cannot sign off on anything.\n\n**Hands-on ↔ Delegation — the former engineer.** Hands-on is reading the alerts and reviewing the firewall rules yourself; delegation is setting the outcome and letting the security lead own the method. Signals for hands-on: a failing function, a new domain, a crisis. Signals for delegation: a lead who has earned it, a scale where your attention is the scarcest resource, a team that waits to be told. Module 8 is built on this dial.\n\n**Urgency ↔ Patience — remediation and program-building.** Urgency is the ninety-day remediation sprint; patience is the two-year identity program. Kwon and Johnson (2014) reward moving before the event, which sounds like urgency and is actually patience: proactive investment is made when nothing is on fire. Overuse of urgency: a remediation pace the organization stops distinguishing from the executive's habit. Overuse of patience: the audit finding \"in progress\" for three cycles.\n\n**Unilateral ↔ Consensus — the policy and the exception.** Unilateral is deciding the MFA policy and informing; consensus is deciding it with the business units. Signals for unilateral: a decision only you can own, a deadlock, an incident. Signals for consensus: a control the business must operate and could quietly route around. Overuse of unilateral: the CISO who says no and is routed around. Overuse of consensus: the exception register that grows every quarter.\n\n**Innovation ↔ Operational Discipline — the platform change and the patch.** Innovation is the new platform and the re-architecture; discipline is patch cadence, baselines, backup tests. Herrmann and Nadkarni (2014) show the tension: the trait that finishes hurts starting. Overuse of innovation: tool churn — adaptability → strategy-of-the-month. Overuse of discipline: the security review that ships nothing.\n\n**Centralization ↔ Decentralization — platform versus product teams.** Centralization is a single security function that gates every deployment; decentralization is security engineers embedded in product teams with the center setting standards. Signals for centralization: an integration, a compliance failure, a post-breach period, a company where the center is the only competence. Signals for decentralization: a scale the center cannot know, an engineering culture that ships daily, a CISO who has become the bottleneck.\n\n### The two overlay dials\n\n**FRAMEWORK.** Data stays on the eight schema dials. The overlays are taught narratively, because technology executives move certain pairs together so often that naming the pair is more useful than naming its parts.\n\n**Control ↔ Enablement** ≈ centralization↔decentralization + caution↔aggression. At the Control end, the security function decides, gates and approves; at the Enablement end, the business decides within guardrails the function designs. Neither is a virtue. Control is right after a breach, during a consent order, in a 40-person company where the function is one person, and for any decision whose downside is unbounded. Enablement is right where the business ships faster than the function can review, where the engineering culture is strong, and where the cost of a gate exceeds the risk it screens. The Risk Corollary is the test: \"Yes — and here is the risk we are accepting, priced\" is an Enablement sentence with a Control-grade risk view behind it. A leader who can only say one of the two sentences is stuck at one end of this dial. Angst et al. (2017) is the warning at the Control end: policies adopted symbolically do not reduce breaches; integration does.\n\n**Prevention ↔ Resilience** ≈ operational discipline↔innovation + patience↔urgency. At the Prevention end, spend goes to stopping the event: hardening, access control, patching, awareness. At the Resilience end, spend goes to surviving it: immutable backups, segmentation, incident readiness, recovery testing, insurance, the ability to run the clinic on paper for three days. Prevention is the discipline setting with patience — it works before the event and pays off slowly (Kwon & Johnson, 2014). Resilience is the innovation setting with urgency — it assumes the event and asks how fast you get up. The mature setting for most organizations is closer to Resilience than their instincts put them, because the base rates (Verizon, 2025, descriptive) make the event likely and the Gordon–Loeb logic makes \"prevent everything\" irrational. The failure at the Prevention end is the program that has never tested a restore; at the Resilience end, the program that has stopped patching because \"we'll recover.\"\n\n### The contextual signals\n\n**FRAMEWORK.** Four signals should move a technology leader's dial, and the mature executive reads them in combination.\n\nThreat level. An active campaign against your sector — four physician groups hit in six weeks — moves aggression toward caution and Prevention toward Resilience, this quarter. The base rate is not the signal; the base rate is always high. The signal is the change in it.\n\nRegulatory posture. An exam cycle, a consent order, a new disclosure rule moves the dial toward Control and discipline. The Kwon and Johnson (2014) caveat is the trap: external pressure weakened the benefit of proactive investment, plausibly because compliance-shaped spending is symbolic spending. Under a regulator, the mature leader spends to pass the exam and separately spends to be secure, and knows the difference.\n\nBalance sheet. Debt, covenant tests and runway move aggression toward caution and shorten the patience the organization can afford. A debt-free firm can absorb a two-month slip; a levered one may not survive a covenant test that a breach or a failed migration triggers. Gordon and Loeb (2002) is the reminder that the balance sheet also caps what rational security spending looks like.\n\nDeal cycle. A pending acquisition, sale or financing moves the dial toward Control and discipline, because diligence will read your exception register, and toward urgency, because the deal has a date. It also raises the price of a breach: Kamiya et al. (2021) found the market re-prices cyber risk after an attack, and a buyer's diligence team does the same.\n\n### Knowing and moving your default\n\n**INTERPRETATION.** Ask a CISO where they sit and they describe where they would like to sit. The evidence that defaults are sticky (Bertrand & Schoar, 2003) says the honest source is behavior: the last ten consequential decisions, where each landed, whether the setting changed when the situation did. Three practices make calibration deliberate. Name the setting before deciding — \"this is a decisiveness call.\" Ask what changed — the seasons model (Hambrick & Fukutomi, 1991) warns that the context moves faster than the leader's perception of it. Watch the overuse signals in Section 7 as leading indicators.\n\n**HYPOTHESIS.** The range a technology executive can reach on each dial predicts sustained effectiveness better than the default does, and the range can be widened by practice. The evidence establishes that context matters and defaults are sticky; it does not yet establish that leaders who train the dial outperform those who do not.", "example": "*Fictional composite.* Coastal Federal Savings is a $2.4B-asset community bank headquartered in New London, Connecticut, with 540 employees, 31 branches, and OCC supervision. Maria Lindqvist has been its CIO and CISO for six years. Her default, by her own account and two 360s, sits toward caution, operational discipline and centralization — the profile the bank's board hired after a predecessor's failed core-banking project. It served the bank through a clean exam cycle and a ransomware wave that hit two regional peers.\n\nFourteen months ago three signals arrived within a quarter. The bank's board approved the acquisition of a $600M-asset savings bank in Rhode Island, closing in ten months. The core-banking vendor announced end-of-support for the on-premises version Coastal ran, with a hosted migration path. And the OCC's annual exam produced a matter requiring attention on third-party risk management — specifically, the bank's oversight of the fintech partners its retail team had signed without technology review.\n\nMaria's default said: slow the migration, centralize the fintech decisions, and take the acquisition's technology integration in-house. That is the Control-and-Prevention cluster, and it had been right for six years. She ran it for about a month, and the signal that she was wrong came from the head of retail, who said in a leadership meeting that the fintech partners were the bank's only deposit growth and that the technology review process had become \"where products go to wait.\"\n\nWhat she did next is the calibration. She read the signals separately rather than as one threat. The deal cycle moved her toward urgency and discipline on the integration: she hired an integration lead and set a decision-rights table with the target's IT head within six weeks. The regulatory posture moved her toward Control on third-party risk — but she designed it as guardrails, not gates: a two-page intake, a risk tier, and a standing rule that tier-one partners got a decision in ten business days. The migration she moved, deliberately, toward aggression: the vendor's hosted platform had better identity and backup controls than the on-premises estate, so the migration was itself the Prevention-to-Resilience move, and delaying it for caution's sake would have kept the bank on the weaker footing longer.\n\nShe left one dial where it was and said so: on the acquisition's day-one connectivity she stayed at caution, because the target's network had never had a penetration test and the integration lead's first finding was a flat network with domain administrators on shared accounts. Day one ran on a segmented bridge for four months.\n\nAt the year's end the acquisition had closed, the migration was in its final wave, the OCC matter was closed, and the retail team had signed two new fintech partners through the intake process in under two weeks each. The exam letter noted the third-party program as improved. Maria's read: her default had been right for the bank she inherited and wrong for the bank she now ran, and the three signals had arrived at once precisely because the bank had grown into a different situation while she was still running the old setting.", "ceo_contrast": "Put four archetypes in Maria Lindqvist's chair the week the head of retail says \"where products go to wait.\"\n\n**The Technical CISO** hears a business complaint about a security process and reads it as evidence the process is working. Products should wait; that is what review is for. The fintech intake gets more thorough, not faster. The gain is that nothing gets signed without a control review. The cost is that the retail team routes around the process — shadow partnerships, pilots that are not called pilots — and the third-party risk the OCC flagged grows in the one place the CISO cannot see. This is the Control end held past what the situation can absorb, and it produces the symbolic-adoption profile: a strong policy, weakly integrated.\n\n**The Business-Risk CISO** hears the complaint and moves fast to Enablement: a lightweight intake, a risk-tier model, fintech partners approved within days. The gain is deposit growth and a retail team that stops routing around security. The cost appears at the exam: an OCC examiner reading the tier-one approvals wants to see the evidence behind the tier, and a Business-Risk CISO who has priced the risk without documenting it has made the right decision in a form the regulator cannot accept. The Regulated-Industry signal was read too lightly.\n\n**The Transformation CIO** sees three change programs and wants to run them as one — migration, integration and the third-party program combined into a fourteen-month transformation with a single steering committee. This is the Zhang and Rajagopalan (2010) inverted-U in a bank: past the peak, the change load exceeds what 540 people can absorb during an acquisition, and the migration wave that slips is the one the regulator asks about. The gain is momentum. The cost is the program that fails because it was three programs.\n\n**The Regulated-Industry CIO/CISO** reads the exam letter as the whole situation and moves everything to Control and discipline until the matter is closed. This is the most defensible archetype in the room, and it is the one Maria's default resembled. The cost is the Kwon and Johnson (2014) caveat: spending shaped by the examiner's finding closes the finding and may do little for the bank's actual exposure, while the migration — the move that would have improved the identity and backup posture most — waits for a quieter year that a growing bank never gets.\n\n**INTERPRETATION.** Maria's move — three signals read separately, three dials moved in three directions, one dial held and named — is calibration. None of the four archetypes is wrong in general. Each is wrong for this bank this year in a different way.", "failure_mode": "**FRAMEWORK.** The Overuse Ladder runs strength → overused strength → liability. The rungs are the CEO course's twelve; the technology versions are what they look like from the CISO's chair.\n\n- **Confidence → arrogance.** \"We would never fall for that.\" Signal: the CISO stops attending blameless reviews.\n- **Optimism → delusion.** The dashboard is green and nobody has tested a restore. Signal: controls that exist only on the board slide.\n- **Persistence → stubbornness.** The architecture I built is the architecture we keep. Signal: the new security lead's objections are answered with history.\n- **Decisiveness → impulsiveness.** The isolate-everything call that takes down the clinics harder than the attacker would have. Signal: post-mortems where the response cost more than the attack.\n- **Attention to detail → micromanagement.** The CISO who reads every alert. Signal: a SOC that waits for the executive before closing a ticket.\n- **Empathy → conflict avoidance.** The exception granted to the owner, the CFO, the surgeon. Signal: an exception register nobody reviews.\n- **Dominance → intimidation.** The CISO whose \"no\" ends conversations. Signal: business units bring finished projects to security, not proposed ones.\n- **Humility → excessive hesitation.** Waiting for the complete risk assessment while the port is open. Signal: \"still gathering information\" at hour six.\n- **Risk tolerance → recklessness.** Enablement without a priced risk view. Signal: \"yes\" said faster than the risk can be described.\n- **Vision → fantasy.** A three-year architecture and a six-month-old critical vulnerability.\n- **Operational rigor → bureaucracy.** The security review that ships nothing. Signal: time-to-approval measured in quarters.\n- **Adaptability → strategy-of-the-month.** Tool churn — a new SIEM, EDR and framework each year. Signal: nobody can say which control is fully deployed.\n\n**INTERPRETATION.** The rungs pair off — rigor/adaptability, decisiveness/humility, dominance/empathy — because each pair is the two ends of a dial, and a leader who overcorrects from one usually lands on the other. The remedy for the review that ships nothing is not the review that approves everything.\n\n**INTERPRETATION.** The ladder is climbed after success. Chatterjee and Hambrick (2011) found praise, not performance, drove narcissistic CEOs' risk; Kamiya et al. (2021) found organizations move toward caution after an attack. The technology executive's most dangerous year is the one after the clean audit, and the most dangerous setting is the post-breach cluster held three years later.\n\n### Early warning signs\n\n- The same setting was used for the last five major decisions regardless of their type.\n- Time-to-approval for security review is measured in quarters, and nobody has calculated what it costs.\n- The exception register is growing, and the executive can name the exceptions but not the risk each carries.\n- The context has visibly changed — a deal, a regulator, a threat wave, a new balance sheet — and the security roadmap has not.\n- The executive can name their strengths and cannot name the liability each becomes."}, "research_refs": ["res.zhang2010", "res.herrmann2014", "res.owens2012", "res.angst2017", "res.kwon2014", "res.kamiya2021", "res.bertrand2003", "res.hambrick1991", "res.chatterjee2011", "res.gordon2002", "res.verizon2025"], "reflection": ["Take your last ten consequential technology or security decisions. Mark where each landed on aggression↔caution, decisiveness↔inquiry and centralization↔decentralization. How many settings did you use? Were the situations that different, or were you?", "Which of the two overlay dials describes the setting that got you promoted? Give one decision from the past year where that setting was wrong for the situation and you used it anyway.", "Name the last exception you granted that you would not have granted to someone with less standing. Which rung of the ladder were you on?", "Which of the four contextual signals — threat, regulator, balance sheet, deal — has changed for your company in the last year? Which dial did it move, and did you move with it?", "When did you last say \"Yes — and here is the risk we are accepting, priced\"? When did you last say \"No — and here is what would change my answer\"? If one is much easier than the other, which end of Control↔Enablement are you stuck at?", "If your engineers set your dial, where would their settings differ from yours? Have you asked?"], "simulation_ref": "sim.m06-two-contexts-migration", "knowledge_check": [{"id": "m06-kc1", "type": "multiple_choice", "question": "Angst, Block, D'Arcy and Kelley (2017) found that in over 5,000 US hospitals:", "answer": "B", "explanation": "The same investment was associated with fewer breaches only where adoption was substantive — deeper integration into IT routines — rather than symbolic.", "options": [{"key": "A", "text": "More security spending was associated with fewer breaches regardless of how it was adopted."}, {"key": "B", "text": "Symbolic adoption of security practices diminished the effectiveness of security investment and was associated with a higher likelihood of breach."}, {"key": "C", "text": "For-profit hospitals had fewer breaches than non-profit ones."}, {"key": "D", "text": "Security investment had no relationship with breaches."}]}, {"id": "m06-kc2", "type": "multiple_choice", "question": "Zhang and Rajagopalan (2010) found the relationship between the level of strategic change and firm performance was:", "answer": "C", "explanation": "Among 193 US CEOs, moderate change was associated with better performance and excessive change with worse — the shape behind the Transformation CIO's peak.", "options": [{"key": "A", "text": "Positive and linear."}, {"key": "B", "text": "Negative and linear."}, {"key": "C", "text": "Inverted-U, with both the upside and downside larger for outsider CEOs."}, {"key": "D", "text": "Flat."}]}, {"id": "m06-kc3", "type": "short_answer", "question": "State the mapping of each overlay dial to the eight schema dials.", "answer": "Control↔Enablement ≈ centralization↔decentralization + caution↔aggression; Prevention↔Resilience ≈ operational discipline↔innovation + patience↔urgency.", "explanation": "The overlays are teaching lenses, not new data; assessment and simulator data stay on the eight schema dials."}, {"id": "m06-kc4", "type": "multiple_choice", "question": "Kwon and Johnson (2014) found that external pressure on US healthcare organizations:", "answer": "B", "explanation": "Proactive investment was associated with lower failure rates, but regulatory pressure weakened the benefit — the trap behind the regulatory-posture signal, where compliance-shaped spending can be symbolic spending.", "options": [{"key": "A", "text": "Increased the effect of proactive security investments on security performance."}, {"key": "B", "text": "Decreased the effect of proactive security investments on security performance."}, {"key": "C", "text": "Had no relationship with security performance."}, {"key": "D", "text": "Eliminated the difference between proactive and reactive investment."}]}], "takeaways": ["The eight dials transfer to the technology executive unchanged; what changes is the decisions — the migration, the incident, the former engineer's team, the platform-versus-product argument — and neither pole of any dial is a virtue.", "The role adds two overlay dials, Control↔Enablement and Prevention↔Resilience, each a named pair of schema dials; the Risk Corollary is the test of whether you can reach both ends of the first.", "Angst et al. (2017) and Kwon and Johnson (2014) supply the security-specific warnings: Control that produces symbolic adoption buys nothing, and regulatory pressure can weaken the benefit of the spending it forces.", "Four contextual signals — threat level, regulatory posture, balance sheet, deal cycle — should move a dial, and the mature leader reads them separately rather than as one threat.", "The Overuse Ladder's technology rungs — the review that ships nothing, the CISO never breached because nothing is deployed, the tool churn, the unreviewed exception register — are climbed after success, and the post-breach cluster held three years later is the most common one."], "videos": ["vid.00-control-enablement-prevention-resilience", "vid.00-the-security-review-that-ships-nothing", "vid.00-the-trait-dial-for-technology-leaders"], "glossary_terms": ["term.trait-dial", "term.overlay-dial", "term.controlenablement", "term.preventionresilience", "term.overuse-ladder", "term.contextual-signal", "term.symbolic-adoption", "term.context-sensitivity-score"], "tags": {"dials": ["aggression_caution", "centralization_decentralization", "decisiveness_inquiry", "hands_on_delegation", "innovation_operational_discipline", "optimism_skepticism", "unilateral_consensus", "urgency_patience"], "archetypes": ["arch.business-risk-ciso", "arch.mid-market-cio-coach", "arch.post-breach-ciso-turnaround", "arch.regulated-industry-cio-ciso", "arch.technical-ciso", "arch.transformation-cio"], "stages": ["mature", "post_merger", "regulatory_reputation_crisis", "scale_up", "turnaround"], "learn_categories": ["decision_making"]}, "estimated_minutes": 90, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/06-trait-dial-for-technology-leaders.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m07", "slug": "maturity-model-for-cios-and-cisos", "title": "The Maturity Model for CIOs and CISOs — Temperament, Capability, Maturity, Fit", "unit": "II. The Signature Frameworks, Adapted", "big_idea": "Temperament gets you into technology, capability gets you the title, maturity keeps your strengths from becoming the reason you were replaced, and fit decides whether any of it works here.", "effectiveness_equation_term": "Traits", "learning_objectives": ["Populate the four levels for the technology executive: Temperament (uncertainty tolerance, agency, emotional regulation under incident); Capability (architecture, vendor and capital judgment, incident command, communication upward, risk quantification, talent); Maturity (calibration, receiving bad news, distinguishing ego from evidence, letting the business own its risk); Fit (this company, reporting line, regulator, stage, mandate).", "Explain why the levels are ordered and why a surplus at a higher level does not substitute for a deficit below it.", "Self-locate on each level with evidence — artifacts, attributed outcomes and other people's ratings — rather than adjectives.", "Use the model as a CEO or board would, to tell a capability gap from a maturity gap from a fit gap in a sitting CIO or CISO."], "sections": {"core_lesson": "The CEO course's Maturity Model — four ordered levels, each presupposing the one below — is the organizing structure of this edition too. What changes for the technology executive is the content of every level and the weight of the top one.\n\n**FRAMEWORK.** Level 1, **Temperament**: uncertainty tolerance, agency, emotional regulation under incident. Level 2, **Capability**: architecture, vendor and capital judgment, incident command, communication upward, risk quantification, talent. Level 3, **Maturity**: calibration, receiving bad news, distinguishing ego from evidence, and letting the business own its risk. Level 4, **Fit**: this company, this reporting line, this regulator, this stage, this mandate.\n\nThe levels are ordered and non-substitutable. A mature, well-placed CISO who cannot price a risk is a well-liked bystander. A capable, well-placed CISO without maturity runs the Overuse Ladder until the strengths become the reason for the exit.\n\n**INTERPRETATION.** One thing is heavier here than in the CEO edition. A CEO's discretion is broad by default; a technology executive's is granted by someone else — which makes Level 4 the largest source of failure and, unusually, partly negotiable. You cannot renegotiate your temperament. You can renegotiate a reporting line.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — Temperament is Traits, Capability and Maturity are Behaviors, and Fit is those multiplied by Context and Moment.", "big_idea": "**Temperament gets you into technology, capability gets you the title, maturity keeps your strengths from becoming the reason you were replaced, and fit decides whether any of it works here.**\n\nNearly all technology-executive development spend goes to Level 2 — frameworks, certifications, board-communication coaching. Nearly all technology-executive failure happens at Levels 3 and 4. The model exists to stop a capability gap, a maturity gap and a fit gap from being treated as one problem with one remedy, because two of the three remedies will then be wrong.", "research": "The model is a synthesis. Each level rests on evidence introduced earlier; the ordering and the non-substitutability claim are **INTERPRETATION** built from the pattern of findings, not a tested result.\n\n**RESEARCH FINDING — Level 1.** The temperament case begins as a contrast. Graham, Harvey and Puri (2013, from the CEO library) found CEOs substantially more risk-tolerant and optimistic than population norms — roughly 80% of US CEOs classified as very optimistic against about 65% of CFOs. Cross-sectional and self-reported: it supports an unusual executive temperament, not that the CIO's or CISO's is the same one, and no comparable psychometric study of technology executives exists in this library. From inside the role, Ashenden and Sasse (2013) interviewed five CISOs and found them naming a perceived lack of power, confusion about role identity and an inability to engage employees as their main obstacles — illustrative, not generalizable. The IANS and Artico *State of the CISO 2026* survey of more than 600 security leaders (**Tier 3, practitioner, self-selected**) reports 52% saying their responsibilities are not manageable with current resources and 69% open to changing jobs within the year. **INTERPRETATION.** That is the load the temperament level has to bear.\n\n**RESEARCH FINDING — Level 2.** Maynard, Onibere and Ahmad (2018), in a systematic review across information security and strategic management, concluded that the CISO's role as a strategist is under-theorized and proposed a competency set for it — a framework contribution that does not test whether having the competencies improves outcomes. Gordon and Loeb (2002) supply the discipline behind one cluster: an analytical model in which optimal security investment depends on an information set's value, vulnerability and the productivity of spending, and in which — for the breach-probability functions the authors assume — optimal investment does not exceed about 37% of expected loss. Not empirical, and the assumptions must be stated whenever the figure is used.\n\n**RESEARCH FINDING — where Level 2 meets Level 4.** Preston, Chen and Leidner (2008) studied CIO strategic decision-making authority; its abstract could not be verified here, so it is cited only for the general proposition. Its peer-reviewed practitioner companion (Preston, Leidner & Chen, 2008, *MIS Quarterly Executive*) crosses authority with capability into four profiles — IT Orchestrator, IT Advisor (capability without authority), IT Mechanic (authority without capability) and IT Laggard — and reports that IT's contribution varies by profile. **INTERPRETATION.** This module's central claim as a two-by-two.\n\n**RESEARCH FINDING — Level 3.** Owens and Hekman (2012, from the CEO library), from 55 leader interviews, identified admitting limits, spotlighting others' strengths and modeling teachability as observable humble-leader behaviors — working only from a leader perceived as competent, and less well under extreme threat or time pressure. Edmondson (1996) gives the security version of receiving bad news: across eight nursing units in two hospitals (146 respondents), units with better team climate and more active manager coaching showed *higher* detected error rates (manager coaching correlated with detected errors at r = .74). Correlational and in healthcare, but the lesson transfers: a low incident count can mean silence rather than safety. Cram, D'Arcy and Proudfoot (2019), meta-analyzing 95 papers across 17 antecedent categories, found employees' attitudes and norms far more strongly associated with security-policy compliance than punishment or rewards — largely survey-based, often measuring intention rather than behavior.\n\n**RESEARCH FINDING — the accountability edge.** Banker and Feng (2019) found breaches attributed to system deficiency associated with about a 72% higher likelihood of CIO turnover, while breaches attributed to criminal fraud or human error showed no significant association. Archival; cause classification comes from public descriptions. **INTERPRETATION.** Accountability appears to track the perceived scope of the executive's duties — the distinction a Level 3 leader has to draw in public without sounding evasive.\n\n**RESEARCH FINDING — Level 4.** Fit has the strongest evidence base of the four, all correlational and none of it a matching rule. Banker, Hu, Pavlou and Luftman (2011) found the right CIO reporting line depended on strategy: CIO-to-CEO in differentiation firms, CIO-to-CFO in cost-leadership firms. Karahanna and Preston (2013), across 81 US hospitals with matched CIO and top-team responses, found the social capital of that relationship associated with alignment and, through alignment, with financial performance. Haislip, Lim and Pinsker (2021), across reported breaches from 2005 to 2017, found firms with a CIO on the top management team associated with fewer reported breaches of all types examined. Peppard (2010) argues from interviews that CIO performance is largely a function of context — in particular the IT savviness of the CEO and leadership team. Karanja (2017) has examined CISO appointments and reporting positions in relation to breach events; its abstract could not be verified here, so nothing more specific may be claimed.\n\n**RESEARCH FINDING / FRAMEWORK — why this order.** Hambrick (2007, from the CEO library) argues executives' characteristics shape choices most where discretion is high and job demands are heavy, because heavy demands push leaders back onto heuristics and dispositions. **INTERPRETATION.** Maturity sits above capability because under load you fall back on temperament, and maturity decides whether that fallback is regulated. Fit sits on top because discretion decides how much any lower level matters — and this edition weights it hardest, since a CIO or CISO does not set their own discretion.\n\n### Where the evidence is weak\n\nNo study tests this four-level model; it is a framework. Level 1 is the weakest link — there is no peer-reviewed psychometric profile of CIOs or CISOs in this library, so it is populated by analogy and by five interviews, and Level 3 borrows from adjacent literatures. Use the model to structure a conversation; do not use it to score a person.", "explanation": "### Why four levels, and why in this order\n\n**FRAMEWORK.** The model answers a question CEOs, boards and technology executives get wrong constantly: when a CIO or CISO is not working, what kind of thing is missing? Four levels, four remedies, four timescales.\n\n**Temperament** is what you arrived with. *Uncertainty tolerance* is the capacity to act on an incomplete asset inventory and a vendor advisory that says \"under investigation\" — every security decision has an unknown denominator, and the leader who needs the denominator is not slow, they are absent. *Agency* shows up as one behavior: asking for what is not yours to ask for — the budget line the CFO did not offer, the seat in diligence, the escalation path to the audit committee. *Emotional regulation under incident* is what this role adds: at hour six the executive's affect sets the room's, and visible fear produces a team that hides findings while visible contempt produces a team that stops bringing them. Temperament is mostly not trainable in adulthood, and it is the raw material of every rung on the Overuse Ladder.\n\n**Capability** is what you learned — six clusters. *Architecture*: knowing what a design does under failure and under attack, and saying so before it is built. *Vendor and capital judgment*: knowing what you are buying, what you are giving up and what it costs to leave. *Incident command*: running a room, holding a timeline, keeping a decision log. *Communication upward*: making a technical risk legible to people who will never read the finding, without inflating it. *Risk quantification*: exposure in money and probability rather than in colors, with Gordon and Loeb (2002) as the discipline. *Talent*: hiring and replacing security people, which is hard because the market is thin and the executive is often the best technician in the room.\n\n**Maturity** regulates the first two. *Calibration* is Module 6's dial plus the literal version: a log of predictions with confidence levels, checked. *Receiving bad news* has a security-specific test — Edmondson (1996) found better climate produced *more* reported errors, so a mature leader reads a falling incident count as ambiguous and asks whether reporting fell instead. *Distinguishing ego from evidence* is what happens when a new hire says the architecture you designed is why the detection gap exists; Module 8 is built on that case. *Letting the business own its risk* is the hardest: you do not own the company's risk, you own the quality of the risk decision. Present a priced choice, let an accountable leader accept it in writing, then support the thing you argued against. Cram, D'Arcy and Proudfoot (2019) is the evidence underneath — a program run as enforcement runs on the weak levers — and Banker and Feng (2019) is the warning: the scope you accept in calm weather is the scope you are judged on in bad.\n\n**Fit** is whether the first three match this job. The reporting line is the most consequential term, and the one Banker et al. (2011) show should follow strategy rather than fashion. Fit is a relation, not a property, and it changes when the situation does.\n\n### Why the levels do not substitute\n\n**INTERPRETATION.** The tempting error is that a surplus above compensates for a deficit below. *Maturity and fit without capability* is the calibrated leader who cannot read an architecture or price a risk: the program is pleasant, the bad news arrives early, and both describe a program someone else is running. In the Preston, Leidner and Chen (2008) profiles this is the IT Mechanic; Owens and Hekman (2012) make the same point from the humility side, since the behaviors work only from a leader perceived as competent.\n\n*Capability and fit without maturity* is the common case, because capability is visible at hiring and maturity is not: the excellent CISO whose team stopped bringing near-misses in year two and whose incident numbers look superb for reasons Edmondson (1996) would recognize. *Capability and maturity without fit* is the distinctive failure of this role — a well-regulated CIO reporting three levels down in a company whose CEO treats technology as a cost line (Peppard, 2010) — and it is frequently not the executive's doing, which is why it gets misdiagnosed as one. The model is forgiving in one direction only: strong lower levels widen the range of situations you fit, because maturity is what lets the dial move.\n\n### Self-locating with evidence, not adjectives\n\n**FRAMEWORK.** \"I'm pragmatic\" is not a location. Each level takes a different evidence type, and using the wrong type is the commonest self-assessment error.\n\n- **Temperament — behavior under load.** The decision log from your worst incident, read for how many consequential calls you made before you had 60% of the facts, and how many you deferred that did not need deferring.\n- **Capability — artifacts, one per cluster.** The last architecture decision record and what it got wrong; the last three vendor renewals and what you conceded; the last memo you sent upward and whether any decision changed because of it; one loss estimate written *before* an event; how long the hire you should have replaced stayed.\n- **Maturity — other people's evidence.** The 360 gap between your self-rating and your team's; the worst thing you heard last quarter, who told you and how long they sat on it; whether you can state the risk each exception carries rather than who asked for it.\n- **Fit — the Fit Equation and a discretion audit.** Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line. Then: what can you spend without asking, who can overrule you, can you reach the audit committee without your boss's permission, and what happened the last three times you said no.\n\n### How a CEO or board should use it\n\n**FRAMEWORK.** The model turns \"the CISO isn't working\" into four conversations. The *temperament screen* is a floor, not a differentiator. The *capability assessment* runs by cluster, with two warnings: selectors over-weight the interpersonal impression in the room and, in technology roles, the credential — evidence of vocabulary rather than of incident command. The *maturity probe* is the part that gets skipped: ask for the last risk decision the candidate handed back to a business owner, and ask former engineers whether bad news went up early and what happened to whoever brought it. The *fit analysis* asks what discretion this person will actually have.\n\n**INTERPRETATION.** A board that will not change the reporting line, the budget authority or the escalation path is not selecting a CISO; it is selecting who will be blamed. **FACT.** Regulation S-K Item 106 has since December 2023 required US public companies to disclose annually the board's oversight of cybersecurity risk and management's role and expertise in assessing and managing material cyber risks (SEC, 2023). **HYPOTHESIS.** Most technology-executive exits described as capability failures are maturity or fit failures — consistent with the discretion literature and with Peppard (2010), and not tested directly.", "example": "*Fictional composite.* Northway Retail Group is a $1.4B-revenue specialty retailer — 240 stores across the Northeast, 6,800 employees, a growing e-commerce channel, cost-leadership strategy. Its first CISO, Dev Anand, was hired twenty months ago from a larger retailer where he had run threat detection. He reports to the CIO, who reports to the CFO.\n\nAt the May board meeting the CEO said the sentence that starts this kind of review: \"I don't think the CISO is working.\" Her evidence was real. A store-systems vulnerability had been open eleven months. The e-commerce team had launched a loyalty integration without security review and mentioned it afterward. Dev's board deck was three slides of maturity scores and a heat map, and when the audit committee chair asked what a breach would cost, he said it depended. Two merchandising VPs described security as an obstacle. The CFO wanted to know why headcount had grown 40% with nothing to show.\n\nThe audit committee chair — a former operations executive — took a month and ran the four levels separately.\n\n**Temperament.** She read the incident log from a February payment-terminal event: Dev took command in eleven minutes, made three containment calls before the forensics vendor reached the bridge, and was right on two. No deficit.\n\n**Capability.** Uneven, and specifically so. Architecture and incident command were strong. Vendor judgment was weak: three overlapping tools in eighteen months, one never deployed past pilot. Risk quantification was absent — \"it depends\" was not modesty; no loss estimate had ever been written.\n\n**Maturity.** Mixed, with one clear gap. The 360 showed his team rating him high on receiving bad news; an analyst had escalated a misconfiguration over Dev's own architecture and been thanked in front of the group. But every business leader described the same pattern: Dev took risk decisions onto himself. When merchandising wanted the loyalty integration he did not price it and hand it back — he said no, was overruled two levels up, and then declined to support the launch. He was carrying other people's risk and losing.\n\n**Fit.** Northway is a cost-leadership retailer, and Banker, Hu, Pavlou and Luftman (2011) found CIO-to-CFO reporting associated with better performance in exactly that strategy, so the structure was defensible on its face. But Dev's line put two people between him and the board, his spending authority stopped at $25,000, and he had never sat in diligence for either acquisition closed since he arrived. The eleven-month vulnerability lived in store systems owned by a VP of retail operations who had declined the maintenance window four times. Dev had escalated twice, to his CIO, and stopped.\n\nThe chair's one-page conclusion: this is not one problem. A **capability gap** in risk quantification and vendor judgment — trainable, with a deadline. A **maturity gap** in letting the business own its risk. And a **fit gap the company created**: no escalation path, no diligence seat, and a systems owner who could decline a window without consequence.\n\nNorthway did three things. It gave Dev a standing audit-committee slot with a direct line to its chair. It replaced the maturity deck with three numbers and one priced decision a quarter, and assigned the FP&A lead to build the first loss models with him — a quarter's work that produced a $9M–$14M range for a card-data event and changed the tooling conversation immediately. And it introduced a risk-acceptance form any business leader may sign for a named risk, in writing, with an expiry date. The VP of retail operations signed one for the store-systems window, and four weeks later took the window.\n\nEleven months on, the vulnerability was closed and the exception register held nineteen signed items with owners and dates. Dev's summary was blunter than the chair's: \"I thought my job was to stop bad decisions. It was to make sure the right person made them, and knew what they cost.\"", "ceo_contrast": "Take the same May meeting and put three archetypes in Dev Anand's chair when the chair delivers the one-page diagnosis.\n\n**The Technical CISO** hears three findings and accepts one. The vendor-judgment gap is fair; the risk-quantification gap gets answered with an objection that quantification is pseudo-precision — you cannot put a number on a threat actor. There is a real argument there, and Gordon and Loeb (2002) rest on assumptions rarely measurable in practice. But the objection is doing other work: protecting an identity in which security is a technical discipline the business should defer to. The gain is honesty about uncertainty; the cost is that the audit committee still cannot decide anything, and a leader who will not give a range gets a budget set by someone who will.\n\n**The Business-Risk CISO** accepts the whole diagnosis in the room and has a loss model in three weeks. Fastest recovery available, with a specific failure: the priced-risk posture without the Control-end rigor behind it. The exception register fills quickly, because handing risk back feels like progress. Six quarters later there are ninety-one signed acceptances, nobody has reviewed the expiries, and the company has documented its way into the same exposure. Handing risk back is only maturity if you track what you handed back.\n\n**The Enterprise CIO (Architect)**, imagined in the combined seat, hears \"fit gap\" and goes to governance: a risk committee, a decision-rights table, a quarterly attestation. Much of this is what Northway lacks. The danger is the one Module 8 names — designing a system and mistaking the design for its operation. A risk-acceptance form no VP ever signs is a document, not a control, and the Architect is least likely to notice the difference from where they sit.\n\n**INTERPRETATION.** The four-level split is what makes the room productive: it separates what Dev must learn, what he must change in himself, and what only the company can give him. Each archetype collapses that split differently, and each collapse is an experienced executive's honest first instinct.", "failure_mode": "**FRAMEWORK.** The model's characteristic failure is mis-level diagnosis — treating a problem at one level as if it lived at another. Four versions recur.\n\n**The capability answer to a maturity problem.** A CISO whose team has stopped reporting near-misses is sent to a board-communication workshop. A CIO who runs one dial setting gets a better portfolio dashboard. The remedy is real, the level is wrong, and the failure continues under a more expensive label.\n\n**The tooling answer to a maturity problem.** The technology-specific version, and the most common. The gap is that the executive does not hear bad news; the response is a GRC platform or an attack-surface subscription. Tools convert a human information problem into a dataset nobody contradicts — the ladder's optimism → delusion rung with a purchase order attached.\n\n**The fit answer to a maturity problem.** The company decides the leader \"isn't right for us,\" replaces them, and hires a different default into the same reporting line, the same spending authority and the same absent escalation path. The cycle repeats in about two years.\n\n**The maturity answer to a fit problem.** The kindest failure and the biggest waste: a calibrated, self-aware CIO with no discretion, coached on influence and executive presence. Peppard (2010) argues CIO performance is bounded by the IT literacy of the CEO and top team, and coaching does not move that boundary; Hambrick (2007) says the same thing structurally, since characteristics matter where discretion exists.\n\n**INTERPRETATION.** The Overuse Ladder maps onto the model directly: every rung begins as a Level 1 or Level 2 strength and becomes a liability through a Level 3 deficit — failing to notice the situation changed. A Level 4 change usually reveals it. A new CEO, an acquisition, a first regulator: the setting that was invisible becomes the problem, and it looks like the leader deteriorated when the situation moved.\n\n### Early warning signs\n\n- The development plan has been entirely Level 2 for three years — frameworks, certifications, tooling.\n- The exception register is growing and the executive can name who asked for each exception but not the risk it carries.\n- The leader has never handed a priced risk back to a named business owner in writing.\n- Two CIOs or CISOs have now left the same seat, and the reasons given were different both times."}, "research_refs": ["res.karanja2017", "res.maynard2018", "res.peppard2010", "res.karahanna2013", "res.haislip2021", "res.banker2011", "res.banker2019", "res.preston2008", "res.ashenden2013", "res.ians2026", "res.gordon2002", "res.cram2019", "res.edmondson1996", "res.sec2023", "res.hambrick2007", "res.graham2013", "res.owens2012"], "reflection": ["For each of the four levels, write one piece of evidence — a decision, an artifact, a piece of feedback — that locates you. Which level was hardest to evidence, and what does that tell you?", "Take the six capability clusters. Which one has no artifact behind it? What is the last written, pre-event loss estimate you produced, and how did it turn out?", "When did you last hand a priced risk back to a named business owner in writing, and then support the decision you argued against? If you cannot find an instance, whose risk are you currently carrying?", "What is the worst thing you heard from your team last quarter? Who told you, how long had they known, and what happened to them afterward?", "Run the discretion audit: what can you spend without asking, who can overrule you, can you reach the audit committee without your boss's permission, and what happened the last three times you said no? Which of these could you renegotiate this year, and which have you simply never asked about?"], "simulation_ref": "sim.m07-ravenswood-second-title", "knowledge_check": [{"id": "m07-kc1", "type": "multiple_choice", "question": "Which of the following belongs at Level 3 (Maturity) rather than Level 2 (Capability) for a technology executive?", "answer": "C", "explanation": "The first three are trainable skills; the willingness to hand risk back and stay supportive is a regulation capacity that governs how those skills get used.", "options": [{"key": "A", "text": "Incident command"}, {"key": "B", "text": "Risk quantification"}, {"key": "C", "text": "Letting a named business owner accept a priced risk in writing, and then supporting the decision"}, {"key": "D", "text": "Vendor and capital judgment"}]}, {"id": "m07-kc2", "type": "multiple_choice", "question": "Banker and Feng (2019) found that CIO turnover was:", "answer": "A", "explanation": "Accountability appears to track the perceived scope of the executive's duties.", "options": [{"key": "A", "text": "About 72% more likely after breaches attributed to system deficiency, with no significant association for breaches attributed to criminal fraud or human error."}, {"key": "B", "text": "Equally likely after all breach types."}, {"key": "C", "text": "Unrelated to breaches of any kind."}, {"key": "D", "text": "More likely after human-error breaches than after system-deficiency breaches."}]}, {"id": "m07-kc3", "type": "multiple_choice", "question": "Edmondson (1996) found that nursing units with better team climate and more active manager coaching reported:", "answer": "B", "explanation": "Manager coaching correlated with detected errors at r = .74 — which is why a falling incident count is ambiguous evidence rather than good news.", "options": [{"key": "A", "text": "Fewer errors, because the climate prevented them."}, {"key": "B", "text": "More errors, which she interpreted as greater willingness to report and discuss them."}, {"key": "C", "text": "No difference in error rates."}, {"key": "D", "text": "Fewer errors, but only in the second hospital."}]}, {"id": "m07-kc4", "type": "short_answer", "question": "A CEO says her CISO \"isn't working.\" Name the four questions the Maturity Model turns that into, and the different remedy each implies.", "answer": "Temperament — can this person bear the load and decide without complete information? Remedy: none; it is a floor. Capability — which of the six clusters has no artifact behind it? Remedy: development or a complementary hire, with a deadline. Maturity — does bad news arrive early, is risk handed back? Remedy: mechanism and feedback, not training. Fit — what discretion does this person actually have? Remedy: change the structure or change the person, and only the company can do the first.", "explanation": "Collapsing the four into one produces the wrong remedy most of the time, and the fit remedy is usually the company's to make."}], "takeaways": ["The four levels are four different kinds of thing with four different remedies: Temperament (uncertainty tolerance, agency, regulation under incident), Capability (architecture, vendor and capital judgment, incident command, communication upward, risk quantification, talent), Maturity (calibration, receiving bad news, ego versus evidence, letting the business own its risk), Fit (company, reporting line, regulator, stage, mandate).", "The levels do not substitute. Maturity makes a capability failure gracious rather than avoidable; capability makes a maturity deficit more expensive; and neither survives a fit gap the company will not close.", "Fit carries more weight in this edition than in the CEO edition, because a technology executive's discretion is granted by someone else — and it is the one term that is partly negotiable, which is why the discretion audit belongs in every self-location.", "For a CEO or board, the model's most valuable output is the mis-level diagnosis it prevents — the capability, tooling, fit and maturity answers applied to the wrong problem account for most of the money spent on technology-executive difficulty and most of the seats that empty twice."], "videos": ["vid.00-capability-gap-maturity-gap-fit-gap", "vid.00-self-location-without-adjectives", "vid.00-the-maturity-model-for-cios-and-cisos"], "glossary_terms": ["term.maturity-model", "term.temperament", "term.capability", "term.maturity", "term.fit", "term.self-location", "term.discretion-audit", "term.risk-quantification", "term.letting-the-business-own-its-risk"], "tags": {"dials": ["decisiveness_inquiry", "hands_on_delegation", "optimism_skepticism", "unilateral_consensus"], "archetypes": ["arch.business-risk-ciso", "arch.enterprise-cio-architect", "arch.post-breach-ciso-turnaround", "arch.regulated-industry-cio-ciso", "arch.technical-ciso"], "stages": ["mature", "regulatory_reputation_crisis", "scale_up", "turnaround"], "learn_categories": ["ceo_fundamentals"]}, "estimated_minutes": 85, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/07-maturity-model-for-cios-and-cisos.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m08", "slug": "player-coach-architect-for-technology-leaders", "title": "Player → Coach → Architect for Technology Leaders", "unit": "III. Context Changes Everything", "big_idea": "The best engineer in the building is rarely the best CIO in the building — and the CISO who personally reads every alert has built a program that fails when they sleep.", "effectiveness_equation_term": "Organizational Context", "learning_objectives": ["Describe the Player (SMB/MSP: hands-on, vendor-managed stacks, the fractional and vCISO reality), Coach (mid-market: hiring the first security lead, cadence, decision rights, metrics) and Architect (enterprise: governance, portfolio, platforms, capital, board reporting) roles and the traits each rewards.", "Name the dominant danger at each scale — insufficient action, inability to let go, isolation and dashboard fiction — and the evidence behind each.", "Diagnose the hands-on engineer trap, from 'I'll just fix it myself' to 'nothing ships without me,' and the enterprise-CIO-in-a-40-person-company mismatch in both directions.", "Design a delegation ladder for security operations, with the rung set per activity and pre-authorized containment thresholds written down."], "sections": {"core_lesson": "The CEO course's three-role model transfers to the technology executive with one change: the roles map onto the size of the *estate and the team*, not only the company, and the security half of the job punishes the transitions harder than the build half does.\n\n**FRAMEWORK.** The **Player** is the technology leader of a small business or a managed-service firm: hands-on, vendor-managing, often fractional, personally the architecture and the on-call rotation. The **Coach** runs a mid-market function: hires the first security lead, builds cadence, writes decision rights, picks the five numbers. The **Architect** runs an enterprise function: governance, portfolio, platforms, capital allocation, board reporting.\n\n**HYPOTHESIS.** Each role has a dominant danger. The Player's is *insufficient action* — the MFA rollout postponed, the restore never tested. The Coach's is the *inability to let go*, which is a competence problem rather than a control problem. The Architect's is *isolation and dashboard fiction*: a picture of the program that is filtered on the way up and symbolic on the way down.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on **Organizational Context**: the same leader, the same traits, a different-sized job.", "big_idea": "**The best engineer in the building is rarely the best CIO in the building — and the CISO who personally reads every alert has built a program that fails when they sleep.**\n\nNeither sentence is about talent. Both are about scale: personal excellence is the product at forty people, a bottleneck at four hundred, and nearly irrelevant at four thousand, where the design of who decides what is the whole job. Each stage rewards exactly the behavior the next one punishes.", "research": "**RESEARCH FINDING.** Bandiera, Prat, Hansen and Sadun (2020, from the CEO library) collected time-use diaries from 1,114 manufacturing CEOs in six countries and reduced hundreds of activity types to an index running from \"manager\" behavior — one-on-ones with operational staff, site visits — to \"leader\" behavior, meaning multi-function meetings with senior executives. A one-standard-deviation move toward the leader end was associated with about 7% higher sales, and the difference became significant only about three years after appointment; they estimate about 17% of firms had a CEO whose type did not fit the firm. One week of diaries per CEO, manufacturing only, and the authors caution this is a matching story rather than proof that leaders beat managers. **INTERPRETATION.** Read as fit rather than ranking, it is this module's spine: behavior types differ, mismatch is common, and the payoff arrives slowly enough that a leader who delegates in January and panics in September is measuring the wrong thing.\n\n**RESEARCH FINDING.** Graham, Harvey and Puri (2015, from the CEO library) surveyed more than 1,000 CEOs and CFOs on delegation and capital allocation. Executives delegated *more* when overloaded or distracted by major events such as acquisitions, and *less* when they had long tenure or financial expertise. Self-reported, cross-sectional, no causal identification. **INTERPRETATION.** The direction is what matters here. Expertise reduces delegation, so for an engineer-turned-CIO deep domain knowledge is the fuel of the hands-on trap, not the cure for it.\n\n**RESEARCH FINDING.** Bloom and Van Reenen (2007, from the CEO library) scored 18 management practices — monitoring, targets, incentives — through double-blind interviews at 732 medium-sized manufacturing firms in four countries, and found practice scores strongly associated with productivity, profitability and survival. Survey-based and correlational. **INTERPRETATION.** These are the Coach's artifacts: at mid-market scale, measured practices replace the founder's personal attention.\n\n**RESEARCH FINDING (Tier 3, practitioner).** Weill and Ross (2004), research-based practitioner work from a study of about 250 enterprises, define IT governance as the framework of decision rights and accountabilities for IT decisions and report that firms with superior governance earn more than 25% higher profits given the same objectives. Not peer-reviewed; the comparison is descriptive and the selection of top performers is the authors' own. **INTERPRETATION.** Cite it for decision rights as a design choice, not as proof that governance causes profit.\n\n**RESEARCH FINDING.** Three studies explain why the Architect's picture degrades. Milliken, Morrison and Hewlin (2003, from the CEO library) interviewed 40 employees: 85% could recall an occasion when they felt unable to raise an important issue with a superior. Detert and Edmondson (2011, from the CEO library) identified taken-for-granted beliefs that speaking up is risky, which predict silence even where the environment is objectively safe. Edmondson (1996) adds the security-relevant twist: across eight nursing units in two hospitals (146 respondents), units with better team climate and more manager coaching reported *higher* detected error rates, manager coaching correlating with detected errors at r = .74. Small samples, correlational, none measuring executive information environments directly. **INTERPRETATION.** If people withhold from a boss one level up, an executive five levels up should assume the incident numbers on their dashboard have been filtered several times — and that a falling number may be a reporting story rather than a security one.\n\n**RESEARCH FINDING.** Angst, Block, D'Arcy and Kelley (2017) supply the other half of dashboard fiction. In a matched panel of over 5,000 US hospitals and 938 breaches from 2005 to 2013, hospitals classified as symbolic rather than substantive adopters of security practices saw the effectiveness of their investment diminished and an increased likelihood of breach. One sector; adoption depth inferred rather than observed; reported breaches only. **INTERPRETATION.** An Architect's design can be adopted symbolically three layers below and still report green.\n\n**RESEARCH FINDING (Tier 3, descriptive).** Two practitioner sources describe the Player's world. The Verizon 2025 Data Breach Investigations Report, drawn from a non-random contributor sample of 12,195 confirmed breaches, reports third-party involvement in 30% of breaches and ransomware present in 88% of SMB breaches. The IANS and Artico *State of the CISO 2026* survey of more than 600 security leaders reports 52% of CISOs at companies below $100M in revenue holding executive-level titles, and 52% overall saying their responsibilities are not manageable with current resources. Self-selected samples, base rates only. **INTERPRETATION.** The Player's posture is largely somebody else's engineering, and the Player's title frequently outruns the function beneath it.\n\n### Where the evidence is weak\n\nNo peer-reviewed study follows technology executives through the Player-to-Coach or Coach-to-Architect transition. The three roles are a **FRAMEWORK** assembled from time-use, delegation, management-practice and silence research plus practitioner observation; the dominant danger at each scale is **HYPOTHESIS**. The two qualitative anchors used later — Peppard (2010) on CIO performance as a function of the CEO's and top team's IT savviness, and Ashenden and Sasse (2013) on CISOs' own reports of low perceived power — are small, interview-based and interpretive. The delegation ladder in Section 4 is a design tool, not a tested intervention.", "explanation": "### Three jobs, one title\n\n**FRAMEWORK.** The **Player** leads technology in a company of roughly ten to a hundred and fifty people, or leads it for a managed-service or business-process firm whose clients are that size. They are the architecture, the vendor manager, the auditor's contact and the after-hours escalation. The stack is largely vendor-managed — remote monitoring, managed detection, a cloud identity platform, a backup provider — so much of the real posture is somebody else's engineering, which is why the Verizon (2025, Tier 3) figures on third-party involvement and SMB ransomware read as a job description rather than a statistic. Many Players are fractional, holding the vCISO role across several client companies at once, with an executive title and little function beneath it (IANS, 2026, Tier 3) — the structural version of the low perceived power Ashenden and Sasse (2013) heard from CISOs directly.\n\n**HYPOTHESIS.** The Player's dominant danger is *insufficient action*: the MFA rollout postponed a quarter, the restore never tested, the managed-detection vendor never asked what it actually monitors, the contract signed with a security schedule nobody read. Small organizations rarely fail from bad architecture. They fail from things that never happened.\n\nThe **Coach** runs a function of roughly a hundred and fifty to two and a half thousand people. The work is hiring the first real security lead and then not being them. Four artifacts mark the transition: the hire; a cadence — weekly operations, monthly risk, quarterly owner or board update; written decision rights covering who approves an exception, who can take a system offline and who signs a vendor; and five numbers everyone sees. Bloom and Van Reenen (2007) is the backbone — measured practices replace personal attention.\n\n**HYPOTHESIS.** The Coach's dominant danger is the *inability to let go*, and it is a competence problem rather than a control problem: you still read a packet capture faster than your security lead. Graham, Harvey and Puri (2015) found delegation falling with tenure and expertise — the trap is competence pointed at the wrong level.\n\nThe **Architect** runs an enterprise function: governance, portfolio, platform strategy, capital allocation and board reporting. Weill and Ross (2004, Tier 3) is the working frame — decision rights and accountabilities as a design object. The Architect's personal effort on any one problem is close to irrelevant; their design of who decides what, on what evidence, is close to everything.\n\n**HYPOTHESIS.** The Architect's dominant danger is *isolation and dashboard fiction*. The silence research (Milliken et al., 2003; Detert & Edmondson, 2011) makes the upward filter structural rather than personal, Edmondson (1996) makes a falling incident count ambiguous, and Angst et al. (2017) makes a well-designed control adoptable symbolically three layers down. An Architect can be wrong for two years and see nothing but green.\n\n### The hands-on engineer trap\n\n**FRAMEWORK.** The trap is a progression, and it starts from a virtue.\n\nStage one is *\"I'll just fix it myself.\"* At twelve people this is correct. Stage two is *\"I'll fix it faster than you will.\"* Someone now owns the problem, and you still solve it first, because you can and because waiting hurts. Stage three is *\"Send it to me before you push it.\"* You no longer solve everything; you check everything. This feels like delegation. It is a review bottleneck with a friendly face. Stage four is *\"Nothing ships without me\"* — decision rights were never designed, only assumed, and the organization has learned that initiative without your blessing is a career risk. Stage five is *\"Nobody else can be trusted with this,\"* which by then is nearly true, because the people who could be were trained out of trying.\n\n**INTERPRETATION.** Each handover is an identity threat disguised as an operational question. Letting someone else own the identity platform admits you are no longer the best engineer in the building — and for most technical leaders, that *was* the basis of their authority before the title existed. Owens and Hekman (2012, from the CEO library) identified modeling teachability and spotlighting others' strengths as observable humble-leader behaviors; here they cost something specific, because they transfer the thing you were respected for.\n\n### Mismatch in both directions\n\n**INTERPRETATION.** Picture an enterprise CIO — twenty years, four thousand people, a governance calendar — who takes the technology chair at a forty-person managed-service firm. She asks for the configuration-management database. There isn't one. She schedules a change advisory board and a quarterly architecture review. Meanwhile a client's tenant still has legacy authentication enabled, the backup for two clients has been failing silently for eleven days, and both senior engineers have taken recruiter calls. The firm needs someone to disable legacy auth this afternoon and take the engineers to lunch. Her dial is set to delegation where the job rewards hands-on, and to patience where it rewards urgency — Peppard's (2010) point about context in its sharpest form.\n\nNow the reverse. The Player who built a forty-person firm's stack takes over technology for nine thousand people. He keeps domain administrator rights \"for emergencies,\" approves firewall changes personally, calls a plant's system administrator directly about an alert, and cancels the architecture review board because \"we'll just decide faster.\" Each was right at forty people. At nine thousand, each destroys a coordination mechanism: every direct call teaches the hierarchy that the chain of command is optional, and every personal approval tells the process its authority is provisional.\n\n### The delegation ladder for security operations\n\n**FRAMEWORK.** Delegation is not a disposition, it is a setting, and the setting belongs to an *activity* rather than to a person. Six rungs:\n\n- **0 — You do it,** and nobody else sees it happen.\n- **1 — You do it, narrated.** Someone shadows and writes the runbook.\n- **2 — They do it, you approve each instance** before execution.\n- **3 — They do it inside a written standard;** you review a sample afterward.\n- **4 — They own the standard;** you review exceptions weekly and the standard quarterly.\n- **5 — They own the outcome and the budget;** you see a metric and a trigger list, and re-enter only on a named trigger.\n\n**INTERPRETATION.** The common error is running the whole function at one rung. In a three-hundred-person company a reasonable spread is: alert triage at 5; endpoint containment at 4 with thresholds written down; identity and firewall change approval moving from 3 to 4 across two quarters; vendor security review at 4 against a tiering standard you still own; exception granting held at 2, because exceptions are where risk concentrates and where standing distorts judgment; incident command at 3, so your lead runs severity-two and below while you run severity-one until they have run three alongside you; and the materiality recommendation at 0, because that accountability is not delegable.\n\nContainment authority is the version that has to exist in writing before the incident: any analyst may isolate a single endpoint; the shift lead may isolate a subnet or disable an account; only the security lead or the executive may take a revenue-bearing system offline; nobody wipes an endpoint before evidence capture.\n\nTwo rules keep the ladder honest. A rung you have not written down is not a rung — unwritten authority defaults to 2, because people ask. And you may drop an activity down a rung after a failure, but you must say in advance for how long, or the drop becomes permanent and the ladder becomes a story you tell about yourself.", "example": "*Fictional composite.* Harborline Business Services is a business-process and managed-service firm headquartered in Hartford, with offices in Providence and outside Boston: $46M revenue, 340 employees, and about 180 small-business and mid-market clients across the Northeast in financial services, healthcare, professional services and retail. It runs back-office operations for those clients and, for roughly half, their IT and security stack.\n\nNadia Okonkwo co-founded Harborline as its network engineer and is now its CIO and CISO. At sixty people she was excellent. At three hundred and forty, five things were true: she approved every firewall and identity change across the client estate; she was the named security contact in sixty client contracts; she completed about ninety client security questionnaires a year herself; she was the after-hours escalation for every alert; and her team had grown to twenty-two, nine reporting directly to her.\n\nThe trigger was not insight. In March a broker-dealer client had credential abuse on an administrator account at 2:14 a.m. Harborline's analyst identified it in nine minutes, could not reach Nadia — she was on a flight — and had no written authority to disable the account. He waited. The account was disabled at 6:40 a.m. The client's summary to its regulator was accurate and unflattering: the provider detected it in nine minutes and acted in four hours and twenty-six minutes. Two months later the same client, ahead of a FINRA examination, asked for a named vCISO with defined escalation authority and a documented incident process. Nadia's honest answer was that the escalation authority was her phone.\n\nThe transition took fourteen months. First, she hired a security lead — Ray Delgado, from a regional bank — and paid above her own band for him. Second, they wrote containment thresholds and posted them in the operations channel: any analyst may isolate an endpoint or disable a non-privileged account; the shift lead may disable a privileged account or isolate a client subnet; only Ray or Nadia may take a revenue-bearing client system offline. Third, they set the ladder per activity and wrote the current rung beside each item on a one-page table: triage at 5, change approval moved from 2 to 3 to 4 over three quarters, questionnaires at 4 against a standard answer library, exceptions held at 2 with Nadia approving.\n\nFourth, a cadence: a Monday operations review Ray ran, a monthly client-risk review, a quarterly session with the founders. Fifth, five numbers on one page every week — mean time to contain, percentage of client estates with phishing-resistant MFA, restore tests completed against plan, overdue exceptions, and clients where Harborline itself held an unreviewed privileged path. Before this, only Nadia knew any of them, and only approximately.\n\nThe hardest change was the contracts: removing her name as security contact from forty-one of sixty agreements took two quarters, three conversations that went badly and one that nearly lost an account.\n\nEighteen months on, mean time to contain was thirty-eight minutes against four hours and twenty-six, questionnaire turnaround had gone from eleven days to three, and Ray had run two severity-one incidents without her. Nadia worked fifty-two hours a week instead of seventy, and spent about a third of it on things a Player would consider waste: hiring, a pricing conversation about the security service line, and a two-day argument about which client segments to stop serving.\n\n**INTERPRETATION.** Nothing here was an attitude change. The mechanisms — written containment authority, a rung per activity, a cadence, five shared numbers — made delegation the default rather than a daily act of will. Nadia's Player instincts had not been wrong. They had been calibrated for a sixty-person firm and carried, unexamined, into a firm five times that size.", "ceo_contrast": "Take Harborline in March, hours after the 2:14 a.m. incident, and put three archetypes in Nadia's chair.\n\n**The SMB / MSP Technology Leader (Player)** reads it as an availability problem and fixes availability: a second phone, a backup escalation number, herself on a formal rotation. Fast, cheap and wrong at this size. The gain is that the next 2 a.m. call gets answered. The cost is that the firm has re-confirmed that the executive is the control, and the next failure arrives when she is in a client meeting rather than on a plane. The Player's danger is not laziness — it is doing the available small thing instead of the unavailable large one.\n\n**The Mid-Market CIO (Coach)** hires the security lead and writes the containment thresholds, which is what Nadia did. The gain is a function that works when she sleeps. The cost lands in months two through six, when Ray makes calls she would have made differently and two of her direct reports test whether the ladder is real by escalating around him. A Coach who does not hold the line converts a real delegation into an expensive second opinion, and the organization learns that the table on the wall is decorative.\n\n**The Enterprise CIO (Architect)**, imagined in this seat, designs the whole system at once: a governance model, a client-risk committee, a RACI covering forty activities, a quarterly attestation. Weill and Ross (2004, Tier 3) would recognize the instinct, and much of it is what Harborline eventually needs. The danger is that at 340 people the design outruns the operators, and decision rights nobody has practiced under pressure will not survive their first 2 a.m. test. Design without a rung-by-rung handover is dashboard fiction with a start date.\n\n**INTERPRETATION.** A fourth archetype, the Technical CISO, would go after the administrator account itself — privileged access management, just-in-time elevation, tighter conditional access. All correct, all worth doing, and none of it touching the four hours and twenty-six minutes. That is the module's asymmetry: the available technical answer competes with the unavailable structural one, and looks more responsible in the moment.", "failure_mode": "**FRAMEWORK.** The Overuse Ladder — strength → overused strength → liability — climbs differently at each scale, because each role rewards a different strength.\n\nAt the **Player** scale the characteristic rung is *humility → excessive hesitation*, dressed as prudence: the MFA rollout waits for a quieter month, the vendor is not challenged because the relationship matters, the restore test is scheduled and re-scheduled.\n\nAt the **Coach** scale it is *attention to detail → micromanagement* and its partner *persistence → stubbornness*. The security lead is hired and then supervised at rung 2 on everything, and their first different-from-yours decision is reversed, politely, in front of the team. Within two quarters they are managing you rather than the function, and the good ones leave — which the Coach experiences as confirmation that nobody else can do this.\n\nAt the **Architect** scale it is *optimism → delusion*: the dashboard is green, the maturity score has improved, and the control exists on the slide rather than on the server. Angst et al. (2017) found symbolic adoption diminished the effectiveness of investment; Edmondson (1996) found better climates produced more reported errors, so improving numbers can mean improving silence. Its partner is *vision → fantasy*: a three-year platform strategy alongside a six-month-old critical vulnerability nobody escalated, because escalating is not what the culture rewards (Milliken et al., 2003).\n\n**INTERPRETATION.** The dangerous moment is not the failure; it is the promotion. Every transition asks the leader to stop doing the thing that earned it, and the evidence that they have not made the transition is usually two levels below them, and quiet.\n\n### Early warning signs\n\n- The executive can name the last five decisions they made personally and cannot name five their team made without them.\n- The new security lead's disagreements are answered with history rather than with evidence.\n- Incident, near-miss or phishing-report counts are improving and nobody has asked whether reporting fell instead.\n- The leader is the named contact, approver or escalation in more places than they can list from memory.\n- A control has been on the board slide for three quarters and nobody has watched it operate."}, "research_refs": ["res.bandiera2020", "res.graham2015", "res.bloom2007", "res.weill2004", "res.peppard2010", "res.milliken2003", "res.detert2011", "res.edmondson1996", "res.angst2017", "res.verizon2025", "res.ians2026", "res.ashenden2013", "res.owens2012"], "reflection": ["Which role does your company's size call for, and which one are you actually running? Give three activities from last month as evidence, not a self-description.", "Take the ten things only you can currently do. For each, write the rung it sits on and the rung it should sit on. Which one have you been protecting because it is the thing you are respected for?", "Where are you on the five stages of the hands-on engineer trap? Name the person whose judgment you overrode most recently, and whether you were right.", "If you were unreachable for seventy-two hours starting now, what would not happen? Which of those items is a genuine accountability and which is an unwritten rung?", "Write your containment thresholds from memory. If you cannot, they do not exist, and your team's real authority is \"ask.\"", "Which of your improving metrics could be explained by less reporting rather than better security, and what would you look at to tell the difference?"], "simulation_ref": "sim.m08-brightwater-isolation", "knowledge_check": [{"id": "m08-kc1", "type": "multiple_choice", "question": "Bandiera, Prat, Hansen and Sadun (2020) estimated that the share of firms whose CEO's behavioral type did not fit the firm was about:", "answer": "B", "explanation": "From time-use diaries of 1,114 manufacturing CEOs in six countries — a matching estimate, which the authors caution is not a verdict that \"leader\" types are better than \"manager\" types.", "options": [{"key": "A", "text": "3%"}, {"key": "B", "text": "17%"}, {"key": "C", "text": "42%"}, {"key": "D", "text": "65%"}]}, {"id": "m08-kc2", "type": "multiple_choice", "question": "Graham, Harvey and Puri (2015) found that executives delegated:", "answer": "C", "explanation": "The direction matters for the hands-on engineer trap: expertise reduces delegation, so deep domain knowledge is the trap's fuel rather than its cure.", "options": [{"key": "A", "text": "More when they had long tenure and deep expertise."}, {"key": "B", "text": "Less when they were overloaded or distracted by major events."}, {"key": "C", "text": "More when overloaded or distracted by major events, and less when they had long tenure or expertise."}, {"key": "D", "text": "At rates unrelated to tenure, expertise or workload."}]}, {"id": "m08-kc3", "type": "multiple_choice", "question": "Milliken, Morrison and Hewlin (2003) interviewed 40 employees. The share who could recall feeling unable to raise an important issue with a superior was:", "answer": "C", "explanation": "If people withhold from a boss one level up, an executive several levels up should assume the picture reaching them has been filtered more than once — the basis of the Architect's dashboard fiction.", "options": [{"key": "A", "text": "24%"}, {"key": "B", "text": "51%"}, {"key": "C", "text": "85%"}, {"key": "D", "text": "100%"}]}, {"id": "m08-kc4", "type": "short_answer", "question": "State the six rungs of the delegation ladder for security operations, and the two rules that keep it honest.", "answer": "0 — you do it; 1 — you do it, narrated, while someone shadows and writes the runbook; 2 — they do it, you approve each instance; 3 — they do it inside a written standard, you review a sample afterward; 4 — they own the standard, you review exceptions weekly; 5 — they own the outcome and the budget, and you re-enter only on a named trigger. The rules: an unwritten rung is not a rung, and a drop after a failure must carry a stated duration.", "explanation": "The rung belongs to an activity rather than a person, and the common error is running an entire function at one setting."}], "takeaways": ["The Player *is* the technology function, the Coach builds one, and the Architect designs the system that runs it — and each role rewards the behavior the next one punishes.", "The dominant dangers are scale-specific: insufficient action at the Player scale, inability to let go at the Coach scale, and isolation plus dashboard fiction at the Architect scale, the last of which the silence and symbolic-adoption research makes structural rather than personal.", "The hands-on engineer trap runs from \"I'll just fix it myself\" to \"nothing ships without me,\" and expertise is its fuel: Graham, Harvey and Puri (2015) found delegation falling with tenure and expertise, and each handover is an identity threat disguised as an operational question.", "Delegation is a setting on an activity, not a disposition. Write the rung, write the containment thresholds, and put a date on every temporary drop — because an unwritten rung is \"ask,\" and \"ask\" is how a program becomes one person deep."], "videos": ["vid.00-player-coach-architect-for-technology-le", "vid.00-the-delegation-ladder-for-security-opera", "vid.00-the-hands-on-engineer-trap"], "glossary_terms": ["term.player", "term.coach", "term.architect", "term.hands-on-engineer-trap", "term.delegation-ladder", "term.decision-rights", "term.dashboard-fiction", "term.pre-authorized-containment", "term.fractional-ciso"], "tags": {"dials": ["centralization_decentralization", "hands_on_delegation", "unilateral_consensus", "urgency_patience"], "archetypes": ["arch.enterprise-cio-architect", "arch.mid-market-cio-coach", "arch.smb-msp-technology-leader-player", "arch.technical-ciso", "arch.transformation-cio"], "stages": ["mature", "scale_up", "startup"], "learn_categories": ["leadership", "scaling", "organizational_design"]}, "estimated_minutes": 80, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/08-player-coach-architect-for-technology-leaders.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m09", "slug": "fit-industry-regulation-stage-reporting-line", "title": "Fit — Industry, Regulation, Stage, and the Reporting Line", "unit": "III. Context Changes Everything", "big_idea": "Industry matters less than the problem — but for technology leaders the regulator and the reporting line are part of the problem.", "effectiveness_equation_term": "Organizational Context", "learning_objectives": ["Profile the technology executive's job in financial services (FINRA/SEC/OCC; broker-dealers and RIAs), healthcare (HIPAA, clinical safety), industrial/OT, retail/consumer, and government/defense, distinguishing framework from evidence.", "Map six stage profiles — startup, scale-up, post-breach turnaround, transformation, post-merger integration, regulatory consent order — to the dial settings each rewards.", "Apply the extended Fit Equation (Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line = CIO/CISO Fit) to a real role.", "Argue when a post-breach company and a pre-IPO company need psychologically similar technology leaders, and where the resemblance breaks."], "sections": {"core_lesson": "Module 8 taught the role — Player, Coach, Architect. This module teaches the room the role is played in. A technology executive who is superb in one company can be replaced in eighteen months in another without changing a single habit, because industry, regulator, stage and reporting line reward different settings on the same dials.\n\nThe CEO edition argued that industry matters less than the problem: a troubled bank and a troubled tire company may need more similar leaders than two healthy banks. That argument survives the move to the CIO and CISO chair, with one adaptation. For the technology executive, the regulator is not background. It writes part of the job description, decides what \"evidence\" means, and sometimes sits in the room. And the reporting line — CEO, CFO, CIO, general counsel, risk — decides how much of the executive's judgment ever reaches the people who allocate capital. Both are terms in the equation, not footnotes.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module changes the **Organizational Context** term. It gives you five industry profiles, six stage profiles, an extended Fit Equation with the Reporting Line added, and one sophisticated move: seeing when two companies that look nothing alike need the same leader. You leave able to write the problem before the profile, and to name the term you personally are weakest on.", "big_idea": "**Industry matters less than the problem — but for technology leaders the regulator and the reporting line are part of the problem.**\n\nA post-breach healthcare system and a pre-IPO payments company share a problem — produce credible, documented evidence of control, fast, under outside scrutiny — that may demand more similar technology leaders than two healthy hospitals with different CEOs. Fit fails at the weakest term, and for the CIO or CISO the weakest term is often the one nobody put in the job posting.", "research": "**RESEARCH FINDING.** The foundational evidence that structure should follow the problem is Banker, Hu, Pavlou & Luftman (2011). In a large-firm archival panel using data from 1990–1993 and 2006, the \"right\" CIO reporting line depended on strategy: differentiation firms performed better when the CIO reported to the CEO, cost-leadership firms when the CIO reported to the CFO — a relationship the authors say holds \"independent of whether IT plays a key strategic role in the firm.\" Associations under controls, with the endogeneity of the reporting choice addressed statistically; the data predate cloud-era roles. It supports \"there is no universally correct reporting line.\" It says nothing about CISOs or about companies smaller than the panel covers.\n\n**RESEARCH FINDING.** Healthcare offers the two cleanest studies of how regulation shapes the return on security effort. Kwon & Johnson (2014), using a Cox proportional-hazard model on US healthcare organizations — chosen because breach disclosure is mandated and investment data exist — found proactive security investment associated with lower subsequent failure rates and better cost-effectiveness than reactive investment, and that \"external pressure decreases the effect of proactive investments on security performance.\" Angst, Block, D'Arcy & Kelley (2017), in a matched panel of over 5,000 US hospitals and 938 breaches (2005–2013), found that \"symbolic\" adoption of security practices diminished the effectiveness of investment and raised breach likelihood, while deeper integration into IT routines was associated with fewer breaches. One-sector, reported-breach-only designs; adoption depth inferred from institutional profile. **INTERPRETATION.** Together they describe the regulated-industry trap: the regulator pushes spending, and spending under pressure tends toward the symbolic. A control adopted to satisfy an examiner buys less than the same control adopted because someone inside wanted it.\n\n**RESEARCH FINDING.** The market prices the *type* of breach, and the type depends on the industry. Campbell, Gordon, Loeb & Zhou (2003) found limited evidence of an overall negative stock reaction to reported breaches, a highly significant negative reaction where the breach involved unauthorized access to confidential data, and none where it did not. Kamiya, Kang, Kim, Milidonis & Stulz (2021) found attacks involving loss of personal financial information associated with shareholder losses much larger than out-of-pocket costs; spillover to industry peers; smaller excess losses where boards had attended to risk management beforehand; and, afterward, increased risk-management and IT investment and reduced risk-taking incentives for managers. Event studies of disclosed attacks; short windows; proxied governance. **INTERPRETATION.** An industry that holds personal financial data lives in a different loss function from one that holds industrial telemetry. That is the first reason the job differs by industry: not the technology, but what the market and the regulator do when the data leaves.\n\n**RESEARCH FINDING.** Kashmiri, Nicol & Hsu (2017) studied 168 publicly listed US retailers around Target's December 2013 breach and found contagion: other retailers lost value on average, more if they resembled Target in size and product market or shared governance ties, less if they had stronger IT capability, marketing ability and CSR records. Single event, single industry, cross-sectional proxies. A competitor's breach is priced against you, moderated by your own visible capabilities.\n\n**RESEARCH FINDING.** Higgs, Pinsker, Smith & Young (2016) found, over 2005–2014, that firms with board-level technology committees were more likely to have *reported* breaches, and that a technology committee mitigated the negative abnormal returns from external breaches. Reported breaches conflate occurrence with detection and disclosure; committee formation is endogenous. **INTERPRETATION.** Governance changes both what gets reported and how the market reads it — a preview of Module 10.\n\n**FACT.** Two rule-and-standard sources define part of the terrain. The NIST Cybersecurity Framework 2.0 (26 February 2024) provides a taxonomy of high-level cybersecurity outcomes for organizations of any size, sector or maturity and adds a Govern function alongside Identify, Protect, Detect, Respond and Recover; it is voluntary, outcome-focused and not evidence of effectiveness. The SEC's cybersecurity disclosure rules (adopted 26 July 2023) require public companies to disclose a material cybersecurity incident on Form 8-K within four business days of determining it is material, and to describe annually their processes for managing material cyber risk, the board's oversight of that risk, and management's role and expertise; incident disclosure applied from 18 December 2023, with 180 extra days for smaller reporting companies. Legal requirements, not findings.\n\n**RESEARCH FINDING.** From the CEO library, Karaevli (2007) studied CEO succession in the US airline and chemical industries from 1972 to 2002 and found no direct main effect of \"outsiderness\": outsiders helped when pre-succession performance was poor and the environment turbulent, and the effect depended on what changed alongside the succession. Zhang & Rajagopalan (2010), also from the CEO library, found among 193 US CEOs an inverted-U relationship between strategic change and performance, with outsiders experiencing larger gains from moderate change and larger losses from excessive change. Archival, observational, about CEOs. **INTERPRETATION.** These are the closest evidence for the stage profiles below; read them as analogy.\n\n**RESEARCH FINDING — TIER 3.** Base rates only, from self-selected practitioner samples: the IANS Research & Artico Search *State of the CISO 2026* survey of more than 600 security leaders reported that 64% of CISOs report to IT leaders and 36% to non-IT leaders; the 2025 Verizon DBIR's contributor sample of 12,195 confirmed breaches reported ransomware present in 44% of breaches and 88% of SMB breaches.\n\n### Where the evidence is weak\n\nAlmost everything above concerns large public companies or US hospitals. There is no peer-reviewed study in this library of the technology executive's job in industrial/OT environments, in government and defense, or in the SMB and MSP world most of this course's first learners inhabit. The industry profiles below are therefore FRAMEWORK and INTERPRETATION, informed by the loss-function evidence and the regulatory facts, not by studies of CISOs in each sector. The stage profiles borrow from CEO succession research. Treat both as lenses to test against your own situation.", "explanation": "### What a regulator does to the job\n\n**FRAMEWORK.** The CEO edition described five forces that make industries produce different CEOs: capital intensity, regulation, cycle length, customer concentration and the nature of the product. For the technology executive, regulation changes character. A regulator does three things to a CIO or CISO that it does not do to most CEOs.\n\nIt defines *evidence*: in an unregulated company, \"we have access controls\" is a claim about the system; in a regulated one it is a claim about a document an examiner can request, and a claim true in the system but false in the document is a finding. It *sets the clock*: exam cycles, notification deadlines and consent-order milestones do not care about your roadmap. And it *changes the loss function*: the market's penalty depends on what kind of data left (Kamiya et al., 2021; Campbell et al., 2003); the regulator's penalty depends on whether you could show you were trying. Two companies with identical technical exposure can have very different jobs at the top of technology, because one of them will be asked to prove it.\n\n**INTERPRETATION.** The healthcare evidence is the warning that comes with the territory: regulatory pressure moves spending toward the symbolic. The regulated-industry executive's central discipline is refusing to let the examiner's list become the program. \"Institutional paranoia\" describes the leader who treats the regulator's minimum as a floor; the failure mode treats it as a ceiling.\n\n### Five industry profiles\n\n**FRAMEWORK.** Teaching profiles, not findings. Each names the dominant loss, the regulator's presence, and the dial settings the profile rewards.\n\n**Financial services.** Broker-dealers are examined by FINRA and the SEC; registered investment advisers by the SEC and the states; banks by the OCC, the Federal Reserve, the FDIC or state regulators depending on charter. The dominant loss is the one Kamiya et al. (2021) measured — personal financial data — compounded by a regulator who arrives on a schedule with a request list and reads your written supervisory procedures against your logs. The job rewards *operational discipline* over *innovation*, *caution* on anything customer-facing, and a skill the CEO course does not teach: writing controls that are true. In a small broker-dealer served by an MSP or a fractional CISO, the vCISO's real product is the gap between the procedures manual and what happens on the network. The rung is rigor → bureaucracy, \"the security review that ships nothing.\"\n\n**Healthcare.** HIPAA and mandated breach notification make this the one sector with clean panel data. The dominant loss is not primarily financial: availability is clinical safety, and a ransomware event that takes down the electronic health record is a patient-safety incident before it is a privacy incident. The job rewards *resilience* on the Prevention ↔ Resilience overlay — recovery time is the metric — and *consensus* with clinicians, who will route around any control that slows care. The trap is the compliance-only CISO who is HIPAA-perfect and operationally fragile.\n\n**Industrial and operational technology.** No study in this library covers it; INTERPRETATION only. The dominant loss is physical: production stops, or something moves that should not. Legacy equipment cannot be patched on an IT schedule, vendors own the control systems, and the plant floor regards IT as a visitor. The job rewards *patience* over *urgency*, *decentralization* — plant managers own their floors — and the resilience end of the overlay, because prevention on a twenty-year-old controller is a fiction.\n\n**Retail and consumer.** Card data, consumer identity, seasonality, thin margins. Kashmiri et al. (2017) show the distinctive feature: a competitor's breach is priced against you, and your own visible IT, marketing and CSR capabilities are the shield. The job rewards *aggression* on customer-facing technology — the business is a technology business whether it admits it or not — and *operational discipline* on the payment perimeter. The card networks and the plaintiffs' bar stand in for the regulator. Control ↔ Enablement sits further toward enablement than anywhere else, and the failure mode is banking's in reverse: enablement → exposure.\n\n**Government and defense.** Clearance, procurement rules, mandated frameworks and a reporting line that runs through appointees or agency heads. Discretion is structurally low; the leader's power is almost entirely borrowed. The job rewards *consensus*, *patience*, and running a program through mandated process without letting the process become the program. It punishes the unilateral operator, whose speed reads to the oversight apparatus as the culture that caused the last problem. Profile only.\n\n### Six stage profiles\n\n**FRAMEWORK.** Stage is the most time-sensitive term of the Fit Equation. Six recognizable situations:\n\n**1. Startup.** The problem is existence; security is a Player's job — the vCISO, the MSP, the founder's laptop. Dial: *hands-on*, *urgency*, *innovation*, enablement. Danger: insufficient action, and no second opinion. Ransomware in 88% of SMB breaches (Verizon, 2025, Tier 3) is the base rate being priced.\n\n**2. Scale-up.** The problem is organization: the first security hire who is not you, decision rights, an actual platform. Dial: *delegation*, *decisiveness* on structure, *operational discipline* arriving for the first time. Danger: the founder-engineer who cannot let go (Module 8).\n\n**3. Post-breach turnaround.** The problem is credibility under blame. Dial: *centralization*, *decisiveness*, *urgency*, *skepticism*, *unilateral* — for a season. Kamiya et al. (2021) describe what companies actually do: raise risk-management and IT investment, cut managers' risk-taking incentives. The CEO course's turnaround paradox applies in full: \"Cut. Replace. Centralize. Decide. Move.\" is correct for a season that ends more quietly than it began.\n\n**4. Transformation.** The problem is changing the operating model — cloud, ERP, platforms — while the business keeps running. Dial: *aggression*, *innovation*, *decisiveness*, with Zhang & Rajagopalan's (2010) inverted U in view: moderate change helps, excessive change hurts, and the outsider's swing is wider both ways. Discretion high, tenure short; \"strategy-of-the-month\" is the rung.\n\n**5. Post-merger integration.** The problem is two of everything and a deal thesis that depends on becoming one. Dial: *decisiveness* early on architecture and identity, *consensus* on culture, *skepticism* about the synergy case, *operational discipline*. The hidden term is security debt: the acquired company's controls are now your attack surface, and nobody priced that in the deal model.\n\n**6. Regulatory consent order.** The problem is legitimacy: a regulator has concluded the company cannot be trusted to run its own controls and has written down what must change and by when. Dial: *caution*, *consensus* with the regulator, *patience*, *inquiry*, *operational discipline*. Nearly the inverse of the post-breach turnaround — and companies move from one to the other, which is why the executive right for the first is so often wrong for the second.\n\n### The extended Fit Equation\n\n**FRAMEWORK.** Industry × Scale × Lifecycle × Strategy × Governance × Problem × **Reporting Line** = CIO/CISO Fit. Multiplicative, so fit fails at the weakest term.\n\nReporting Line is the term the CEO course did not need, and Banker et al. (2011) is the evidence that it is not decorative. **INTERPRETATION.** Reporting to the CFO puts the technology executive inside the cost conversation; to the CEO, inside the strategy conversation; to the CIO — as roughly two-thirds of CISOs do, per the IANS 2026 practitioner survey — inside the delivery conversation, where the person judging the risk is the person whose projects carry it. None is wrong. Each is wrong for a particular problem. A CISO built for the strategy conversation, sitting two levels below it, experiences the job as a slow argument with a wall — and the wall experiences the CISO as someone who does not understand the business.\n\nThe practical test: for each of the seven terms, write one line describing the company and one describing yourself. Circle the term where the lines disagree most. That is your fit problem, and it is usually not the one the recruiter discussed.\n\n### When a post-breach company and a pre-IPO company need the same leader\n\n**INTERPRETATION.** A healthcare system nine months after a ransomware event, under regulator inquiry and plaintiff discovery. A payments company eighteen months from a listing. Different industries, different moods — one grieving, one celebrating — and, on the surface, opposite stage profiles.\n\nNow write the *problem*. The post-breach company must produce, quickly, documented and auditable evidence that its controls exist and work, for an outside party that assumes they do not. The pre-IPO company must produce the same evidence for outside parties — underwriters, auditors, and after listing the SEC's annual disclosure of risk processes, board oversight and management expertise (FACT: SEC, 2023) — that will assume nothing. Both are evidence-factory problems. Both reward *centralization* of control ownership for a season, *operational discipline*, *decisiveness* on structure, *skepticism* about every inherited claim, and a leader who communicates upward in the outside party's language. Both punish the enablement-first leader who regards documentation as overhead.\n\nThe resemblance breaks at the information environment. The post-breach company is a blame environment, where reporting has usually collapsed — nobody wants to be the next finding. The pre-IPO company is an optimism environment, where nobody wants to slow the listing. Same leader, same dials, opposite silences to break. **HYPOTHESIS.** The technology executive who has done one is unusually well-suited to the other — and unusually likely to misread the silence, because the last silence had a different cause.", "example": "*Fictional composite.*\n\nMarcus Oyelaran had been CISO of Quarrystone Health Partners — a physician-owned group of 46 practices in Connecticut and Massachusetts, $380M revenue, 2,400 employees — for eleven months when the ransomware event happened. The EHR was down six days. Two clinics reverted to paper. The Office for Civil Rights opened an inquiry; a class action followed within a month. His reporting line, which had run to a CIO who left that quarter, was moved to the CEO.\n\nWhat he did over the next fourteen months was not clever. He centralized ownership of every control under his own office, replaced the MSP that held the backup contract, and wrote a control inventory that mapped each control to evidence — a log, a ticket, a review — rather than to a policy sentence. He reported monthly to the board in one format: what we said we had, what we can prove we have, the gap, the date. He was blunt with clinicians and unpopular for a season. The inquiry closed with a corrective action plan rather than a penalty; the litigation settled.\n\nEighteen months later a search firm called about Larkspur Payments — a Boston payments company, $210M revenue, 900 employees, venture-backed, planning a listing within two years. The CFO was frank: \"We have a security team that ships fast and documents nothing. The underwriters will ask for what you built at Quarrystone.\" Oyelaran's dials — *centralization*, *operational discipline*, *skepticism*, *decisiveness* on structure — had been set in a blame environment. He was about to use them in an optimism environment.\n\nIt worked, mostly. The control inventory transferred almost verbatim; the monthly format became the audit committee's format. Engineering leaders who expected a \"no\" machine got a CISO who said yes to nearly everything and priced it: \"Yes — and here is the risk we are accepting, in customer-record terms, until the access-review automation lands in Q3.\" The listing's disclosure of risk processes and board oversight was drafted from his inventory.\n\nThe place it did not work was the one the hypothesis predicts. At Quarrystone, silence had meant fear, and he had broken it by making reporting safe. At Larkspur, silence meant enthusiasm; nobody was afraid, they were busy. He spent four months reading the absence of bad news as the health of the program before an engineer mentioned, in passing, that a customer-facing API had shipped without the review his inventory said was mandatory — not concealed, just not considered worth mentioning. The control existed in the document and not in the system: the symbolic-adoption pattern (Angst et al., 2017), produced not by a regulator but by a roadmap.\n\nHe fixed it as he had fixed things before: a direct line from engineering leads to his office, a standing \"what shipped without us\" item in the weekly, and a written note to the CEO that he had misread the environment. Same leader, same dials, second silence — recognized late, because it sounded like the first one.\n\nThe coda: a year after the listing, an industrial firm with a plant-floor OT estate approached him. He declined. \"The problem there is patience,\" he told the recruiter, \"and I have been hired twice for the opposite.\"", "ceo_contrast": "Put four archetypes in the Larkspur seat — pre-IPO, an optimism environment, an engineering culture that ships and does not document, eighteen months to a listing.\n\n**The Technical CISO** sees the undocumented estate as an engineering problem and starts fixing it personally: reviewing code, hardening the API gateway, writing detections. Gain: real control improves fast, and engineers respect the competence. Cost: the underwriters do not ask whether the API is hardened; they ask for evidence that a process hardens every API. This leader builds protection and not proof, and the Fit Equation fails at the Problem term.\n\n**The Business-Risk CISO** reads the room correctly: the company's currency is speed and the board wants the listing. This leader prices everything, says yes often, and builds the disclosure narrative early. Gain: the best relationship with the CFO and the cleanest board materials of the four. Cost: pricing risk in an optimism environment tends toward under-pricing, because every number is negotiated with people who want it lower. \"Yes\" as identity. The API that shipped without review goes unnoticed longer here, because this leader has fewer direct lines to engineers and more to executives.\n\n**The Post-Breach CISO** — Oyelaran's own archetype — brings the evidence factory ready-made. Gain: the fastest path to an auditable program. Cost: the turnaround dials — *centralization*, *unilateral*, *urgency* — were set for a blame environment, and in an optimism environment they read as distrust. Engineering leaders who were never at fault are treated as if they were. The leader who does not notice the season has ended becomes the reason the best engineers leave in year two.\n\n**The Regulated-Industry CIO/CISO** treats the listing as a regulator arriving: reads the disclosure rule, builds to it, staffs a compliance function early. Gain: nothing surprises this leader at the listing; the SEC's annual disclosure requirements (FACT) are met on the first filing. Cost: the examiner's list becomes the program — the Kwon & Johnson (2014) pattern in which external pressure weakens the return on proactive investment. A payments company that is compliance-perfect and product-slow has fit the Governance term and failed the Strategy term.\n\nNone of the four is wrong for Larkspur. Each fails at a different term, and a board that names the term before hiring gets a better leader than one that names the archetype.", "failure_mode": "**FRAMEWORK — the Overuse Ladder for fit.** The rungs fit-failure climbs are familiar, with technology-specific labels: rigor → bureaucracy (\"the security review that ships nothing\"); caution → paralysis (\"the CISO who is never breached because nothing is ever deployed\"); operational discipline → the examiner's checklist as the whole program; decisiveness → the turnaround playbook imported into a company that is not in a turnaround; adaptability → strategy-of-the-month in a transformation that never consolidates.\n\nThe destructive pattern is not usually a bad leader. It is a good leader for a situation that has ended or a company that was never in it. The post-breach CISO's centralization becomes, in a healthy company, a bottleneck engineers route around, and the workarounds become the attack surface. The regulated-industry leader's evidence discipline becomes, in a startup, a documentation regime a twelve-person engineering team cannot carry, so they stop reading it. The transformation CIO's aggression, past the top of the inverted U (Zhang & Rajagopalan, 2010), produces a company that has changed its operating model three times and mastered none. In each case the leader experiences the mismatch as the organization's failure to understand risk, and the organization experiences it as a leader who does not understand the business. Both are right about the other.\n\n**INTERPRETATION.** The regulator adds a distinctive rung: regulator-as-identity. The leader whose authority came from the examiner — \"FINRA requires it,\" \"OCR will ask\" — loses the ability to argue for anything the examiner does not require, and the program shrinks to the request list. Kwon & Johnson's (2014) finding that external pressure weakens proactive investment is the empirical shadow of this rung.\n\n### Early warning signs\n\nFor the technology executive:\n\n- You describe your current company's problem in the vocabulary of your last company's problem.\n- Your justification for a control begins with a regulator's name more often than with a loss scenario.\n- Engineers, clinicians or plant managers have built workarounds to your controls, and you learned of them from an incident rather than from them.\n- Your reporting line changed and your reporting format did not.\n\nFor the CEO or board:\n\n- The technology leader was hired for a stage the company has now left, and nobody has re-asked the fit question.\n- Board materials describe compliance status and never describe expected loss.\n- The CISO reports to a CIO whose delivery targets the CISO is supposed to price, and no one has designed the escalation path for the day they disagree."}, "research_refs": ["res.banker2011", "res.kwon2014", "res.angst2017", "res.kamiya2021", "res.campbell2003", "res.kashmiri2017", "res.higgs2016", "res.nist2024", "res.sec2023", "res.karaevli2007", "res.zhang2010", "res.ians2026", "res.verizon2025"], "reflection": ["Write the extended Fit Equation for your current role — one line per term for the company, one for yourself. Which term disagrees most? Was that term discussed when you were hired?", "Name the last control you implemented because a regulator, auditor or client questionnaire required it. Is it substantive or symbolic in your organization today? How do you know?", "Which industry profile describes your temperament best, and which describes your current employer? If they differ, what has closing the gap cost?", "Which of the six stage profiles is your company in now? Which will it be in within two years? Can you move your dials that far, by evidence rather than intention?", "Your reporting line: what conversation does it put you inside, and what conversation does it keep you out of? Whose problem is that?", "Recall a silence you misread — a period of no bad news that turned out to mean something other than health. What did it sound like, and what did you assume?", "If you were offered the post-breach mandate and the pre-IPO mandate on the same day, which would you take — and which would your last three employers say you should take?"], "simulation_ref": "sim.m09-halloran-pike-exam", "knowledge_check": [{"id": "m09-kc1", "type": "multiple_choice", "question": "Banker, Hu, Pavlou & Luftman (2011) found that the CIO reporting line associated with better performance depended on what?", "answer": "B", "explanation": "The archival study argues structure should follow strategy \"independent of whether IT plays a key strategic role\"; an association from data covering 1990–1993 and 2006, about CIOs rather than CISOs.", "options": [{"key": "A", "text": "Firm size — larger firms did better with the CIO reporting to the CEO"}, {"key": "B", "text": "The firm's strategic positioning — differentiation firms did better with CIO-to-CEO, cost-leadership firms with CIO-to-CFO"}, {"key": "C", "text": "Whether the CIO had a technical or business background"}, {"key": "D", "text": "Industry regulation intensity"}]}, {"id": "m09-kc2", "type": "multiple_choice", "question": "Kwon & Johnson (2014) found that in US healthcare, external (regulatory) pressure had what effect on proactive security investment?", "answer": "C", "explanation": "Proactive investment was associated with lower failure rates and better cost-effectiveness, but \"external pressure decreases the effect of proactive investments on security performance\" — the empirical shadow of the symbolic-adoption pattern in Angst et al. (2017).", "options": [{"key": "A", "text": "It increased the effectiveness of proactive investment"}, {"key": "B", "text": "It had no measurable effect"}, {"key": "C", "text": "It decreased the effect of proactive investment on security performance"}, {"key": "D", "text": "It converted reactive investment into proactive investment"}]}, {"id": "m09-kc3", "type": "short_answer", "question": "State the extended Fit Equation and explain in one sentence why the Reporting Line term is included for the technology executive but not for the CEO.", "answer": "Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line = CIO/CISO Fit; the CEO's discretion is broad by default while the CIO's or CISO's is set by someone else, and Banker et al. (2011) show the same CIO associated with different performance depending on where the line runs.", "explanation": "The equation is multiplicative, so fit fails at the weakest term — often the reporting line nobody discussed at hiring."}, {"id": "m09-kc4", "type": "short_answer", "question": "Explain why a post-breach company and a pre-IPO company may need psychologically similar technology leaders, and name where the resemblance breaks.", "answer": "Both are evidence-factory problems — produce documented, auditable proof of control quickly for an outside party — rewarding centralization for a season, operational discipline, decisiveness on structure and skepticism about inherited claims; the resemblance breaks at the information environment, because the post-breach silence is fear and the pre-IPO silence is enthusiasm.", "explanation": "Write the problem before the profile; the same dials can be right for both while the leader misreads the second silence because it sounds like the first."}], "takeaways": ["Industry matters less than the problem — but for the technology executive the regulator defines what evidence means, sets the clock and changes the loss function, and the reporting line decides which conversation your judgment reaches. Both are terms in the Fit Equation.", "Reporting-line evidence (Banker et al., 2011) says structure should follow strategy; healthcare evidence (Kwon & Johnson, 2014; Angst et al., 2017) says regulatory pressure pushes spending toward the symbolic, and symbolic adoption does not buy protection.", "The market prices the type of breach, not the fact of one (Campbell et al., 2003; Kamiya et al., 2021), and prices a competitor's breach against you in consumer industries (Kashmiri et al., 2017). The industry profiles are lenses built on that loss function, not findings about CISOs.", "Six stage profiles reward different dial settings, and the executive right for one is often wrong for the next. The consent-order profile is nearly the inverse of the post-breach turnaround.", "Write the problem before the profile. A post-breach company and a pre-IPO company can need the same leader; the silence each produces is different, and reading the second as if it were the first is the characteristic error of the leader who fit the first."], "videos": ["vid.00-six-stage-profiles-for-technology-leader", "vid.00-the-extended-fit-equation", "vid.00-the-regulator-in-the-room"], "glossary_terms": ["term.fit-equation-extended", "term.reporting-line", "term.regulatory-consent-order", "term.symbolic-vs-substantive-adoption", "term.proactive-vs-reactive-investment", "term.spillover-breach-contagion", "term.written-supervisory-procedures", "term.operational-technology-ot", "term.prevention-resilience", "term.control-enablement"], "tags": {"dials": ["aggression_caution", "centralization_decentralization", "innovation_operational_discipline", "unilateral_consensus", "urgency_patience"], "archetypes": ["arch.enterprise-cio-architect", "arch.post-breach-ciso-turnaround", "arch.regulated-industry-cio-ciso", "arch.smb-msp-technology-leader-player", "arch.transformation-cio"], "stages": ["mature", "post_merger", "regulatory_reputation_crisis", "scale_up", "startup", "turnaround"], "learn_categories": ["scaling", "risk"]}, "estimated_minutes": 85, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/09-fit-industry-regulation-stage-reporting-line.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m10", "slug": "working-with-the-ceo-and-the-board", "title": "Working with the CEO and the Board — Structural Power, Budgets, Disclosure", "unit": "III. Context Changes Everything", "big_idea": "A CIO's or CISO's discretion is granted, not assumed; the mature executive spends the first year building the relationships that grant it and the rest keeping the board's attention proportionate to the risk.", "effectiveness_equation_term": "Organizational Context", "learning_objectives": ["Explain structural power and social capital as the two sources of CIO/CISO authority, and say which one each current problem is limited by.", "Design a board reporting cadence that is honest, proportionate and priced, and defend it against the demand for a single reassuring number.", "Run the budget conversation as risk pricing rather than fear, using Yes-And / No-Unless and a defensible expected-loss argument.", "Score the eleven-item discretion audit for your own role and identify the two items that actually bind.", "Adapt reporting and escalation design to the CEO you actually have, using the documented case of a technical, broadcasting CEO as the extreme."], "sections": {"core_lesson": "Module 9 taught the room. This module teaches the two people in it who decide how much of your judgment ever becomes a decision.\n\nA CEO's latitude is broad by default. A technology executive's is issued — by a reporting line someone else drew, a budget process someone else runs, a committee calendar someone else sets. Two sources produce it. **Structural power** is what is written down: where you report, what you can spend, what you can stop, whose name is on the risk acceptance. **Social capital** is what is not: whether the CFO believes your numbers, whether the audit chair calls you before the meeting. Structural power without social capital produces a leader nobody listens to who can nevertheless block things. Social capital without structural power produces a well-liked advisor whose advice is optional.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on **Organizational Context**, and specifically on the fraction of your Behaviors that survives the trip upward. You leave with three instruments: a board cadence that is honest, proportionate and priced; a budget conversation run as risk pricing instead of fear; and an eleven-item discretion audit you can score in twenty minutes and act on for a year.", "big_idea": "**A CIO's or CISO's discretion is granted, not assumed; the mature executive spends the first year building the relationships that grant it and the rest keeping the board's attention proportionate to the risk.**\n\nAuthority you were not given can be earned, but only in the currency the institution actually trades in: evidence, priced positions, and a record of having been right and having said when you were not. And attention has an optimum. A board that hears nothing about cyber is not being protected; a board that hears about it monthly at the same volume stops hearing it at all.", "research": "**RESEARCH FINDING.** Preston, Chen & Leidner (2008) names the variable: CIO *strategic decision-making authority* — what the organization actually lets the technology executive decide. The citation is confirmed but the abstract could not be retrieved for this library, so no effect size or sample may be quoted from it. Its peer-reviewed practitioner companion (Preston, Leidner & Chen, 2008) is the usable artifact: crossing authority with strategic leadership capability yields four profiles — **IT Orchestrator** (high/high), **IT Advisor** (low authority, high capability), **IT Mechanic** (high authority, low capability), **IT Laggard** (low/low) — with IT's contribution to performance varying by profile. Perceptual, cross-sectional, associations. It supports the claim that authority and capability must be matched; it says nothing about how to obtain authority.\n\n**RESEARCH FINDING.** Karahanna & Preston (2013) measured the relationship itself: with matched responses from CIOs and top-management-team members at 81 US hospitals, the structural, cognitive and relational dimensions of CIO–TMT social capital facilitated knowledge exchange, and alignment mediated the path to financial performance. One sector, cross-sectional, correlational — evidence that relationship quality is a mechanism, not proof that a warmer relationship causes better returns.\n\n**RESEARCH FINDING.** The most useful finding here is a null one. Preston & Karahanna (2009), using 243 matched CIO–top-team pairs, found shared understanding of the role of IS was built by shared language, shared domain knowledge and *formal* \"systems of knowing.\" Contrary to the authors' expectation, informal social interaction and experiential similarity did **not** significantly affect it. Cross-sectional survey, self-reported constructs. **INTERPRETATION.** The mechanism beats the friendship. Design the cadence; the golf is optional.\n\n**RESEARCH FINDING.** Feeny, Edwards & Simpson (1992) originated the framing — the relationship, not the CIO's skills alone, as the unit of analysis; its abstract could not be retrieved for this library, so cite it for the framing only. Gerow, Grover, Thatcher & Roth (2014) later pooled the alignment literature and found all mean corrected correlations with performance positive — a meta-analysis of cross-sectional surveys with modest, heterogeneous effects.\n\n**RESEARCH FINDING.** Two studies describe what boards do to outcomes. Higgs, Pinsker, Smith & Young (2016) found that over 2005–2014 firms with board-level technology committees were *more* likely to report breaches — plausibly because they detect and disclose more — and that a committee mitigated the negative abnormal returns from external breaches. Kamiya, Kang, Kim, Milidonis & Stulz (2021) found firms whose boards had attended to risk management before an attack suffered smaller excess losses. Archival, associations, governance proxied. **INTERPRETATION.** Visible oversight changes both what surfaces and how the market reads it — the strongest argument here for building the cadence before you need it.\n\n**RESEARCH FINDING.** Amir, Levi & Livne (2018) compared attacks firms disclosed with attacks they withheld that were later revealed from outside: withheld attacks were associated with an equity decline of approximately 3.6% in the month of discovery, disclosed attacks about 0.7%. The period predates mandatory disclosure, and withheld attacks are observable only when someone else finds them. Concealment is priced when discovered.\n\n**FRAMEWORK.** From the CEO library: managerial discretion (Hambrick & Finkelstein, 1987) holds that how much an executive matters depends on the latitude the environment, the organization and the executive's own makeup allow; Hambrick's (2007) update adds that characteristics matter most where discretion exists and job demands are heavy. Both conceptual; Wangrow, Schepker & Barker's (2015) review finds support strongest for environmental sources and weakest for individual ones. Note the irony: the *organizational* source — the least studied — is the dominant one for a CIO or CISO.\n\n**RESEARCH FINDING.** Peppard (2010), interview-based in a refereed practitioner journal, argues CIO performance is largely contextual and names \"the pivotal role of the IT savviness of the CEO and the leadership team.\" It points where Ashenden & Sasse's (2013) five CISO interviews point: the leaders themselves named low perceived power and unclear role identity as their main obstacles.\n\n**FRAMEWORK.** Gordon & Loeb (2002) supplies the budget instrument: optimal security investment depends on the value of the information set, its vulnerability and the productivity of spending, and — for the two classes of breach-probability function the authors assume — does not exceed about 37% of expected loss. Analytical, not empirical; other functions justify higher fractions. Quote the bound only with its assumptions attached.\n\n**FACT and TIER 3.** The SEC's cybersecurity rules (adopted 26 July 2023) require disclosure of a material cybersecurity incident on Form 8-K within four business days of the materiality determination, and annual disclosure of processes for managing material cyber risk, **the board's oversight of that risk, and management's role and expertise** — the board's oversight is now a disclosed object. The NACD/ISA *Director's Handbook on Cyber-Risk Oversight* (2023) is the de facto US reference for what directors are advised to do; practitioner guidance, not evidence it works. The IANS/Artico *State of the CISO 2026* survey of 600+ security leaders reports 64% of CISOs reporting to IT leaders and 36% to non-IT leaders, and 52% saying their responsibilities are not manageable with current resources — self-selected sample, base rates only.\n\n### Where the evidence is weak\n\nNearly all of the CIO evidence is survey-based, cross-sectional and perceptual, much of it from one sector or from before cloud, before the SEC rule, and before the CISO was a board-facing role. There is no study in this library of *CISO* authority, of board cyber cadence, of budget negotiation, or of any of the three instruments below; Banker, Hu, Pavlou & Luftman (2011) tells you the right reporting line depends on strategy and nothing more specific. Everything in section 4 that is not explicitly cited is FRAMEWORK and INTERPRETATION.", "explanation": "### Two sources of authority\n\n**FRAMEWORK.** List every decision in your organization that carries technology or security risk, and mark how you would actually affect each one. Some you affect because a document says so — you approve the change, you sign the exception, you can stop the release. That is structural power, and it survives your absence and a bad quarter. Others you affect because someone chooses to ask you and believe your number. That is social capital, and it evaporates the week you are wrong in public and cannot say so. **Personality × Power** applies with a twist: Power here is granted rather than seized, so the same person holds different amounts of it in two companies. The **IT Mechanic** blocks anything and explains nothing, and is removed by a CEO tired of losing arguments he cannot follow. The **IT Advisor** is this course's more common tragedy: the excellent fractional CISO whose recommendations are read, admired and not funded. Opposite remedies — the Mechanic must price rather than prohibit; the Advisor must convert goodwill into written structure.\n\n**INTERPRETATION.** Order matters. Social capital is the only currency available in year one, because nobody rewrites a reporting line for a stranger; year two is spent converting it into written decision rights while goodwill is high. Skip the first and you get told no; skip the second and you spend a tenure re-earning permission you should have banked.\n\n### Instrument 1 — the board cadence: honest, proportionate, priced\n\n**FRAMEWORK.** Board reporting fails in two directions: a wall of green indicators teaches the board that this topic never contains news, and an unstructured recitation of threats teaches them it is permanently alarming. Three properties fix both. **Honest** means bad news has a permanent home in the format and that home is never empty; if \"what we got wrong\" is blank two quarters running, either your program has no learning function or your reporting has a filter. Edmondson (1996) is the diagnostic: units with better climate reported *more* errors, so a falling incident count can mean rising silence. **Proportionate** means volume tracks exposure, not the news cycle. **Priced** means every risk carries a number with a method: \"High\" is not a number, and \"roughly $4–7M of expected annual loss, driven mostly by third-party access, method in the appendix, and here is what I am unsure about\" is.\n\nThe quarterly pack, four parts, in order:\n\n1. **Position.** Two or three sentences — what we protect, the largest exposures, what changed — written so the audit chair can repeat it accurately in a hallway.\n2. **Priced exposure.** Three to five risks, each with an owner, a loss range and method, the decision that would reduce it, and its cost. Accepted risks carry the accepter's name and a review date.\n3. **Evidence.** Not maturity scores: for each control you claim, what would an examiner or a plaintiff's expert be shown?\n4. **What we got wrong.** Near-misses, failed tests, self-discovered findings, and last quarter's forecasts that did not hold. Including yours.\n\nTwo standing rules: **pre-agree the escalation trigger** — write into the minutes now what would cause you to contact the chair between meetings — and **no single index**, which is section 9 in full.\n\n### Instrument 2 — the budget conversation as risk pricing\n\n**FRAMEWORK.** Fear-based budgeting works exactly once per CEO. It buys a spike after an industry breach, decays, and makes your funding a function of other people's disasters. Arrive instead with a priced portfolio and let the business choose. Gordon & Loeb (2002) is the discipline, and its bound of roughly 37% of expected loss carries two cautions you should volunteer yourself: the bound depends on assumed classes of breach-probability function, and your expected loss is an estimate you constructed rather than a fact you retrieved. A CFO who watches you attack your own model will believe the rest of it.\n\nThree columns, not one. **Buying down:** spend that reduces expected loss, with the reduction and the method — \"this costs $310K a year and moves third-party access from about $5M of expected annual loss to about $2M; confidence in the $5M is moderate.\" **Accepting:** risk you recommend the company keep, priced, with a named accepter and a review date — a portfolio rather than a wish list, and the Risk Corollary in budget form: *\"Yes — and here is the risk we are accepting, priced.\"* **Cannot price:** exposures where you have no defensible number, said plainly, with a costed proposal for getting one. Executives lose credibility faster by pricing what they cannot than by admitting they cannot.\n\n**INTERPRETATION.** Then run **Yes-And / No-Unless** on requests coming the other way, with the changing condition real and reachable: a compensating control, a contract term, a test result, a date. A \"No\" whose condition is unreachable is a \"No\" wearing a costume.\n\n### Instrument 3 — the eleven-item discretion audit\n\n**FRAMEWORK.** Discretion is usually discussed as a property of a person. For a technology executive it is mostly a property of the chair — so measure the chair. Score each item 0–3; total out of 33.\n\n| # | Item | 0 | 3 |\n|---|---|---|---|\n| 1 | **Reporting line** | Two-plus levels down, inside a function whose delivery you police | To the CEO or an executive peer, with a line to a board committee |\n| 2 | **Budget authority** | You request; someone else decides line by line | You own an envelope and reallocate within it |\n| 3 | **Veto rights** | None, written or practical | Written authority to stop a release, deployment or vendor above a threshold, overridable only by a named executive who signs the acceptance |\n| 4 | **Board access** | Someone else summarizes your material | Standing agenda item, plus a session a year without other management present |\n| 5 | **Hiring authority** | Every requisition through a committee that is not yours | You own the plan and select your own leaders |\n| 6 | **Incident command** | Ad hoc; decided during the incident | Written declaration authority, defined powers (isolate, disconnect, engage counsel and forensics), pre-approved retainers |\n| 7 | **Architecture sign-off** | Informed after the decision | Named approver above defined thresholds |\n| 8 | **Vendor selection** | Told which vendors, told when | Veto plus a seat above a spend or data-access threshold |\n| 9 | **Regulator relationship** | No direct contact, ever | Named as accountable; you meet examiners directly, with counsel |\n| 10 | **Headcount** | Fractional or borrowed | Staffed to a plan you wrote and the board saw |\n| 11 | **Mandate clarity** | No written mandate; success undefined | Written mandate, metrics, horizon, and the conditions under which it changes |\n\n**The score describes the chair, not the occupant.** A fractional CISO at a 60-person client should score low on 5, 9 and 10; that is correct design, not failure. Item 1 is not a quality ranking — Banker et al. (2011) found the performance-associated reporting line depended on strategy, and roughly two-thirds of CISOs report into IT (IANS, 2026, Tier 3) without that being an error.\n\n**Score it twice** — as you see it, and as your CEO would. The gap is the most valuable output, and it is widest on items 3, 6 and 11: the ones both parties assume are settled and neither has written down.\n\n**Move two items, not eleven.** Roughly 0–11 is *borrowed authority*: you are an IT Advisor, and one relationship change ends your program. Roughly 12–22 is *mixed*, where the binding constraint is usually 3, 6 or 11. Roughly 23–33 is *high structural power*, where the question inverts to whether your capability matches what you were given. An executive who raises all eleven at once reads as someone building a fiefdom and gets none. Items 6 and 11 are the cheap ones: incident command authority costs nothing in calm and cannot be negotiated mid-crisis, and mandate clarity is free.\n\n### Named case — the technical CEO\n\n**FACT.** NVIDIA was founded on 5 April 1993 by Jensen Huang, Chris Malachowsky and Curtis Priem; Huang has been President and CEO since inception, about thirty-three years. He appears here because he is the best-documented example of a technical founder-CEO who has deliberately engineered his company's *information environment* rather than its org chart. A structural problem to solve, not a model to copy.\n\n**A very wide span, reported inconsistently.** Huang has described his direct-report group as **50** (Stanford GSB, 25 April 2024) and as **60** (Stripe Sessions 2024); Fortune reported 55 in January 2025. The honest statement is **\"roughly 50–60, varying by year and by which interview is cited\"** — any source giving one figure is freezing a moving number. His rationale: \"CEOs should have the most reports by definition because the people that report to the CEO require the least amount of management.\" The arrangement, he said, \"probably removes something like 7 layers.\"\n\n**No one-on-ones — with his own staff.** At Stripe Sessions 2024: \"I don't do one-on-ones and my staff is quite large. Almost everything that I say, I say to everybody,\" and, pressed, \"I really discourage 1-on-1s.\" **This is documented about Huang and his own staff, plus his stated general discouragement. It is not a company-wide prohibition**, and no source establishes what NVIDIA managers below him do.\n\n**\"Top 5 Things,\" and its ceiling.** Employees have sent short bulleted emails listing the top five things in their area, reaching executives directly; Fortune reported in December 2024, drawing on Tae Kim's *The Nvidia Way*, that Huang sampled around a hundred a day including Sunday evenings, to \"detect the weak signals.\" **This must not be taught in the unqualified present tense**: Business Insider reporting, covered secondarily in February 2026, describes NVIDIA restricting the system so the emails are distributed more narrowly, at a company well past 30,000 employees.\n\n**Two boundaries.** The maxim \"the mission is the boss\" circulates widely as Huang's but traces to summaries of Tae Kim's book rather than to Huang saying it in a citable venue; **treat it as Kim's formulation, not as a quotation.** And NVIDIA reached a $5 trillion market capitalization (CNBC, 30 October 2025), but **no public source establishes any causal link between the span of control, the absence of one-on-ones, the T5T channel and any NVIDIA result.** Every management claim above is self-reported in promotional settings, with no audit and no counterfactual.\n\n**INTERPRETATION — four lessons for a technology executive under a broadcasting CEO.**\n\n**First, there is no back channel, so stop planning around one.** A CEO who says \"almost everything that I say, I say to everybody\" has removed the traditional lever, the quiet pre-brief before the board meeting. Influence must be exercised in the room, in front of peers, which raises the standard on the argument and eliminates impression management as a tool. Over-invest in the artifact: the written position must survive being read cold by fifteen people at once.\n\n**Second, pre-negotiate the escalation exception, in writing.** Security work has an irreducible category that cannot be broadcast: an active incident, an insider investigation, a credible allegation against a named executive. Under a leader who discourages private meetings, a narrow, pre-agreed exception for incident escalation and investigative confidentiality is mandatory — agreed in calm, naming who, how, and what happens in the first hour. That is item 6 of the audit, and failing to secure it beforehand is a foreseeable, avoidable failure. Huang's practice concerns *his* staff; your own team's one-on-ones are a separate decision, and nothing here argues for imitation.\n\n**Third, T5T is a weak-signal design pattern with a headcount ceiling — teach both halves.** The mechanism has the shape of good security telemetry: lightweight, high-frequency, unfiltered, valuable for signals too weak to escalate alone. Build the analogue — a low-friction line from engineers, help-desk staff and client teams straight to you — and build the tripwire for its failure, because the reported narrowing past roughly 30,000 employees is the more instructive half: a channel that has silently become filtered leaves an executive on a stale picture with undiminished confidence. Milliken, Morrison & Hewlin (2003), from the CEO library, found most employees can recall withholding an important concern from a superior. Assume filtering; audit the channel's reach.\n\n**Fourth, removed layers make an explicit decision-rights map mandatory.** The rationale presumes senior people who need no scaffolding, which says nothing about who decides two levels down — exactly where you must find the accountable owner for a risk acceptance. In a hierarchical firm the org chart implies that map; where layers have been removed it must be built by hand: who can accept which class of risk, at what threshold, recorded where, reviewed when. Weill & Ross (2004, Tier 3) is the practitioner argument that decision rights are a design choice; in a flat structure they are a choice nobody has made yet. Peppard (2010) is the counterweight to any romance about technical CEOs: literacy makes the argument faster, but literacy is not scaffolding, and ambiguity about who decides is where security risk accumulates.", "example": "*Fictional composite.*\n\nInes Delgado became the first CISO of Wren Harbor Systems — a Providence industrial-software company, $290M revenue, 1,100 employees, private-equity owned — in the January after a competitor's ransomware event made the trade press. The CEO, Tomas Wren, had founded the company as a controls engineer and still read pull requests.\n\nShe spent her first week scoring the discretion audit. Reporting line, to the CTO: 1. Budget authority: 1. Veto rights: 0. Board access, via the CTO's slide: 0. Hiring: 1. Incident command: 0 — there was a response plan, unsigned, naming a committee. Architecture sign-off: 1. Vendor selection: 1. Regulator relationship: 1. Headcount, four people: 1. Mandate clarity: 0. Nine out of thirty-three, written on the first page of a notebook and shown to nobody for eleven months. She picked two items — incident command authority and a budget envelope — and let the other nine wait.\n\nThe first quarter she did nothing structural. She priced. She rebuilt the board material from fourteen slides of green indicators into the four-part pack, and in the first one she reported a red: a third-party integration platform held credentials to 340 customer environments, and she estimated $6–11M of expected annual loss from it, method in the appendix, confidence moderate, driver named. Under *what we got wrong* she wrote that her own team had inherited and re-signed a client questionnaire attesting to quarterly access reviews that had not run since the previous spring.\n\nThe audit chair, Priya Anand, called the following week — the first call, which is the metric that matters. The question was not about the number. It was: \"How do you know your $6M isn't $60M?\" Delgado said she did not, named the two assumptions that would move it most, and offered to have the range independently checked. Anand asked for the check and put a standing cyber item on the agenda.\n\nThe second-quarter budget ran on three columns. Buying down: $480K against roughly $9M of exposure, with expected reductions, the method, and the Gordon–Loeb caution stated plainly. Accepting: two risks the company should keep, priced, with Wren's name on one and the COO's on the other. Cannot price: an AI feature the product team was building against a model API, where she said she had no defensible number and asked for $60K to get one. The CFO approved the third column first, which surprised her, then most of the first.\n\nIncident command authority arrived in the fourth quarter, by accident. A Saturday alert turned out to be a contained credential-stuffing attempt, but for ninety minutes nobody could say who was allowed to disconnect the integration platform. On the Monday she wrote a one-page authority memo — declaration thresholds, four named powers, pre-approved forensics retainer — and Wren signed it in eight minutes, because he had spent Saturday on the call watching the ambiguity himself. It was the cheapest thing she ever got, and she got it only because she had spent a year being the person whose numbers survived scrutiny.\n\nRe-scored in December: 19 out of 33. Two items moved on purpose and four by consequence. The item she never moved — the reporting line — she had stopped caring about, because board access had done the work she wanted the reporting line to do.", "ceo_contrast": "Put four archetypes in Delgado's chair in that first quarter: a nine-out-of-thirty-three score, a founder-engineer CEO, an audit chair who has never been briefed directly, and a platform holding credentials to 340 customer environments.\n\n**The Technical CISO** goes at the platform. Within six weeks the integration is segmented and the risk is genuinely lower. Gain: real reduction, fast, and engineering respects the competence. Cost: nobody outside engineering knows it happened, the discretion score is unchanged, and at budget time this leader asks for money from executives with no priced picture of what was avoided. Capability without authority — and the fix is not more technical work.\n\n**The Business-Risk CISO** goes at the board. The four-part pack lands in month one and the standing agenda item arrives a quarter earlier than it did for Delgado. Gain: the fastest route to structural power available. Cost: the numbers are early and the confidence is high, and a founder-CEO who reads pull requests will find the one assumption that is wrong. Pricing before you have earned the right to be checked is how a promising CISO becomes \"the one who said $6M and it was nothing.\" *Optimism* wants dialing toward *skepticism* about one's own estimates before the first pack, not after.\n\n**The Enterprise CIO (Architect)** builds apparatus: a risk committee, a decision-rights map, a policy hierarchy, a RACI for exceptions. Gain: at a company three times larger in four years this eventually has to exist. Cost: with four security staff the apparatus outruns the organization's capacity to feed it, and a founder-CEO reads it as bureaucracy arriving ahead of results. Right instrument, wrong year.\n\n**The Post-Breach CISO (Turnaround)** treats the competitor's event as if it were Wren Harbor's own: centralize, freeze, demand, escalate. Gain: urgency genuinely helps a company that has never had a CISO. Cost: *centralization*, *unilateral* and *urgency* were set for an organization that had already failed; here they read as an outsider assigning blame for a crime nobody committed, and there is no social capital left when the incident-command memo needs signing.\n\nNone of the four is wrong about the platform. They differ on what the first quarter is *for* — and in a nine-out-of-thirty-three chair, it is for becoming the person whose numbers are believed.", "failure_mode": "**FRAMEWORK — the Overuse Ladder for structural power and access.**\n\n*Access → dependence.* Authority running entirely through one relationship — a sponsoring CEO, a friendly audit chair — is a program with a single point of failure, and it fails on the day of a succession, not the day of a breach.\n\n*Proportionality → minimization.* The discipline of not over-alarming hardens into never alarming. The pack gets smoother, the reds get softer, \"what we got wrong\" gets shorter, and the executive experiences this as maturity. Edmondson (1996) is the diagnostic: an improving incident count in a worsening reporting climate looks identical to an improving program.\n\n*Pricing → false precision.* A number with a method becomes a number with a decimal point, then a number nobody remembers constructing, then a number the business plans against. Gordon & Loeb (2002) is a reasoning tool whose inputs are estimates; a model presented as measurement is a liability in the costume of rigor.\n\n*Conviction → epistemic arrogance.* A technically expert executive under a technically expert CEO can slide from productive conviction into treating every challenge as a comprehension failure in the challenger. It ends the same way for both.\n\n### Early warning signs\n\nFor the technology executive:\n\n- You cannot name the last thing you told the board that they did not want to hear.\n- Your influence on a decision this quarter came entirely from someone choosing to ask you.\n- Your incident-response plan names a committee and no individual, and nobody has signed it.\n- You keep a risk register the board sees and a private list of what actually worries you, and they differ.\n\nFor the CEO or board:\n\n- Cyber reporting arrives filtered through the person whose delivery targets it constrains.\n- The pack shows maturity scores and compliance status but no expected loss and no named risk accepters.\n- Nothing has ever been reported between meetings, and nobody has agreed what would cause it to be.\n- The technology executive is described as \"great in the room\" by everyone and holds no written authority to stop anything."}, "research_refs": ["res.preston2008", "res.preston2009", "res.karahanna2013", "res.feeny1992", "res.gerow2014", "res.higgs2016", "res.nacd2023", "res.sec2023", "res.hambrick1987", "res.hambrick2007", "res.wangrow2015", "res.banker2011", "res.peppard2010", "res.gordon2002", "res.kamiya2021", "res.amir2018", "res.ashenden2013", "res.edmondson1996", "res.milliken2003", "res.weill2004", "res.ians2026"], "reflection": ["Score the eleven-item discretion audit for your role, then score it again as your CEO would. Where is the gap widest, and what does it tell you that neither of you has written down?", "Name the last decision you affected purely through social capital. What happens to it if the person who asked you leaves?", "Open your last board or executive pack. Where in it does bad news structurally belong? If nowhere, who decided that — you, or the format you inherited?", "What is your expected annual loss from your largest exposure, and which two assumptions would move it most? If you cannot answer in ninety seconds, what would it take?", "Write your escalation trigger: the conditions under which you would contact the board chair between meetings. Has anyone agreed to it? If not, what has stopped you asking?", "Which two discretion items actually bind you this year, and what would you stop asking for in order to get them?", "If your CEO broadcasts rather than confides — or simply never meets you alone — what is your written substitute for the private escalation you have been assuming you have?"], "simulation_ref": "sim.m10-kettlebrook-one-number", "knowledge_check": [{"id": "m10-kc1", "type": "multiple_choice", "question": "Preston & Karahanna (2009), using 243 matched CIO–top-management-team pairs, found what about shared understanding of the role of IS?", "answer": "B", "explanation": "Contrary to the authors' expectation, informal socializing and similarity did not significantly affect shared understanding, while shared language, shared domain knowledge and formal \"systems of knowing\" did — survey evidence that the designed mechanism beats the friendship.", "options": [{"key": "A", "text": "Informal social interaction between the CIO and the top team was the strongest driver"}, {"key": "B", "text": "Formal mechanisms and shared knowledge mattered, while informal social interaction and experiential similarity did not significantly affect it"}, {"key": "C", "text": "Shared understanding had no measurable relationship with alignment"}, {"key": "D", "text": "Experiential similarity between CIO and top team was the strongest driver"}]}, {"id": "m10-kc2", "type": "multiple_choice", "question": "Higgs, Pinsker, Smith & Young (2016) found that over 2005–2014, firms with board-level technology committees:", "answer": "B", "explanation": "Committees were associated with more *reported* breaches — plausibly more detection and disclosure — and with smaller negative abnormal returns from external breaches, so this is evidence about visibility as much as safety.", "options": [{"key": "A", "text": "Reported fewer breaches and suffered larger stock-price penalties"}, {"key": "B", "text": "Reported more breaches and suffered smaller stock-price penalties from external breaches"}, {"key": "C", "text": "Reported fewer breaches and suffered smaller stock-price penalties"}, {"key": "D", "text": "Showed no difference in either reporting or market reaction"}]}, {"id": "m10-kc3", "type": "short_answer", "question": "Distinguish structural power from social capital, and explain why an executive high on one and low on the other fails differently in each case.", "answer": "Structural power is written authority — reporting line, budget envelope, veto rights, board access, incident command — and survives unpopularity; social capital is the quality of the relationship with the top team (Karahanna & Preston, 2013) and determines whether anyone asks or believes you. High structure with low capital produces the \"IT Mechanic,\" who blocks what he cannot explain; high capital with low structure produces the \"IT Advisor,\" whose recommendations are read and not funded (Preston, Leidner & Chen, 2008).", "explanation": "Opposite failures, opposite remedies — the Mechanic must price rather than prohibit, the Advisor must convert goodwill into written decision rights before it decays."}, {"id": "m10-kc4", "type": "short_answer", "question": "Name the four claims about Jensen Huang's information practices that this module requires you to qualify, and give the qualification for each.", "answer": "(1) Direct reports: roughly 50–60, varying by year and by which interview is cited (50, 60 and 55 across three 2024–25 sources) — never a single figure. (2) One-on-ones: documented that *he* does not hold them with *his own staff*, plus his stated discouragement; not a company-wide prohibition. (3) \"Top 5 Things\": documented as of 2024 and subsequently reported as narrowed past ~30,000 employees — never the unqualified present tense. (4) \"The mission is the boss\": not a verified Huang quotation; it traces to Tae Kim's account and should be attributed to him or dropped.", "explanation": "No public source links any of these practices to NVIDIA's results, so the case is taught as a structural problem — no back channel, a pre-negotiated escalation exception, a weak-signal channel with a headcount ceiling, a mandatory decision-rights map — never as an endorsement."}], "takeaways": ["Discretion is granted, not assumed. It comes from structural power (what is written down) and social capital (whether anyone asks or believes you), and the two fail in opposite directions — the IT Mechanic who blocks what he cannot explain, the IT Advisor whose advice is admired and unfunded.", "Build the mechanism, not the friendship: in 243 matched CIO–executive pairs formal structures and shared knowledge drove shared understanding while informal socializing did not (Preston & Karahanna, 2009), and in 81 hospitals relationship quality was associated with alignment and, through it, with performance (Karahanna & Preston, 2013).", "A board cadence should be honest, proportionate and priced. Visible oversight changes both what surfaces and how the market prices it (Higgs et al., 2016; Kamiya et al., 2021), and concealment is priced when discovered (Amir et al., 2018).", "Run the budget in three columns — buying down, accepting, cannot price — using Gordon & Loeb (2002) with its assumptions stated; fear-based budgeting works once per CEO. Then score the eleven-item discretion audit twice, once as you see it and once as your CEO would, and move only the two items that actually bind.", "Adapt to the CEO you have. Under a broadcasting technical CEO — documented for Jensen Huang as roughly 50–60 direct reports, no one-on-ones with his own staff, and a weak-signal email channel later reported as narrowed, none of it causally linked to NVIDIA's results — there is no back channel, the escalation exception must be pre-negotiated in writing, the weak-signal channel must be audited for silent filtering, and the decision-rights map must be built by hand."], "videos": ["vid.00-structural-power-and-social-capital", "vid.00-the-board-cadence-honest-proportionate-p", "vid.00-the-eleven-item-discretion-audit", "vid.00-working-with-a-technical-ceo"], "glossary_terms": ["term.structural-power", "term.social-capital", "term.managerial-discretion", "term.discretion-audit", "term.board-reporting-cadence", "term.risk-pricing", "term.decision-rights-map", "term.risk-acceptance", "term.escalation-exception", "term.weak-signal-channel", "term.risk-corollary"], "tags": {"dials": ["aggression_caution", "decisiveness_inquiry", "hands_on_delegation", "optimism_skepticism", "unilateral_consensus"], "archetypes": ["arch.business-risk-ciso", "arch.enterprise-cio-architect", "arch.post-breach-ciso-turnaround", "arch.regulated-industry-cio-ciso", "arch.technical-ciso"], "stages": ["mature", "regulatory_reputation_crisis", "scale_up", "turnaround"], "learn_categories": ["power_governance"]}, "estimated_minutes": 80, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/10-working-with-the-ceo-and-the-board.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m11", "slug": "what-five-leaders-teach", "title": "What Five Leaders Teach — Venables, Farshchi, Clinton, Carter, Halamka", "unit": "IV. The Leaders and the Capstone", "big_idea": "Five documented careers, read for decisions rather than personalities, show the same thing the research shows: fit, calibration and information environment beat charisma.", "effectiveness_equation_term": "Current Moment", "learning_objectives": ["For each of the five leaders, state the situation, the documented decision, the result as reported, and what it teaches against the course frameworks.", "Contrast the five on the dials and the overlays, including Farshchi's post-breach control posture against Venables' and Clinton's enablement posture.", "Identify what is contested or thinly documented in each record — including that Clinton's record is inputs only, because a private company's security outcomes are unobservable, and that his 2025 'AI employee' forecast was publicly scored as having missed.", "Extract cross-case patterns without hero worship: reporting line and board mechanisms, crisis ownership, tenure and calibration, enablement versus control."], "sections": {"core_lesson": "This module does what the course has so far refused to do: it names real people. Five of them — Phil Venables, Jamil Farshchi, Jason Clinton, Rob Carter and John Halamka — read strictly for what they decided, what mechanism they installed, and what was reported afterwards, by whom.\n\nThe discipline is the point. A leader profile is the most seductive artifact in executive education, because a career reads like a causal story and almost never is one. So the module teaches a method before it teaches a person: locate the situation, isolate the documented decision, name who reported the result, then ask what it teaches. Adjectives about the person are excluded because they are unfalsifiable and they crowd out the mechanism you could copy.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on **Organizational Context**, because the five careers show context doing far more of the work than any personal quality could. By the end you should be able to read any leader profile and say which sentences are evidence, which are company statements, and which are admiration in a suit.", "big_idea": "**Five documented careers, read for decisions rather than personalities, show the same thing the research shows: fit, calibration and information environment beat charisma.**\n\nThey also show something about the record itself. The security leaders you can read about are the ones who were breached, who published, or who worked in the open — so the reading list is a sample drawn by publicity, not by effectiveness. Learn the mechanisms; distrust the shape of the collection.", "research": "This section is about **method**: what a documented career can and cannot support. Every study below is evidence about the *record*, not about any of the five.\n\n**RESEARCH FINDING — selection into visibility.** Banker & Feng (2019) matched disclosed breaches to executive changes and found that breaches attributed to *system deficiency* increased CIO turnover likelihood by 72 percent, while breaches attributed to criminal fraud or human error showed no significant association. Archival; breach-cause classification depends on public descriptions; associations only. **INTERPRETATION.** This is the mechanism that populates reading lists like this one. A technology executive becomes publicly legible at the moment blame is assigned, and blame tracks the perceived scope of the job. The careers we can document are therefore disproportionately those where something failed in a way that was classified as the executive's own.\n\n**RESEARCH FINDING — the unobserved denominator.** Amir, Levi & Livne (2018) compared attacks firms disclosed with attacks they withheld that were later revealed by outside sources: withheld attacks were associated with about a 3.6% decline in equity value in the month of discovery, disclosed attacks with about 0.7%. Identification of \"withheld\" attacks depends on later external discovery; the study pre-dates mandatory disclosure. **INTERPRETATION.** The design contains the lesson. Attacks never discovered cannot appear in any dataset, and neither can the careers built on top of them. When a profile says \"no publicly reported breach during his tenure,\" the honest reading is that the record mixes clean programs with undiscovered ones in unknown proportion.\n\n**RESEARCH FINDING — the count is ambiguous in both directions.** Higgs, Pinsker, Smith & Young (2016) found firms with board-level technology committees *more* likely to have reported breaches over 2005–2014, plausibly because they detect and disclose more. Edmondson (1996) found that across eight nursing units, stronger team climate and more active manager coaching were associated with *higher* detected error rates (r = .74). Both correlational; both conflate occurrence with reporting. **INTERPRETATION.** A high incident count can mean good detection; a low one can mean silence. Neither alone distinguishes a strong program from a quiet one — which is why a leader's public incident history is poor evidence about them.\n\n**RESEARCH FINDING — the record is not a neutral window.** Hayward, Rindova & Pollock (2004, from the CEO library) theorize that media-created executive celebrity fosters hubris and strategic persistence. Malmendier & Tate (2009, from the CEO library) find that CEOs who attain \"superstar\" status through media awards tend to underperform afterwards, earn more, and divert effort outside the firm, particularly where governance is weak. About CEOs, not CIOs or CISOs. **INTERPRETATION.** Together they undo the intuitive use of recognition: an award is not a measurement of past performance but a treatment applied to a career, and the measured associations of that treatment are unflattering. Every award in the five profiles is therefore listed only to be discounted.\n\n**FACT — company-reported outcomes.** The most quotable numbers here are statements by companies about themselves: Equifax's posture score and its sub-one-minute mean time to detect; FedEx's estimated $300 million first-quarter impact from NotPetya. These are facts about what the company said, produced by vendor benchmarking tools or internal accounting rather than independent audit. Cite them as disclosure, never as measured effects of an executive.\n\n**FACT — the private-company blind spot.** For one of the five there is no outcome evidence of any kind. Anthropic is private: incident history, budgets, headcount, detection and response metrics, red-team results and audit findings are all unobservable from outside. Clinton's record is therefore *inputs only* — stated threat models, named control mechanisms, published decision frameworks. **INTERPRETATION.** That is not a deficiency of the case; it is the case. It shows in clean form what is true in weaker form for all five: reputation in this profession is built on the legibility of a leader's reasoning, and legibility is not evidence that the reasoning worked.\n\n### Where the evidence is weak\n\nNo study in either library measures the effect of an individual CIO or CISO on security outcomes, and none could easily be designed: the outcome is rare, partly unobservable, confounded by industry and scale, and reported by the interested party. Everything in Section 4 connecting a decision to a result is therefore **INTERPRETATION**.", "explanation": "### Phil Venables — the long-horizon Architect with no crisis\n\n**Situation.** CISO of Goldman Sachs from 2000 to 2017 with the standing of a partner, then chief operational risk officer; first CISO of Google Cloud, December 2020 to March 2025. Neither chair was created by a breach.\n\n**Documented decisions.** He stayed — seventeen years in one chair and, on leaving, \"being a CISO for 30 years spanning 4 CISO roles.\" He built institutions outside his own firm: co-founder of the Center for Internet Security (2000), co-founder and chairman of Sheltered Harbor (2015–2020), chair of SIFMA's cyber committee (2017–2020). In November 2025 he set out \"CISO 2.0\" — the CISO as \"peer business executive,\" \"peer technology leader,\" and \"long-term player\" — moving the organization \"from a fire station, reacting to disasters, to a flywheel.\" In 2026 he proposed Control Reliability Engineering, treating \"a Control Incident (a failed control)\" with \"the same gravity as a Security Incident.\"\n\n**Reported result.** None measurable. No major breach was publicly reported at Goldman during his tenure, which per Section 3 is not evidence.\n\n**What it teaches.** The **Architect's leverage runs past the firm**: Sheltered Harbor mutualizes recovery risk across competitors, rational only if your risk includes the state of the institutions around you. And the **long-horizon argument is the only defense a no-crisis program has** — Farshchi's discretion was supplied by an event; this had to be re-argued every budget cycle.\n\n### Jamil Farshchi — the post-crisis mandate, taken twice\n\n**Situation.** CISO of The Home Depot from March 2015, about six months after the 2014 breach of 56 million payment cards; CISO of Equifax from February 2018; EVP and CTO from March 2024, with Equifax appointing a separate CISO in 2025.\n\n**Documented decisions.** The reporting line was structural from the start — CISO direct to the CEO, with a line to the board. CEO Mark Begor's Senate testimony of 7 March 2019 records the machinery: an incremental $1.25 billion of security and technology spending for 2018–2020, \"nearly 1,000\" IT and security professionals added in 2018, security goals attached to the bonuses of 3,900 employees, and a \"Board Cyber Audit Framework\" of metrics developed by the CISO. From 2020 the company published a Security Annual Report annually. His own description in May 2018: \"basically an open checkbook,\" and \"before a breach, your success is dependent on convincing people about the value of security. I don't have to do that.\"\n\n**Reported result — company-reported.** Posture scores exceeding technology and financial-services industry averages for six consecutive years (the sixth reported after a separate CISO was in post); mean time to detect under one minute; a roughly $3 billion transformation called \"principally complete\" in March 2026.\n\n**What it teaches.** The mechanisms are copyable and the conditions are not. Direct reporting, a named board metric format and an annual published report **convert temporary attention into permanent format** — the real problem of a post-breach mandate, because attention decays faster than programs mature. Bonus linkage is the most copied and least examined element, and the research argues against it: Cram, D'Arcy & Proudfoot (2019), pooling 95 studies, found attitudes and personal norms far stronger predictors of compliance than punishment and rewards. **INTERPRETATION.** It buys visible compliance in a chastened company; Angst et al. (2017) adds that symbolic adoption buys no protection.\n\n### Jason Clinton — the inputs-only record\n\n**Situation.** About eleven and a half years at Google, latterly leading Chrome infrastructure security; **inaugural CISO of Anthropic from April 2023 to approximately September 2025, and Deputy CISO since**, when Anthropic hired Vitaly Gudanets as CISO. Anthropic is private, so nothing about outcomes is observable.\n\n**Documented decisions.** He organized his own time around one asset: \"I probably spend almost half of my time as a CISO thinking about protecting that one file\" — the model-weights file — with the threat model stated as denial to criminals, terrorists and states rather than protection of intellectual property. The controls his organization implemented were published in May 2025: two-party control requiring a physical security key, a justification and second-party authorization at the time of request; egress bandwidth controls restricting data flow out of the environments where weights reside; binary allowlisting; mandatory cryptographic commit signatures. That document names the adversary classes it covers and places sophisticated state-sponsored attackers using novel attack chains explicitly out of scope. In July 2026 he authored a public decision procedure for agentic AI: \"our jobs are to make agentic risk legible and bounded,\" a four-question model (\"What untrusted content does it ingest? What actions can it take, and on whose behalf? What is the blast radius if it is misaligned? What observability do I have?\"), least agency, and admin-paced rollout gated on telemetry.\n\n**Reported result.** **None.** No incident history, no metrics, no budget, no audit findings.\n\n**What it teaches.** Three things, none requiring belief that the program works. **The dial is set per asset, not per person**: maximum control on the crown jewel, deliberate enablement elsewhere. **Publishing your ceiling is a maturity behaviour** — naming the attacker class your controls do not stop is the institutional form of \"I cannot do this yet.\" And the **calibration case**: in April 2025 he told Axios that AI \"virtual employees\" with their own credentials would begin operating on corporate networks within roughly a year; a year later John Gruber wrote that the prediction \"has fallen flat on its face\" and called the original piece \"an advertisement\" rather than a security warning. **INTERPRETATION.** A missed public forecast is an ordinary cost of speaking publicly, and its teaching value lies in what follows — plus a warning for anyone speaking through a vendor's channel: the audience decides whether you were warning or selling.\n\n### Rob Carter — the inherited estate\n\n**Situation.** CIO of FedEx for roughly 25 years to 30 June 2024, running the technology behind about 15 million daily shipments and a decade-long programme to simplify what he called the company's \"accidental architecture.\"\n\n**Documented decisions and the event.** He ran a decade-long simplification of the estate while integrating a newly acquired European subsidiary onto it. In June 2017 NotPetya hit that subsidiary, TNT Express, mid-integration. FedEx disclosed on 20 September 2017 an estimated $300 million first-quarter impact, later put at about $400 million; stated it had **no cyber insurance covering the loss** and was \"re-examining the cyber-insurance market\"; and described a recovery requiring restoration of \"every facility, hub and depot.\"\n\n**Reported result.** The loss figures above are the company's own. A securities class action over the disclosure was dismissed with prejudice on 4 February 2021.\n\n**What it teaches.** **M&A integration is a security decision, usually made by people who are not in the room.** The exposure was not FedEx's own controls but an inherited estate nobody had priced into the deal model. Kamiya et al. (2021) is the closest evidence: attacks are associated with shareholder losses exceeding out-of-pocket costs. **INTERPRETATION.** The uninsured loss is the more useful half — risk transfer is a pricing decision in the Gordon–Loeb (2002) sense, taken here only after the loss landed.\n\n### John Halamka — crisis ownership in public\n\n**Situation.** CIO of CareGroup and Beth Israel Deaconess Medical Center from 1998. Between 13 and 18 November 2002 a spanning-tree loop, triggered by a large research data upload, took the hospital network down for about three and a half days and forced clinicians back to paper.\n\n**Documented decisions.** He shut the network down entirely rather than continuing partial isolation, brought in Cisco's assurance team, rebuilt the core over a weekend — and documented the failure publicly: \"I made a mistake. And the way I can fix that is to tell everybody what happened so they can avoid this.\"\n\n**Reported result.** The episode became the Harvard Business School case *CareGroup* (McFarlan & Austin, 29 January 2003, no. 303-097) — the only one of the five records that does not depend primarily on the subject's own account.\n\n**What it teaches.** Partial isolation, then full shutdown, then rebuild is a resilience decision taken against a prevention instinct — in a hospital, a patient-safety decision before an IT one. The deeper lesson is what preceded it: infrastructure lifecycle neglected because it was invisible. The public post-mortem is the Two-Sentence Test's second sentence, performed institutionally.\n\n### Cross-case patterns\n\n**FRAMEWORK — four patterns, stated as patterns and not as findings.**\n\n**1. Reporting line and board mechanisms decide whether judgment travels.** Farshchi's line to the CEO and his Board Cyber Audit Framework are the clearest instance: a *format* the board adopted, which outlives the person who wrote it. Venables' partner standing is the same variable supplied by governance; Clinton's reporting line is not public at all. Banker et al. (2011) is the evidence that the line matters and none is universally correct. **INTERPRETATION.** The transferable act is not \"report to the CEO\" but to install one repeatable reporting format the board owns.\n\n**2. Crisis ownership is a decision about the information environment, not about courage.** Halamka shut the network down and then published; FedEx disclosed a nine-figure impact and its own lack of insurance; Farshchi made the metrics public annually. Ashenden & Sasse (2013) found CISOs describing low perceived power, unclear role identity and weak engagement as their central obstacles — and public ownership of failure moves all three at once.\n\n**3. Tenure and calibration travel together.** Venables and Carter are the long tenures, and both records are about multi-year architecture rather than a single decision. Zhang & Rajagopalan (2010, from the CEO library) found an inverted-U between strategic change and performance, with a wider swing for outsiders. **INTERPRETATION.** Long tenure is the precondition for one kind of program and a risk factor for one kind of blindness; the question is whether the leader re-derives the plan or merely continues it. Clinton's publicly scored forecast shows what re-deriving requires: a dated claim someone can check.\n\n**4. Enablement versus control is a per-situation setting.** Farshchi's post-breach posture is control-weighted, correctly, for a season; Venables' CISO 2.0 and Clinton's \"legible and bounded\" are enablement-weighted, in organizations not on fire; Halamka's shutdown is maximal control for four days inside a career of clinical enablement. **INTERPRETATION.** Enablement is not the more sophisticated setting. All five were chosen against a situation, and every failure in Section 7 is a setting that outlived the situation justifying it.", "example": "*Fictional composite.*\n\nDevika Raman is CIO and CISO of Sable Ridge Managed Services, a 90-person BPM/MSP firm in Worcester, Massachusetts, running the network, help desk, email and security program for about 140 SMB and mid-market clients — a dozen broker-dealers and RIAs, thirty medical and dental practices, the rest professional services. Revenue is $21 million; her security budget, including her own time, is under $600,000.\n\n\nIn March the founder-CEO forwarded her a magazine profile of a well-known post-breach CISO with three words: \"Can we do this?\" The profile described a direct line to the CEO, $1.25 billion of incremental spend, a thousand hires in a year, bonuses wired to security goals for 3,900 people, and a board metrics framework. Her first instinct was to reply that the comparison was absurd. Her second, better instinct was to separate the mandate from the mechanism.\n\nThe mandate, she wrote back, was supplied by an event: a public breach had reset the reporting line, the budget and the board's attention before that CISO arrived. Sable Ridge had no such event, so every mechanism would have to be argued on its merits, annually, against payroll and a sales hire. Bonus linkage for 3,900 people is meaningless in a firm of ninety — and worse, it installs a compliance lever where the actual constraint was that engineers did not tell her things.\n\nTwo mechanisms transferred, and cost almost nothing. The first was a **named format the owners adopt**: one page for the quarterly owners' meeting — what we said we had, what we can prove we have, the gap, the date, and the two risks we are accepting on purpose. The second was **evidence per control**: she rewrote the program so every control pointed at a log, a ticket or a review rather than a policy sentence. Eleven weeks of work, and it surfaced that quarterly access reviews at four clients existed only as attestations.\n\nThen the part she did not plan. In September a broker-dealer client's compliance officer asked Raman to walk her board through \"how you know your controls work.\" Raman used the same one-pager with the client's controls in it. By December, seven clients were paying a monthly fee for the format, and Sable Ridge had a vCISO product built from a mechanism extracted from a company two thousand times its size. What she did not copy was what the profile spent most of its words on: the person.\n\n**INTERPRETATION.** The transferable content of a famous career is never the temperament and rarely the budget. It is the two or three mechanisms that survive being stripped of their conditions — found by reading for what was installed, not for what was admired.", "ceo_contrast": "**INTERPRETATION — this section is inference and should be read as hedged.** None of the five has been asked this question in public; what follows is how their *documented decisions* would most plausibly be applied, and a reader who treats it as prediction has already made the module's central error.\n\n**The dilemma.** Your audit committee chair asks for one number. \"I don't want a dashboard. I want a single answer to 'are we secure?' that I can hold you to.\" Thirty seconds, and a chair who is not being unreasonable.\n\n**Venables would most plausibly refuse the number and offer a different one:** indicators for whether each named control is currently performing to its stated objective, and which degraded this quarter. Gain: an honest, movable number with an engineering meaning. Cost: it needs a control inventory most companies lack, and the chair may hear evasion first.\n\n**Farshchi's documented answer is a benchmarked score with a board format around it** — a posture score against industry averages, published annually. Gain: the chair gets what they asked for, and it survives a change of CISO. Cost: the failure mode Angst et al. (2017) describe — the score becomes the program and adoption drifts symbolic.\n\n**Clinton's documented posture points at scope rather than score:** state what the controls cover and, explicitly, what they do not. Gain: the most honest answer available, and it makes a later incident survivable. Cost: it hands the committee a sentence that reads badly in litigation and worse in a newspaper.\n\n**Carter's answer would most plausibly be financial, and would include what is not insured** — his documented experience is a nine-figure loss at an acquired subsidiary against no applicable cover. Gain: it speaks the committee's native language and forces the insurance question. Cost: expected-loss numbers in security are estimates wearing a suit.\n\n**Halamka's answer would most plausibly be about recovery:** how long the organization can run without its systems, and how recently that was proved. Gain: testable, and in clinical or logistics settings the number that matters. Cost: it says nothing about confidentiality, which the market prices most sharply.\n\n**INTERPRETATION.** Four of the five refuse the question as asked and substitute a number they can defend. That refusal — in one sentence, with an alternative attached — is the skill this section teaches.", "failure_mode": "**FRAMEWORK — the Overuse Ladder applied to admiration.** The rungs run *reading* → *imitation* → *identification* → *identity*. The first is what this module asks for; the second is defensible when conditions match; the third is where the leader stops asking whether the situation is the same; the fourth is where a borrowed record answers questions it was never asked.\n\n**Idolization.** The damage is not that the admired leader was wrong; it is that admiration replaces analysis and mechanisms arrive without their conditions. A CISO who has internalized a famous post-breach program reaches for its instruments as a set, when only two of them fit.\n\n**Copying a post-breach playbook into a company that is not post-breach.** The most common and most expensive version. Turnaround settings — centralization, urgency, decisiveness, unilateral action, a control-weighted posture — are correct for a season and corrosive afterwards, because they are premised on an organization that has just failed and knows it. Applied to a company that has not, they read as distrust of people who were never at fault. The damage is specific: engineers route around the bottleneck, the workarounds become the attack surface, and you learn about them from an incident rather than from a person.\n\n**Mistaking visibility for effectiveness.** The reading list is drawn by publicity (Section 3), and the career-level version of the error is optimizing for whatever made your models legible. Malmendier & Tate (2009, from the CEO library) is the sharpest warning: award-winning CEOs subsequently underperformed, earned more, and diverted effort outside the firm, especially where governance was weak. **HYPOTHESIS.** The security-chair analogue — a CISO's conference and publishing load shifting attention away from the program — is untested, but plausible enough that a board should be able to ask about it without it being an insult.\n\n### Early warning signs\n\n- You describe your company's problem in another executive's vocabulary, and the sentence still works if you delete your company's name.\n- A mechanism is in your plan and you cannot state the condition that made it work where you found it.\n- Your program has adopted a benchmark score, and nobody can say what would make it fall.\n- Your incident count is falling and you have not asked whether reporting is falling with it (Edmondson, 1996)."}, "research_refs": ["res.banker2019", "res.amir2018", "res.hayward2004", "res.malmendier2009", "res.higgs2016", "res.edmondson1996", "res.kamiya2021", "res.banker2011", "res.gordon2002", "res.angst2017", "res.cram2019", "res.zhang2010", "res.ashenden2013"], "reflection": ["Take the leader whose record you find most persuasive. Write the three conditions that made their mechanisms work, and mark which of the three you have. What does the gap cost you?", "Which element of your current program did you import from someone else's story, and what evidence do you have that it fits here?", "If your incident count fell 40% next quarter, what would you check before reporting it as good news?", "Write the sentence Clinton's published scoping implies for your own program: \"Our controls are designed to stop ____; they are not designed to stop ____.\" Who above you needs to hear it, and what has stopped you saying it?", "Name your inherited estate — systems you did not choose, from an acquisition, a client, an MSP or a predecessor. When was its condition last priced, and by whom?", "If forced to give an audit committee one number, which of the five answers in Section 6 would you give?"], "simulation_ref": "sim.m11-brightmoor-mandate", "knowledge_check": [{"id": "m11-kc1", "type": "multiple_choice", "question": "Banker & Feng (2019) found CIO turnover significantly more likely after which kind of breach?", "answer": "B", "explanation": "Accountability tracked the perceived scope of the executive's duties — an archival association, and the mechanism by which technology executives become publicly documentable at all.", "options": [{"key": "A", "text": "Any publicly disclosed breach"}, {"key": "B", "text": "Breaches attributed to system deficiency (about 72% more likely), but not those attributed to criminal fraud or human error"}, {"key": "C", "text": "Breaches involving personal financial information only"}, {"key": "D", "text": "Breaches at firms with a board technology committee"}]}, {"id": "m11-kc2", "type": "multiple_choice", "question": "What methodological point does this module draw from Amir, Levi & Livne (2018)?", "answer": "B", "explanation": "\"Withheld\" attacks are identified only by later external discovery, so the set of executives with no public incident is not the set with no incident.", "options": [{"key": "A", "text": "That firms should always disclose immediately"}, {"key": "B", "text": "That withheld attacks were associated with about a 3.6% equity decline versus 0.7% for disclosed ones — and, because undiscovered attacks are unobservable, a \"clean\" record mixes clean programs with undiscovered ones"}, {"key": "C", "text": "That market reactions reliably measure breach severity"}, {"key": "D", "text": "That mandatory disclosure eliminated the difference"}]}, {"id": "m11-kc3", "type": "multiple_choice", "question": "Which statement about the Jason Clinton record is accurate as this curriculum uses it?", "answer": "B", "explanation": "(a) and (c) are wrong on the facts — Vitaly Gudanets became CISO in September 2025, and the forecast was publicly scored as having missed in May 2026 — and (d) inverts the record, which places such attackers explicitly out of scope.", "options": [{"key": "A", "text": "He is Anthropic's CISO, and the program's outcomes appear in the company's annual report"}, {"key": "B", "text": "He was Anthropic's inaugural CISO from April 2023 to approximately September 2025 and is now Deputy CISO; the record is inputs only, because a private company's security outcomes, incidents, budgets and metrics are unobservable"}, {"key": "C", "text": "His 2025 forecast about AI virtual employees was subsequently vindicated"}, {"key": "D", "text": "The published model-weight controls are claimed to defeat sophisticated state-sponsored attackers"}]}, {"id": "m11-kc4", "type": "short_answer", "question": "A CISO tells you reported security incidents fell 40% year on year. Give two readings and say what you would check first.", "answer": "Either detection improved, or reporting fell — Edmondson (1996) found better team climate associated with *more* detected errors, and Higgs et al. (2016) found firms with board technology committees reported *more* breaches. Check the denominator: near-miss and phishing-report volumes, self-reported clicks, and whether anything changed in how incidents are classified or who classifies them.", "explanation": "Low counts can signal silence rather than safety; the count alone distinguishes nothing."}], "takeaways": ["Read a career for the situation, the documented decision, who reported the result, and the mechanism — never for the person.", "The reading list is drawn by publicity, not effectiveness. Banker & Feng (2019) explain who becomes documentable; Amir et al. (2018) why a clean record is ambiguous; Malmendier & Tate (2009, from the CEO library) why awards are a treatment rather than a measurement.", "Company-reported outcomes are facts about what a company said. Clinton's record has no outcomes at all, because a private company's security results are unobservable, and the curriculum says so rather than filling the gap.", "Four patterns survive the five cases: install a board *format* rather than chasing a reporting line; own the crisis in public; treat long tenure as a precondition and a risk together; and set the control–enablement dial against the situation, not the personality.", "Every failure mode here is a setting that outlived its situation, and the earliest warning sign is hearing your own problem described in someone else's words."], "videos": ["vid.00-four-patterns-across-five-leaders", "vid.00-reading-a-career-for-decisions", "vid.00-why-the-quiet-ones-have-no-record"], "glossary_terms": ["term.selection-into-visibility", "term.survivorship-security-records", "term.company-reported-outcome", "term.inputs-only-record", "term.crisis-ownership", "term.board-cyber-audit-framework", "term.control-reliability-engineering", "term.least-agency", "term.accidental-architecture", "term.idolization"], "tags": {"dials": ["aggression_caution", "centralization_decentralization", "decisiveness_inquiry", "hands_on_delegation", "urgency_patience"], "archetypes": ["arch.business-risk-ciso", "arch.enterprise-cio-architect", "arch.post-breach-ciso-turnaround", "arch.regulated-industry-cio-ciso", "arch.technical-ciso"], "stages": ["mature", "post_merger", "regulatory_reputation_crisis", "scale_up", "turnaround"], "learn_categories": ["leadership"]}, "estimated_minutes": 95, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/11-what-five-leaders-teach.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "m12", "slug": "the-two-sentence-ciso", "title": "The Two-Sentence CISO — Visibility, Blame, and Mature Conviction", "unit": "IV. The Leaders and the Capstone", "big_idea": "Visibility ≠ effectiveness, and blame ≠ accountability. The rarest technology leader can say \"Yes — and here is the risk, priced\" and \"I was wrong about that risk. Change the control.\" in the same quarter.", "effectiveness_equation_term": "Behaviors", "learning_objectives": ["Explain why the public knows breached CISOs and celebrity CIOs rather than quiet operators, and what the celebrity research does and does not establish.", "Distinguish blame from accountability using four tests, and explain why executive turnover after a breach tracks perceived scope of duties rather than causal contribution.", "Articulate what each of the four sentences — the Two-Sentence Test plus the Risk Corollary — actually requires of the person saying it.", "Produce a Personal Calibration Plan: tendency profile, three dials, fit and discretion analysis, bad-news mechanisms, 90-day commitments, and the Risk Corollary rehearsed with your CEO."], "sections": {"core_lesson": "This is the capstone, and it asks one question: what would it take for you to be a technology executive whose judgment is worth having when it is inconvenient?\n\nTwo confusions stand in the way. The first is between **visibility and effectiveness**. You can name breached CISOs and a handful of celebrated CIOs; you cannot name the operators who ran clean programs for a decade, because prevention has no press release and the counterfactual is unobservable. The second is between **blame and accountability**. Blame is what an organization does after a bad outcome, and it lands where perceived scope of duties says it should. Accountability is a design decision made in advance — who owns which risk, at what threshold, recorded where. A company can have plenty of the first and none of the second.\n\nThe course's closing device is four sentences. Two from the CEO edition: **\"We're going to do this.\"** and **\"I was wrong. Change the plan.\"** Two added by the security chair — the **Risk Corollary**: **\"Yes — and here is the risk we are accepting, priced.\"** and **\"No — and here is what would change my answer.\"** Each requires something specific, and the requirement is usually structural rather than temperamental.\n\nIn the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on **Behaviors**, and produces the artifact the course exists for: a Personal Calibration Plan you write about yourself, with dates.", "big_idea": "**Visibility ≠ effectiveness, and blame ≠ accountability. The rarest technology leader can say \"Yes — and here is the risk, priced\" and \"I was wrong about that risk. Change the control.\" in the same quarter.**\n\nAlmost everyone can manage one of those. The leader who only prices is eventually the one who accepted the wrong thing and never revisited it; the leader who only revises never made a decision anyone could act on. Holding both is not a personality; it is a set of mechanisms plus the standing to use them.", "research": "**FRAMEWORK.** Hayward, Rindova & Pollock (2004), from the CEO library, developed the construct of CEO celebrity: journalists attribute a firm's distinctive and consistent strategic actions to the CEO's disposition, and the CEO who internalizes that attribution becomes overconfident about their own efficacy and persists with the actions that generated the celebrity even after they stop paying off. It is a theory-building paper with propositions, not an empirical test, so cite it for the mechanism rather than for effect sizes.\n\n**RESEARCH FINDING.** Malmendier & Tate (2009), from the CEO library, supplies the empirical half. Using prestigious business-press awards as a shock to status and comparing winners with matched predicted winners who did not win (US large firms, 1975–2002), award-winning CEOs subsequently underperformed relative to their own prior record and to the matched group; they received higher pay, spent more time on outside activities such as board seats and book-writing, and their firms showed more earnings management, with the effects strongest where governance was weak. Mean reversion is partly but not entirely addressed by the matching design. **INTERPRETATION.** No equivalent study exists for CIOs or CISOs. The mechanism is plausible in a security chair and unproven there.\n\n**RESEARCH FINDING.** Chatterjee & Hambrick (2011), also from the CEO library, found that narcissistic CEOs appear to discount objective performance feedback while amplifying their risk taking in response to media praise and awards. Archival proxies for narcissism; associations. Read together with the two studies above, the pattern is that public recognition changes what an executive attends to — and the specific thing it displaces is the unglamorous, corrective signal.\n\n**RESEARCH FINDING.** Banker & Feng (2019) is the accountability evidence. Breaches attributed to system deficiency increased CIO turnover likelihood by 72 percent; breaches caused by criminal fraud or human error showed no significant association with CIO turnover. CEO turnover rose after both system-deficiency and human-error breaches; CFO turnover showed no relationship. Archival matching of disclosed breaches to executive changes, with breach cause classified from public descriptions, and turnover is not always dismissal. **INTERPRETATION.** Consequences track the *perceived scope of the executive's duties*, not their causal contribution. That is a description of blame, and it is why \"were you at fault?\" and \"were you removed?\" are different questions.\n\n**RESEARCH FINDING.** Amir, Levi & Livne (2018) compared attacks firms disclosed with attacks they withheld that outsiders later revealed: withheld attacks were associated with a decline of approximately 3.6% in equity value in the month of discovery, against about 0.7% for disclosed attacks. Archival, pre-dating mandatory disclosure, and withheld attacks are observable only when someone else finds them. Concealment is priced when discovered — the market's version of the boundary the Sullivan case draws in law.\n\n**RESEARCH FINDING.** Edmondson (1996) is the reason a quiet year is not self-evidently a good one. In eight nursing units across two hospitals (146 respondents), units with stronger team climates and more active nurse-manager coaching showed *higher* detected drug-error rates — the correlation between manager coaching and detected errors was r = .74, and with intercepted errors r = .71. Correlational, in healthcare, with error rates drawn from reporting systems that climate itself affects, which is the paper's point. Her 1999 study of 51 teams then linked psychological safety to learning behavior and performance, cross-sectionally and in a single company. Low incident counts can signal silence rather than safety.\n\n**RESEARCH FINDING.** Two more studies bound what a leader's authority actually rests on. Ashenden & Sasse (2013), interviewing five CISOs, found they described their central obstacles as low perceived power, confusion about role identity and weak engagement with employees — illustrative, not generalizable. Cram, D'Arcy & Proudfoot (2019), pooling 95 papers across 17 antecedent categories, found employees' attitudes, personal norms and ethics were the strongest predictors of security-policy compliance while punishment and rewards were among the weakest — largely survey-based studies measuring intention more often than behaviour. **INTERPRETATION.** The lever the blame-oriented organization reaches for first is the one the evidence rates lowest.\n\n**TIER 3.** For base rates only, from a self-selected practitioner sample: the IANS/Artico *State of the CISO 2026* survey of more than 600 security leaders reports that 52% say their responsibilities are not manageable given current resources and 69% are open to changing jobs within the next year.\n\n### Where the evidence is weak\n\nThere is no study in either library of CISO or CIO celebrity, of what public profile does to a security executive's judgment, or of whether any of the four sentences improves any outcome. The celebrity research is about CEOs in a different labour market, with awards as the status shock and share price as the outcome; a security executive has neither. Banker & Feng (2019) concerns CIOs, not CISOs, and measures turnover rather than fault. The Sullivan case is a documented legal record about one person, not evidence about a population. Everything in section 4 that is not explicitly cited is FRAMEWORK and INTERPRETATION.", "explanation": "### Why the public knows the breached and the celebrated\n\n**INTERPRETATION.** There are two doors through which a technology or security executive's name reaches the public. One is a breach. The other is a stage — a keynote, a profile, an award, a vendor's advisory board. Both are visibility events, and neither is a measurement. The operators who ran good programs for a decade without an incident are invisible by construction, because the evidence of their work is an absence, and absences are not news.\n\nHayward et al. (2004) explain the machinery. Journalists need a cause, and a person is a better cause than a control framework, so distinctive and consistent action gets attributed to disposition. In security this attribution runs backwards: the distinctive, consistent, *visible* action is almost always an incident response, so the person the public associates with security competence is disproportionately someone who was present at a failure. The most-known names in the field are a sample selected on the outcome the field exists to prevent.\n\nThen the second-order effect. Malmendier & Tate (2009) found award-winning CEOs underperforming their own prior record afterwards, earning more, and diverting effort outward; Chatterjee & Hambrick (2011) found narcissistic CEOs discounting objective feedback while amplifying risk-taking in response to praise. **HYPOTHESIS.** The security analogue is not that a famous CISO becomes reckless. It is that a CISO who has become a public representative of their program acquires a reason not to hear that the program is worse than described — and the corrective signal a CISO depends on (the near-miss, the click, the misconfiguration) is exactly the signal that is easiest not to hear. Untested in this population.\n\nThe course's phrasing: **visibility ≠ prevalence; visibility ≠ effectiveness.** A profile is evidence that someone found you interesting.\n\n### Blame is not accountability\n\n**FRAMEWORK.** Banker & Feng (2019) found CIO departures about 72% more likely after breaches attributed to system deficiency and no significant association after breaches attributed to fraud or human error. Note what that is not: a finding that CIOs cause system-deficiency breaches. It is a finding that organizations remove executives when the failure falls inside the perceived boundary of their job. Blame follows the shape of the role description.\n\nAccountability is different, and four tests separate them.\n\n**Was it named in advance?** Accountability is written down before the outcome — this person accepts this class of risk to this threshold. Blame is assigned afterwards, from the outcome backwards.\n\n**Does it attach to a role or a person?** Accountability survives a personnel change because the obligation belongs to the chair. Blame is about the individual and ends when they leave, which is why blame is cheaper and changes nothing.\n\n**Does it produce a system change or a roster change?** After a genuinely accountable failure, the control, the threshold or the decision right changes. After a blame event, the org chart changes and the control does not.\n\n**Could the person have said no beforehand?** Accountability without the authority to refuse is a trap. This is where Module 10's discretion audit returns: an executive scoring zero on veto rights and incident command authority is being held accountable for outcomes they had no structural means to prevent.\n\nThe organizational cost of confusing the two is measurable in the reporting culture. Cram et al. (2019) found sanctions among the weakest predictors of security-policy compliance and employees' own norms among the strongest; Edmondson (1996) found better-led units reporting *more* errors. A blame-oriented program produces the number an executive wants to see and none of the information they need.\n\n### The four sentences and what each requires\n\n**FRAMEWORK.** Each sentence has a precondition that is usually structural, not emotional.\n\n**\"We're going to do this.\"** Requires a priced position you can defend, the standing to state it (Module 10), and willingness to own the consequence when the price turns out to be wrong. Its failure mode is the executive who converts every decision into an options paper so that no sentence is ever attributable.\n\n**\"I was wrong. Change the plan.\"** Requires three things and only one of them is character. It requires a *mechanism* that tells you — the Information-Environment Stack from Module 5: near-miss reporting, blameless review, standing red-team, direct lines from engineers, the quarterly \"what we got wrong.\" It requires a *record* of what you believed and when, or you cannot tell revision from revisionism. And it requires an environment where saying it is survivable, which is a fact about your CEO as much as about you.\n\n**\"Yes — and here is the risk we are accepting, priced.\"** Requires quantification you can defend and will volunteer the weakness of (Gordon & Loeb, 2002, and its assumptions), a *named* accepter who is not you, a written record, and a review date. A \"yes\" without those four is not a priced acceptance; it is agreement with extra vocabulary.\n\n**\"No — and here is what would change my answer.\"** Requires that the changing condition be real and reachable — a compensating control, a contract term, a test result, a date. Falsifiability is the whole point. A \"no\" whose condition cannot be met is a refusal in costume, and the business learns to route around you rather than negotiate with you.\n\n**INTERPRETATION.** The pair that is genuinely rare is the *third and second in the same quarter*: pricing a risk, accepting it in public, then returning three months later to say the price was wrong. That is what \"enablement with institutional paranoia\" looks like when it is real rather than a slogan.\n\n### The Sullivan case\n\n**FACT.** Joseph Sullivan, then chief security officer of Uber and previously chief security officer of Facebook, was convicted in October 2022 of obstruction and misprision of a felony for concealing Uber's 2016 breach, was sentenced in 2023, and had his conviction affirmed by the Ninth Circuit on 13 March 2025 (*United States v. Sullivan*, No. 23-927).\n\n**INTERPRETATION.** The case is taught here for one reason and misused for several others, so be precise about all of them. It is not evidence about Sullivan's competence as a security executive; nothing in the record speaks to that. It is not a case about being breached — Uber's breach is not what was prosecuted. It is a case about *concealment from the people entitled to know*, decided by a court, and it marks the outer boundary of the first sentence. \"We're going to do this\" is a decision you own; it stops being a decision and becomes something else at the point where the choice is to keep a material fact from a regulator.\n\nTwo connections make it a course case rather than a news story. Amir et al. (2018) is the market's version of the same boundary: withheld attacks later discovered were associated with roughly a 3.6% equity decline against 0.7% for disclosed ones — concealment is priced when it is found. And the SEC's 2023 rules have since converted part of the judgment into a dated obligation: a material incident is disclosed on Form 8-K within four business days of the materiality determination (FACT). What remains judgment is the determination itself, and that judgment is made by someone under pressure who believes the situation is contained. Every executive in this course will at some point believe a situation is contained.\n\n### The five leaders, in one line each\n\nModule 11 does this properly, with sources. Here they are only pointers to where the four sentences have been visible in documented careers: **Phil Venables** (CISO at Goldman Sachs, then Google Cloud) on long-horizon program building and public first-person reasoning; **Jamil Farshchi** (CISO at Home Depot and Equifax, later CTO) on the post-breach mandate and the structural mechanisms that came with it; **Jason Clinton** (Anthropic's inaugural CISO from April 2023 to September 2025, now Deputy CISO) on published decision frameworks — and on a record that is *inputs only*, since a private company's security outcomes are unobservable, plus a dated public forecast that was later scored as having missed; **Rob Carter** (FedEx CIO across roughly twenty-five years to June 2024) on tenure long enough to own a full architecture cycle; **John Halamka** (CareGroup/BIDMC CIO, later Mayo Clinic Platform) on owning a crisis in public. No new facts here. Go to Module 11 before you cite any of them.\n\n### The Personal Calibration Plan\n\n**FRAMEWORK.** The deliverable of this course. Six parts, written about yourself, in a document with dates, revisited quarterly.\n\n**1. Tendency profile.** Your assessment results plus two behavioral anchors per tendency — actual decisions, dated, that show the tendency operating. A tendency you cannot evidence with a decision is a self-description, not a profile. Note explicitly where your self-rating and your last 360 disagreed.\n\n**2. Three dials to move.** Not eight. For each: the current setting, the setting the *next twelve months* require, the evidence that you are currently at the first, and the specific recurring situation in which you will practise the second. \"Move optimism toward skepticism\" is a wish. \"In every vendor-security review, write the failure scenario before reading the vendor's questionnaire\" is a dial movement.\n\n**3. Fit and discretion analysis.** The extended Fit Equation — Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line — with one line for the company and one for you on each term, and the weakest term circled (Module 9). Then the eleven-item discretion audit from Module 10, scored twice: as you see it and as your CEO would. Name your reporting line's actual effect: which conversation it puts you inside, and which it keeps you out of. Banker et al. (2011) is the reminder that no line is universally right; Karahanna & Preston (2013) is the reminder that the relationship is a mechanism you can build even where the line is fixed.\n\n**4. Bad-news mechanisms.** The Information-Environment Stack, with the current state of each layer and the one you will install next quarter: near-miss reporting, blameless post-incident review, standing red-team, direct lines from engineers and client teams, and the quarterly \"what we got wrong.\" Milliken et al. (2003), from the CEO library, is the working assumption: most employees can recall withholding an important concern from a superior, so assume filtering and audit reach rather than trusting volume.\n\n**5. Three 90-day commitments.** Each with a date, an observable outcome, and a named person who will tell you if it did not happen. Examples of the right shape: \"By 15 March, one written risk acceptance signed by a named business executive, with a review date.\" \"By 30 April, the incident-command authority memo signed.\" \"By 31 May, a blameless review published internally for an incident where my own decision was a contributing factor.\"\n\n**6. The Risk Corollary, rehearsed with your CEO.** Not a metaphor — a scheduled conversation with a real decision in it. Bring one thing you are saying yes to with the risk priced and a named accepter, and one thing you are saying no to with the condition that would change your answer. Ask your CEO two questions afterwards: which sentence was easier to hear, and what would have made the other one credible. Owens & Hekman (2012), from the CEO library, identify admitting mistakes and limits as one of three observable humble-leader behaviors that spread to teams — with the caveat that humility appears less effective under extreme threat and time pressure, which is precisely why this conversation is scheduled in calm.", "example": "*Fictional composite.*\n\nDr. Naomi Etuk had been CISO of Bellhaven Grove Health Partners — a 3,100-employee integrated health system in western Massachusetts — for three years when her CEO forwarded her a note from a national conference organizer inviting her to keynote on \"the health system that didn't get hit.\" She wrote her Personal Calibration Plan that weekend instead of a talk.\n\n**Tendency profile.** Two anchors per tendency, dated. The uncomfortable one: under time pressure she had twice overridden her own architecture review — once for a scheduling platform in March, once for a remote-radiology integration in September — and both times had told herself it was pragmatism. Her 360 the previous year had a comment she had dismissed: *decisive, but the reasons change afterwards.*\n\n**Three dials.** Optimism → skepticism, practised in one recurring place: the vendor review, where she would now write the failure scenario before opening the questionnaire. Hands-on → delegation, because she was still personally approving every firewall change and her deputy had stopped proposing them. Urgency → patience on the clinical-workflow controls, where speed had produced three documented workarounds by nurses in one quarter — the Edmondson (1996) pattern in reverse: not silence, but people telling her in the form of behaviour rather than words.\n\n**Fit and discretion.** The weakest term of the Fit Equation was Reporting Line: she reported to the CIO, whose delivery targets she priced. Discretion audit, scored as she saw it: 16. Scored as she believed her CEO would: 22. The six-point gap sat almost entirely on veto rights and mandate clarity — items neither of them had ever written down and both assumed were settled.\n\n**Bad-news mechanisms.** Near-miss reporting existed and produced four reports a quarter, which she had been reading as good news. She reclassified it as a suspicious number for a 3,100-person organization and made auditing its reach the next quarter's project.\n\n**Three commitments.** A signed risk acceptance for the legacy imaging system from the chief medical officer, with a review date, by 15 March. A blameless review of the September radiology integration — her own override — published internally by 30 April. Written veto thresholds agreed with the CIO and CEO by 31 May.\n\n**The Risk Corollary rehearsed.** She booked forty minutes with the CEO. The yes: the ambient-documentation AI pilot the clinicians wanted, priced at roughly $2–4M of expected annual loss in its first configuration, accepted by the chief medical officer, reviewed in six months. The no: extending remote access to a third-party billing vendor without a contractual right to audit, with the condition stated — the audit clause, or a broker in front of it.\n\nIt did not go as rehearsed. The CEO accepted the yes without argument and pushed hard on the no, and Etuk discovered mid-sentence that her condition was not actually reachable in the vendor's contract cycle — a \"no\" in costume. She said so out loud, which was the part of the exercise she had not planned, and left with a worse-defined position and a better one to build.\n\nShe declined the keynote. Then, six weeks later, she accepted a different invitation: a panel on failed integrations, where the material was the September override and the review she had published about it.", "ceo_contrast": "Give the same magazine invitation, and the same calibration plan, to four archetypes.\n\n**The Technical CISO** declines the profile immediately and privately, and the instinct is sound — the visibility research (Hayward et al., 2004; Malmendier & Tate, 2009) describes a real hazard. Gain: no exposure, no distortion, no time lost. Cost: this leader also declines the internal visibility that would let anyone check their reasoning, and their calibration plan lists eight dials they intend to move by force of will and no mechanism that would tell them they had not. Refusal is not calibration; it is the same avoidance in a more respectable coat.\n\n**The Business-Risk CISO** takes the profile and does it well, redirecting the story toward mechanisms and the team. Gain: hiring improves, the CEO is pleased, the board reads it as validation of their oversight. Cost: this leader now has a public description of the program, and the gap between description and reality becomes a thing to manage rather than a thing to report. Watch the *what we got wrong* section of the next two board packs; if it shortens, the profile is doing the work the research predicts.\n\n**The Post-Breach CISO (Turnaround)** treats a clean year with suspicion and refuses to call it a result at all. Gain: exactly the right reading of Edmondson (1996) — the quiet may be silence — and the most rigorous audit of the near-miss channel of the four. Cost: a team that has genuinely performed well is told, for the third year running, that nothing has been proven, and the best detection engineer leaves for somewhere that says thank you. The dials set for a blame environment do not stand down when the blame does.\n\n**The Enterprise CIO (Architect)** hands the profile to the communications function and turns the calibration plan into a governance artifact: a RACI, a metrics tree, a quarterly review board. Gain: the plan survives this leader's departure, which is more than most calibration plans manage. Cost: a document nobody experiences as personal, and the one thing the exercise was for — the dated, uncomfortable, first-person admission — is delegated into a process. The Two-Sentence Test cannot be performed by a committee.\n\nThe invitation is not the decision. The decision is what each leader does with the fact that a good year is ambiguous evidence.", "failure_mode": "**FRAMEWORK — the Overuse Ladder for candor and conviction.**\n\n*Conviction → epistemic arrogance.* \"We're going to do this\" hardens into a habit of treating challenge as a failure of comprehension in the challenger. The tell is that the executive can recall being disagreed with but not being persuaded.\n\n*Candor → performance of candor.* \"I was wrong\" becomes a ritual, delivered fluently and always about something cheap — a tool choice, a timeline — and never about a risk acceptance the person argued for. Ritual self-criticism buys the reputation for humility while insulating the decisions that matter. It is harder to detect than concealment because it looks like the thing the course asked for.\n\n*Pricing → the number nobody checks.* A priced acceptance with a named accepter and a review date is a control. The same acceptance with no review date is a document that ages into a liability, and the executive who produced it will be surprised to find their name on it.\n\n*Refusal → \"no\" as identity.* The condition attached to the \"no\" becomes decorative, then unreachable, then absent. The business stops negotiating and starts routing around, and the workarounds become the attack surface.\n\n*Visibility → constituency.* The executive acquires an external audience whose expectations differ from the company's, and begins optimizing for the audience that applauds rather than the one that pays. Malmendier & Tate (2009) found award winners diverting effort into outside activities; the security version is a speaking calendar that grows while the near-miss channel quietly dies.\n\n### Early warning signs\n\n- Your last three \"I was wrong\" statements were all about tools and none about a risk you priced.\n- Your near-miss reports fell this year and you described that to the board as improvement.\n- You cannot name a person who told you something unwelcome in the last quarter.\n- You have a public description of your program and a private one, and you know which is accurate.\n- The condition attached to your last \"no\" has not been met and nobody has asked about it since."}, "research_refs": ["res.hayward2004", "res.malmendier2009", "res.chatterjee2011", "res.banker2019", "res.amir2018", "res.edmondson1996", "res.edmondson1999", "res.ashenden2013", "res.cram2019", "res.owens2012", "res.milliken2003", "res.gordon2002", "res.hambrick1987", "res.banker2011", "res.karahanna2013", "res.sec2023", "res.ians2026"], "reflection": ["Name the last time you said \"I was wrong\" about a risk you had personally priced and argued for. If you cannot, is that because it has not happened or because it was not said out loud?", "Which of the four sentences is hardest for you, and is the obstacle temperament, mechanism or standing? Which of those three could you change this quarter?", "Take your last risk acceptance. Is there a named accepter who is not you, and a review date that has not passed? If not, what does that document actually do?", "Your incident-reporting numbers moved last year. Write both readings — the program improved, and the reporting climate degraded. What evidence would distinguish them, and do you have it?", "If a national publication profiled you next month, what in your program would you not want a careful reader to ask about? Who else already knows about it?", "If you were removed after a breach tomorrow, would it be blame or accountability? Answer using the four tests, not your feelings.", "Write the two Risk Corollary sentences you will say to your CEO this quarter, with the real decision attached to each. Put the date in your calendar before you finish this module."], "simulation_ref": "sim.m12-sablewood-profile", "knowledge_check": [{"id": "m12-kc1", "type": "multiple_choice", "question": "Malmendier & Tate (2009), using business-press awards as a status shock in US large firms from 1975 to 2002, found that award-winning CEOs subsequently:", "answer": "B", "explanation": "Effects were strongest where governance was weak, and their firms also showed more earnings management; the matching design partly but not fully addresses mean reversion, and no equivalent study exists for CIOs or CISOs.", "options": [{"key": "A", "text": "Outperformed matched non-winners and reduced their outside commitments"}, {"key": "B", "text": "Underperformed relative to their own prior record and to matched non-winners, earned more, and spent more time on outside activities"}, {"key": "C", "text": "Showed no measurable change in performance or behaviour"}, {"key": "D", "text": "Underperformed only in firms with strong governance"}]}, {"id": "m12-kc2", "type": "multiple_choice", "question": "Banker & Feng (2019) found CIO turnover was about 72% more likely after which kind of breach?", "answer": "C", "explanation": "Fraud and human-error breaches showed no significant association with CIO turnover, which suggests consequences track the perceived scope of the executive's duties rather than causal contribution — a description of blame, not of accountability.", "options": [{"key": "A", "text": "Any publicly disclosed breach"}, {"key": "B", "text": "Breaches caused by criminal fraud"}, {"key": "C", "text": "Breaches attributed to system deficiency"}, {"key": "D", "text": "Breaches caused by human error"}]}, {"id": "m12-kc3", "type": "short_answer", "question": "State the four tests that distinguish blame from accountability, and explain why the fourth test connects this module to the discretion audit.", "answer": "Was it named in advance, or assigned from the outcome backwards? Does it attach to a role or to a person? Does it produce a system change or a roster change? Could the person have said no beforehand?", "explanation": "The fourth test links directly to Module 10 — an executive with no veto rights and no incident command authority is being held accountable for outcomes they had no structural means to prevent, which is blame wearing accountability's vocabulary."}, {"id": "m12-kc4", "type": "short_answer", "question": "Name the four sentences and state one concrete requirement for each — something a person or organization must have, not a disposition.", "answer": "\"We're going to do this\" requires a priced position and the standing to state it. \"I was wrong. Change the plan\" requires a mechanism that tells you (the Information-Environment Stack) and a dated record of what you previously believed. \"Yes — and here is the risk we are accepting, priced\" requires a named accepter who is not you, plus a written record and a review date. \"No — and here is what would change my answer\" requires a condition that is real and reachable.", "explanation": "Each precondition is structural rather than temperamental, which is why the Personal Calibration Plan pairs the dials with a discretion analysis and dated commitments instead of intentions."}], "takeaways": ["Visibility ≠ effectiveness. You know breached CISOs and celebrated CIOs because both are visibility events; prevention has no press release, and the field's best-known names are a sample selected on the outcome the field exists to prevent (Hayward et al., 2004; Malmendier & Tate, 2009; Chatterjee & Hambrick, 2011 — all about CEOs, none about CISOs).", "Blame ≠ accountability. Executive consequences after a breach track the perceived scope of duties, not causal contribution (Banker & Feng, 2019). Test the difference four ways: named in advance, attached to a role, producing a system change, and preceded by the authority to refuse.", "A quiet year is ambiguous evidence. Units with better climate reported *more* errors (Edmondson, 1996), so falling incident counts must be read against the reporting climate — and sanctions, the lever blame reaches for, are among the weakest predictors of compliance (Cram et al., 2019).", "The four sentences have structural preconditions: a priced position and standing; a mechanism and a dated record; a named accepter and a review date; a reachable condition. The Sullivan case (convicted October 2022, conviction affirmed 13 March 2025) marks the outer boundary of the first sentence — it is about concealment from those entitled to know, not about being breached — and Amir et al. (2018) is the market's version of the same line.", "Write the Personal Calibration Plan: tendency profile with dated anchors, three dials with a recurring situation each, fit and discretion analysis including the reporting line, the bad-news stack with next quarter's layer named, three 90-day commitments with observables, and the Risk Corollary rehearsed with your CEO as a scheduled conversation with a real decision in it."], "videos": ["vid.00-blame-is-not-accountability", "vid.00-building-your-personal-calibration-plan", "vid.00-the-four-sentences", "vid.00-visibility-is-not-effectiveness"], "glossary_terms": ["term.two-sentence-test", "term.risk-corollary", "term.visibility-vs-effectiveness", "term.blame-vs-accountability", "term.celebrity-cio", "term.personal-calibration-plan", "term.information-environment-stack", "term.productive-conviction", "term.epistemic-arrogance", "term.risk-acceptance"], "tags": {"dials": ["aggression_caution", "decisiveness_inquiry", "hands_on_delegation", "optimism_skepticism", "unilateral_consensus"], "archetypes": ["arch.business-risk-ciso", "arch.enterprise-cio-architect", "arch.post-breach-ciso-turnaround", "arch.smb-msp-technology-leader-player", "arch.technical-ciso"], "stages": ["mature", "regulatory_reputation_crisis", "scale_up", "turnaround"], "learn_categories": ["power_governance"]}, "estimated_minutes": 90, "label_default": "INTERPRETATION", "meta": {"source_path": "modules/12-the-two-sentence-ciso.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}], "archetypes": [{"id": "arch.business-risk-ciso", "name": "Business-Risk CISO", "family": "style", "one_line": "The security leader who speaks in prices rather than controls — board-fluent, enablement-first, trusted by the business, and dangerous when \"yes\" becomes an identity and nobody has verified the controls behind the price.", "disclaimer": "Archetypes are educational lenses, not personality categories. Real technology executives are usually two or three at once. The Business-Risk CISO is a *style* lens — a way of holding the security job, not a company size. It is the Technical CISO's counterpart, and the two are best read as settings on the same person: not which one you are, but which one the company in front of you needs more of this year.", "sections": {"definition_and_situation": "**FACT.** The Business-Risk CISO frames security as a portfolio of priced exposures rather than a set of controls. They came from risk, audit, consulting, product or a technical role they deliberately grew out of. Their authority is granted rather than earned in the console: they are in the room because executives find them useful.\n\n**RESEARCH FINDING.** A systematic review found the CISO's strategic role under-theorized and proposed a competency set for the CISO-as-strategist rather than the technical specialist (Maynard, Onibere & Ahmad, 2018; conceptual). **RESEARCH FINDING (practitioner).** In a 2026 survey of 600+ security leaders, 47% held EVP/SVP-level titles and 36% reported to a non-IT executive (IANS Research & Artico Search, 2026; self-selected). **INTERPRETATION.** The role's center of gravity is moving this way — a fact about titles, not evidence that it produces better security.", "dominant_job_requirements": "Put a number, with stated assumptions, on the company's material exposures. Run the Risk Corollary as a working method — \"Yes, and here is the risk we are accepting, priced\" — with a written owner for every accepted risk who is not the CISO. Own the board relationship and the disclosure judgment. Make security a condition of doing business rather than a tax on it.\n\n**FRAMEWORK.** The Gordon–Loeb model gives this archetype its intellectual backbone: optimal security investment depends on an information set's value, vulnerability and the productivity of spending, and under the breach-probability functions the authors assume it does not exceed about 37% of expected loss (Gordon & Loeb, 2002; analytical, and the bound holds only under stated assumptions). **INTERPRETATION.** The model licenses a priced answer. It does not supply the expected loss, and the Business-Risk CISO's characteristic error is treating a number they constructed as a number they measured.", "likely_useful_traits": "Comfort with quantification under uncertainty. Tolerance for being the person who says an exposure is acceptable. Curiosity about how the business makes money, because the exposures worth pricing are attached to revenue. And the stamina to hold a risk-acceptance conversation to a decision rather than a follow-up.\n\n**RESEARCH FINDING.** Successful cyberattacks that exposed personal financial information were associated with shareholder wealth losses much larger than out-of-pocket costs, consistent with reputational damage; losses were smaller at firms whose boards had attended to risk management before the attack, and firms increased risk-management and IT investment afterward (Kamiya, Kang, Kim, Milidonis & Stulz, 2021; archival, board attention proxied). **INTERPRETATION.** This is the archetype's strongest evidence: the cost of a breach is largely reputational, it varies by data type, and prior governance attention is associated with a smaller penalty. All three are arguments a CFO can act on.", "dangerous_traits": "- **Optimism → delusion.** The archetype's signature failure: a risk register of priced exposures where none of the prices has been tested against a real incident.\n- **Delegation → abdication** (extension rung). \"Engineering owns that control\" — with nobody verifying that it runs.\n- **Empathy → conflict avoidance.** The exposure that stays accepted because withdrawing the acceptance would embarrass a peer.\n- **Confidence → arrogance.** A quantification model whose assumptions have not been shown to anyone who could break them.\n- **Adaptability → strategy-of-the-month.** A new framework each year, none of them implemented deeply.\n\n**INTERPRETATION.** The Technical CISO's ladder ends in a queue; this one ends in a number nobody checked. **RESEARCH FINDING.** Across 5,000+ US hospitals and 938 breaches (2005–2013), the same security investment was associated with fewer breaches only where adoption was substantive rather than symbolic (Angst, Block, D'Arcy & Kelley, 2017). **INTERPRETATION.** Symbolic adoption is precisely what a well-run pricing exercise can conceal, because both the tool and the number exist.", "decision_style": "Framed as trade-offs, decided in forums, documented. The characteristic decision is a risk acceptance with an owner, a price, a compensating control and an expiry date. **FRAMEWORK.** The Two-Sentence Test is easy here in its first half — this archetype says \"we're going to do this\" fluently — and its hard half is narrower than it looks: \"I was wrong. Change the control.\"", "communication_style": "The strongest in the library: board decks that show consequence rather than coverage, a CFO conversation in loss terms, an engineer conversation in constraints. **RESEARCH FINDING.** Five UK CISOs described low perceived power and unclear role identity as their central obstacles (Ashenden & Sasse, 2013; illustrative). **INTERPRETATION.** This archetype has largely solved that problem — which creates its own risk, because a CISO who is never resisted may be one who has stopped asking for things.", "relationship_with_management_team": "Peer to the CFO, the general counsel and the business-unit heads; sometimes distant from the engineers who operate the controls. **RESEARCH FINDING.** In 81 US hospitals, the structural, cognitive and relational quality of the CIO–top-team relationship was associated with IS alignment and, through alignment, with financial performance (Karahanna & Preston, 2013; one sector, perceptual). **INTERPRETATION.** Relationship quality is a mechanism, and this archetype has it. The discipline is to spend it: a well-liked CISO who has never made an executive uncomfortable has capital they are not converting into controls.", "approach_to_risk": "Priced, owned and revisited. **RESEARCH FINDING.** Over 2005–2014, firms with board-level technology committees were more likely to have reported breaches in a given year — plausibly because they detected and disclosed more — and committee presence mitigated the negative abnormal returns from external breaches (Higgs, Pinsker, Smith & Young, 2016; endogenous committee formation). **INTERPRETATION.** Visible governance changes both what is reported and how the market responds — an argument for the transparency this archetype is good at. On the overlays, Control ↔ Enablement sits toward enablement and Prevention ↔ Resilience near center; the calibration question is whether the accepted exposures have ever been stress-tested by someone whose job is to disprove them.", "approach_to_capital": "Top-down and comparative: what the program costs against what it protects, as a portfolio the CFO can reason about. **RESEARCH FINDING.** Before mandatory disclosure, attacks firms withheld and that were later exposed were associated with about a 3.6% equity decline versus 0.7% for firm-disclosed attacks (Amir, Levi & Livne, 2018). **FACT.** Since December 2023, US public companies must disclose a material cyber incident on Form 8-K Item 1.05 within four business days of determining materiality, and describe board oversight and management's cyber expertise annually under Regulation S-K Item 106 (SEC, 2023). **INTERPRETATION.** Disclosure is a capital-markets event with a deadline, and the person who can hold a materiality conversation with the general counsel is usually this archetype.", "approach_to_talent": "Hires for translation and for depth they do not personally have. The team's shape is the tell: strong GRC and quantification, thin detection engineering. **INTERPRETATION.** The essential hire is a deputy who will contradict the price — technical enough to say \"that control is not running the way your model assumes,\" and senior enough to say it in front of the CFO.", "common_blind_spots": "- The control behind the number, never verified.\n- The accepted risk whose owner has left the company.\n- The client or third party who inherited an exposure the company priced for itself.\n- The CEO's optimism, which this archetype tends to share. **RESEARCH FINDING.** In a large survey, CEOs scored substantially more risk-tolerant and optimistic than the general population (Graham, Harvey & Puri, 2013, from the CEO library; associations, not causes). **INTERPRETATION.** A security leader whose disposition matches the CEO's removes the friction the role exists to supply.\n- The quiet quarter, read as evidence the prices were right.", "common_failure_mode": "\"Yes\" as identity. Every request is enabled, every exposure priced, the register grows, and actual control coverage falls behind the narrative describing it. The failure surfaces as a breach in a domain the CISO had explicitly accepted, with a paper trail showing they accepted it — the worst of both positions: the risk was known and the control was not there. **RESEARCH FINDING.** CIO departures were about 72% more likely after breaches attributed to system deficiencies than after fraud or human error (Banker & Feng, 2019). **INTERPRETATION.** A priced acceptance does not read as a system deficiency to a board — until the compensating control turns out to have been notional. Early warning signs: no risk acceptance withdrawn in a year; the last verification of a major control was a vendor attestation; the board has never seen a metric go the wrong way; the CISO cannot name a thing they refused this quarter.", "where_it_works": "Public companies with disclosure obligations and an engaged board; client-facing businesses where security is a commercial gate; companies whose security function has technical depth and no standing; regulated firms needing an executive who can talk to an examiner and a CFO in the same afternoon; and paired with a technical deputy.", "where_it_fails": "In a company with no real control foundation, where pricing exposures substitutes for building anything. In the first year after a breach, when the organization needs decisions rather than frameworks. And in an SMB or MSP, where a priced risk register is worth less than a tested restore.", "typical_dial_settings": "**FRAMEWORK.** Defaults: aggression (−1), decisiveness (−1), optimism (0), delegation (+2), urgency (0), consensus (+1), innovation (−1), decentralization (+1). The mild leftward lean on aggression and innovation encodes enablement: this archetype's default answer is yes-with-conditions. Delegation at +2 is structural — the controls are operated by people who do not report to the CISO — and it is the setting most likely to become abdication. Optimism sits at 0 rather than negative deliberately: the archetype's danger is inherited optimism, so neutral is a correction, not a description. Decentralization at +1 reflects federated risk ownership, which only works when the owners are named. A learner near this profile should ask when they last verified, personally, a control they had priced.", "adjacent_archetypes": "Under pressure it becomes an apologist for the business — the CISO who explains why every exposure was reasonable — or drifts into pure governance, producing artifacts nobody operates. It should grow toward the Technical CISO's verification discipline without giving up the pricing: a leader who can say \"here is the number, here is what I checked myself, and here is the assumption that would break it.\" After an incident it is usually replaced by the Post-Breach CISO.", "research_anchors": "- Gordon & Loeb (2002): security spend as a function of expected loss; the ~37% bound under stated assumptions.\n- Kamiya et al. (2021): breaches exposing personal financial data associated with losses far above out-of-pocket costs; smaller where boards had attended to risk management.\n- Higgs et al. (2016): board technology committees associated with more reported breaches and smaller market penalties.\n- Amir, Levi & Livne (2018): withheld attacks ~3.6% equity decline versus 0.7% for disclosed ones.\n- SEC (2023, FACT): 8-K Item 1.05 within four business days; annual Item 106 disclosure.", "vignette": "*Fictional composite.* Vantis Commerce is an $840M payments-software company in Austin, Texas, with 2,900 employees and a CISO, Rennie Okafor, who came from enterprise risk at a card network. She reports to the general counsel, sits on the disclosure committee, and briefs the audit committee quarterly with three slides: the four exposures that could be material, what each would cost, and what is being done about each.\n\nThe board likes her. Sales likes her more: her team turns client security questionnaires around in a day, and last quarter she closed a $9M renewal by walking a client's CISO through the architecture.\n\nHer register has eleven accepted risks. Nine have named owners. One — legacy tokenization in a platform acquired two years ago — has been accepted three times with the same compensating control: \"enhanced monitoring.\" Last month the detection lead mentioned, without emphasis, that the monitoring rule for that platform has been disabled since a January migration.\n\nRennie's prices may all be right. The archetype's question is whether anyone in her organization is paid to check the assumptions underneath them — and whether she would hear it if they did."}, "overuse_rungs": ["confidence->arrogance", "optimism->delusion", "empathy->conflict_avoidance", "adaptability->strategy_of_the_month"], "dial_defaults": {"aggression_caution": -1, "decisiveness_inquiry": -1, "optimism_skepticism": 0, "hands_on_delegation": 2, "urgency_patience": 0, "unilateral_consensus": 1, "innovation_operational_discipline": -1, "centralization_decentralization": 1}, "related_modules": ["m02", "m03", "m04", "m06", "m07", "m09", "m10"], "related_archetypes": ["arch.technical-ciso", "arch.enterprise-cio", "arch.regulated-industry-cio-ciso", "arch.post-breach-ciso", "arch.smb-msp-technology-leader"], "research_refs": ["res.gordon2002", "res.kamiya2021", "res.higgs2016", "res.maynard2018", "res.ashenden2013", "res.amir2018", "res.sec2023", "res.angst2017", "res.karahanna2013", "res.banker2019", "res.ians2026", "res.graham2013"], "meta": {"source_path": "archetypes/business-risk-ciso.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "arch.enterprise-cio", "name": "Enterprise CIO", "family": "scale", "one_line": "The Architect — runs technology for an enterprise through governance, portfolio, platforms, capital and board reporting rather than through work they can see, and whose dominant danger is isolation dressed as a green dashboard.", "disclaimer": "Archetypes are educational lenses, not personality categories. Real technology executives are usually two or three at once. The Enterprise CIO is a *scale* lens — the Architect position in Player → Coach → Architect — and describes the job of leading technology where the CIO cannot see the work and must design the system through which it is done. The person holding it is often also a Regulated-Industry leader by sector and a Transformation CIO by mandate, and in most enterprises the CISO reports to them, which makes calibrating two jobs against each other part of this one.", "sections": {"definition_and_situation": "**FACT.** An enterprise technology function has hundreds or thousands of people, multiple business units with their own priorities, platforms shared across them, a capital budget large enough to appear in the annual report, and a board that now asks about cyber risk by name. **RESEARCH FINDING (practitioner).** In a 2026 survey of 600+ security leaders, 64% of CISOs reported to IT leaders — the CIO or CTO — and 36% to non-IT executives (IANS Research & Artico Search, 2026; self-selected sample, not peer-reviewed).\n\n**INTERPRETATION.** The situation produces an executive whose leverage is indirect. The Architect's decisions are policies, standards, funding rules and organizational designs; the outcomes arrive through people the CIO will never meet, reported upward through layers with every incentive to round toward green. The job is to build instruments — governance, portfolio, metrics, dissent channels — that make the invisible visible without pretending the dashboard is the territory.", "dominant_job_requirements": "Design decision rights across business units and platforms. Run the portfolio: what to fund, what to stop, what to standardize. Allocate capital between running the enterprise and changing it. Report to the board proportionately and honestly. Match the reporting line to the strategy. Hire and calibrate the CISO. And keep a channel open to the engineers, because nothing else on this list works without one.\n\n**RESEARCH FINDING (practitioner).** In an MIT CISR study of about 250 enterprises, IT governance — the framework of decision rights and accountabilities for IT decisions — was associated with more than 25% higher profits among firms with superior governance, given the same strategic objectives (Weill & Ross, 2004; descriptive, not causal, and \"top performers\" were the authors' selection). **RESEARCH FINDING.** In a large-firm archival panel, CIO-to-CEO reporting was associated with better performance in differentiation-strategy firms and CIO-to-CFO in cost-leadership firms (Banker, Hu, Pavlou & Luftman, 2011; data predates the cloud era). **FRAMEWORK.** Governance and reporting line are design choices in the extended Fit Equation, not status prizes.", "likely_useful_traits": "Systems thinking, comfort with abstraction, patience measured in years, political skill without politicking, and the capacity to distinguish a status report from a fact. **RESEARCH FINDING.** A practitioner-facing companion to peer-reviewed work on CIO authority crosses strategic decision-making authority with strategic leadership capability and describes four profiles — IT Orchestrator (high/high), IT Advisor (capability without authority), IT Mechanic (authority without capability), IT Laggard — reporting that IT's contribution to performance varies with the profile (Preston, Leidner & Chen, 2008). **INTERPRETATION.** The Architect needs both halves, and the enterprise grants authority slowly; the useful trait is the one that earns it — the ability to make business leaders feel that technology decisions are theirs.\n\n**RESEARCH FINDING.** Pooled across the alignment literature, every dimension of IT–business alignment was positively associated with performance, and the much-discussed \"alignment paradox\" largely disappeared in meta-analysis (Gerow, Grover, Thatcher & Roth, 2014; underlying studies correlational).", "dangerous_traits": "- **Systems thinking → analysis paralysis** (extension rung). The architecture review that becomes a permanent institution.\n- **Delegation → abdication** (extension rung). Not knowing how anything works, and being proud of it.\n- **Rigor → bureaucracy.** The security review that ships nothing; the governance forum that decides nothing.\n- **Confidence → arrogance.** The platform bet made on a vendor's roadmap and defended for five years.\n- **Humility → hesitation.** Endless consultation with business units who would prefer the CIO decided.\n\n**RESEARCH FINDING.** Both managers' sensemaking (dismissing dissenters) and employees' self-censorship filter critical information out of upward communication (Tourish & Robson, 2006, from the CEO library; conceptual). In a 40-person interview study, 85% recalled withholding an important issue from a superior, mostly from fear of being labeled negatively or of futility (Milliken, Morrison & Hewlin, 2003, from the CEO library; small, exploratory). **INTERPRETATION.** Isolation is the Architect's ladder: each rung removes one more person willing to say the platform is late.", "decision_style": "Policy over transaction, portfolio over project. The characteristic Architect decision is a standard, a funding rule or an organizational boundary, made through forums in which business unit leaders have a real vote. The mature Architect distinguishes the decisions that must be centralized (identity, data classification, security baselines, the ERP core) from those that should be pushed to the businesses (product features, local tooling), and writes the boundary down. **FRAMEWORK.** The Two-Sentence Test at this scale is about stopping things: \"We're going to do this\" is easy to say about a new platform; \"I was wrong, change the plan\" is the sentence that kills the program the CIO sponsored, in front of the board that funded it.", "communication_style": "Board fluency without theater. The Architect is asked the question every technology committee asks — \"are we secure?\" — and must answer with a proportionate, priced view rather than a number. **RESEARCH FINDING.** Interview-based research argues CIO performance is bounded by the IT savviness of the CEO and top team (Peppard, 2010; qualitative). **INTERPRETATION.** The Architect's communication task is to raise that savviness deliberately — a board education cadence, business-unit leaders who can explain their own technology risks — so the CIO stops being the only person in the room who understands the question.", "relationship_with_management_team": "Two teams: the CIO's own leadership of VPs and the enterprise's executive committee. **RESEARCH FINDING.** In 81 US hospitals, the structural, cognitive and relational quality of the CIO–top-team relationship was associated with IS alignment and, through alignment, with financial performance (Karahanna & Preston, 2013; one sector, perceptual measures). Over 2005–2017, firms with a CIO on the top management team reported fewer data breaches of every type examined, and CEOs with IT expertise were associated with fewer reported breaches (Haislip, Lim & Pinsker, 2021; reported breaches only, associations). **INTERPRETATION.** The seat at the table is a mechanism, not a perk. The defining internal relationship is with the CISO: whether the CISO can escalate past the CIO to the board when they disagree, and whether the CIO built that path on purpose.", "approach_to_risk": "Owned through the CISO, priced for the board, governed through the technology or risk committee. **RESEARCH FINDING.** Over 2005–2014, firms with board-level technology committees were more likely to have reported breaches in a given year — plausibly because they detected and disclosed more — and the presence of a committee mitigated the negative abnormal returns from external breaches (Higgs, Pinsker, Smith & Young, 2016; committee formation is endogenous). **INTERPRETATION.** Visible board oversight changes both what gets reported and how the market responds; the Architect who resists a technology committee to avoid scrutiny has the incentive backward. On the overlays, Control ↔ Enablement is the enterprise's central design tension — centralized baselines, decentralized delivery — and Prevention ↔ Resilience should sit near center, with recovery objectives tested per platform.", "approach_to_capital": "Portfolio discipline: a stated split between run and change, multi-year platform investments with owners for the benefits, and a regular kill list. The Architect's capital failure is symmetric — starving the run to fund the strategy until an outage exposes it, or funding every business unit's request to avoid a fight. The distinctive discipline is stopping: the mature Architect can name the three programs cancelled last year and what the money did instead.", "approach_to_talent": "Leaders of leaders. The Architect hires VPs who can run functions the CIO will not inspect, plans succession for their own role, and makes the CISO hire as a calibration decision: a Technical CISO under a business-fluent CIO, or a Business-Risk CISO under a technical one. **INTERPRETATION.** The enterprise talent risk is homogeneity at the top — a leadership team of career enterprise operators with no one who has run a small company or an incident bridge in a decade.", "common_blind_spots": "- Dashboard fiction: every program green until the quarter it is red.\n- The engineer the CIO has not spoken to in a month, who knows the platform is late.\n- Exceptions approved three layers down that the CIO has never seen aggregated.\n- The third party that holds the enterprise's most privileged access.\n- The CISO's silence, mistaken for agreement.\n\n**RESEARCH FINDING.** In eight hospital units, better team climate and more manager coaching were associated with *higher* detected error rates (Edmondson, 1996). **INTERPRETATION.** Low incident counts across an enterprise are a number about reporting climate before they are a number about security.", "common_failure_mode": "Isolation and dashboard fiction. The CIO learns of the outage from the CEO, of the breach from the regulator, of the platform's failure from the business unit that quietly built its own. The Information-Environment Stack — near-miss reporting, blameless review, standing red team, engineer direct lines, the quarterly \"what we got wrong\" — was never built because the dashboards seemed sufficient. Early warning signs: no engineer has briefed the CIO directly in a month; every status is green; the board deck has not changed shape in six quarters; the CISO's risk register has no accepted risks with the CIO's name on them.", "where_it_works": "Large, multi-business enterprises; companies with shared platforms and a real capital budget; regulated firms whose boards need a fluent counterpart; any organization where the technology leader's leverage must be indirect because the work is too large to see.", "where_it_fails": "In the 40-person company — the \"enterprise CIO in a small company\" mismatch Module 8 names — where governance is overhead and the owner wanted someone who could fix the firewall. In a turnaround that needs a Player. And inside the enterprise, when the Architect has designed a system so complete that nobody in it can tell them it is failing. **RESEARCH FINDING.** Managerial discretion — the latitude an executive actually has — arises from the environment, the organization and the individual (Hambrick & Finkelstein, 1987, from the CEO library; conceptual). **INTERPRETATION.** The enterprise CIO's discretion is wide on architecture and narrow on almost everything else; the archetype fails when the CIO mistakes one for the other.", "typical_dial_settings": "**FRAMEWORK.** Defaults: caution (+1), inquiry (+1), skepticism (+1), delegation (+3), patience (+1), consensus (+2), operational discipline (+1), decentralization (+1). Delegation at +3 is the library's only rightward extreme on that dial and it is structural: the Architect cannot do the work. Consensus at +2 reflects that enterprise decisions bind business units that must own them. The mild rightward lean elsewhere is the enterprise's default weight — caution because the blast radius is large, patience because platforms take years, skepticism because every report has been rounded. Decentralization at +1 rather than higher because baselines, identity and security must stay central. A learner near this profile should ask whether delegation at +3 has become abdication, and name the last thing they verified themselves.", "adjacent_archetypes": "Under pressure the Enterprise CIO becomes a bureaucrat — the governance forums keep meeting after the decisions have stopped — or a Transformation CIO without a mandate, announcing platforms the enterprise will not fund. In a crisis it should be able to borrow the Post-Breach CISO's centralization briefly. It should grow into an Architect whose information environment is as designed as their architecture: an Enterprise CIO who hears bad news first.", "research_anchors": "- Weill & Ross (2004; Tier 3): decision rights and accountabilities as governance; >25% higher profits reported for well-governed firms.\n- Banker, Hu, Pavlou & Luftman (2011): CIO reporting line associated with performance conditional on strategy.\n- Preston, Leidner & Chen (2008): IT contribution varies with the CIO's authority × capability profile.\n- Karahanna & Preston (2013); Haislip, Lim & Pinsker (2021): CIO–top-team relationship and CIO presence on the TMT associated with alignment and fewer reported breaches.\n- Higgs et al. (2016): board technology committees associated with more reported breaches and smaller market penalties.\n- Tourish & Robson (2006); Milliken et al. (2003), CEO library: upward information filtering.", "vignette": "*Fictional composite.* Northgate Mutual is a $6.4B-revenue property and casualty insurer in Hartford, Connecticut, with 11,000 employees and a technology organization of 2,300 under CIO Marcus Ellery, nine years in the role. Marcus runs a mature governance model: an architecture board, a portfolio council of business-unit presidents, a quarterly technology committee of the board that he briefs personally. Every program in the current deck is green. The CISO, hired four years ago from a bank, reports to him.\n\nLast week a claims-platform engineer, in an elevator, mentioned to Marcus that the new policy-administration system — $140M, three years, green in every review — has been running its nightly batch on a workaround since spring, and that the security exception permitting it was approved by a director who has since left. The CISO knew. He had raised it once, in a one-on-one, and Marcus had said \"keep me posted.\"\n\nNothing in Northgate's governance is broken; every forum did what it was designed to do. The information reached the CIO through the one channel he had not designed. The archetype's question is what Marcus builds next: another review, or the direct lines that would have carried this news in spring — and whether the CISO's next disagreement has a path that does not run through Marcus's calendar."}, "overuse_rungs": ["confidence->arrogance", "humility->hesitation", "rigor->bureaucracy"], "dial_defaults": {"aggression_caution": 1, "decisiveness_inquiry": 1, "optimism_skepticism": 1, "hands_on_delegation": 3, "urgency_patience": 1, "unilateral_consensus": 2, "innovation_operational_discipline": 1, "centralization_decentralization": 1}, "related_modules": ["m02", "m04", "m05", "m08", "m09", "m10"], "related_archetypes": ["arch.mid-market-cio", "arch.transformation-cio", "arch.business-risk-ciso", "arch.technical-ciso", "arch.regulated-industry-cio-ciso"], "research_refs": ["res.banker2011", "res.peppard2010", "res.weill2004", "res.gerow2014", "res.karahanna2013", "res.haislip2021", "res.higgs2016", "res.preston2008", "res.ians2026", "res.edmondson1996", "res.tourish2006", "res.milliken2003", "res.hambrick1987"], "meta": {"source_path": "archetypes/enterprise-cio.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "arch.mid-market-cio", "name": "Mid-Market CIO", "family": "scale", "one_line": "The Coach — the first real technology leader of a company that has outgrown one person, who must build a leadership team, a cadence and decision rights while making the ERP and cloud decisions that will outlast their tenure.", "disclaimer": "Archetypes are educational lenses, not personality categories. Real technology executives are usually two or three at once. The Mid-Market CIO is a *scale* lens — the Coach position in Player → Coach → Architect — describing the job of leading technology in a company large enough to need a team and small enough that the CIO can still see all of it. Most people holding it are also the CISO. Its dial defaults are the most centered in the library: the Coach's task is to find the settings, not to run on one.", "sections": {"definition_and_situation": "**FACT.** A mid-market company — roughly $50M to $1B in revenue — typically has a technology function of ten to sixty people, managers promoted for being good engineers, an ERP older than some of the staff, a managed service provider that used to do everything, and a CEO who has just decided that \"IT\" needs a leader with a title. Security is the CIO's own second hat.\n\n**RESEARCH FINDING.** An event study found that, for firms in industries undergoing IT-driven transformation, announcements of newly created CIO positions provoked positive market reactions (Chatterjee, Richardson & Zmud, 2001) — a signal of expected value, not evidence of realized value. **INTERPRETATION.** The company creating its first CIO role is buying an expectation; the Coach converts it through a team that does not yet exist.", "dominant_job_requirements": "Build the first leadership team — infrastructure, applications, security — and make them managers, not senior engineers with new titles. Install a cadence: weekly operating review, monthly service review, quarterly portfolio gate. Write down decision rights, especially who may accept a security risk and at what threshold. Make the ERP or cloud decision as a business decision with a ten-year horizon. Renegotiate the MSP from \"does everything\" to \"does what we choose.\" Settle, with the CEO, where the CIO reports.\n\n**RESEARCH FINDING.** In a large-firm archival study, CIO-to-CEO reporting was associated with better performance in differentiation-strategy firms and CIO-to-CFO reporting in cost-leadership firms (Banker, Hu, Pavlou & Luftman, 2011; data predates the cloud era). **FRAMEWORK.** The extended Fit Equation's *Reporting Line* term is negotiable at this scale; negotiate it against the strategy, not your status.", "likely_useful_traits": "Patience with people learning to manage; the ability to let a lead make a decision the CIO would have made differently; business literacy that reaches the P&L; systems over heroics. **RESEARCH FINDING.** Across 1,114 manufacturing CEOs in six countries, more \"leader-like\" time use (multi-function meetings with senior colleagues rather than one-on-ones with operational staff) was associated with about 7% higher sales, emerging only after roughly three years; an estimated 17% of firms had a mismatched CEO type (Bandiera, Prat, Hansen & Sadun, 2020, from the CEO library; a matching finding, not a ranking). **INTERPRETATION.** The Coach's calendar shows the transition first: if it is still full of tickets in year two, the Player kept the title.\n\n**RESEARCH FINDING.** In 243 matched CIO–top-team pairs, shared understanding of IT's role was built by formal mechanisms and shared domain knowledge — not by informal socializing (Preston & Karahanna, 2009; cross-sectional). **INTERPRETATION.** The useful trait is structure-building, not charm: the steering committee that meets, the roadmap the CFO can read.", "dangerous_traits": "- **Detail → micromanagement.** The Coach who still plays: on every bridge, reviewing every change, the reason the managers wait.\n- **Empathy → conflict avoidance.** Keeping the infrastructure manager who cannot manage because he built the network.\n- **Rigor → bureaucracy.** The change board that ships nothing; the security review as veto rather than price.\n- **Adaptability → strategy-of-the-month.** A different ERP vendor after every conference.\n- **Delegation → abdication** (extension rung). \"The MSP handles security\" — with nobody inside who could tell if it did.\n\n**INTERPRETATION.** Executives report delegating more when overloaded and less with long tenure (Graham, Harvey & Puri, 2015, from the CEO library); the CIO promoted from within has the tenure and not yet the overload, so delegation must be chosen before it is forced.", "decision_style": "Through the team, in cadence. The characteristic Coach decision is a process decision — who decides, when, with what evidence — and the ERP or cloud decision is the test case because it outlasts the CIO's tenure. The mature Coach runs it as inquiry first (site visits, references, a real total-cost model), commits in public, and revisits only at the quarterly gate. **FRAMEWORK.** The Two-Sentence Test here means \"We're going to do this\" said to a steering committee, and \"I was wrong, change the plan\" said to the same committee, in front of managers who need to see it is survivable.", "communication_style": "Upward to a CEO whose IT literacy may be low, sideways to a CFO who owns the capital, downward to managers learning to hear \"what do you recommend?\" **RESEARCH FINDING.** Interview-based research argues CIO performance is bounded by the IT savviness of the CEO and leadership team, and that blaming CIOs for disappointing IT returns misplaces accountability (Peppard, 2010; qualitative). **INTERPRETATION.** The Coach teaches upward as deliberately as downward, in the CEO's vocabulary.", "relationship_with_management_team": "The first leadership team is the archetype's defining creation, and the critical design question is whether the security lead can say no to the applications lead and keep their standing. **RESEARCH FINDING.** In 81 US hospitals, the quality of the CIO–top-team relationship was associated with better IS alignment and, through alignment, with financial performance (Karahanna & Preston, 2013; one sector, perceptual measures); pooled across the literature, alignment is positively associated with performance (Gerow, Grover, Thatcher & Roth, 2014). **INTERPRETATION.** Relationship quality is a mechanism, built in the room where the business plans.", "approach_to_risk": "The Coach is usually the CISO too, so the Risk Corollary is spoken in the first person: \"Yes — we can go live before the pen-test remediation is finished, and here is the risk we are accepting, priced.\" Decision rights make that sentence honest: a written threshold above which the CEO, not the CIO, accepts the risk. On the overlays, Prevention ↔ Resilience leans toward resilience: a mid-market company will not out-prevent a determined attacker and can, with tested backups and named recovery objectives, out-recover one. **RESEARCH FINDING.** Across 5,000+ hospitals, security investment was associated with fewer breaches only where adoption was substantive, not symbolic (Angst, Block, D'Arcy & Kelley, 2017). The mid-market risk is buying the tool the auditor asked for and never integrating it.", "approach_to_capital": "The first real capital case of the CIO's career: an ERP program at several million dollars, a cloud migration that converts capex to opex and surprises the CFO in year two, a security budget the board now asks about. **RESEARCH FINDING (practitioner).** In an MIT CISR study of about 250 enterprises, firms with superior IT governance — decision rights and accountabilities for IT decisions — reported more than 25% higher profits than poorly governed firms with the same objectives (Weill & Ross, 2004; descriptive, not causal). **INTERPRETATION.** Capital discipline here is governance discipline: who proposes, who decides, who owns the benefit after go-live.", "approach_to_talent": "Hire managers who can hire. Promote engineers into management only with coaching and a way back. Make the first security hire before the incident. Convert the MSP: keep what it does well at scale (monitoring, patching, helpdesk), bring in-house what the company must understand itself (architecture, identity, risk acceptance). **INTERPRETATION.** The talent error is symmetrical — promoting the best engineer without support, or hiring an enterprise VP into a company that needs someone who will still touch the console on a bad day.", "common_blind_spots": "- Shadow IT, bought on a card because the cadence felt slow.\n- The MSP's standing access, which nobody inside has reviewed.\n- The CEO's actual expectations, never written down, discovered at budget time.\n- Measuring activity — tickets closed, projects green — rather than outcomes.\n- The cadence itself, abandoned in month four as \"bureaucracy.\"", "common_failure_mode": "Inability to let go, in one of two forms. The Coach who still plays: in every bridge, every design, every vendor call; managers who escalate everything because the CIO answers everything. Or the ERP program that becomes the CIO's whole tenure, with the security hat left on the chair. Early warning signs: the CIO is incident commander for every incident; no manager has made a decision the CIO disagreed with and let stand; the steering committee has never said no to the CIO. **RESEARCH FINDING.** A practitioner-facing companion to peer-reviewed work on CIO authority describes authority without capability (\"IT Mechanic\") and capability without authority (\"IT Advisor\") as under-performing profiles (Preston, Leidner & Chen, 2008). The Coach risks both.", "where_it_works": "Companies between roughly $50M and $1B where technology has become a constraint on growth; companies replacing a founder-era stack or making their first security hire; PE-backed platforms in the year after acquisition, before the transformation mandate arrives.", "where_it_fails": "In the 40-person company, where the cadence is overhead and the owner wants the Player back. In the enterprise, where the Coach can no longer see the work and the instruments of visibility — governance, portfolio, platforms — have not been built. In a company whose real problem is a transformation mandate delivered without discretion.", "typical_dial_settings": "**FRAMEWORK.** Defaults: aggression (0), decisiveness (0), skepticism (+1), hands-on (+1), urgency (0), unilateral (+1), operational discipline (+1), centralization (0). The four zeros are deliberate: the Coach's job is to read the company and set the dials, so the defaults are a starting position rather than a stance. Delegation at +1 corrects the Player's habits — one notch, not three, because the mid-market CIO still needs to know how the environment works. Consensus at +1 because decision rights are being built and the team must own them. Skepticism at +1 is aimed at vendors and the CIO's own green status reports; operational discipline at +1 because the cadence is the product.", "adjacent_archetypes": "Under pressure the Mid-Market CIO regresses to the Player — the hands-on engineer trap — or hardens into a bureaucrat whose change board is the reason the business bought its own software. It should grow into the Enterprise CIO as the company scales, or the Transformation CIO when a board hands it a mandate. While it holds the CISO hat, it borrows the Technical CISO's depth and the Business-Risk CISO's pricing without being either full time.", "research_anchors": "- Banker, Hu, Pavlou & Luftman (2011): the \"right\" CIO reporting line depended on strategy — CEO for differentiation, CFO for cost leadership.\n- Preston & Karahanna (2009): formal mechanisms and shared knowledge, not socializing, were associated with CIO–TMT shared understanding.\n- Karahanna & Preston (2013): CIO–TMT social capital associated with alignment and, through it, performance (81 hospitals).\n- Weill & Ross (2004; Tier 3): decision rights as governance; >25% higher profits reported for well-governed firms.", "vignette": "*Fictional composite.* Merrimack Valley Packaging is a $180M, 640-person family-owned corrugated-packaging manufacturer in Lowell, Massachusetts, with three plants and a 14-person IT department that until last year reported to the controller. Dana Whitcombe was hired as its first CIO from a $2B distributor where she ran applications. She inherited a 17-year-old ERP, an MSP in Nashua holding every admin credential, two managers who are excellent engineers, and a CEO who told her \"just make it not break.\"\n\nIn nine months she has hired a security lead, started a weekly operating review, and brought a $6.2M ERP recommendation to a steering committee she had to build first. The CFO wants to know why the MSP cannot just \"keep it running.\" The plant managers want to buy their own scheduling software. The security lead has flagged that the MSP's remote-access tool has no MFA, and the MSP says fixing it will delay the ERP work.\n\nDana could fix the remote-access tool herself in a Saturday. She has not. Whether that restraint is delegation or abdication depends on Tuesday's review — and on whether the security lead, not Dana, tells the MSP no."}, "overuse_rungs": ["detail->micromanagement", "empathy->conflict_avoidance", "rigor->bureaucracy", "adaptability->strategy_of_the_month"], "dial_defaults": {"aggression_caution": 0, "decisiveness_inquiry": 0, "optimism_skepticism": 1, "hands_on_delegation": 1, "urgency_patience": 0, "unilateral_consensus": 1, "innovation_operational_discipline": 1, "centralization_decentralization": 0}, "related_modules": ["m02", "m03", "m06", "m08", "m09", "m10"], "related_archetypes": ["arch.smb-msp-technology-leader", "arch.enterprise-cio", "arch.transformation-cio", "arch.technical-ciso", "arch.business-risk-ciso"], "research_refs": ["res.banker2011", "res.weill2004", "res.preston2009", "res.karahanna2013", "res.peppard2010", "res.gerow2014", "res.chatterjee2001", "res.preston2008", "res.bandiera2020", "res.graham2015", "res.angst2017"], "meta": {"source_path": "archetypes/mid-market-cio.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "arch.post-breach-ciso", "name": "Post-Breach CISO", "family": "ownership-situation", "one_line": "Hired in the weeks after the incident to centralize, replace, decide and move — with the turnaround paradox waiting at the end of it: the settings that save a security program in year one suffocate it by year three.", "disclaimer": "Archetypes are educational lenses, not personality categories. Real technology executives are usually two or three at once. The Post-Breach CISO is an *ownership-situation* lens: it describes a mandate handed out in a specific fortnight, usually to someone who is a Technical or Business-Risk CISO by style. It is the security edition of the turnaround, and it carries the turnaround's paradox — the behaviors that rescue the program are the behaviors that must be dismantled once it is rescued.", "sections": {"definition_and_situation": "**FACT.** The mandate follows a disclosed incident: ransomware that stopped operations, a data breach with notification obligations, an intrusion found by a customer or a regulator. Budget is available for the first time. Attention is total and temporary. The predecessor has usually left.\n\n**RESEARCH FINDING.** CIO departures were about 72% more likely after breaches attributed to system deficiencies, and showed no significant association after breaches attributed to criminal fraud or human error; CEO turnover rose after both system-deficiency and human-error breaches (Banker & Feng, 2019; archival, breach cause coded from public descriptions). **INTERPRETATION.** Accountability tracks the perceived scope of the executive's duties. The incoming CISO should read the classification of the breach carefully, because it defines what they are being held to.\n\n**RESEARCH FINDING.** Successful attacks exposing personal financial information were associated with shareholder losses far exceeding out-of-pocket costs; firms increased risk-management and IT investment afterward and reduced managers' risk-taking incentives (Kamiya, Kang, Kim, Milidonis & Stulz, 2021; archival). **INTERPRETATION.** The budget the new CISO is handed is the market's reaction converted into a plan.", "dominant_job_requirements": "Stop the bleeding: containment, credential reset, privileged-access lockdown, log retention. Establish a single command structure. Fix the two or three things everyone already knows are broken, publicly and fast, to buy credibility for the slower work. Rebuild the reporting relationship with the board and, if applicable, the regulator. And decide what the program will look like when the emergency ends — in month three, not month thirty.\n\n**FACT.** For US public companies, a material cybersecurity incident must be disclosed on Form 8-K Item 1.05 within four business days of the materiality determination, with annual disclosure of board oversight and management's cyber expertise under Regulation S-K Item 106 (SEC, 2023). **INTERPRETATION.** The disclosure clock is a design constraint on incident command, not a legal afterthought.", "likely_useful_traits": "Decisiveness under incomplete information. Physical stamina. The ability to absorb blame that is not yours without either accepting or relitigating it. Clarity about the difference between what is broken and what is merely unfamiliar. And enough security in one's own judgment to overrule people who have been here longer and were wrong.\n\n**RESEARCH FINDING.** In US healthcare, proactive security investment was associated with lower subsequent failure rates and greater cost-effectiveness than reactive investment, and external pressure weakened the benefit of proactive investment (Kwon & Johnson, 2014; one sector, hazard-model associations). **INTERPRETATION.** This is the uncomfortable finding for the archetype: reactive money is the least efficient money in the literature, and the Post-Breach CISO is spending it. The task is to convert reactive budget into a proactive posture before the attention window closes.", "dangerous_traits": "- **Decisiveness → impulsiveness.** Replacing a platform in week three because it was implicated, before anyone knows whether it failed.\n- **Urgency → recklessness.** A remediation program that itself introduces outages and change risk.\n- **Dominance → intimidation.** A war-room culture in which nobody brings a second opinion.\n- **Rigor → bureaucracy.** The emergency control that becomes permanent process, long after the emergency.\n- **Skepticism → cynicism.** Treating everyone who was here before as complicit.\n\n**RESEARCH FINDING.** In eight hospital units, stronger team climate and more manager coaching were associated with *higher* detected error rates (Edmondson, 1996; correlational, error rates drawn from reporting systems that climate itself affects). **INTERPRETATION.** A post-breach program that runs on blame will see its reported incident numbers fall, and will mistake that for progress. This is the archetype's most dangerous available illusion.", "decision_style": "Command. Decisions are made quickly, announced, and revisited on a schedule rather than on request. The characteristic decision is a centralization: identity, privileged access, endpoint, logging and vendor risk pulled to one team with one owner. **FRAMEWORK.** The Two-Sentence Test is inverted here. \"We're going to do this\" is expected daily; the rarity is \"I was wrong. Change the plan\" — said about a control this CISO installed in month two, and said publicly, because that is the sentence that tells the organization the emergency has a governor.", "communication_style": "Short, factual, frequent, and careful about tense: what is known, what is suspected, what is being tested. Legal is in the room. **INTERPRETATION.** The communication risk is over-promising in the first month — a remediation date, a \"fully contained\" — that the facts later contradict, which costs more credibility than the breach did.", "relationship_with_management_team": "Briefly, enormous. The Post-Breach CISO has more executive attention than any other archetype in this library and less time to use it. **RESEARCH FINDING.** Over 2005–2017, firms with a CIO on the top management team reported fewer data breaches of all types examined, and CEOs with IT expertise were associated with fewer reported breaches (Haislip, Lim & Pinsker, 2021; reported breaches only, associations under controls). **INTERPRETATION.** The structural change matters more than the personal relationship, and it is available only now: a seat, a committee, a written escalation path. The CISO who spends the attention window on remediation alone has fixed the estate and left the structure exactly as it was.", "approach_to_risk": "Prevention-heavy and control-first, by design and briefly by necessity. **RESEARCH FINDING.** Over 2005–2014, firms with board technology committees were more likely to report breaches, with the relationship stronger for newer committees, and committee presence mitigated the negative abnormal returns from external breaches (Higgs, Pinsker, Smith & Young, 2016; endogenous committee formation). **INTERPRETATION.** New oversight bodies surface more, not less; the Post-Breach CISO should expect their own reported numbers to rise and should say so in advance. On the overlays, Control ↔ Enablement sits hard toward control in year one — and the whole archetype is a lesson in how hard it is to move back.", "approach_to_capital": "Spend fast, but on things that survive the attention window: identity, logging, backup and recovery, third-party access. **RESEARCH FINDING (practitioner).** IBM/Ponemon's 2025 sample of about 600 breached organizations put the average breach cost at $4.44 million and mean time to identify and contain at 241 days (IBM & Ponemon Institute, 2025; vendor-sponsored, order-of-magnitude only). **RESEARCH FINDING.** Across 5,000+ US hospitals, the same investment was associated with fewer breaches only where adoption was substantive rather than symbolic (Angst et al., 2017). **INTERPRETATION.** The post-breach budget is the easiest money in security to spend symbolically.", "approach_to_talent": "Replace a small number of people quickly and visibly; keep more incumbents than instinct suggests, because they know where things are. Build for the second year: the responders who make month two work are not necessarily the people who will run a program in month thirty.", "common_blind_spots": "- The organization's exhaustion, which arrives around month nine and is invisible from the war room.\n- Near-misses, which stop being reported once the program starts assigning fault.\n- The controls installed under emergency authority that no one owns operationally.\n- The regulator's or customer's timeline, which outlasts the internal urgency by years.\n- The successor question: what this program requires of a CISO who is not in crisis.", "common_failure_mode": "The turnaround paradox. **FRAMEWORK.** \"Cut. Replace. Centralize. Decide. Move.\" saves a program in year one and suffocates it in year three: the change-advisory process nobody can get through, the security team that owns everything and is therefore the constraint on everything, engineers who have stopped proposing anything. **RESEARCH FINDING.** Among 193 US CEOs, strategic change showed an inverted-U relationship with performance, with outsiders experiencing both larger gains from moderate change and larger losses from excessive change, driven by later tenure years (Zhang & Rajagopalan, 2010, from the CEO library; archival). And outsider leadership showed no general advantage — it helped mainly where prior performance was poor or the environment turbulent (Karaevli, 2007, from the CEO library). **INTERPRETATION.** Both findings point the same way: this archetype is well matched to the situation that produced it and poorly matched to the one it creates. Early warning signs: no control has been retired in a year; the exception queue is the business's main complaint; incident reports are falling while near-miss reports are falling faster; the CISO still chairs a daily call that could be weekly.", "where_it_works": "The first twelve to eighteen months after a material incident; companies under a regulatory remediation order; carve-outs inheriting an unknown estate; any environment where nobody currently owns the basics.", "where_it_fails": "In a healthy program, where the same posture reads as an occupation. In a highly federated company that will route around a central security team rather than submit to it. And in this CISO's own third year, when the situation has changed and the dials have not.", "typical_dial_settings": "**FRAMEWORK.** Defaults: aggression (−2), decisiveness (−2), skepticism (+2), hands-on (−1), urgency (−3), unilateral (−2), operational discipline (+2), centralization (−3). Two extremes — urgency at −3 and centralization at −3 — are the mandate's settings, not the person's, and they are the two that must move first. Skepticism at +2 is the appropriate posture toward inherited assurances: assume nothing was verified. Operational discipline at +2 reflects that the fix is mostly hygiene done consistently rather than anything novel. Hands-on at −1 rather than lower is a deliberate correction: a CISO who personally runs the response has no capacity left for the structural work that is the actual mandate. A learner near this profile should write down, now, the month in which each extreme setting is scheduled to move — and who is allowed to tell them it is overdue.", "adjacent_archetypes": "Under pressure this archetype becomes a permanent emergency, or a Technical CISO whose \"no\" is now backed by a real incident and therefore unanswerable. It should grow into the Business-Risk CISO — the same authority, converted from control to price — or hand the program to one. It is the security counterpart of the Transformation CIO, and where both mandates land on one person, the risk of change beyond the organization's absorption limit roughly doubles.", "research_anchors": "- Banker & Feng (2019): CIO turnover about 72% more likely after system-deficiency breaches; no association for fraud or human-error breaches.\n- Haislip, Lim & Pinsker (2021): CIO presence on the top team associated with fewer reported breaches of all types, 2005–2017.\n- Kwon & Johnson (2014): proactive investment associated with lower failure rates and better cost-effectiveness than reactive investment.\n- Kamiya et al. (2021): losses far exceeding out-of-pocket costs; post-attack increases in risk-management investment.\n- Higgs et al. (2016): new board technology committees associated with more reported breaches; smaller market penalties.\n- Zhang & Rajagopalan (2010); Karaevli (2007), CEO library: the inverted-U of change and the conditional value of outsiders.", "vignette": "*Fictional composite.* Ridgeline Medical Supply is a $540M distributor of clinical consumables in Rochester, New York, with 1,400 employees and four distribution centers. In February, ransomware deployed through a third-party remote-access tool took order entry down for eleven days; the company notified customers, disclosed, and lost a national account. The CIO left in March. Dev Anand was hired in April as the company's first CISO, reporting to the CEO, with $12M over eighteen months.\n\nBy August he had reset every privileged credential, pulled identity and endpoint under his team, imposed a change freeze on the ERP, terminated the remote-access vendor, and replaced two of the five infrastructure managers. Reported incidents rose in the second quarter, which he had told the board to expect. The board is pleased.\n\nIt is now the following March. The change freeze is still in place. Two application managers have taken to asking forgiveness rather than permission. Phishing-report volume — which Dev tracks — has fallen by half since October, and he has been reading it as awareness training working.\n\nEverything Dev did was correct in April. The archetype's question is which of those decisions is still correct now, and whether anyone at Ridgeline believes they are allowed to tell him."}, "overuse_rungs": ["decisiveness->impulsiveness", "dominance->intimidation", "rigor->bureaucracy"], "dial_defaults": {"aggression_caution": -2, "decisiveness_inquiry": -2, "optimism_skepticism": 2, "hands_on_delegation": -1, "urgency_patience": -3, "unilateral_consensus": -2, "innovation_operational_discipline": 2, "centralization_decentralization": -3}, "related_modules": ["m04", "m05", "m06", "m07", "m09", "m11", "m12"], "related_archetypes": ["arch.technical-ciso", "arch.business-risk-ciso", "arch.transformation-cio", "arch.regulated-industry-cio-ciso", "arch.enterprise-cio"], "research_refs": ["res.banker2019", "res.haislip2021", "res.kwon2014", "res.kamiya2021", "res.higgs2016", "res.sec2023", "res.edmondson1996", "res.angst2017", "res.karaevli2007", "res.zhang2010", "res.ibm2025"], "meta": {"source_path": "archetypes/post-breach-ciso.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "arch.regulated-industry-cio-ciso", "name": "Regulated-Industry CIO/CISO", "family": "industry", "one_line": "Technology and security leadership where a regulator sits inside governance — financial services, healthcare, defense — and \"enablement with institutional paranoia\" is not a disposition but the written job description.", "disclaimer": "Archetypes are educational lenses, not personality categories. Real technology executives are usually two or three at once. The Regulated-Industry CIO/CISO is an *industry* lens, and the one lens here that changes the composition of the room: a supervisor, an examiner or a contracting officer has standing to ask questions and impose consequences without buying anything. The person holding it is also a Player, Coach or Architect by scale and a Technical or Business-Risk CISO by style.", "sections": {"definition_and_situation": "**FACT.** Financial services (SEC, FINRA, OCC, state regulators), healthcare (HIPAA and its Security Rule, state privacy law, clinical safety), defense and government contracting, utilities and critical infrastructure. The common feature is not the rulebook. It is that an external party can compel evidence, set a remediation timetable, and end the business relationship.\n\n**FACT.** Since February 2024 the NIST Cybersecurity Framework 2.0 has organized cybersecurity outcomes into six functions — Govern, Identify, Protect, Detect, Respond, Recover — adding **Govern**, which places executive and board accountability alongside the technical functions; it is voluntary and outcome-focused rather than prescriptive (NIST, 2024). **FACT.** Since December 2023, US public companies must disclose material cyber incidents on Form 8-K Item 1.05 within four business days of determining materiality, and describe board oversight and management's cyber expertise annually under Regulation S-K Item 106 (SEC, 2023).\n\n**INTERPRETATION.** The situation produces an executive whose evidence obligations are as real as their control obligations. In this world, a control that works but cannot be demonstrated is worth less than one that works and can.", "dominant_job_requirements": "Operate the controls *and* produce the evidence that they operated. Keep a defensible record of decisions, exceptions and their owners. Absorb examinations without letting the program become the audit. Manage third parties whose failures are attributed to you. And, under a consent order or corrective action plan, deliver on a timetable set by someone else.\n\n**FRAMEWORK.** \"Enablement with institutional paranoia\" — a description, not a diagnosis — is the working posture, and it is the job description rather than a temperament. The Risk Corollary acquires a third clause here: yes, priced, *and documented*.", "likely_useful_traits": "Patience with process. A memory for commitments. The ability to say \"I don't know yet, and here is how we will find out\" to someone with subpoena power. And honesty about which spending buys security and which buys demonstrability.\n\n**RESEARCH FINDING.** In US healthcare, proactive security investment was associated with lower subsequent failure rates and better cost-effectiveness than reactive investment — and external pressure *decreased* the effect of proactive investment on security performance (Kwon & Johnson, 2014; one sector, disclosed breaches, hazard-model associations). **INTERPRETATION.** That last clause is the archetype's central warning from the evidence: regulatory pressure can crowd out the judgment that made proactive investment effective, converting a security program into a compliance program that happens to own firewalls.\n\n**RESEARCH FINDING.** Across 5,000+ US hospitals and 938 breaches (2005–2013), the same investment was associated with fewer breaches only where adoption was substantive rather than symbolic (Angst, Block, D'Arcy & Kelley, 2017). **INTERPRETATION.** Regulation reliably produces adoption; it does not reliably produce the substantive kind.", "dangerous_traits": "- **Rigor → bureaucracy.** The signature failure: a control set optimized for the examination rather than the adversary.\n- **Caution → paralysis.** Nothing ships, and the business builds it somewhere the regulator cannot see either.\n- **Humility → hesitation.** Deferring every judgment to counsel until the technology function has no view of its own.\n- **Persistence → stubbornness.** Defending a legacy platform because re-certifying its replacement would be painful.\n- **Optimism → delusion.** \"We passed the exam\" as a security claim.", "decision_style": "Documented, precedent-aware, slower on purpose. The characteristic decision is a control design plus its evidence design: how the control will be demonstrated, to whom, how often. Exceptions are formal, owned and time-boxed, because an undocumented exception is a finding waiting to be written. **FRAMEWORK.** \"I was wrong. Change the plan\" is harder in a regulated firm because the prior plan is on file — which is why the mature leader files the change too, rather than defending a position they have stopped believing.", "communication_style": "Three audiences, three registers: the board (governance and consequence), the examiner (evidence, dates, ownership), the business (what they may do and under what conditions). **RESEARCH FINDING (practitioner).** The NACD/ISA *Director's Handbook on Cyber-Risk Oversight* frames cyber as an enterprise-risk and governance matter rather than an IT matter (NACD & ISA, 2023; consensus practitioner guidance, not peer-reviewed). **INTERPRETATION.** Boards in regulated firms arrive fluent in oversight language — an opportunity and a trap, because it is easy to have a satisfying governance conversation in which nobody describes what would actually happen.", "relationship_with_management_team": "The general counsel and chief compliance officer are peers with overlapping jurisdiction, and the boundary must be explicit: legal owns the obligation, technology owns the control, and someone must own the risk. **RESEARCH FINDING.** Over 2005–2017, firms with a CIO on the top management team reported fewer data breaches of every type examined (Haislip, Lim & Pinsker, 2021; reported breaches only, associations). **RESEARCH FINDING.** Firms with board technology committees reported more breaches over 2005–2014, plausibly because they detected and disclosed more, and their firms suffered smaller stock-price penalties from external breaches (Higgs, Pinsker, Smith & Young, 2016; endogenous committee formation). **INTERPRETATION.** Structure is a control here in the same sense a firewall is.", "approach_to_risk": "Priced, but with a constraint the other archetypes do not carry: some risks may not be accepted at any price, because acceptance is not the firm's to grant. **FRAMEWORK.** The Gordon–Loeb logic still applies — optimal spend is a function of an information set's value, vulnerability and the productivity of spending, and under the authors' assumed breach-probability functions does not exceed about 37% of expected loss (Gordon & Loeb, 2002; analytical) — but expected loss here includes penalties, remediation orders, examination cycles and licence risk, the largest and least modelled terms. On the overlays, Control ↔ Enablement sits toward control; Prevention ↔ Resilience near center, because recovery objectives are increasingly examined directly.", "approach_to_capital": "Multi-year, with a visible compliance component and a hard question underneath: which of this spend reduces risk, and which produces evidence? Both are legitimate; conflating them makes a program expensive and brittle at once. **RESEARCH FINDING.** After the Target breach, 168 publicly listed US retailers experienced negative abnormal returns, with smaller losses for firms with stronger IT capability, marketing ability and CSR records (Kashmiri, Nicol & Hsu, 2017; single event, one industry). **INTERPRETATION.** A peer's incident is priced against you, and demonstrable capability insulates. In regulated sectors the same dynamic arrives as an examination sweep after a peer's failure.", "approach_to_talent": "Hire for evidence discipline as well as engineering: people who can write a control narrative, sit an examination, and still know how the system works. **RESEARCH FINDING.** Pooled across 95 studies, employees' attitudes, personal norms and normative beliefs were far more strongly associated with policy compliance than punishment or rewards (Cram, D'Arcy & Proudfoot, 2019; largely intention-based surveys). **INTERPRETATION.** The temptation in a regulated firm is to lead with sanction because the rulebook does; the evidence says the levers that work are the ones that make people believe the rule is right.", "common_blind_spots": "- Mistaking a clean examination for a secure environment.\n- Third parties and subcontractors operating under your obligations — the vendor with your regulator's exposure and none of your controls.\n- Legacy systems kept alive because re-certification is expensive.\n- Clinical, trading or operational technology that is regulated for safety and never patched.\n- The near-miss that goes unreported because the reporting channel is also the disciplinary channel. **RESEARCH FINDING.** In eight hospital units, better team climate and more manager coaching were associated with *higher* detected error rates (Edmondson, 1996). **INTERPRETATION.** In a regulated firm the incentive to under-report is structural, not cultural, which makes the leader's protection of the reporting channel a control in its own right.", "common_failure_mode": "The compliance program that ate the security program. Findings are closed, artifacts are current, the examination goes well, and the actual attack path — an unmanaged third party, a flat network behind a certified perimeter, an OT segment nobody owns — was never in scope. The mirror failure is the leader who resents the regulator and slow-walks remediation until a consent order removes their discretion entirely. Early warning signs: the roadmap is organized by control framework rather than risk; the third-party register is a list rather than an assessment; the team can produce evidence faster than an incident timeline.", "where_it_works": "Banks, broker-dealers, insurers and asset managers; hospitals, payers, and the BPM and revenue-cycle firms that process their data; defense and government suppliers; utilities and industrial operators; and the MSPs and outsourcers who inherit these obligations by contract without inheriting the budget.", "where_it_fails": "In a fast product company where the same posture is overhead. Under a mandate requiring speed the evidence regime cannot match. And whenever the regulator becomes the strategy: a program that justifies itself only by pointing at a rule has stopped making judgments, and **RESEARCH FINDING** the healthcare evidence suggests external pressure weakens exactly the proactive investment that worked (Kwon & Johnson, 2014).", "typical_dial_settings": "**FRAMEWORK.** Defaults: caution (+2), inquiry (+1), skepticism (+2), delegation (+1), patience (+1), consensus (+1), operational discipline (+2), centralization (−1). This is the library's most uniformly rightward profile, and it is the environment's, not the person's: consequences are asymmetric, so caution and discipline dominate. Patience at +1 is the multi-year remediation horizon. Centralization at −1 is the exception — policy, evidence and identity are pulled to the center even though delivery is federated, because the firm must speak with one voice to an examiner. The setting most likely to be wrong is caution at +2, which quietly becomes paralysis. A learner near this profile should name the last thing they enabled that a strict reading of policy would have blocked, and what they did to make it defensible.", "adjacent_archetypes": "Under pressure it becomes a compliance function with a security title, or — after a finding — the Post-Breach CISO, with the remediation timetable set externally. It should grow toward the Business-Risk CISO's pricing discipline without losing the evidence discipline: a leader who can tell a board what the firm would lose, what the regulator would do, and which is driving the recommendation. In an SMB or MSP it compresses into the Player carrying other companies' regulatory obligations — the hardest version of this archetype in the library.", "research_anchors": "- Kwon & Johnson (2014): proactive investment associated with lower failure rates; external pressure weakened its effect.\n- Kashmiri, Nicol & Hsu (2017): 168 US retailers lost value after the Target breach, less so where IT, marketing and CSR capability were stronger.\n- NIST (2024, FACT): CSF 2.0's six functions, with Govern added as co-equal.\n- SEC (2023, FACT): 8-K Item 1.05 four-business-day disclosure; annual Item 106 disclosure.\n- Angst et al. (2017): regulation produces adoption, not necessarily the substantive kind.\n- Higgs et al. (2016); Haislip et al. (2021): board and top-team structure associated with reporting and breach outcomes.", "vignette": "*Fictional composite.* Charter Hill Business Services is a 240-person BPM firm in Hartford, Connecticut, providing finance, compliance-operations and IT services to 30 SMB and mid-market clients: three FINRA-registered broker-dealers, a 90-provider physician group, a community bank, and a dozen professional-services firms. Nadia Okonkwo is VP of technology and risk — CIO, CISO and de facto compliance lead, with a team of nine.\n\nShe holds business associate agreements for the physician group, books and records obligations she must support for the broker-dealers, and a bank client currently operating under a corrective action plan whose examiners have begun asking about its service providers by name. Charter Hill's own security program is decent: MFA everywhere, tested restores, a real third-party register.\n\nThis quarter, three things collided. A broker-dealer's examination requested evidence of supervisory review of communications Charter Hill archives on its behalf, going back three years; retention had been configured for two. The physician group asked to pilot an AI scribe that would move PHI to a vendor with no signed BAA. And Charter Hill's founder wants \"regulated-industry security\" on the website by the spring conference.\n\nNadia can produce evidence for most of it. The archetype's question is which of these she will say no to, in writing, with the condition that would change her answer — and whether the founder understands that saying yes to all three is itself a regulatory position."}, "overuse_rungs": ["optimism->delusion", "persistence->stubbornness", "humility->hesitation", "rigor->bureaucracy"], "dial_defaults": {"aggression_caution": 2, "decisiveness_inquiry": 1, "optimism_skepticism": 2, "hands_on_delegation": 1, "urgency_patience": 1, "unilateral_consensus": 1, "innovation_operational_discipline": 2, "centralization_decentralization": -1}, "related_modules": ["m03", "m05", "m06", "m07", "m09", "m10", "m12"], "related_archetypes": ["arch.business-risk-ciso", "arch.technical-ciso", "arch.post-breach-ciso", "arch.enterprise-cio", "arch.smb-msp-technology-leader"], "research_refs": ["res.kwon2014", "res.kashmiri2017", "res.nist2024", "res.sec2023", "res.angst2017", "res.higgs2016", "res.gordon2002", "res.cram2019", "res.nacd2023", "res.haislip2021", "res.edmondson1996"], "meta": {"source_path": "archetypes/regulated-industry-cio-ciso.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "arch.smb-msp-technology-leader", "name": "SMB / MSP Technology Leader", "family": "scale", "one_line": "The one-person CIO and CISO of a small company or the MSP that serves fifty of them — hands on a vendor-managed stack, no peer to check the work, and a dominant danger of doing too little rather than too much.", "disclaimer": "Archetypes are educational lenses, not personality categories. Real technology executives are usually two or three at once. The SMB / MSP Technology Leader is a *scale* lens — the Player position in Player → Coach → Architect — and it describes a job, not a person: whoever holds it may be a Technical CISO by style and a Business-Risk CISO in that afternoon's client meeting. Most technology executives hold this job; almost no research is written about it.", "sections": {"definition_and_situation": "**FACT.** In companies below a few hundred people, technology and security are usually one job held by one person, a fractional person, or a managed service provider. The stack is vendor-managed: identity, email, endpoint and backup are subscriptions run by someone else's engineers. In a BPM or MSP firm, the same leader also carries the clients' risk — the CISO-by-default of dozens of companies that never hired one.\n\n**RESEARCH FINDING (practitioner data).** The situation is measured only descriptively. In the 2026 IANS/Artico survey of 600+ security leaders, 52% of CISOs at companies under $100M in revenue held executive-level titles, and 52% of all respondents said their responsibilities were \"not manageable given current resources\" (IANS Research & Artico Search, 2026; self-selected, not peer-reviewed). In the 2025 Verizon DBIR sample of 12,195 breaches, ransomware was present in 88% of SMB breaches and third-party involvement had doubled to 30% (Verizon, 2025; convenience sample, base rates only).\n\n**INTERPRETATION.** Three things produce the archetype. There is no second opinion: no peer, no deputy, no risk committee. Feedback is nearly silent — a quiet year looks identical whether the controls worked or nobody attacked. And the owner's IT literacy sets the ceiling, which interview-based CIO research describes as the role's general condition (Peppard, 2010) and which is simply truer here.", "dominant_job_requirements": "Get the basics in place substantively, not symbolically: multi-factor authentication without an exceptions list, backups that have actually been restored, patching that happens, logs that go somewhere. Price risk for an owner who thinks in payroll cycles. Manufacture the second opinion the organization does not provide — a peer group, an outside assessment, a fractional CISO. Manage vendors as the team you do not have.\n\n**FRAMEWORK.** In the extended Fit Equation, this archetype's *Reporting Line* term is the owner's attention span. The Risk Corollary is the daily instrument: \"Yes, keep the exception — and here is what it costs us if it is used against us.\" / \"No — and here is the control that would change my answer.\"", "likely_useful_traits": "Agency, breadth, tolerance for ambiguity, and a plain way of talking to people who do not want a technical explanation. Skepticism toward vendor claims — every product in the stack was sold to this person by someone. Enough calm to run an incident alone at 2 a.m., and enough humility to know that being alone is the problem.\n\n**RESEARCH FINDING.** Across 5,000+ US hospitals and 938 breaches from 2005 to 2013, the same security investments were associated with fewer breaches only where adoption was substantive rather than symbolic; symbolic adopters tended to be smaller, older, for-profit organizations in smaller systems (Angst, Block, D'Arcy & Kelley, 2017). **INTERPRETATION.** One sector, with adoption depth inferred from institutional profile — but the pattern describes the SMB stack precisely: a tool bought is not a control installed.", "dangerous_traits": "- **Humility → hesitation.** The dominant danger. \"We should\" for eighteen months; \"we did\" never.\n- **Delegation → abdication** (the extension rung). \"The MSP handles it\" — the vendor-managed stack becomes nobody's outcome. In an MSP, the mirror image: \"the client declined it.\"\n- **Confidence → arrogance.** Nobody is checking, so the year-one architecture is never re-examined.\n- **Detail → micromanagement.** The Player *is* the stack; every ticket comes to them and the strategic work never starts.\n\n**RESEARCH FINDING.** Five UK CISOs interviewed in depth described low perceived power, unclear role identity and weak employee engagement as their main obstacles (Ashenden & Sasse, 2013; illustrative, not generalizable). **INTERPRETATION.** At SMB scale the role is three roles, and the leader's only authority is the owner's borrowed authority.", "decision_style": "Fast, singular, and unreviewed. Most decisions are technical acts taken in the console; the important ones — which vendor, which exceptions, which client to fire — look small at the time. The mature Player builds a place where decisions get a second look: a one-page risk register the owner has signed, a quarterly outside review, a peer asked \"what would you do?\" before the purchase. **FRAMEWORK.** The Two-Sentence Test is easy in its first half here and hard in its second, because \"I was wrong\" has no one to hear it.", "communication_style": "Translation, constantly: to the owner in dollars and downtime, to the vendor in tickets, to clients in what they will pay for. The trap is speaking the vendor's vocabulary to people who tune it out. **RESEARCH FINDING.** Pooled across 95 studies, employees' values and norms were far more strongly associated with security-policy compliance than sanctions or rewards were (Cram, D'Arcy & Proudfoot, 2019; largely intention-based surveys). **INTERPRETATION.** In a 40-person company, security culture is the leader's own credibility, built in the kitchen rather than the policy.", "relationship_with_management_team": "There is no management team. There is an owner, an operations lead, a bookkeeper who runs payroll, and three vendors. In an MSP, add account managers with quotas and fifty client owners with exceptions. **INTERPRETATION.** Since CIO effectiveness is bounded by the top team's IT literacy (Peppard, 2010), the Player's most important relationship is educational: raising the owner's literacy one decision at a time until the owner can be the second opinion.", "approach_to_risk": "Enablement with institutional paranoia at its smallest scale — a description, not a diagnosis. **FRAMEWORK.** The Gordon–Loeb model treats security spend as a function of an information set's value, vulnerability and the productivity of spending; under the breach-probability functions the authors assume, optimal investment does not exceed 37% of expected loss (Gordon & Loeb, 2002; an analytical model whose assumptions must be stated). Nobody at this scale can measure expected loss. The reasoning still helps: a rough number for \"what a bad week costs us,\" and the habit of asking what each control buys against it, is more than most SMBs have. **RESEARCH FINDING.** In US healthcare, investment before a failure was associated with lower failure rates and better cost-effectiveness than investment after one (Kwon & Johnson, 2014; one sector).", "approach_to_capital": "There is almost none; there is opex. Subscriptions, a renewal calendar, and the cyber-insurance application — which has quietly become the SMB's most effective security regulator, because the underwriter asks about MFA and backups and the owner wants the policy. The disciplined Player uses the insurer's questions as leverage and the renewal as a deadline.", "approach_to_talent": "The talent decision is the second person: an engineer, an MSSP, or a fractional CISO. **RESEARCH FINDING.** In a survey of more than 1,000 CEOs and CFOs, executives delegated more when overloaded and less when long-tenured (Graham, Harvey & Puri, 2015, from the CEO library; self-reported). **INTERPRETATION.** Overload arrives before the willingness to delegate; the first hire is typically two years late and made during an incident. Bandiera, Prat, Hansen & Sadun (2020, from the CEO library) treated \"manager\" versus \"leader\" behavior as a matching question, not a ranking; here the manager type fits, until it does not.", "common_blind_spots": "- The thing no one has checked: the restore never run; the admin account the departed engineer still holds.\n- The owner's own exception, and the reluctance to price it.\n- The MSP's privileged access as the largest single concentration in the environment.\n- Mistaking a quiet year for a secure one. **RESEARCH FINDING.** In eight hospital units, better team climate was associated with *more* reported errors, not fewer (Edmondson, 1996). **INTERPRETATION.** Zero reported phishing clicks where nobody would admit one is a number about silence.", "common_failure_mode": "Insufficient action discovered by a Friday ransomware event: a long list of known gaps, each individually deferrable; an owner never given a priced choice; a stack that was \"managed\" but not owned; an incident in which the leader is the only person who knows how anything works. Early warning signs: no restore test in twelve months; an MFA exceptions list longer than three names; no outsider has looked at the environment in two years; the leader cannot name the top three risks with a dollar figure beside each.", "where_it_works": "Companies under roughly $50M in revenue, MSP and BPM firms whose product is other companies' operations, fractional and vCISO engagements, and early-stage companies where the cost of not acting exceeds the cost of a wrong action — wherever one competent person, honest about what they cannot see, beats a committee that does not exist.", "where_it_fails": "When the company crosses into the mid-market and needs a Coach who builds a team rather than a Player who is the team. When the client base becomes regulated and the leader is asked to be a CISO in an exam without the standing or the evidence. When hands-on competence has become the reason nothing scales.", "typical_dial_settings": "**FRAMEWORK.** Defaults: aggression (−1), decisiveness (−1), skepticism (+1), hands-on (−3), urgency (−2), unilateral (−1), operational discipline (+1), centralization (−2). The leftward lean on aggression, decisiveness and urgency is a correction: the dominant danger is doing too little. Hands-on at −3 is the only extreme, and it is the situation's setting rather than the person's — there is no one to delegate to. Skepticism at +1 is aimed at vendors and at the leader's own quiet year. Centralization at −2 reflects that everything runs through one person, the condition the leader should be working to end. On the overlays, Prevention ↔ Resilience leans toward resilience: recovery objectives matter more than the perimeter.", "adjacent_archetypes": "Under pressure this archetype becomes the permanently hands-on engineer — the trap Module 8 names — or, in an MSP, drifts toward a Business-Risk CISO who prices risk for clients without the controls to back the price. It should grow into the Mid-Market CIO when the company grows, or, in an MSP, into a Business-Risk CISO with a Technical CISO's discipline underneath: able to put a number on a client's exposure and also verify the backup ran.", "research_anchors": "- IANS Research & Artico Search (2026; Tier 3): 52% of sub-$100M CISOs hold executive titles; 52% say the role is not manageable.\n- Verizon (2025; Tier 3): ransomware in 88% of SMB breaches; third-party involvement 30%.\n- Angst et al. (2017): substantive, not symbolic, adoption associated with fewer breaches.\n- Gordon & Loeb (2002): spend as a function of expected loss; the 37% bound under stated assumptions.\n- Cram, D'Arcy & Proudfoot (2019): values and norms outweigh sanctions in policy compliance.\n- Edmondson (1996): low reported-error counts can signal silence rather than safety.", "vignette": "*Fictional composite.* Priya Natarajan is director of technology — the only technology title — at Harborline Business Services, a 62-person BPM/MSP firm in Providence, Rhode Island, running back-office operations and IT for 44 clients: dental groups, two small broker-dealers, a dozen law and accounting firms, a regional retailer. Harborline's own stack is three vendors and a helpdesk of four. Priya holds domain admin for 38 client environments.\n\nThis month: a broker-dealer owner wants his MFA exception kept because the prompt \"slows down trading\"; the retailer's backup job has reported success for nine months and never been restored; Harborline's founder wants a \"security services\" one-pager for sales by Friday; the cyber-insurance renewal asks whether privileged access is reviewed quarterly. Nobody at Harborline can check her answers.\n\nShe has a list. She has had it for a year. Everything on this page is on it. The question is not whether Priya is competent. It is whether her hands-on dial at −3 is why the list never gets shorter, and who she will ask to read it."}, "overuse_rungs": ["confidence->arrogance", "detail->micromanagement", "humility->hesitation"], "dial_defaults": {"aggression_caution": -1, "decisiveness_inquiry": -1, "optimism_skepticism": 1, "hands_on_delegation": -3, "urgency_patience": -2, "unilateral_consensus": -1, "innovation_operational_discipline": 1, "centralization_decentralization": -2}, "related_modules": ["m01", "m02", "m03", "m05", "m06", "m08", "m09"], "related_archetypes": ["arch.mid-market-cio", "arch.business-risk-ciso", "arch.technical-ciso", "arch.regulated-industry-cio-ciso", "arch.post-breach-ciso"], "research_refs": ["res.verizon2025", "res.ians2026", "res.gordon2002", "res.angst2017", "res.ashenden2013", "res.cram2019", "res.edmondson1996", "res.peppard2010", "res.kwon2014", "res.bandiera2020", "res.graham2015"], "meta": {"source_path": "archetypes/smb-msp-technology-leader.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "arch.technical-ciso", "name": "Technical CISO", "family": "style", "one_line": "Engineer-first and deep in the control plane — credible with the people who build the systems, and dangerous when rigor hardens into bureaucracy and \"no\" becomes an identity rather than a priced answer.", "disclaimer": "Archetypes are educational lenses, not personality categories. Real technology executives are usually two or three at once. The Technical CISO is a *style* lens — how a security leader thinks and where their authority comes from, not what size company they work in. Its opposite number here is the Business-Risk CISO, and most strong security leaders are a blend of the two.", "sections": {"definition_and_situation": "**FACT.** The Technical CISO came up through engineering — networks, systems, detection, application security — and still reads architecture diagrams for pleasure. Their authority is earned rather than granted: engineers do what they say because they believe the CISO could do it. Companies produce this archetype by promoting from inside the security team, when the product *is* technology, or when a technical CEO will not respect anyone who cannot argue the mechanism.\n\n**RESEARCH FINDING.** A systematic literature review found \"little emphasis on understanding the role of the CISO as a strategist\" and proposed a competency set for the CISO-as-strategist rather than the technical specialist (Maynard, Onibere & Ahmad, 2018; conceptual, no outcome test). **INTERPRETATION.** The literature's framing is the archetype's whole tension: the technical depth that makes the CISO credible is not the capability the role is judged on above a certain scale.", "dominant_job_requirements": "Know how the environment actually works, not how the diagram says it does. Build detection and response that function at 3 a.m. without the CISO. Set standards engineers respect because they are technically correct. Say no to the thing that is genuinely unsafe — and yes, with a price, to the rest. Translate for a board that will not follow the mechanism.\n\n**FRAMEWORK.** The Risk Corollary is where this archetype is tested. \"No — and here is what would change my answer\" is what separates a Technical CISO from a veto; a \"no\" with no stated condition is a preference wearing a control's uniform.", "likely_useful_traits": "Depth, precision, and a strong internal model of how systems fail. Skepticism toward vendor claims and toward one's own controls. Willingness to test in production reality — restores actually run, detections actually fired, the red team actually got in. Steadiness during an incident, which is largely technical: the calm comes from knowing what the log means.\n\n**RESEARCH FINDING.** In US healthcare, security investment made before a failure was associated with lower subsequent failure rates and better cost-effectiveness than investment made after one (Kwon & Johnson, 2014; one sector, hazard-model associations); across 5,000+ hospitals and 938 breaches, the same investment was associated with fewer breaches only where adoption was substantive rather than symbolic (Angst, Block, D'Arcy & Kelley, 2017). **INTERPRETATION.** Building before the incident, and integrating rather than purchasing, are the archetype's strongest evidence-backed assets.", "dangerous_traits": "- **Rigor → bureaucracy.** The signature failure: the security review that ships nothing, the exception process with a four-week queue, the standard that assumes engineering capacity the company does not have.\n- **Detail → micromanagement.** Reading every alert personally; a program that degrades whenever the CISO sleeps.\n- **Skepticism → cynicism.** Every business request heard as an attempt to get around a control.\n- **Confidence → arrogance.** Certainty that the control the CISO designed is the control that is running.\n- **Persistence → stubbornness.** Defending a three-year-old architecture decision against current evidence.\n\n**RESEARCH FINDING.** Five UK CISOs interviewed in depth described low perceived power, confusion about role identity, and an inability to engage employees as the main obstacles to their credibility; the authors argue CISOs must remove the blockages that keep security a specialist function (Ashenden & Sasse, 2013; five interviews, illustrative). **INTERPRETATION.** This archetype's defense against low perceived power is technical authority, which works with engineers and fails in the room where the budget is set — until depth becomes the reason the CISO is not invited.", "decision_style": "Evidence-first, mechanism-level, reluctant to decide before the data is in. The characteristic decision is a standard or an architectural constraint, argued on the merits. In an incident this archetype is at its best: decisive, calm, working from the telemetry. In a budget cycle it is at its weakest, because the argument that persuades an engineer prices nothing. **FRAMEWORK.** The Two-Sentence Test is easy here in its second half and hard in its first: \"I was wrong\" comes naturally to people trained on failing tests; \"We're going to do this\" is harder when the evidence is never quite complete.", "communication_style": "Precise, concrete, occasionally too precise. The habit that builds trust downward — never overstating what is known — reads upward as hedging. **RESEARCH FINDING.** Pooled across 95 studies, employees' attitudes, personal norms and normative beliefs were far more strongly associated with policy compliance than punishment or rewards (Cram, D'Arcy & Proudfoot, 2019; largely intention-based surveys). **INTERPRETATION.** This archetype reaches for the levers the meta-analysis ranks weakest — controls, sanctions, mandatory training — because they are the ones it can build.", "relationship_with_management_team": "Strongest with engineering and infrastructure leaders; weakest with sales, finance and the general counsel. **RESEARCH FINDING.** A practitioner-facing companion to work on CIO authority crosses decision authority with leadership capability into four profiles — IT Orchestrator, IT Advisor, IT Mechanic, IT Laggard — reporting that IT's contribution to performance varies with the profile (Preston, Leidner & Chen, 2008). **INTERPRETATION.** This archetype risks the \"Advisor\" position — capability the organization has not granted authority to — and the remedy is not more depth. It is one peer relationship outside technology, built before it is needed.", "approach_to_risk": "Prevention-leaning, control-centric, often more risk-averse than the company's economics justify. **FRAMEWORK.** The Gordon–Loeb model treats optimal security spending as a function of an information set's value, vulnerability and the productivity of spending; under the breach-probability functions the authors assume, optimal investment does not exceed about 37% of expected loss, and it can be rational to spend less on the *most* vulnerable assets (Gordon & Loeb, 2002; analytical model, bound holds only under its assumptions). **INTERPRETATION.** This is the model the archetype most needs and least likes, because it says some exposure should be left standing. On the overlays, Control ↔ Enablement sits well toward control and Prevention ↔ Resilience toward prevention; the calibration question is whether recovery objectives have been tested as rigorously as the perimeter.", "approach_to_capital": "Bottom-up and defensible: a roadmap of controls, each technically justified, priced by license and headcount. The weakness is the top-down question — what does the whole program buy, and what would we accept losing? — which needs a loss estimate this archetype refuses to make because it would be a guess. **INTERPRETATION.** It would be. Making it anyway, with assumptions stated, is the difference between a budget conversation and a request.", "approach_to_talent": "Hires for depth and mentors well; engineers stay for this CISO. The failure is a team shaped like the leader — strong detection engineers, nobody who can sit in a client meeting or write a control narrative for an auditor. **RESEARCH FINDING (practitioner).** In a 2026 survey of 600+ security leaders, 52% said their responsibilities were not manageable given current resources (IANS Research & Artico Search, 2026; self-selected). **INTERPRETATION.** Depth does not scale by working harder, and the hire that fixes it is the one this archetype postpones: a deputy better with people than with packets.", "common_blind_spots": "- The business case for the thing they blocked, which may have been worth the risk.\n- The exception queue — a business impact the CISO is causing and not measuring.\n- Third parties, where the 2025 DBIR sample of 12,195 breaches put third-party involvement at 30% (Verizon, 2025; convenience sample, base rates only).\n- Their own alert volume, mistaken for coverage.\n- The engineer who stopped reporting near-misses after the last root-cause meeting felt like a trial.\n\n**RESEARCH FINDING.** In eight hospital units, stronger team climate and more manager coaching were associated with *higher* detected error rates (Edmondson, 1996; correlational), and in a 40-person interview study 85% recalled withholding an important issue from a superior (Milliken, Morrison & Hewlin, 2003, from the CEO library; exploratory). **INTERPRETATION.** A Technical CISO's incident numbers measure reporting climate before they measure security.", "common_failure_mode": "\"No\" as identity. The program becomes a gate; the business routes around it; shadow systems appear; the CISO learns about the AI tool from the vendor invoice. The quieter form is a technically excellent program the CEO cannot describe and therefore will not fund properly. **RESEARCH FINDING.** CIO departures were about 72% more likely after breaches attributed to system deficiencies, but not after fraud or human error (Banker & Feng, 2019; archival). **INTERPRETATION.** Accountability tracks the perceived scope of the executive's duties, and this archetype's duties are perceived as the system — an argument for depth, and for making sure someone senior understands what the depth buys. Early warning signs: the exception backlog is growing; business units have their own tooling budget; no risk acceptance approved this quarter; the board deck has more controls than consequences.", "where_it_works": "Product and platform companies where security is an engineering problem; regulated firms that must demonstrate substantive control operation; post-breach environments in the first eighteen months; and as the second half of a pairing with a business-fluent CIO.", "where_it_fails": "In a sales-led company where the job is mostly negotiation. In an MSP where the same rigor applied to forty client environments produces a queue instead of a program. And in the CISO's own promotion, when the job stops being about controls and starts being about pricing, and the dials have not moved.", "typical_dial_settings": "**FRAMEWORK.** Defaults: caution (+2), inquiry (+1), skepticism (+3), hands-on (−2), urgency (0), unilateral (−1), operational discipline (+2), centralization (−2). Skepticism at +3 is the archetype's defining setting — professional doubt as a working method, useful until it becomes a personality. Caution and operational discipline at +2 describe a leader who would rather ship late than ship exposed. Hands-on and centralization at −2 are the settings that must move first as scale grows; unilateral at −1 reflects that control decisions are made, not negotiated. Urgency sits at 0: patient about programs, fast in incidents. A learner near this profile should ask what they said yes to last month, and what it cost them.", "adjacent_archetypes": "Under pressure it becomes a gatekeeper — the security review that ships nothing — or retreats into the console and stops attending the meetings where risk is actually accepted. It should grow toward the Business-Risk CISO without discarding the depth: able to state a loss estimate with its assumptions and to let the business own an exposure. In a crisis it converges with the Post-Breach CISO, which is why it is often hired into one.", "research_anchors": "- Maynard, Onibere & Ahmad (2018): the CISO-as-strategist is under-theorized; a competency framework, not an outcome finding.\n- Ashenden & Sasse (2013): CISOs described low perceived power, unclear role identity and weak employee engagement as their obstacles (five interviews).\n- Cram, D'Arcy & Proudfoot (2019): values and norms outweigh sanctions in policy compliance (95 studies).\n- Gordon & Loeb (2002): optimal spend as a function of expected loss; the ~37% bound under stated assumptions.\n- Banker & Feng (2019): CIO turnover about 72% more likely after system-deficiency breaches.", "vignette": "*Fictional composite.* Kestrel Operations Group is a 310-person BPM/MSP in Nashua, New Hampshire, running finance and back-office operations for 60 SMB and mid-market clients across New England — two community banks, a dental services organization, a dozen professional-services firms. Tomás Berger is its first dedicated CISO, hired eighteen months ago from a detection-engineering lead role at a payments company.\n\nHe is unambiguously good. He rebuilt logging across every client tenant, found a shared administrator credential that had survived two acquisitions, and runs a quarterly restore test that actually restores. The engineers trust him completely.\n\nHe has also blocked the sales team's client-facing AI intake pilot three times: no data-flow documentation, no retention answer, a vendor that would not complete the security questionnaire. He is right on every point. The exception queue stands at 34 items, median age six weeks. Two clients have asked whether Kestrel is \"hard to work with,\" and the founder — who reads the pipeline weekly and the risk register never — has begun routing product questions around him.\n\nNothing Tomás has said is wrong. The archetype's question is whether he has said the other half of the sentence: not \"no,\" but \"no — and here is what would change my answer,\" with a number beside it."}, "overuse_rungs": ["confidence->arrogance", "persistence->stubbornness", "detail->micromanagement", "rigor->bureaucracy"], "dial_defaults": {"aggression_caution": 2, "decisiveness_inquiry": 1, "optimism_skepticism": 3, "hands_on_delegation": -2, "urgency_patience": 0, "unilateral_consensus": -1, "innovation_operational_discipline": 2, "centralization_decentralization": -2}, "related_modules": ["m01", "m02", "m03", "m05", "m06", "m07", "m08"], "related_archetypes": ["arch.business-risk-ciso", "arch.post-breach-ciso", "arch.smb-msp-technology-leader", "arch.regulated-industry-cio-ciso", "arch.enterprise-cio"], "research_refs": ["res.ashenden2013", "res.maynard2018", "res.cram2019", "res.gordon2002", "res.angst2017", "res.edmondson1996", "res.kwon2014", "res.banker2019", "res.ians2026", "res.verizon2025", "res.milliken2003", "res.preston2008"], "meta": {"source_path": "archetypes/technical-ciso.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "arch.transformation-cio", "name": "Transformation CIO", "family": "ownership-situation", "one_line": "Hired to change how the company works rather than to run what it has — unusually high discretion, unusually short tenure, and a signature danger of change without end, announced faster than the organization can absorb it.", "disclaimer": "Archetypes are educational lenses, not personality categories. Real technology executives are usually two or three at once. The Transformation CIO is an *ownership-situation* lens — a mandate, not a temperament, and temporary by design. The person holding it is usually also an Enterprise or Mid-Market CIO by scale; what makes the archetype distinct is that someone with the power to do so has decided the current operating model is the problem, and has said so out loud.", "sections": {"definition_and_situation": "**FACT.** A transformation mandate is issued by a board, a private-equity sponsor, a new CEO or a merger. It names an operating-model change — ERP consolidation, cloud migration, shared services, post-merger integration — funds it above the normal capital line, and attaches a horizon of eighteen to thirty-six months. The CIO who takes it is often an outsider, hired because insiders were judged unlikely to break what they built.\n\n**RESEARCH FINDING.** An event study found markets reacted positively to announcements of newly created CIO positions at firms \"competing in industries undergoing IT-driven transformation\" (Chatterjee, Richardson & Zmud, 2001; pre-2001 data; market reaction measures belief, not realized value). **INTERPRETATION.** The situation produces an executive with borrowed conviction: discretion that is real but granted, priced in expectations, and repossessed the quarter the sponsor's attention moves.", "dominant_job_requirements": "Name the target operating model in language the business can repeat. Sequence it so something works in the first six months. Defend the funding through a budget cycle in which no benefits have arrived. Rebuild decision rights, because the operating model *is* the decision rights. Keep the lights on while changing the wiring. And decide, in writing, what will *not* change.\n\n**RESEARCH FINDING (practitioner).** In an MIT CISR study of about 250 enterprises, firms with superior IT governance — decision rights and accountabilities for IT decisions — reported more than 25% higher profits than poorly governed firms with the same objectives (Weill & Ross, 2004; descriptive, not causal). **INTERPRETATION.** Transformations are sold as technology and delivered as governance; the platform is the visible artifact of a decision-rights change nobody put on a slide.", "likely_useful_traits": "Tolerance for being disliked. Narrative discipline — the same three sentences for two years. The ability to hold a target state loosely enough to re-sequence and firmly enough that people stop waiting it out. And the skill to convert a sponsor's mandate into business-unit ownership before the sponsor leaves.\n\n**RESEARCH FINDING.** Karaevli's 30-year study of two US industries found no general performance advantage for outsider CEOs; outsiders helped mainly where prior performance was poor or the environment turbulent, and the effect depended on what changed alongside the succession (Karaevli, 2007, from the CEO library; archival, two industries). **INTERPRETATION.** Read across to the CIO, this says the outsider transformation leader is not better — the outsider is better *matched* to a situation that is already broken. In a healthy company, the same person is an irritant.", "dangerous_traits": "- **Adaptability → strategy-of-the-month.** The signature failure. Every sponsor conversation produces a re-sequenced roadmap; the organization learns that waiting is a strategy.\n- **Vision → fantasy.** A target-state architecture nobody has costed, defended for three years against evidence.\n- **Urgency → recklessness.** Cutting the run budget to fund the change until an outage reveals what the run budget was doing.\n- **Confidence → arrogance.** Treating incumbents' objections as incumbency rather than information.\n- **Rigor → bureaucracy.** The transformation office that outlives the transformation.\n\n**RESEARCH FINDING.** Among 193 US CEOs, strategic change showed an inverted-U relationship with performance — moderate change helped, excessive change hurt — and outsiders saw both larger gains from moderate change and larger losses from excessive change, with the pattern driven by later tenure years (Zhang & Rajagopalan, 2010, from the CEO library; archival, change proxied by resource allocation). **INTERPRETATION.** The clearest empirical warning available to this archetype: the danger is not change, it is the second and third wave, launched after the first worked.", "decision_style": "Fast, sequenced, visibly irreversible. The characteristic decision is a commitment device — decommissioning the old platform, moving the budget, publishing a date — chosen because it removes the option to drift back, and paired, in the mature version, with a stated stopping condition. **FRAMEWORK.** The Two-Sentence Test is asymmetric here: \"We're going to do this\" is the job description, and \"I was wrong, change the plan\" is expensive, because the mandate was granted on the strength of the first. A Transformation CIO who has never said the second has been lucky or has stopped listening.", "communication_style": "Repetition over novelty: the same target state, the same three metrics, the same proof point, in three vocabularies. **RESEARCH FINDING.** Interview-based research argues CIO performance is bounded by the IT savviness of the CEO and leadership team (Peppard, 2010; qualitative). **INTERPRETATION.** Transformation is the one situation where a CIO can raise that savviness quickly, because the business is paying attention; the mistake is spending it on architecture diagrams.", "relationship_with_management_team": "Two relationships decide the outcome: the sponsor, and the business-unit leaders who must own the model after the program office closes. **RESEARCH FINDING.** In 81 US hospitals, the quality of the CIO–top-team relationship was associated with IS alignment and, through it, with financial performance (Karahanna & Preston, 2013; one sector, perceptual measures); pooled across the literature, every dimension of alignment was positively associated with performance and the \"alignment paradox\" largely disappeared (Gerow, Grover, Thatcher & Roth, 2014; meta-analysis of correlational studies). **INTERPRETATION.** The characteristic error is treating the sponsor relationship as sufficient. Sponsors change; the business-unit president who never agreed to the shared service will still be there in year three, and the model will quietly revert.", "approach_to_risk": "Elevated on purpose, and usually under-priced. Migrations concentrate risk: privileged access is broadest, change volume highest, and the security team most likely to be told to accept an exception \"for the cutover.\" **RESEARCH FINDING.** Across 5,000+ US hospitals and 938 breaches (2005–2013), the same security investment was associated with fewer breaches only where adoption was substantive rather than symbolic (Angst, Block, D'Arcy & Kelley, 2017). **INTERPRETATION.** Transformation is the library's richest source of symbolic adoption — controls bought with the program and integrated by nobody. The Risk Corollary is the discipline: \"Yes, we cut over on the 14th — and here is the risk, priced, with the compensating control and its expiry date.\" On the overlays, Control ↔ Enablement sits hard toward enablement, which is why Prevention ↔ Resilience must move toward resilience.", "approach_to_capital": "A large, time-boxed, politically visible number. The discipline is three protections: a run budget that is not raided, a benefits owner in the business for every workstream, and a stopping rule written before the money is spent. **RESEARCH FINDING.** In a large-firm archival study, CIO-to-CEO reporting was associated with better performance in differentiation-strategy firms and CIO-to-CFO in cost-leadership firms (Banker, Hu, Pavlou & Luftman, 2011; data predates the cloud era). **INTERPRETATION.** These mandates arrive with a temporary reporting line to the CEO or sponsor; negotiate where the role lands afterward, because the answer decides whether the model survives.", "approach_to_talent": "Bring three or four people who have done it, promote a visible insider early so the change is not purely imported, and be honest that some incumbents are being asked to do a job they did not apply for. **INTERPRETATION.** The signature error is a leadership team assembled for the program rather than for the company that follows it.", "common_blind_spots": "- The run estate, starved quietly to fund the change.\n- The security exceptions granted \"for the migration,\" none of which expire.\n- The business unit that publicly agreed and privately kept its own system.\n- The organization's absorption limit — a real constraint, never in the plan.", "common_failure_mode": "Strategy-of-the-month, ending in program fatigue: the roadmap changes three times, the six-month proof point never lands, the sponsor departs, and the next CIO is hired to \"simplify.\" **RESEARCH FINDING.** CEO conscientiousness appears to cut both ways — dampening the initiation of strategic change while improving the performance of changes actually implemented (Herrmann & Nadkarni, 2014, from the CEO library; 120 SMEs, correlational). **INTERPRETATION.** The trait that starts transformations is not the trait that finishes them. Early warning signs: the target-state deck rewritten twice this year; no workstream stopped; the run budget down two years running; nothing off the exception register; \"once transformation is done\" in general use.", "where_it_works": "Post-merger integrations; PE-backed platforms in the value-creation window; companies whose operating model no longer fits the market; regulated firms rebuilding under a remediation order — the conditions of poor prior performance and turbulence under which outsiderness was associated with gains rather than losses (Karaevli, 2007, from the CEO library).", "where_it_fails": "In a healthy company that needed operational excellence and got a program. Where the sponsor cannot hold the mandate two budget cycles. And in the CIO's third year, when the situation has changed and the person has not. **RESEARCH FINDING.** Managerial discretion arises from the environment, the organization and the individual (Hambrick & Finkelstein, 1987, from the CEO library; conceptual), and long tenures carry a risk of paradigm commitment and declining environmental fit (Hambrick & Fukutomi, 1991; Miller, 1991, from the CEO library). **INTERPRETATION.** Transformation discretion is unusually wide and unusually short-lived; the archetype fails when the CIO spends year three exercising authority the situation has withdrawn.", "typical_dial_settings": "**FRAMEWORK.** Defaults: aggression (−2), decisiveness (−1), optimism (−1), delegation (+1), urgency (−2), unilateral (−1), innovation (−2), centralization (−1). The leftward profile belongs to the mandate, not the person: a transformation is bought precisely because the organization's own settings are too cautious, too patient and too consensual to change itself. Innovation at −2 and centralization at −1 encode the operating-model bet — new ways of working, pulled toward a center that can enforce them. Delegation at +1 rather than lower is deliberate: the scope exceeds any individual. The setting to watch is urgency at −2, because no organization sustains it for three years. A learner near this profile should name the dial they will move in month eighteen, and the evidence that will tell them it is time.", "adjacent_archetypes": "Under pressure it becomes the strategy-of-the-month leader, or borrows the Post-Breach CISO's centralization without the excuse. It should grow into the Enterprise CIO — dials moved right, running the model it built — or hand over to someone better at operating than changing. In an SMB or MSP it compresses into the Player.", "research_anchors": "- Chatterjee, Richardson & Zmud (2001): positive market reaction to newly created CIO positions in industries undergoing IT-driven transformation — expected, not realized, value.\n- Karaevli (2007), CEO library: no general outsider advantage; outsiders helped where performance was poor or the environment turbulent.\n- Zhang & Rajagopalan (2010), CEO library: inverted-U between strategic change and performance, larger both ways for outsiders.\n- Gerow et al. (2014): alignment positively associated with performance across dimensions.\n- Weill & Ross (2004; Tier 3): governance as decision rights; >25% higher profits reported.", "vignette": "*Fictional composite.* Corvina Risk Services is a $410M, 2,100-person insurance-services platform in Bridgewater, New Jersey, assembled by a private-equity sponsor from six regional claims and underwriting-support businesses. Eleven months ago the sponsor hired Alina Reyes as CIO with a $34M mandate: one claims platform, one identity domain, one shared service desk, by the end of the second year, ahead of a sale.\n\nAlina has done this before. She brought three people, decommissioned two legacy platforms on schedule, and stood up a program office whose weekly burndown the sponsor actually reads. She is also the de facto CISO. To hit the July cutover she has approved fourteen security exceptions — service accounts without MFA, a shared administrator credential for the migration tooling, logging deferred on two acquired environments. Six carry expiry dates.\n\nLast month the sponsor's operating partner asked whether the same team could also \"do AI intake\" this year, and the CEO of the largest acquired business — who has never joined the shared service desk — supported the idea warmly.\n\nThe transformation is working. The question the archetype puts to Alina is not whether to take the new workstream. It is which dial she moves first, and whether those fourteen exceptions come off the register before sale diligence finds them."}, "overuse_rungs": ["confidence->arrogance", "vision->fantasy", "rigor->bureaucracy", "adaptability->strategy_of_the_month"], "dial_defaults": {"aggression_caution": -2, "decisiveness_inquiry": -1, "optimism_skepticism": -1, "hands_on_delegation": 1, "urgency_patience": -2, "unilateral_consensus": -1, "innovation_operational_discipline": -2, "centralization_decentralization": -1}, "related_modules": ["m02", "m06", "m07", "m08", "m09", "m10"], "related_archetypes": ["arch.mid-market-cio", "arch.enterprise-cio", "arch.post-breach-ciso", "arch.business-risk-ciso", "arch.regulated-industry-cio-ciso"], "research_refs": ["res.chatterjee2001", "res.gerow2014", "res.karaevli2007", "res.zhang2010", "res.banker2011", "res.weill2004", "res.peppard2010", "res.angst2017", "res.herrmann2014", "res.hambrick1987", "res.hambrick1991", "res.miller1991", "res.karahanna2013"], "meta": {"source_path": "archetypes/transformation-cio.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}], "simulations": [{"id": "sim.m01-founders-mfa", "title": "Ridiculous For Someone At My Level", "module_ref": "m01", "setup": {"company_snapshot": {"name": "Bellhaven Business Services", "is_fictional": true, "industry": "Business-process outsourcing and managed IT/security services for SMB and mid-market clients", "revenue": "$18M", "headcount": 130, "stage": "scale_up", "ownership": "private", "governance": "Privately held New England services firm with a small operating board; roughly 90 SMB and mid-market clients across financial services, healthcare, professional services and retail. About a third of clients buy a fractional (vCISO) security service on top of managed IT.", "ceo_tenure": "You have held the combined CIO and CISO chair since the firm was roughly half its current size.", "ceo_mandate": "Be the single technology executive for the firm and, through the vCISO practice, for the clients who buy it — building the platform the business sells while owning the security risk of running privileged access into ninety client environments."}, "situation": "You are the CIO and CISO of a 130-person business-process and managed-services firm in the Boston suburbs, serving about 90 SMB and mid-market clients. Your largest client is Kestrel Wealth Advisors, a registered investment adviser with $2.1 billion under management, 60 employees, and a founder who owns 70% of it. Kestrel is 22% of your firm's revenue and the reference account your CEO uses to win every other financial-services client.\n\nKestrel's founder has decided that multi-factor authentication is \"ridiculous for someone at my level.\" He travels constantly, changes phones, and last month was locked out of email during a client meeting. He has told your account manager that he wants MFA turned off for his account, that \"the other partners can keep it,\" and that if your firm cannot accommodate a simple request, his chief operating officer will get quotes from two competitors. Your CEO — who, like most CEOs, is inclined to believe this will all work out — has asked you to \"find a way.\"\n\nYou know the facts. Kestrel is a regulated adviser holding client financial data, and the founder's account is the highest-value target in the firm. Your vCISO engagement letter says you \"advise and implement\" controls under the client's direction. You also know that the founder's actual problem — lockouts while traveling — has technical solutions he has not been offered. The account manager has a call with the founder tomorrow and wants to know what to say.", "constraint": "The account manager's call is tomorrow. Kestrel is 22% of revenue and the reference account for the firm's entire financial-services pipeline. Your engagement letter makes you an adviser and implementer under the client's direction — you do not own the decision, only the consequences of it.", "known": ["Kestrel is 22% of firm revenue and the reference account your CEO uses to win financial-services clients.", "Kestrel is an SEC-registered adviser holding client financial data, and the founder's account — 70% owner, constant traveller — is the highest-value target in the firm.", "The founder's stated problem is lockouts while travelling, and technical answers to that problem exist which he has never been offered.", "Your vCISO engagement letter says you advise and implement controls under the client's direction; the client owns the decision.", "Your CEO, drawn from a population unusually inclined to believe things work out, has asked you to find a way, and the account manager's call is tomorrow."], "unknown": ["Whether the founder is testing the relationship or has made this a matter of status he cannot back down from.", "What Kestrel's own compliance officer knows about the request, and whether she would authorize it in writing.", "Whether the two competitor quotes are genuine leverage or a negotiating line.", "How a regulator, a plaintiff or the press would treat your firm's name beside Kestrel's after an incident, regardless of whose signature is on the acceptance.", "Whether passkeys or hardware keys would actually remove the friction he experiences, or would fail him in the same airport."], "discretion_level": "medium"}, "choices": [{"label": "A", "narrative": "Grant the exception, priced. Turn off MFA for the founder under a written risk acceptance he signs personally, with compensating controls — access restricted to registered devices, shortened sessions, enhanced monitoring — and tell your CEO the risk has been accepted by the person who owns it.", "tendency_signals": {"dials": {"aggression_caution": -1, "hands_on_delegation": 1, "optimism_skepticism": 1}, "tendencies": {"N": "high", "B": "high", "F": "high"}, "maturity_levels": [3]}, "tradeoffs": "Suggests you have internalized the first sentence of the Risk Corollary and want the risk owned by the person choosing it. Compensating controls on a founder's account are partial, a signed acceptance transfers accountability on paper but not in the press where your firm's name sits beside Kestrel's, and a regulated adviser's principal accepting a control exception may have obligations to his own regulator that neither of you has priced.", "context_that_favors": "A client whose compliance function is genuinely in the loop and will read what the principal signed.", "context_that_punishes": "A relationship in which your firm would be treated as the security function in any post-incident review regardless of paper.", "strong_ceo_would_evaluate": "Whether the exception is being priced or merely documented, and whether the founder has been offered the alternative first.", "second_order_effects": "Every other client principal now learns that exceptions are available and come with a signature — which is either a product or a queue, depending on what you build next.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Refuse. Tell the account manager the answer is no, explain to the founder that a regulated adviser cannot run its principal's account without MFA, and let your CEO decide whether to keep the account on those terms.", "tendency_signals": {"dials": {"aggression_caution": 1, "unilateral_consensus": -1, "decisiveness_inquiry": -1}, "tendencies": {"I": "high", "B": "low", "K": "low"}, "maturity_levels": [1]}, "tradeoffs": "Suggests you read the founder's account as a control you will not trade at any price and will let the commercial consequence land on the CEO's desk. The gain is clarity; the cost is the Technical CISO's wall — no price, no path, and a CEO who learns that his CISO's answer to the firm's largest client was a policy citation.", "context_that_favors": "A diversified client base and a founder who is testing rather than deciding.", "context_that_punishes": "A firm where 22% of revenue cannot be lost in a quarter.", "strong_ceo_would_evaluate": "Whether 'no' here is a decision or a reflex — and whether anything was said about what would change the answer.", "second_order_effects": "The organization learns that the security function ends conversations, and stops starting them; the next request goes to the account manager instead of to you.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Solve the founder's real problem and hold the line. Take the call yourself, offer hardware keys or passkeys plus registered-device trust so he is prompted rarely and never locked out while travelling, say plainly that MFA stays on, and name what would change your answer.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "unilateral_consensus": 1, "urgency_patience": -1}, "tendencies": {"F": "high", "O": "high", "N": "high"}, "maturity_levels": [3, 4]}, "tradeoffs": "Suggests you noticed that the founder's demand and his problem are different, and that \"No — and here is what would change my answer\" can be delivered as help. It requires you, not the account manager, to take a call with a difficult client; hardware keys have their own friction; and a founder who has decided to be insulted may not accept a solution from the person who declined his demand.", "context_that_favors": "A founder whose objection is really about lockouts rather than about standing.", "context_that_punishes": "A founder for whom the exception has already become a matter of status.", "strong_ceo_would_evaluate": "Whether the alternative genuinely removes the friction — a passkey that still fails in an airport is a refusal with extra steps — and what specific written direction, such as one from Kestrel's compliance officer, would change the answer.", "second_order_effects": "Your firm now has a standard answer for every principal who wants an exception, and it is a product rather than a policy — which is also a claim on your calendar.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Grant it quietly for ninety days. Turn it off, have the account manager say it is \"being handled,\" and use the ninety days to work on the founder.", "tendency_signals": {"dials": {"optimism_skepticism": -1, "urgency_patience": 1, "unilateral_consensus": -1}, "tendencies": {"I": "low", "M": "low", "N": "overuse"}, "maturity_levels": [1]}, "tradeoffs": "Suggests you are treating the problem as a relationship to be managed rather than a risk to be priced, and would rather not have the decision on paper. The risk is unpriced, unowned and undocumented; the founder learns nothing about the alternative; and the ninety days end with the same conversation and less credibility.", "context_that_favors": "Almost nothing here — at best, a genuine belief that the founder will accept the alternative once the immediate confrontation is off the table.", "context_that_punishes": "Any incident in the window, after which the record shows the firm's CISO turned off a control on the highest-value account at a regulated client and had the account manager say it was being handled.", "strong_ceo_would_evaluate": "Why the decision is one they would rather not write down, and what that reluctance is telling them about the decision.", "second_order_effects": "This is the alternation failure the module names — the builder's half keeping the account and the risk officer's half declining to sign for it — and the technicians who execute it learn which half to ask.", "follow_up_ref": "fu-D"}, {"label": "E", "narrative": "Escalate it as a commercial decision. Tell your CEO this is a business call — whether to keep a 22% client on his terms — and that you will implement whatever the firm decides, with your objection noted in email.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1}, "tendencies": {"E": "overuse", "A": "low", "N": "high"}, "maturity_levels": [2]}, "tradeoffs": "Suggests you believe the decision belongs to the business — half right — and that your job ends at implementing it with an objection on file. But you have handed a security decision to a CEO whose base rate says he will find a way to say yes, without the price or the alternative he would need to decide well.", "context_that_favors": "A firm where the decision genuinely is commercial and the CEO has the priced alternative in front of him when he makes it.", "context_that_punishes": "A CEO who reads 'objection noted' as the technology executive stepping aside, and a record that later shows the CISO knew and delegated upward.", "strong_ceo_would_evaluate": "Whether the escalation carries a price and an alternative, or only a signature line — and whether this is the last step or the first.", "second_order_effects": "\"Objection noted\" is the IT Advisor profile from inside: capability without authority, by choice, and it becomes the firm's habit for every future exception.", "follow_up_ref": "fu-E"}], "debrief_common": {"fit_analysis": "A 130-person MSP where one person holds both technology chairs, at a client that is 22% of revenue and the reference account for the whole financial-services pipeline. Discretion here is medium and granted rather than assumed: the engagement letter makes you an adviser under the client's direction, so your judgment reaches the decision only if you put it there in a form the client and your CEO can act on. The situation is a clean instance of the module's central claim — a CEO drawn from an unusually optimistic population is asking a technology executive selected for vigilance to make an optimistic answer possible, and neither of them is being unreasonable about their own job. The founder's demand and the founder's problem are different things, which is the detail every default setting is likely to miss: the Technical CISO refuses the demand, the Business-Risk CISO prices it, and neither asks about the lockouts. Personality × Power runs through the whole scenario, because the person with the least formal authority over the decision is the one who will be named in any review of it.", "research_that_bears": [{"text": "In a large survey using validated instruments, CEOs scored markedly more risk-tolerant and more optimistic than population norms — roughly 80% of US CEOs classified 'very optimistic' against roughly 65% of CFOs — so the person asking you to 'find a way' is drawn from a population unusually inclined to believe it will work out.", "label": "RESEARCH_FINDING", "ref": "res.graham2013"}, {"text": "CISOs interviewed about their obstacles named a perceived lack of power, confusion about role identity, and an inability to engage employees effectively — the influence problem described from inside the role.", "label": "RESEARCH_FINDING", "ref": "res.ashenden2013"}, {"text": "CIO effectiveness depends on the match between the authority an organization grants and the capability the executive brings; capability without authority is a recognized under-performing profile, not a virtue.", "label": "RESEARCH_FINDING", "ref": "res.preston2008"}, {"text": "The Risk Corollary — 'Yes, and here is the risk we are accepting, priced' / 'No, and here is what would change my answer' — is the instrument that converts a temperament clash into a decision the business can make. Only options that state one of the two sentences are doing the job.", "label": "FRAMEWORK"}], "defensible_choices": "C is the strongest single answer, and C followed by A — the alternative first, the priced exception only if the alternative genuinely fails and Kestrel's compliance function directs it — is the sequence most mature technology executives would run. B is defensible where the firm can afford it and where the refusal still names what would change the answer. E is defensible only as the last step after C and A, and only if the escalation carries a price and an alternative rather than a signature line. D is the choice the setup was built to make you recognize in yourself; it is not unusual, which is why it is here.", "trait_dial_readout": "A sits toward aggression and delegation with skepticism kept high. B sits toward caution and unilateral. C sits toward inquiry and consensus with urgency high — the setting furthest from the CISO default. D sits toward optimism and patience for reasons that are not virtues. E sits toward delegation past the point where the job is still yours. On the overlay dials, A and C are Enablement with a price attached; B is Control; D and E are neither, because no risk was priced by anyone.", "two_sentence_question": "Can you say \"We're going to do this\" to the founder and \"I was wrong. Change the plan\" to your CEO about the same account in the same quarter? And for the option you chose, can you state both sentences of the Risk Corollary — the risk being accepted and its price, or what would change your answer? If you can state only one, the setup found your default."}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "Ten weeks on. The founder signed the acceptance personally. MFA is off on his account, sessions are shortened, access is restricted to two registered devices, and the monitoring rules fire to your SOC. He has been notably pleasant to your CEO ever since.\n\nTwo things arrived this week. Kestrel has engaged an outside compliance consultant to prepare for a mock SEC examination, and she has asked your firm for \"the file on any control exceptions,\" including who authorized each one and on what basis. And your service-desk lead mentioned, unprompted, that when the founder replaced his phone in Zurich six weeks ago a technician granted a temporary device-trust bypass at two in the morning so he could reach email — no new signature, no ticket beyond \"per the exception,\" no notification to you. The bypass ran nine days before anyone closed it.\n\nSeparately, two other financial-services principals have asked your account managers for \"whatever Kestrel has.\" Your CEO thinks the compliance consultant's request is good news: proof the firm documents things.", "choices": [{"label": "A", "narrative": "Treat the Zurich bypass as the finding: run a blameless review with the service desk, then rebuild the exception as a standard instrument — fixed expiry, named client signatory, defined compensating controls, and a quarterly read of the register by someone other than you.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you read the nine days as a mechanism failure rather than a technician's mistake, and are converting a one-off acceptance into something the firm can operate. The tradeoff is time and the appearance, to the compliance consultant, that your controls were improvised until she asked; a register built this month dates itself. It works where the review genuinely stays blameless — the technician who mentioned it is the reason you know — and fails where the standard becomes a faster way to say yes to the next principal."}, {"label": "B", "narrative": "Withdraw the exception at Kestrel now, citing the compensating-control failure, and re-enable MFA before the mock examination begins.", "tendency_signals": {"dials": {"aggression_caution": 1, "urgency_patience": -1, "unilateral_consensus": -1}}, "debrief": "Suggests you priced the exception on the compensating controls and are willing to pull it the moment they demonstrably did not hold — which is what a priced risk means. The tradeoff is that the founder signed in good faith and will experience a withdrawal timed to an examination as your firm protecting itself, and your CEO will hear it that way too. Defensible where the bypass shows the control set cannot be operated at two in the morning; costly where you never told him it could be withdrawn and on what trigger."}, {"label": "C", "narrative": "Give the compliance consultant the complete file, including the nine-day bypass, and let Kestrel decide whether the exception continues while you keep it live.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are holding to the engagement letter's logic: the client directs, you advise and implement, and the client's own compliance function is exactly the body that should now weigh it. The tradeoff is that full disclosure of an undocumented bypass will land on the founder as a report about him, and that leaving the exception live while it is reviewed means the same gap runs through the examination. Strongest where the consultant has standing with the founder; weakest where she reports to him."}]}, {"id": "fu-B", "after_choice": "B", "situation": "Twelve weeks on. Kestrel did not leave. What happened instead is narrower and stranger: the COO took the two competitor quotes, and one of the bidders — a boutique that sells fractional CISO services and nothing else — agreed to the exception in writing. Kestrel has now moved only the security-oversight scope of its contract to that firm. You keep the managed IT, the privileged access into every Kestrel system, and the business associate and vendor obligations that come with them. You no longer see the security decisions.\n\nMFA is off on the founder's account. You know because your engineers were asked to make the change and did, on the boutique's written instruction, with your account manager's approval.\n\nYour CEO calls the outcome \"the best available result.\" He has also, twice in the past month, brought you into sales conversations after the scope was agreed rather than before. Kestrel remains 22% of revenue. The boutique's principal has emailed you, pleasantly, proposing a quarterly \"coordination call.\"", "choices": [{"label": "A", "narrative": "Keep the contract and write the record: a letter to Kestrel and an internal note to your CEO stating exactly which security decisions your firm no longer advises on, which controls are now disabled at whose direction, and what that means if there is an incident.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you accept the commercial outcome and are making sure the boundary is documented before rather than after something happens. The tradeoff is that a letter is not a control: your engineers still hold the credentials, and no post-incident account will treat a scope letter as the reason your privileged access was used. Defensible where the letter is short, specific and acknowledged in writing by Kestrel; hollow where it is filed and never mentioned again."}, {"label": "B", "narrative": "Tell your CEO you will not run privileged access into a client whose security decisions you no longer see, and recommend either resigning the account or repricing it to reflect the risk your firm now carries without the mandate.", "tendency_signals": {"dials": {"aggression_caution": -1, "unilateral_consensus": -1, "decisiveness_inquiry": -1}}, "debrief": "Suggests you have concluded that implementation without advisory standing is the worst of both positions and are willing to put 22% of revenue behind that view. The tradeoff is that you already spent your credibility once on this account, and a second escalation reads to a CEO as a campaign rather than an assessment. It works where the repricing option is real and quantified; it fails where the only version of it the CEO hears is 'resign the client.'"}, {"label": "C", "narrative": "Accept the boutique's coordination call and use it: propose a joint session with Kestrel's compliance officer to review what controls sit behind the exception they granted, and offer to run the technical verification.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are trying to rebuild influence through the one channel still open rather than through the contract you lost, and are curious about whether the exception has anything behind it. The tradeoff is that you are volunteering to verify another firm's control decisions without authority over them, which is the IT Advisor profile with a new logo; and if the verification finds nothing, you will have to decide what to do with that. Strongest where the compliance officer becomes your actual counterparty; weakest where the call stays between the two vendors."}]}, {"id": "fu-C", "after_choice": "C", "situation": "Eight weeks on. The call went better than expected. The founder took two hardware keys, one for the office and one that lives in his passport wallet, and has not been locked out since. He told a peer at an industry dinner that your firm \"actually solved it,\" and that peer's COO has called your CEO.\n\nTwo consequences you did not plan. The passkey rollout at Kestrel surfaced a legacy service account for the portfolio-accounting system that thirty of the sixty staff share, with a password last changed in 2021 and no MFA possible on it at all — a bigger exposure than the founder's account ever was, and one nobody had raised in three years of engagement. And your account manager, having watched you take the call, has begun telling other clients that \"our CISO will handle it personally.\" Three such calls are now in your calendar for next week, on top of the Kestrel remediation.\n\nYour CEO is delighted on both counts. He has asked whether the personal call can be part of the standard financial-services proposal.", "choices": [{"label": "A", "narrative": "Productize it: build the principal conversation into a documented service, train a senior engineer to run it, and put yourself on escalation only after the first three.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "centralization_decentralization": 1}}, "debrief": "Suggests you recognized that what worked was a method rather than your presence, and are moving from Player toward Coach before the calendar makes the decision for you. The tradeoff is that the thing clients bought was the CISO taking the call, and a trained engineer delivering the same script is not the same product to a founder who wanted to be taken seriously. It works where the method is written down honestly, including what to say when the answer is still no; it fails where the engineer is sent without the authority to hold the line."}, {"label": "B", "narrative": "Keep taking the calls yourself for two more quarters while you fix the shared service account, and tell the account manager to stop promising you without asking.", "tendency_signals": {"dials": {"hands_on_delegation": -1, "urgency_patience": -1}}, "debrief": "Suggests you have judged that the shared account is the real risk and that the personal calls are how the firm keeps the standing to fix things like it. The tradeoff is that two quarters is how long it takes for 'the CISO handles it' to become a contractual expectation, and the shared account is exactly the kind of finding that gets postponed by a full calendar. Defensible where you name the date you stop; it becomes the Player trap where you do not."}, {"label": "C", "narrative": "Take the shared service account to Kestrel's compliance officer as its own priced finding — the exposure, the remediation cost, and the conditions under which you would keep operating the system as it is.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you are spending the credit from the founder's win immediately, on the larger problem, and to the person in the client's organization who can act on it rather than to the one who is pleased with you. The tradeoff is that it reframes a success story as a discovery of something your firm missed for three years, and the compliance officer may reasonably ask why. Strongest where you own the three years plainly; weakest where the finding is presented as though the passkey project found it by design."}]}, {"id": "fu-D", "after_choice": "D", "situation": "Day sixty-one of the ninety. Your detection provider escalates at 06:20: a successful sign-in to the founder's mailbox from an autonomous system in a country he is not in, followed nine minutes later by the creation of an inbox rule that moves messages containing \"wire,\" \"custodian\" and \"invoice\" to a rarely used folder. The session was terminated by an anomaly rule forty minutes in. There is no evidence yet that anything was read or sent, and the rule was still empty when your team removed it.\n\nThe record around it is worse than the event. The ticket that disabled MFA reads \"per CISO.\" Your account manager's email to Kestrel's COO — \"this is being handled\" — is in writing and is eight weeks old. Nobody at Kestrel has signed anything. The founder is on a flight and unreachable for six hours. Your CEO's first question on the phone was whether you have to tell them at all, given that nothing appears to have happened.\n\nThe ninety days are not up.", "choices": [{"label": "A", "narrative": "Re-enable MFA immediately and tell Kestrel's COO and compliance officer today, in writing, including the fact that MFA was disabled at the founder's request with no signed acceptance and that the ticket names you.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1, "urgency_patience": -1}}, "debrief": "Suggests you have decided that the undocumented exception is now the material fact and that disclosing it while it is still your disclosure is worth more than the eight weeks of goodwill it costs. The tradeoff is that you are notifying before the investigation is complete, on an event that may prove to be nothing, and the founder learns of both the intrusion and your account of the arrangement while airborne. Withheld events that are later exposed are priced far more harshly than disclosed ones, which is the argument for today rather than Friday."}, {"label": "B", "narrative": "Re-enable MFA now, complete the forensic scoping first, and notify at the end of the week with a full timeline, a mailbox audit and a signed acceptance for whatever controls remain.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "urgency_patience": 1}}, "debrief": "Suggests you believe a partial notification produces wrong remediation and that four days buys a picture the client can act on. The tradeoff is that the interval between what you knew at 06:20 and what you said on Friday is the interval someone else will later characterize, and 'we were scoping' and 'we were withholding' look identical from outside. Defensible where the delay is written down with its reasons on the day; fragile where the reason it feels safer is that Friday is after the founder lands."}, {"label": "C", "narrative": "Report to your own CEO and the firm's insurer and counsel first, and let the CEO decide what Kestrel is told and when.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are treating this as a firm-level exposure with legal and coverage consequences that outrun your authority, which is partly true and is what the insurer's notice conditions require. The tradeoff is that you are handing a disclosure decision to the person who has just asked whether disclosure is necessary, on a control that was disabled without a signature at his request that you find a way. Defensible where counsel is instructed to advise on obligations rather than on exposure; it is the same delegation upward as the original choice where it is not."}]}, {"id": "fu-E", "after_choice": "E", "situation": "Ten weeks on. Your CEO decided: exception granted, objection on file, MFA off on the founder's account with session limits your team applied without being asked. Kestrel renewed early.\n\nThe decision has since travelled. Two other financial-services clients have asked for the same arrangement, both citing Kestrel by name — your account manager, it emerges, uses it as an example of the firm's flexibility. Your CEO now wants you to write the standard language so that \"we do this consistently.\"\n\nAt the same time, a large prospect's outside auditor has sent your firm a vendor questionnaire. Question 14 asks for your documented process for control exceptions at client organizations, including who may approve one and whether the security function's objection can be overruled. Question 15 asks how many exceptions are currently open and when each was last reviewed. You know the answers to neither with confidence; there is no register, and the only record of your objection is one email in your own sent items.", "choices": [{"label": "A", "narrative": "Write the standard yourself — expiry dates, compensating controls, a named client signatory, and a quarterly review by someone other than you — and accept that you are institutionalizing a decision you objected to.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "hands_on_delegation": -1}}, "debrief": "Suggests you have decided that an exception process you designed is better than one the account managers improvise, even though authoring it makes you the owner of an outcome you opposed. The tradeoff is that a well-built process makes exceptions easier to grant as well as easier to see, and the objection in your sent items becomes historically interesting rather than operative. It works where the quarterly reviewer is genuinely someone else; it becomes paperwork where the reviewer is you under a different heading."}, {"label": "B", "narrative": "Answer the auditor accurately — there is no documented process, exceptions are approved commercially, and the security function's objection can be and was overruled — and take the answer to your CEO as the case for a decision right.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you are willing to spend a live sales opportunity to convert a structural weakness into a decision the firm has to make, and that you would rather the auditor hear it from you than infer it. The tradeoff is that the honest answer may cost the prospect, and a CEO who loses a deal to his CISO's candour will remember the sequence rather than the principle. Defensible where the answer is accompanied by the process you propose to build; reckless where it is only the diagnosis."}, {"label": "C", "narrative": "Decline to author the standard, and propose instead that an outside vCISO peer builds the exception register and reviews it quarterly on the board's behalf.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "decisiveness_inquiry": 1}}, "debrief": "Suggests you want the independence you could not get by objecting, bought from outside rather than argued for inside. The tradeoff is that a retained peer with no authority produces a register and not a decision right, the auditor may read an outsourced reviewer as evidence that the internal function was overruled, and you have again declined to author the thing you will be held to. Strongest where the peer reports to the board rather than to the CEO; weakest where the arrangement exists so that nobody has to have the argument."}]}], "reflection": "Write down the last three times a client, a CEO or a business owner asked you to turn something off. For each: did you find out what problem they were actually trying to solve before you answered, and did your answer contain a price or a condition? Then write down which of the three you would be comfortable reading aloud from a post-incident exhibit.", "tags": {"dials": ["optimism_skepticism", "aggression_caution", "decisiveness_inquiry", "unilateral_consensus", "hands_on_delegation"], "archetypes": ["arch.smb-msp-technology-leader", "arch.business-risk-ciso", "arch.technical-ciso", "arch.regulated-industry-cio-ciso"], "stages": ["scale_up", "mature"], "learn_categories": ["ceo_fundamentals", "risk", "decision_making"]}, "discretion_level": "medium", "research_refs": ["res.graham2013", "res.ashenden2013", "res.preston2008", "res.maynard2018", "res.hambrick1987", "res.li2010", "res.haislip2021", "res.ians2026", "res.verizon2025", "res.amir2018", "res.milliken2003"], "meta": {"source_path": "modules/01-why-cios-and-cisos-arent-normal-either.md#9-leader-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m02-tidewater-reporting-line", "title": "Where Should The Director Report", "module_ref": "m02", "setup": {"company_snapshot": {"name": "Tidewater Managed Services", "is_fictional": true, "industry": "Business-process outsourcing and managed IT/security services, New England", "revenue": "$34M", "headcount": 240, "stage": "scale_up", "ownership": "private", "governance": "Privately held with an outside board whose audit committee chair is a retired bank executive. 160 clients across financial services, healthcare, professional services and retail; the newest and most profitable contracts — two broker-dealers and a hospital-affiliated physician group — require 'independent security oversight' of the managed environment, audited annually.", "ceo_tenure": "Four years holding the combined CIO and CISO chair.", "ceo_mandate": "Run the platform 160 clients depend on, carry the firm's own security risk, and personally lead the vCISO practice that produces half of Tidewater's security revenue — while proposing, next week, the structure that decides whether one person should keep doing all three."}, "situation": "You are the CIO and CISO of Tidewater Managed Services, a business-process and managed-services firm outside Boston: 240 employees, $34 million in revenue, 160 clients across financial services, healthcare, professional services and retail in New England. You have held both jobs for four years. Tidewater's newest and most profitable contracts are with two broker-dealers and a hospital-affiliated physician group, and all three contracts require \"independent security oversight\" of the managed environment — language the clients' auditors read as meaning that the person who runs the systems is not the only person who assesses them.\n\nThe CEO has approved a Director of Security hire and asked you where the role should report. The CFO wants it under you, to keep the budget in one place. The audit committee chair of the firm's outside board — a retired bank executive — wants a direct line from the new director to the committee. The CEO wants no new direct reports and has said, privately, that \"you've been doing both jobs fine.\" The head of client services has pointed out that half of Tidewater's security revenue comes from vCISO engagements that you personally lead, and that a director who reports elsewhere could become a rival to that practice. The hire will start in ninety days. You have to propose the structure at next week's board meeting.", "constraint": "You propose at next week's board meeting; the hire starts in ninety days. Three client contracts already require independent security oversight and are audited annually. The CEO has ruled out new direct reports, the CFO wants one budget, and the audit committee chair wants a line that skips you — and you are the person whose work the oversight would most be assessing.", "known": ["Three of the most profitable contracts require 'independent security oversight,' which the clients' auditors read as: the person who runs the systems is not the only person who assesses them.", "The CEO has approved the hire, wants no new direct reports, and has said privately that you have been doing both jobs fine.", "The CFO wants the role under you for budget reasons; the audit committee chair wants a direct line to the committee.", "Half of Tidewater's security revenue comes from vCISO engagements you personally lead, and the head of client services expects a rival practice if the director reports elsewhere.", "You have one week to propose and ninety days before the person starts."], "unknown": ["Whether the audit committee chair will actually use a direct line, or whether it becomes a twice-yearly hour of theatre.", "How strictly the three clients' auditors will read 'independent oversight' — paper escalation path, or a person who does not report to the CIO.", "Whether the CEO, having accepted a structure, would route security questions back to you anyway.", "Whether 'you've been doing both jobs fine' means both arguments have been winning, or only that one has been made.", "How fast the security practice will grow, and therefore whether a second executive is justified this year or in three."], "discretion_level": "medium"}, "choices": [{"label": "A", "narrative": "Director reports to you, with a dotted line to the audit committee. You keep both titles and the budget; the director presents to the committee twice a year without you in the room, and the committee chair can call them directly.", "tendency_signals": {"dials": {"centralization_decentralization": -1, "unilateral_consensus": 1, "hands_on_delegation": -1}, "tendencies": {"G": "high", "E": "low", "N": "high"}, "maturity_levels": [2]}, "tradeoffs": "Suggests you want the build and the control under one head while creating a formal channel that skips you. The tradeoff is that a dotted line is exactly as independent as the person it dots to: if the director's bonus, priorities and career run through you, the committee's twice-yearly hour is theatre unless the chair uses it.", "context_that_favors": "An audit committee chair who will actually call, and clients whose auditors accept a documented escalation path.", "context_that_punishes": "Contract language read strictly — or the fact that you are the person whose work most needs assessing.", "strong_ceo_would_evaluate": "What the director could say to the committee that would cost them something with you, and whether the honest answer is 'nothing.'", "second_order_effects": "The firm has a security director who is structurally the CIO's subordinate, and the vCISO practice now has an internal peer who reports to its principal.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Director becomes CISO and reports to the CEO; you keep the CIO title and the vCISO practice. Tidewater gets a genuine two-chair structure and the clients get their independence; the CEO gets a direct report he did not want.", "tendency_signals": {"dials": {"centralization_decentralization": 1, "hands_on_delegation": 1, "aggression_caution": -1}, "tendencies": {"E": "high", "K": "high", "F": "high"}, "maturity_levels": [4]}, "tradeoffs": "Suggests you have concluded the two arguments need two people at Tidewater's size and regulatory exposure, and are willing to give up half your title to get it. The tradeoffs are real: the CEO said no more direct reports and does not want to arbitrate technical risk; a CISO without engineers is the IT Advisor profile; and the head of client services is right that the vCISO practice may fracture.", "context_that_favors": "Clients who will pay for demonstrable independence, and a CEO who can be persuaded that the direct report is the price of the contracts.", "context_that_punishes": "A CEO who accepts the structure and then routes every security question back to you anyway.", "strong_ceo_would_evaluate": "The structural change priced the way the module prices a go-live — what it buys, what it costs, who signs — with the vCISO practice question settled before the board meeting rather than after.", "second_order_effects": "You have modeled the Two-Sentence Test at the level of your own job, and the organization watches whether the CIO can commit to a plan that reduces the CIO.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Director reports to the general counsel as head of security and compliance. Security becomes an enterprise-risk function alongside legal and client contracting; you keep the engineering and the budget.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "aggression_caution": 1, "centralization_decentralization": 1}, "tendencies": {"M": "high", "N": "high", "G": "low"}, "maturity_levels": [2]}, "tradeoffs": "Suggests you see security at Tidewater as primarily a contractual and regulatory matter, which for a firm selling into broker-dealers and healthcare is half true. The gain is that disclosure, client contracting and control assessment sit together and the 'independent oversight' requirement is unambiguous; the cost is compliance drift — a director measured on audit findings, separated from the engineers who implement controls.", "context_that_favors": "A general counsel with genuine risk-management capacity.", "context_that_punishes": "A GC who is a contracts lawyer with a part-time paralegal, in a firm whose actual risk is a technician's credential being used against sixty clients at once.", "strong_ceo_would_evaluate": "Who, under this design, argues the engineering side of a control decision — and whether anyone in the room can.", "second_order_effects": "Security decisions acquire a legal cadence; incidents inherit it too, which is felt first in the hour that matters most.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Keep both jobs; hire the director as an operational lead under you; put a retained external vCISO peer on the audit committee's side to provide the independent oversight the contracts require.", "tendency_signals": {"dials": {"centralization_decentralization": -1, "hands_on_delegation": -1, "unilateral_consensus": -1}, "tendencies": {"A": "high", "E": "low", "K": "low"}, "maturity_levels": [2]}, "tradeoffs": "Suggests you believe the Player-stage design — decision rights written down, with the second opinion institutionalized — can still carry a 240-person firm, and that independence can be bought rather than built. The gain is speed, continuity and a second opinion genuinely outside your head and your reporting line; the cost is that the auditors may not accept a retained peer as oversight and the director hired under this design will find it hard to become the CISO later.", "context_that_favors": "A board that trusts the CEO's 'you've been doing both jobs fine.'", "context_that_punishes": "The day a client's auditor asks who at Tidewater can overrule the CIO on security and the answer is a consultant.", "strong_ceo_would_evaluate": "Whether 'fine' means both arguments have been winning, or that only one has been made.", "second_order_effects": "You have declined to test whether the firm has outgrown you holding both chairs, and the test will now be run by someone else on their timing.", "follow_up_ref": "fu-D"}, {"label": "E", "narrative": "Defer the structural question. Hire the director under you now, run for a year, and revisit the reporting line when the security practice is large enough to justify a second executive.", "tendency_signals": {"dials": {"urgency_patience": 1, "decisiveness_inquiry": 1}, "tendencies": {"C": "low", "D": "high", "J": "high"}, "maturity_levels": [1]}, "tradeoffs": "Suggests you believe structure should follow the problem and the problem is not yet clear — a legitimate reading of the reporting-line evidence. The cost is that 'revisit in a year' is how reporting lines are never decided, that a director hired into an undefined structure will read it as a verdict on their standing, and that the clients' contract language is a present obligation.", "context_that_favors": "Genuine uncertainty about the practice's growth, with a dated trigger attached.", "context_that_punishes": "Everyone who needs an answer next week — the chair, the auditors, and the person accepting the job.", "strong_ceo_would_evaluate": "The difference between deferring the decision and deferring the design: you can hire under you now with the decision rights written, the escalation path live, and a dated trigger — revenue, headcount, a regulator's letter — for the structural change.", "second_order_effects": "The organization learns whether the CIO/CISO can commit to a plan that changes their own job, or only to plans that do not.", "follow_up_ref": "fu-E"}], "debrief_common": {"fit_analysis": "A 240-person MSP that has grown into regulated clients faster than it has grown its structure, with one person holding the builder's mandate and the risk officer's mandate and personally owning the revenue line that would be assessed. Discretion is medium and unusually visible: you do not decide, you propose — but the proposal is about your own authority, which is the rarest and most revealing kind of recommendation a technology executive makes. The Fit Equation's Reporting Line term is the whole scenario, and the module's test is the only thing that discriminates between the options: does the risk argument reach the decision without passing through the person who most wants to overrule it, and are overrulings written down. Note what the situation does not contain — an outcome study telling you which line is better for CISOs, because none exists in this library. What it does contain is three contracts, a chair who may or may not call, and a CEO whose 'you've been doing both jobs fine' is either a compliment or a finding.", "research_that_bears": [{"text": "In a large-firm archival study the 'right' CIO reporting line depended on strategy: CIO-to-CEO was associated with better performance in differentiation firms and CIO-to-CFO in cost-leadership firms — structure should follow the problem, and the data say nothing about CISOs.", "label": "RESEARCH_FINDING", "ref": "res.banker2011"}, {"text": "In 243 matched CIO–executive pairs, formal mechanisms and shared knowledge — not informal socializing or experiential similarity — were what produced shared understanding of IT's role, which is why decision rights should be written rather than managed over lunch.", "label": "RESEARCH_FINDING", "ref": "res.preston2009"}, {"text": "In a 2026 practitioner survey of more than 600 security leaders, roughly two-thirds of CISOs reported to the CIO or CTO and about a third to non-IT leaders. A self-selected, vendor-adjacent Tier 3 survey: a base rate for what is common, not evidence of what works.", "label": "RESEARCH_FINDING", "ref": "res.ians2026"}, {"text": "No outcome study in this library compares CISO reporting lines. The module therefore supplies a test rather than a rule — does the risk argument reach the decision unfiltered, and are overrulings recorded — and any option can pass or fail it depending on who occupies the chairs.", "label": "INTERPRETATION"}], "defensible_choices": "B and A are both defensible, and the honest answer is that the research does not choose between them; the module's test does. A with a chair who actually calls the director passes; A with a chair who does not, fails. B passes structurally and fails if the CEO routes everything back to you. D is defensible at 120 people and thin at 240 with regulated clients. C is defensible only with a real risk function under the GC. E is defensible as a designed deferral with a dated trigger, and not otherwise.", "trait_dial_readout": "A sits toward centralization with a small step toward consensus. B sits toward decentralization and delegation — the furthest move from the combined-chair default. C sits toward operational discipline and caution. D sits toward centralization and hands-on. E sits toward patience, for good or bad reasons. On the overlay dials, A and D are Control designs with a consultation layer; B and C move authority outward, which is Enablement only if the person receiving it can use it.", "two_sentence_question": "Can you say \"We're going to do this\" about a structure that reduces your own authority, and \"I was wrong. Change the plan\" if the structure you proposed does not produce a director who can tell the committee something you would not? And for the option you chose: what risk is Tidewater accepting, priced in client trust, speed and your own bandwidth, and what would change your answer?"}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "Fourteen weeks on. The director started, is good, and has spent her first ninety days on the thing you did not ask her to look at: the vCISO practice. Her draft paper says that for thirty-one client engagements, the annual security attestation is signed by the same person who designed and operates the controls it attests to — you — and that no independent review exists for any of them. She notes that both broker-dealer clients' auditors have begun asking who assesses the assessor, and that one has scheduled an interview with \"the person responsible for independent oversight,\" meaning her.\n\nThe audit committee chair has not called her once. Her first committee session is in three weeks, without you in the room, and she has asked whether she should present the paper there.\n\nYour CEO does not know about it. The head of client services, who has seen a summary, has told you the paper \"reads like an attack on the practice,\" and has asked whether the director understands that the practice pays for her salary.", "choices": [{"label": "A", "narrative": "Tell her to present it unedited, and call the chair yourself beforehand to say it is coming and that you asked for none of it to be softened.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are treating the dotted line as real on the first occasion it costs you something, which is the only test of a dotted line there is. The tradeoff is that a committee learns of a structural weakness in the firm's most profitable practice before the CEO does, and you will have to explain to him why you routed it that way. It works where the chair reads your call as evidence rather than as pre-framing; it fails where he concludes that a finding you endorse is a finding you have already contained."}, {"label": "B", "narrative": "Remediate first: buy independent review for the thirty-one engagements, then present the finding and the fix together, jointly, at the same committee session.", "tendency_signals": {"dials": {"urgency_patience": -1, "hands_on_delegation": -1}}, "debrief": "Suggests you want the committee to receive a solved problem rather than an open one, and are willing to spend money in three weeks to make that true. The tradeoff is that the director's first independent act has been converted into a joint announcement of your competence, and she will notice; so may the auditor who interviews her. Defensible where the remediation is genuine and dated; corrosive where 'present it together' means the finding arrives already answered and nobody at the committee ever sees what she wrote."}, {"label": "C", "narrative": "Ask her to route it through you as a joint paper to the CEO first, on the grounds that the vCISO practice is a commercial matter and the committee is not where the firm's revenue model gets debated.", "tendency_signals": {"dials": {"centralization_decentralization": -1, "unilateral_consensus": -1}}, "debrief": "Suggests you read the paper as a business question wearing an assurance question's clothes, which is partly true — the practice's economics are not the committee's remit. The tradeoff is that the first substantive use of the dotted line has been redirected through the person it exists to bypass, and both the director and the chair now know what the line is worth. Favored where the CEO will act quickly on it; punished where he does not, and the auditor's interview happens anyway."}]}, {"id": "fu-B", "after_choice": "B", "situation": "Eleven weeks on. Tidewater has a CISO reporting to the CEO. The clients accepted it immediately; one broker-dealer named it in a renewal as a reason for the renewal.\n\nInside, three things have happened. The CEO has forwarded you eleven security questions in six weeks, twice after the CISO had already answered them, once with the note \"you know this stuff better.\" The CISO has issued her first formal finding — that platform engineers, your people, hold standing domain administrative rights across all 160 client tenants with no just-in-time elevation and no review — and has asked for a remediation date. And the head of client services reports that four vCISO clients have asked which of you is actually their CISO, because the proposals say you and the org chart says her.\n\nShe has asked the CEO for a segregated security budget. The CFO has asked you whether you support that. You have not answered.", "choices": [{"label": "A", "narrative": "Take the finding at face value, commit to a remediation date on her timeline, and start visibly routing the CEO's security questions back to her.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you understand that a structure only becomes real when the CIO behaves as though it is, and that standing admin rights across 160 tenants is a finding you would have wanted someone to make. The tradeoff is that just-in-time elevation across every client tenant is a large engineering programme you have not budgeted, and accepting her date without negotiating it sets a precedent about who sets platform priorities. It works where you tell the CEO plainly why you are redirecting him; it reads as sulking where you simply stop answering."}, {"label": "B", "narrative": "Ask the CEO for a written decision-rights document — who signs risk acceptances, who owns client-facing security scope, what happens when the CIO and CISO disagree — before the next finding lands.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "decisiveness_inquiry": 1}}, "debrief": "Suggests you have concluded that the reporting line was the easy half and the decision rights are the half that determines whether the structure works — which is what the formal-mechanism evidence would predict. The tradeoff is that asking for the rules immediately after receiving an unwelcome finding will be read as a response to the finding, however true it is that the document should have existed at the hire. Strongest where you draft it with the CISO rather than about her; weakest where the first version reserves the disagreements for you."}, {"label": "C", "narrative": "Propose folding the vCISO practice under the new CISO — the revenue line, the client relationships and the attestations — and give up leading it.", "tendency_signals": {"dials": {"centralization_decentralization": 1, "hands_on_delegation": 1, "aggression_caution": -1}}, "debrief": "Suggests you are following the logic of your own proposal to its end: if the clients' independence requirement is real, the person signing their attestations should not be the person running their systems. The tradeoff is that you are handing away half the security revenue and the relationships that generate the rest of the pipeline, to a CISO who has just found fault with your platform, before you know whether she can sell. Defensible where the client confusion is already costing renewals; premature where it is four clients asking a reasonable question."}]}, {"id": "fu-C", "after_choice": "C", "situation": "Thirteen weeks on. The general counsel now owns security and compliance, and on paper it has gone well: a policy set, a client-obligations register mapping each contract's control families, and an audit-findings tracker the hospital client's assessor described as the best they had seen from a firm this size. The 'independent oversight' language is satisfied without argument.\n\nThen, three weeks ago, a technician's credential was used against two client tenants at 21:40 on a Friday. The detection fired. What followed was that the on-call engineer paged the security director, who — following the new incident procedure — notified the GC for a privilege determination before client notification. The GC was at a wedding. Client notification went out Monday at 11:00, sixty-one hours after detection, on an incident your engineers had contained by 22:30 on the Friday.\n\nNobody broke a rule. Both clients have asked, separately, why they heard on Monday. The GC's view is that the process worked and needs a deputy. Your security director has asked you, privately, who is supposed to argue the engineering side of a decision like that.", "choices": [{"label": "A", "narrative": "Propose a written split of incident authority: the director owns assessment and the standing to declare, you own containment and response, the GC owns disclosure and privilege — with a named deputy and a maximum notification clock.", "tendency_signals": {"dials": {"centralization_decentralization": 1, "decisiveness_inquiry": 1}}, "debrief": "Suggests you are fixing the mechanism rather than relitigating the structure, and that the sixty-one hours was a decision-rights gap rather than a reporting-line error. The tradeoff is that three owners in one incident is three places to wait, and a maximum clock is a promise the firm will be held to on a worse night than this one. It works where the clock is short enough to bind and the deputy is real; it fails where the split is agreed and never rehearsed."}, {"label": "B", "narrative": "Take it to the CEO as evidence the design is wrong: a security function separated from the engineers who respond produces slow response, and the director should move under you.", "tendency_signals": {"dials": {"unilateral_consensus": -1, "urgency_patience": -1}}, "debrief": "Suggests you regard one bad Friday as sufficient evidence to reverse a structure you proposed eleven weeks ago, and are willing to say so. The tradeoff is that the clients' independence requirement has not changed, moving the director under you re-creates the problem the contracts were written to prevent, and a CEO watching his CIO reverse his own design will discount the next proposal. Defensible where the incident exposed something structural rather than a wedding; weak where a deputy would have solved it."}, {"label": "C", "narrative": "Leave the structure alone and instrument it: measure detection-to-notification on every incident for two quarters and take the distribution to the audit committee with the sixty-one hours in it.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "urgency_patience": 1}}, "debrief": "Suggests you would rather bring the committee evidence than an argument, and are willing to let the design prove or condemn itself on a measured number. The tradeoff is two quarters of the same exposure while you collect, and the clients who already asked about Monday will not be waiting for your distribution. It is strongest where the measurement is published internally from the first week so the GC's office feels the clock; it becomes a way of not deciding where the data go only to the committee."}]}, {"id": "fu-D", "after_choice": "D", "situation": "Ten weeks on. The operational lead you hired is better than the job you gave him. The retained external peer has produced two quarterly reviews, both competent.\n\nThen the hospital-affiliated physician group's auditor rejected the arrangement. Her written finding is narrow and hard to argue with: the retained peer is engaged and paid by Tidewater, has no reporting line to the board, and can be dismissed by the executive whose work he reviews. She has cited the contract's independent-oversight clause and opened a sixty-day cure period. The two broker-dealers' audits are in four and seven months and use similar language.\n\nYour CEO's reaction was to ask whether you could \"get the chair to write a letter.\" The audit committee chair, told about the finding, said that he had wanted a direct line in the first place.\n\nAnd the operational lead has asked you, without drama, who he would escalate to if he ever disagreed with you about a client's risk. You did not have an answer for him.", "choices": [{"label": "A", "narrative": "Convert the retained peer into a board-appointed adviser: engaged by the audit committee, paid from its budget, with a direct line to the chair and no ability for the executive to dismiss him.", "tendency_signals": {"dials": {"centralization_decentralization": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are keeping your design and repairing the specific defect the auditor named, which is the cheapest route through the cure period and honest about what was wrong. The tradeoff is that a board-appointed reviewer with a direct line is most of a CISO without the operating capacity, the chair now has a security relationship that is not you, and the auditor may still read a part-time adviser as thin. Defensible where the chair actively wants the role; hollow where he signs the engagement letter and disappears."}, {"label": "B", "narrative": "Promote the operational lead to CISO reporting to the CEO inside the cure period, and answer his question by giving him the escalation he asked about.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "urgency_patience": -1, "centralization_decentralization": 1}}, "debrief": "Suggests you have accepted that the firm outgrew the design and are willing to say so in the sixty days rather than the sixty months. The tradeoff is that you are promoting a ten-week hire into an executive role under audit scrutiny, that the CEO's objection to new direct reports has not changed, and that the man's question was about disagreeing with you — which he will now be structurally able to do before he is ready. It works where he is genuinely capable; it is an expensive way to close a finding where he is not."}, {"label": "C", "narrative": "Negotiate the contract language rather than the structure: propose an agreed definition of independent oversight to the client, backed by the peer reviews and the escalation path, and hold the design.", "tendency_signals": {"dials": {"aggression_caution": -1, "unilateral_consensus": -1}}, "debrief": "Suggests you think the auditor is applying an enterprise standard to a 240-person firm and that the right fight is over what the clause should mean. The tradeoff is that you are asking a HIPAA-covered client to relax an assurance requirement during a cure period, the two broker-dealers will read whatever you agree, and the operational lead's question is still unanswered. Favored where the client's own security officer is a peer who understands the scale; punished where the negotiation reads as a vendor arguing with its own contract."}]}, {"id": "fu-E", "after_choice": "E", "situation": "Twelve weeks on. You hired the director under you and said the structure would be revisited within the year. You did not set a trigger.\n\nThree things have happened since. The director, six weeks in, asked the CHRO what the path to CISO looked like and was told there was no defined path; she has interviewed elsewhere twice, which you know because a mutual contact mentioned it. At the last board meeting the audit committee chair asked what had been decided about the reporting line and you said it was under review, which he repeated back to you slowly. And the first broker-dealer's annual audit has landed with a single finding — no independent security oversight of the managed environment — and a remediation date ninety days out, copied to that client's own compliance committee.\n\nThe CEO's position is unchanged: no new direct reports, and you have been doing both jobs fine. The CFO has now also asked whether the finding creates a disclosure obligation to the other two regulated clients under their contracts. You do not know.", "choices": [{"label": "A", "narrative": "Announce the structure now on the audit's clock — CISO reporting to the CEO, with a dated review at twelve months — even though the growth question you deferred for is still open.", "tendency_signals": {"dials": {"decisiveness_inquiry": -1, "urgency_patience": -1}}, "debrief": "Suggests you have accepted that the decision is being made by an auditor's calendar because you declined to make it on yours, and would rather choose late than be assigned. The tradeoff is that the structure now arrives as a remediation item rather than a design, the director may already be leaving, and the CEO will experience it as being overruled by a client. Defensible because the ninety days are real; costly because everyone can see what produced it."}, {"label": "B", "narrative": "Give the director the decision rights in writing this week — escalation path that skips you, risk-acceptance signature, exception log read by the committee — and set the dated trigger for the reporting-line change you should have set at the hire.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you are separating the design from the org chart and doing the half that was always available, which is the module's own distinction between deferring a decision and deferring a design. The tradeoff is that the auditor's finding is about structure, not mechanism, and a written escalation path may not close it; nor does it answer what the director was told about her own future. It works where the trigger is specific and public; it is the same deferral in better handwriting where it is not."}, {"label": "C", "narrative": "Tell the audit committee chair plainly that you deferred, why you deferred, what it has cost — the finding, and probably the director — and ask the committee to set the structure.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "optimism_skepticism": 1}}, "debrief": "Suggests you are saying the second sentence to the person most entitled to hear it and handing the decision to the body whose requirement you underweighted. The tradeoff is that a chair who wanted a direct line from the beginning will now design one, you will get a structure you did not propose, and the CEO learns his CIO went to the committee with a problem before bringing him a solution. Strongest where the chair values the diagnosis; expensive where the CEO reads it as the CIO recruiting the board against him."}]}], "reflection": "Draw your current decision rights on one page: who signs a risk acceptance, who can overrule you on security, who hears about it when they do, and who reads the exception log. Then mark every box where the answer is you, and write what would have to be true — in revenue, headcount, client contracts or your own bandwidth — before you would give one of them away.", "tags": {"dials": ["centralization_decentralization", "hands_on_delegation", "unilateral_consensus", "urgency_patience", "innovation_operational_discipline"], "archetypes": ["arch.smb-msp-technology-leader", "arch.mid-market-cio", "arch.business-risk-ciso", "arch.regulated-industry-cio-ciso"], "stages": ["scale_up", "mature", "regulatory_reputation_crisis"], "learn_categories": ["organizational_design", "power_governance", "leadership"]}, "discretion_level": "medium", "research_refs": ["res.banker2011", "res.chatterjee2001", "res.peppard2010", "res.weill2004", "res.preston2008", "res.preston2009", "res.karahanna2013", "res.gerow2014", "res.haislip2021", "res.higgs2016", "res.ians2026", "res.nist2024", "res.maynard2018", "res.hambrick1987"], "meta": {"source_path": "modules/02-two-jobs-one-chair.md#9-leader-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m03-harrowgate-budget", "title": "Tell Me What We Stop Protecting", "module_ref": "m03", "setup": {"company_snapshot": {"name": "Harrowgate Diagnostics", "is_fictional": true, "industry": "Clinical laboratory network — 22 patient-service centers across New Jersey and eastern Pennsylvania", "revenue": "$310M", "headcount": 1900, "stage": "mature", "ownership": "family", "governance": "Privately held by a family trust with an independent board and an audit committee. Two hospital-affiliated clients hold contractual security requirements naming specific control families, audited annually. The CIO/CISO signs an annual attestation to the audit committee that the program's controls operate as described.", "ceo_tenure": "Two years in the combined CIO and CISO role.", "ceo_mandate": "Close out an external assessment that left eleven of nineteen findings open, and stand up a program — segmentation, monitoring, identity governance — that the hospital-affiliated clients' auditors and the audit committee will accept."}, "situation": "You are the CIO and CISO of Harrowgate Diagnostics, a clinical laboratory network with 22 patient-service centers across New Jersey and eastern Pennsylvania: $310 million in revenue, 1,900 employees, privately held by a family trust with an independent board. You have held the combined role for two years; the last external assessment closed eleven of nineteen findings.\n\nYour approved plan is $4.1 million, of which $1.3 million is new: network segmentation across the lab-instrument estate, a managed detection contract with 24/7 coverage, and identity governance for the 400 contract phlebotomists and per-diem staff whose access is provisioned generously and deprovisioned late.\n\nNine weeks in, reimbursement changes cut the projected margin. The CEO calls you in with the CFO and says your number is now $3.2 million, the reduction is permanent, and — to her credit — asks the right question: \"I'm not asking you to do the same work for less. Tell me what we stop protecting, and what that costs us if it goes wrong.\"\n\nTwo constraints. The two largest hospital-affiliated clients have contractual security requirements that name specific control families and are audited annually. And you personally sign an annual attestation to the audit committee that the program's controls operate as described. You have a week.", "constraint": "One week to answer. The $3.2 million is permanent, not a timing problem. Two client contracts name specific control families and are audited annually, and your personal attestation to the audit committee is the instrument that says the program operates as described.", "known": ["The approved plan was $4.1 million, of which $1.3 million was new work: segmentation, 24/7 managed detection, and identity governance for 400 contract and per-diem staff.", "The new number is $3.2 million and the CEO has stated the reduction is permanent.", "The CEO asked the right question — what stops being protected, and what that costs if it goes wrong — which means the answer will be held to.", "Two hospital-affiliated clients' contracts name specific control families and are audited annually.", "You personally sign an annual attestation to the audit committee that the controls operate as described; eleven of nineteen assessment findings are closed."], "unknown": ["Your own loss distribution: Harrowgate has no internal history that would let you price a week of instrument and results-system downtime in dollars.", "Whether the reduced versions of three programs would each be substantive or each be symbolic.", "Whether the hospital clients' auditors would treat a documented, board-accepted gap as a finding or as a breach of the control-family language.", "Whether the family trust would read a named attestation floor as professional judgment or as leverage.", "Whether the margin pressure is genuinely permanent or the first of several reductions."], "discretion_level": "medium"}, "choices": [{"label": "A", "narrative": "Cut one line whole and price the hole. Drop the managed detection contract ($540,000), keep segmentation and identity governance, and publish a one-page priced statement of what is now unmonitored overnight and at weekends, signed by a named executive.", "tendency_signals": {"dials": {"aggression_caution": 1, "innovation_operational_discipline": 1, "unilateral_consensus": 1}, "tendencies": {"M": "high", "N": "high", "G": "high"}, "maturity_levels": [3]}, "tradeoffs": "Suggests you accept that the business sets the envelope and your job is to make the trade-off legible. The tradeoff is sharp: detection is the control most directly tied to time-to-notice, and the practitioner base rate for mean time to identify and contain a breach is measured in months, not days — an order of magnitude, not a forecast for Harrowgate.", "context_that_favors": "A board that reads the exception log and an executive willing to put their name on the acceptance.", "context_that_punishes": "An organization where the acceptance is filed and never revisited, so a temporary gap becomes structural.", "strong_ceo_would_evaluate": "Whether cutting one line whole beats cutting three partially — the symbolic-adoption evidence suggests it does, because three partial adoptions may be three symbolic ones.", "second_order_effects": "The organization learns that cuts produce named, signed consequences, which raises the price of the next cut and makes the exception log worth reading.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Shift from prevention toward resilience. Cut segmentation to a single pilot zone, fund detection and a tested restore capability in full, and tell the board you are optimizing for recovery speed rather than for how unlikely you are to be hit.", "tendency_signals": {"dials": {"aggression_caution": -1, "urgency_patience": -1, "innovation_operational_discipline": -1}, "tendencies": {"B": "high", "F": "high", "H": "high"}, "maturity_levels": [3]}, "tradeoffs": "Suggests you have read your exposure correctly: for a lab network the catastrophic scenario is instruments and results systems down for a week, not a headline. But segmentation is the control most specific to that scenario, so pilot-only segmentation plus funded recovery bets that you can restore faster than you can prevent.", "context_that_favors": "A business where downtime is unaffordable and recovery has never actually been tested end to end.", "context_that_punishes": "Hospital clients whose control families name segmentation explicitly — in which case this is a contract breach with a security rationale.", "strong_ceo_would_evaluate": "Whether the restore target is a number anyone has met under load, and what the contract language actually says before the pilot scope is set.", "second_order_effects": "A tested restore is the one control whose value you can demonstrate without a breach, which changes what the next budget conversation can be about.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Refuse the number as stated. Present the minimum viable program — the $3.7 million below which you will not sign the attestation as written — and say what would change your answer: a narrowed attestation scope, a client-funded control, or a documented board acceptance of the gap.", "tendency_signals": {"dials": {"unilateral_consensus": -1, "optimism_skepticism": 1, "aggression_caution": 1}, "tendencies": {"I": "high", "A": "high", "K": "low"}, "maturity_levels": [2]}, "tradeoffs": "Suggests you believe the attestation is the real constraint and your signature the asset being spent. The gain is the cleanest use of \"No — and here is what would change my answer,\" with three genuine trades rather than a refusal. The cost is that a floor you name is a floor you must hold: sign at $3.2 million after saying you would not, and your future no is worthless.", "context_that_favors": "A board that takes attestations seriously and an audit committee that will hear the three alternatives as alternatives.", "context_that_punishes": "A family trust that reads it as holding the company hostage nine weeks into a margin problem.", "strong_ceo_would_evaluate": "The two things being conflated — whether the program is adequate, and whether a document they sign is accurate — because only the second is theirs to refuse.", "second_order_effects": "Your signature becomes a priced instrument, which works about once per company, and everyone now knows the price.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Take the number and take the year. Absorb the cut across all three items, deliver reduced versions of each, and spend the year building the loss data and control metrics that would let you win next cycle with evidence rather than assertion.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "urgency_patience": 1}, "tendencies": {"O": "high", "C": "low", "M": "low"}, "maturity_levels": [1]}, "tradeoffs": "Suggests you believe the real deficiency is that you cannot yet price your own program — a defensible diagnosis and this module's premise. But \"reduced versions of each\" is the definition of symbolic adoption, which the hospital evidence associates with an increased likelihood of breach, and the governance is untouched too.", "context_that_favors": "A genuinely low-threat year and a board that will act on arithmetic once you have it.", "context_that_punishes": "The moment anything happens, because the honest post-incident answer is that you knew the program was thin and chose to study it.", "strong_ceo_would_evaluate": "Whether the measurement can ride on top of A or B rather than replace them — it almost always can, and costs little.", "second_order_effects": "A year of data changes the next conversation from assertion to arithmetic, if there is a next conversation on your terms.", "follow_up_ref": "fu-D"}], "debrief_common": {"fit_analysis": "A mature, family-trust-owned lab network where the technology executive holds both chairs, has been in post two years, and has a personal attestation on the line. Discretion is medium: the envelope is the CEO's, but the allocation, the framing and the signature are yours, and the CEO has asked the one question that makes the allocation reviewable later. The situation is a pricing problem disguised as a budget problem — every option is an implicit loss estimate, and the only difference between them is whether the estimate is written down and whose name is on it. Note what Harrowgate does not have: any internal loss history, which means the numbers you use will be borrowed from non-random practitioner samples and must be labeled as such when you use them. The Risk Corollary is the instrument here, not the sentiment: a yes needs a price and a signatory, a no needs a trade the business can actually execute.", "research_that_bears": [{"text": "The Gordon–Loeb model treats security spending as a function of expected loss with falling marginal returns; its widely quoted result that optimal investment does not exceed 37% of expected loss holds only for the breach-probability functions the authors assume, and later work shows other functions justify 50% or more. It is a discipline for the argument, not a budget.", "label": "FRAMEWORK", "ref": "res.gordon2002"}, {"text": "Across more than 5,000 hospitals and 938 breaches, the same security investment was associated with fewer breaches only where adoption was substantive; symbolic adoption diminished the effect and was associated with a higher likelihood of breach. Funding a tool without its operator is not half a control.", "label": "RESEARCH_FINDING", "ref": "res.angst2017"}, {"text": "In US healthcare, security investment made before a failure was associated with lower subsequent failure rates and was more cost-effective than investment made after one — and external regulatory pressure decreased the effect of proactive investment, which is the trap in compliance-shaped spending.", "label": "RESEARCH_FINDING", "ref": "res.kwon2014"}, {"text": "The 2025 IBM/Ponemon sample of roughly 600 breached organizations put average breach cost at $4.44 million and average time to identify and contain at 241 days. A non-random, vendor-adjacent sample: usable as an order of magnitude for how long unmonitored means unnoticed, never as Harrowgate's exposure.", "label": "RESEARCH_FINDING", "ref": "res.ibm2025"}], "defensible_choices": "A and B are both defensible and reach opposite conclusions from the same premise — the mark of a real dilemma. C is defensible only if the floor is genuine and the attestation language actually breaks at $3.2 million; otherwise it is a tactic that costs you the instrument. D is weakest as stated and becomes defensible the moment the measurement rides on A or B. Whichever you choose, the test is the same: is there a priced statement of what the company is now accepting, and did someone other than you sign it?", "trait_dial_readout": "A sits toward caution and operational discipline, with a step toward consensus in the signing. B moves toward aggression and urgency — a deliberate bet, taken fast. C is furthest toward unilateral and skepticism. D sits toward inquiry and patience, and risks the passive end of both. On the overlay dials, A is a Control decision made legible; B is the clearest Prevention-to-Resilience move in the course; C is Control defended at the level of the executive's own signature; D is neither pole held long enough to be either.", "two_sentence_question": "Can you say \"We're going to do this\" about a program you know is thinner than it should be — and \"I was wrong. Change the plan\" in month seven if the thing you cut turns out to be the thing that mattered? And for your option: what risk is Harrowgate accepting, priced in dollars and days-to-notice, and what would change your answer?"}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "Nine weeks on. The detection contract is gone, the one-page acceptance is signed by the COO, and it has already done work: two capital requests this quarter arrived with their own risk paragraphs, unprompted.\n\nThree things have changed. The hospital-affiliated client's annual audit questionnaire arrived and question 6.3 asks specifically about continuous monitoring coverage outside business hours; the control family named in the contract includes it. Your business-hours analyst found, in log review, an after-hours attempt to move laterally from a patient-service center workstation toward the results environment — blocked by a firewall rule, discovered thirty-one hours later, no impact. And the CFO has told you that a delayed instrument purchase has freed $260,000 of capital that must be committed this quarter or it goes back.\n\n$260,000 buys roughly half a detection contract. Your COO, who signed the acceptance, has asked whether taking it means the acceptance was wrong. Your CEO has asked nothing; she considers the matter settled.", "choices": [{"label": "A", "narrative": "Take the $260,000 and buy nights-and-weekends-only coverage — half the contract, and the half that closes the gap you named.", "tendency_signals": {"dials": {"aggression_caution": 1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you priced the gap honestly enough that you are willing to buy it back the moment money appears, and that partial coverage aimed precisely at the named window is substantive rather than symbolic. The tradeoff is that a half-contract has to be operated by the same people who are already stretched, and the acceptance you published nine weeks ago now reads as a bargaining position rather than a judgment. Defensible where the scope maps exactly onto the hole you documented; it becomes the symbolic-adoption trap where the coverage is bought and the escalation path is not."}, {"label": "B", "narrative": "Answer question 6.3 truthfully and tell the hospital client about the coverage gap in writing before its auditor finds it, together with the acceptance and the compensating log review.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1, "urgency_patience": -1}}, "debrief": "Suggests you have concluded that a documented gap disclosed by you is a different object from the same gap found by an auditor, and that the thirty-one hours makes the disclosure urgent rather than optional. The tradeoff is that you are volunteering a control-family deviation to a client with contractual remedies, without having first asked the CEO whether the firm wants to fund a fix instead. Concealment that is later exposed is priced far more harshly than disclosure, which is the argument; the counter-argument is that the client may simply require the control at your expense."}, {"label": "C", "narrative": "Decline the $260,000 and hold the acceptance as written, on the grounds that a half-funded detection capability is exactly the partial adoption the evidence warns about.", "tendency_signals": {"dials": {"decisiveness_inquiry": -1, "urgency_patience": 1}}, "debrief": "Suggests you take the symbolic-adoption finding seriously enough to refuse money, and want the priced acceptance to remain the honest description of the program rather than something that quietly heals. The tradeoff is that you are turning down the only capital available this year for the gap you yourself called the sharpest, and 'we declined the funding' is a difficult sentence in front of an auditor or after an incident. Strongest where you can show that $260,000 buys a console nobody watches; weak where it would have bought the nights."}]}, {"id": "fu-B", "after_choice": "B", "situation": "Twelve weeks on. The restore capability is real and tested, which is more than most programs can say: a full lab-information-system restore ran end to end in nine hours against the four-hour target you set. The segmentation pilot covers one instrument zone in the largest center and works.\n\nThen a competitor lab forty miles away was hit with ransomware and was substantially down for eleven days; two of your referring physician groups mentioned it unprompted. Your CEO, who eleven weeks ago made a permanent reduction, has now offered $700,000 back mid-year. Her framing was specific: \"for whatever stops that happening here.\"\n\nThe hospital-affiliated clients' audits are in six weeks and their control families name segmentation. Your restore gap — nine hours against four — is the number you would spend the money on if nobody were watching. And your infrastructure lead has pointed out, correctly, that a full estate segmentation cannot be designed and delivered in six weeks whatever it costs.", "choices": [{"label": "A", "narrative": "Take the money and fund segmentation as she framed it, closing the contract exposure and the coming audit finding.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are spending a threat-wave window on the control your contracts actually name, which is both the compliant answer and the one the CEO will fund without argument. The tradeoff is that the money arrives because of a scenario your restore work addresses better, the six-week audit cannot be met by a program that takes longer than six weeks, and spending under regulatory and client pressure is exactly where the evidence says the benefit of proactive investment weakens. Defensible where the segmentation plan is real and dated; symbolic where it exists to be shown."}, {"label": "B", "narrative": "Take it and spend it on the restore gap and the recovery runbook, telling the CEO plainly that you are buying recovery rather than prevention and why, for a lab, that is what stops eleven days.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you are refusing to let a fear-shaped budget dictate the control, and are willing to correct the CEO's framing while accepting her money. The tradeoff is that you leave the named control family unfunded six weeks before it is audited, and the CEO may reasonably feel that money given for one thing was spent on another — which is a credibility cost you pay in the next cycle. Strongest where you show her the competitor's eleven days as a recovery failure rather than a prevention failure; weakest where you cannot evidence that claim."}, {"label": "C", "narrative": "Commit nothing until a written data-flow and instrument inventory says where segmentation would actually go, accepting that the audit arrives before the analysis finishes.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "urgency_patience": 1}}, "debrief": "Suggests you would rather spend $700,000 correctly in the next quarter than quickly in this one, and that a segmentation design without an inventory is how partial adoptions happen. The tradeoff is that mid-year money rarely survives a quarter, the audit will find an unfunded control family and an unfinished analysis, and 'we were studying it' is the weakest sentence available in front of a client assessor. Defensible where the inventory genuinely does not exist; it is the passive end of inquiry and patience where it is a way of not choosing."}]}, {"id": "fu-C", "after_choice": "C", "situation": "Six weeks on. The floor worked, partly. The audit committee took the attestation point seriously; the CEO went back to the model and found $3.55 million, and has asked whether you sign at that.\n\nTwo complications. The family trust's chair has asked the independent director to look at \"whether the CISO's attestation is being used as a budget instrument\" — the phrase was reported to you by the CFO, who thought you should know. And your own pre-attestation review has turned up something worse than a shortfall: one of the eleven findings you have been counting as closed, identity governance for the contract phlebotomist population, was closed on a vendor's written assertion that automated deprovisioning was live. Your engineer has now checked. It is live for badge access and not for the results system.\n\nSo the floor you named may have been wrong in both directions: $3.55 million might be enough, and the attestation you were protecting may already be inaccurate for a reason that has nothing to do with money.", "choices": [{"label": "A", "narrative": "Sign at $3.55 million and disclose the unverified closure in the same letter, with the correction plan and date.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "aggression_caution": -1}}, "debrief": "Suggests you are separating the two things you were conflating: the program's adequacy is a budget question the business has now answered reasonably, and the attestation's accuracy is yours to correct whatever the number. The tradeoff is that signing below your stated floor teaches the organization the floor moved, and disclosing a false closure in the same document invites the question of what else was closed on assertion. It is the most honest option and the one that costs you the instrument."}, {"label": "B", "narrative": "Hold the floor and raise it: the unverified closure is new information, the number goes up rather than down, and you say so to the committee.", "tendency_signals": {"dials": {"unilateral_consensus": -1, "aggression_caution": 1}}, "debrief": "Suggests you are treating the discovery as evidence that your estimate was too low rather than as a reason to fold, which is defensible arithmetic and terrible politics in a week when the trust's chair is already asking whether your signature is leverage. The tradeoff is that you will be right and disbelieved, and the independent director's review will now examine a floor that moved upward after the CEO met it. Strongest where the committee has seen you withdraw an ask before; unrecoverable where they have not."}, {"label": "C", "narrative": "Withdraw the floor as an instrument, narrow the attestation to the scope you have personally verified, and sign that — naming what is excluded and why.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you have decided the argument was never about the money but about what a signature can honestly cover, and are prepared to make the document smaller rather than the program bigger. The tradeoff is that a narrowed attestation is a visible reduction in assurance that the hospital clients' auditors may read as a finding, and the committee may prefer a broad attestation they trust to a narrow one they have to interpret. It converts your signature from leverage into a measuring instrument, which is what it was supposed to be."}]}, {"id": "fu-D", "after_choice": "D", "situation": "Twelve weeks on. The measurement program is the best thing you have built: near-miss counts, time-to-detect on simulated events, an exception register with ages, and the first honest coverage map Harrowgate has ever had.\n\nIt has told you something you did not want. The reduced identity-governance rollout covered 140 of the 400 contract and per-diem staff — the ones on the badge system — and of the 260 uncovered, 31 people who left Harrowgate in the last eight months still hold active credentials to the results environment. Two of those accounts have authenticated in the last thirty days. You do not yet know by whom.\n\nAnd the CFO has asked you for your metrics. The cyber-insurance renewal questionnaire is due in nine days, the broker has flagged that the identity-governance answers are warranties rather than descriptions, and the CFO has said, pleasantly, that she assumes the answers are all yes because that was what the plan funded.", "choices": [{"label": "A", "narrative": "Answer the questionnaire exactly as the data read — 140 of 400, 31 orphaned accounts, two recent authentications — and let the premium or the exclusion land where it lands.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you understand that a warranty answered optimistically is worse than no policy, because it converts a control gap into a coverage denial at exactly the moment coverage matters. The tradeoff is that an honest answer nine days before renewal will move the premium or add an exclusion, and the CFO will experience the year you spent measuring as the year you produced the bad answer. It is hard to argue against and expensive to do."}, {"label": "B", "narrative": "Investigate and close the 31 accounts this week, answer as of the corrected date, and disclose the remediation and its trigger in the questionnaire's notes.", "tendency_signals": {"dials": {"urgency_patience": -1, "hands_on_delegation": -1}}, "debrief": "Suggests you are fixing the thing before describing it, which is the right order of operations, and are unwilling to answer for a state you can change in a week. The tradeoff is that the two authentications may be an incident rather than an untidiness, and closing accounts is the fastest way to destroy the evidence that would tell you which; a questionnaire answered on a seven-day-old remediation is also a statement about the other 260. Strongest where the investigation precedes the closure; misleading where the note omits why the date was chosen."}, {"label": "C", "narrative": "Take the coverage map and the 31 accounts to the CEO now as the mid-year case for restoring the identity line, rather than waiting for the cycle the year of measurement was meant to win.", "tendency_signals": {"dials": {"decisiveness_inquiry": -1, "aggression_caution": -1}}, "debrief": "Suggests you have decided the evidence arrived early and is strong enough to spend now, which is what the year was for — and that waiting for the annual cycle while credentials of departed staff authenticate is not a study, it is a choice. The tradeoff is that reopening a permanent reduction at mid-year on your own initiative uses the credibility the measurement bought, and the questionnaire deadline is nine days regardless of what the CEO decides. Defensible where the ask is small and specific; it repeats the original error where it is the whole $900,000 again."}]}], "reflection": "Take the last control you asked to be funded and write the four numbers behind it: the asset or path, the annual probability without it, the loss if it happens as a range, and the control's effect on that probability. Mark which are quotes and which are guesses. Then write the sentence you would have to say to your CEO if all four are guesses — and decide whether you have ever said it.", "tags": {"dials": ["aggression_caution", "optimism_skepticism", "innovation_operational_discipline", "urgency_patience", "unilateral_consensus"], "archetypes": ["arch.regulated-industry-cio-ciso", "arch.business-risk-ciso", "arch.technical-ciso", "arch.mid-market-cio"], "stages": ["mature", "scale_up"], "learn_categories": ["risk", "decision_making", "ceo_fundamentals"]}, "discretion_level": "medium", "research_refs": ["res.gordon2002", "res.campbell2003", "res.cavusoglu2004", "res.kamiya2021", "res.kashmiri2017", "res.amir2018", "res.kwon2014", "res.angst2017", "res.verizon2025", "res.ibm2025", "res.weill2004", "res.ians2026", "res.graham2013"], "meta": {"source_path": "modules/03-pricing-risk.md#9-leader-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m04-narragansett-notification", "title": "Eleven Of A Hundred And Forty", "module_ref": "m04", "setup": {"company_snapshot": {"name": "Narragansett Business Services", "is_fictional": true, "industry": "Business-process outsourcing and managed IT/security services, New England", "revenue": "$28M", "headcount": 210, "stage": "scale_up", "ownership": "founder", "governance": "Founder-led, privately held. 140 clients including two SEC-registered investment advisers, a publicly traded regional bank holding company, three HIPAA-covered physician practices, several law firms and a retail chain. Master services agreements require notification of a security incident affecting client data with no defined deadline.", "ceo_tenure": "You hold the combined CIO and CISO chair; the founder is CEO.", "ceo_mandate": "Run the remote-management platform through which 140 client environments are administered, and own the security of the privileged access that makes the business possible."}, "situation": "You are the CIO and CISO of Narragansett Business Services, a business-process and managed-services firm in Providence, Rhode Island: $28 million in revenue, 210 employees, 140 clients across New England — two SEC-registered investment advisers, a publicly traded regional bank holding company, three physician practices under HIPAA, several law firms and a retail chain.\n\nAt 05:50 on a Thursday your detection provider escalates: a technician's session token appears to have been replayed from an unfamiliar network against your remote-management platform. By 09:00 you have confirmed indicators in 11 client environments and no evidence yet about the other 129. Logging retains 30 days; the token may have been valid longer. Scoping the full estate takes roughly 96 hours; a partial answer for the top 40 clients by sensitivity is possible in about 24.\n\nThree pressures. Your master services agreements require notification of a \"security incident affecting client data\" with no defined deadline. The bank holding company is a public filer whose own four-business-day 8-K clock starts when it determines materiality, so your timing shapes its legal position. And your CEO, who founded the firm, said one thing on the 09:00 call: \"We tell people when we know something. Let's not scare 140 clients over 11.\"\n\nYou decide by noon.", "constraint": "You decide by noon. Full scoping takes about 96 hours; a partial answer for the top 40 by sensitivity takes about 24. Logging retains 30 days and the token may have been valid longer, so the picture you have at 09:00 may be structurally incomplete. The MSAs set a duty to notify with no deadline attached to it.", "known": ["A technician's session token was replayed against your remote-management platform from an unfamiliar network; indicators are confirmed in 11 client environments as of 09:00.", "Scoping the full 140-client estate takes roughly 96 hours; a partial answer for the top 40 by sensitivity takes about 24.", "Logging retains 30 days and the token may have been valid longer, so the earliest date of access may be unknowable.", "One client is a public filer whose four-business-day disclosure clock begins when it determines materiality — a determination your notification timing shapes.", "The MSAs require notification of a security incident affecting client data and set no deadline; the CEO has stated a preference for waiting until you know something."], "unknown": ["Whether the other 129 environments were touched, and whether the logs that would say so still exist.", "Whether credentials were used for anything beyond access — exfiltration, persistence, or nothing at all.", "What a client can actually do with a 'possibly affected' notice at 09:00, which differs by client.", "Whether the bank's own security team has already seen indicators from its side.", "How your notification, your internal messages and your eventual timeline will read side by side in a document production a year from now."], "discretion_level": "high"}, "choices": [{"label": "A", "narrative": "Notify all 140 clients now, stating what is confirmed (11 environments), what is unknown, the logging limitation and your scoping timeline — accepting the churn that \"we don't yet know if you're affected\" will cause.", "tendency_signals": {"dials": {"urgency_patience": -1, "decisiveness_inquiry": -1, "optimism_skepticism": 1}, "tendencies": {"N": "high", "B": "high", "K": "high"}, "maturity_levels": [3]}, "tradeoffs": "Suggests you weight the client's right to know above the commercial cost of uncertainty, and would rather be early and imprecise than late and complete. The tradeoff is real: 129 clients get an alarming message about an event that may not have touched them, and a few leave.", "context_that_favors": "A sophisticated, regulated client base that would rather assess itself than be assessed for.", "context_that_punishes": "A client base that reads uncertainty as incompetence and buys managed services precisely so it does not have to think about this.", "strong_ceo_would_evaluate": "What a client can actually do with a 'possibly affected' notice at 09:00 — where the answer is 'rotate credentials and watch,' the notice has operational value; where it is 'worry,' it may not.", "second_order_effects": "You set the precedent that Narragansett tells clients before it is comfortable, which is expensive once and valuable permanently.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Notify the 11 confirmed now and the top 40 by sensitivity within 24 hours, the remaining 99 at 96 hours when scoping completes, on a schedule you publish in writing today.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "innovation_operational_discipline": 1, "decisiveness_inquiry": 1}, "tendencies": {"F": "high", "M": "high", "N": "high"}, "maturity_levels": [3, 4]}, "tradeoffs": "Suggests you are holding two duties at once: get information first to those who most need it, without pretending to knowledge you lack. The schedule is itself a commitment a client can hold you to. The cost is that 'top 40 by sensitivity' is your ranking, made under pressure, and the 99 will ask why they were third.", "context_that_favors": "A ranking that rests on written, pre-existing criteria rather than on judgment formed this morning.", "context_that_punishes": "Any appearance that the tiering tracks revenue — and any slip, because a published schedule you then miss is worse than no schedule.", "strong_ceo_would_evaluate": "Writing the criteria before naming the tiers, and putting the public filer in the first tranche regardless, because its clock depends on yours.", "second_order_effects": "Narragansett acquires a notification standard it will be held to in every future incident, which is the point and the risk.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Notify nobody today. Engage counsel and the insurer, brief the bank's CISO privately under the contract's incident clause, and issue one complete notification at 96 hours when you can tell each client their actual status.", "tendency_signals": {"dials": {"urgency_patience": 1, "aggression_caution": 1}, "tendencies": {"D": "high", "G": "high", "C": "low"}, "maturity_levels": [2]}, "tradeoffs": "Suggests you believe a precise answer is worth four days, and that partial notices do more harm than good. The case is genuine — half-scoped notifications generate wrong remediation, and the 30-day logging limit means your 09:00 picture may mislead. But four days of unwitting exposure for 129 clients is four days they cannot act.", "context_that_favors": "Contracts that specify an agreed scoping window, and a client base that has agreed to it in advance.", "context_that_punishes": "Everywhere else — and particularly a public filer whose materiality determination is delayed by your silence without its knowledge.", "strong_ceo_would_evaluate": "How the interval will be characterized later: 'scoping' and 'withholding' describe the same four days, and the person doing the characterizing will not be you.", "second_order_effects": "Telling the public filer and the regulated advisers today turns this into B; not telling them makes the four days the thing everyone examines afterwards.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Notify all 140 now, framed as \"a vendor security event under investigation,\" without stating that the entry point was your own privileged-access path — precise about impact, vague about origin, while the facts settle.", "tendency_signals": {"dials": {"unilateral_consensus": -1, "optimism_skepticism": -1}, "tendencies": {"K": "low", "N": "overuse", "A": "high"}, "maturity_levels": [1]}, "tradeoffs": "Suggests you are trying to satisfy the duty to warn while protecting the firm's core commercial claim — that your privileged access is safe to grant. The argument underneath is real, because early attribution is often wrong. But this option does not withhold a fact you are unsure of; it withholds the fact you are most sure of, and it is the one that determines what a client does next.", "context_that_favors": "Nothing in this setup. The strongest version of the argument is that attribution can change, which is an argument for saying what you know and when you knew it, not for omitting it.", "context_that_punishes": "Discovery, disclosure by a client's own forensic firm, or a journalist — after which the omission, not the incident, is the story.", "strong_ceo_would_evaluate": "One question: beside the full timeline in a client's litigation exhibit, would this framing read as caution or as concealment?", "second_order_effects": "The line is not between complete and incomplete but between incomplete and misleading, and withheld events that are later exposed are priced far more harshly than disclosed ones.", "follow_up_ref": "fu-D"}], "debrief_common": {"fit_analysis": "A founder-led MSP whose entire product is privileged access into 140 environments, at the moment that access is the incident. Discretion is at its maximum: for the hours the event is live the technology executive has more real authority than anyone in the building, which is exactly when dispositions run unsupervised. The situation is not a scoping problem; scoping has a known duration. It is a disclosure-timing problem in which one client's regulatory clock, three HIPAA-covered practices' obligations and the firm's commercial claim about its own platform all depend on a decision you make with a quarter of the facts. The CEO's sentence — 'let's not scare 140 clients over 11' — is not obstruction; it is the optimism the founder was selected for, arriving at the worst hour to receive it. What the module asks you to notice is that the record being created this morning is most of what any later account of your judgment will have to work with.", "research_that_bears": [{"text": "Since December 2023, US public companies must disclose material cybersecurity incidents on Form 8-K within four business days of determining that the incident is material — the determination, and the pace of making it, sit inside the company. Your notification timing therefore shapes the bank holding company's legal position.", "label": "FACT", "ref": "res.sec2023"}, {"text": "Before mandatory disclosure, attacks that firms withheld and that were later exposed were associated with roughly a 3.6% equity decline, against 0.7% for firm-disclosed attacks — evidence that concealment is priced when it is discovered.", "label": "RESEARCH_FINDING", "ref": "res.amir2018"}, {"text": "CIO departures were about 72% more likely after breaches attributed to system deficiencies, but not after breaches attributed to criminal fraud or human error. It is how a breach is publicly characterized, not merely that one occurred, that moves the outcome for the technology executive.", "label": "RESEARCH_FINDING", "ref": "res.banker2019"}, {"text": "The operative distinction in a first notification is not between complete and incomplete but between incomplete and misleading. An omission is material when it changes what the person relying on the notice does next.", "label": "INTERPRETATION"}], "defensible_choices": "A and B are both defensible and disagree; the choice turns on what your clients can do with an uncertain notice. C is defensible only where contracts define a scoping window and the public filer and regulated clients are told today anyway — which is B wearing C's clothes. D is not defensible: the omitted fact is the operative one, and the standard is not whether a statement is true but whether it misleads the person relying on it. Whichever you choose, the test is the same: could you show your notification, your timeline and your internal messages side by side without any of the three contradicting the others?", "trait_dial_readout": "A sits toward urgency and decisiveness, and toward skepticism about your own incomplete picture. B sits toward consensus and operational discipline — the most designed, and the slowest to produce. C sits toward patience and caution, risking the passive end of both. D sits toward unilateral and optimism, the combination this module warns about. On the overlay dials, every option except D is a Resilience posture with a different clock; D is a Control decision about the firm's story rather than about the incident.", "two_sentence_question": "Can you say \"We're going to do this\" at noon with a time box and named kill criteria — and \"I was wrong. Change the plan\" at 18:00, to the same clients you told at noon? And for your option: what risk is Narragansett accepting, priced in clients, contractual exposure and the bank's disclosure timing, and what would change your answer in the next six hours?"}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "Five weeks on. You told all 140 at 11:40 that Thursday. Six clients have since left, four of them from the 129 who turned out to be unaffected; two prospects cited the notification as the reason they signed.\n\nScoping finished at 96 hours and found 14 environments, not 11. Three of the additional clients had been told at 11:40 that there was no evidence of activity in their tenant.\n\nThe bank holding company used your 09:00 notice to start its own assessment, determined materiality on the Friday and filed, describing an incident at a third-party service provider. A regional trade publication named Narragansett on Monday. Two prospects and one insurer have asked for your post-incident report.\n\nAnd on the internal side, the engineer who escalated at 05:50 mentioned to his team lead, who mentioned it to you, that he nearly waited until 07:00: the last time he paged out of hours it turned out to be a misconfigured scanner, and he said he \"felt stupid for a week.\"", "choices": [{"label": "A", "narrative": "Publish a written correction to all 140 covering the 11-to-14 change, and offer the full post-incident report to any client, prospect or insurer who asks for it.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are treating the first notification as a running account rather than a single statement, and are willing to correct a public number upward while the story is still live. The tradeoff is that a second communication re-alarms 126 clients who are fine, and a post-incident report given to prospects becomes a document you cannot control the circulation of. It works where the correction is short and the report is honest about the logging limit; it backfires where the report is written to be shown."}, {"label": "B", "narrative": "Correct the three affected clients directly and privately, and decline the prospects' and insurer's requests for the report on counsel's advice.", "tendency_signals": {"dials": {"aggression_caution": 1, "centralization_decentralization": -1}}, "debrief": "Suggests you distinguish between clients with a right to their own status and third parties with an interest in your paperwork, and are protecting a document that may end up in litigation. The tradeoff is that the three corrections contradict a statement made to 140 people, and a firm that answered 'we can't share that' after building its reputation on early disclosure has taught clients where the openness stops. Defensible where the report genuinely contains other clients' data; corrosive where the reason is that it is unflattering."}, {"label": "C", "narrative": "Make the corrections, then spend the next month on the 05:50 problem: a blameless review of the escalation, and a standing rule that an out-of-hours page which turns out to be nothing is a good outcome, said publicly and by name.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you have identified the sentence that should frighten you most in the whole five weeks — an engineer who nearly did not page — and are treating the near-silence as the more durable finding than the miscount. The tradeoff is that a month spent on internal climate is a month not spent on the client-facing remediation the prospects are asking about, and the rule only means anything the third time it is honored. It works where you can name a false alarm you were glad to receive; it is a slogan where you cannot."}]}, {"id": "fu-B", "after_choice": "B", "situation": "Four weeks on. Tranche one went out at 11:30 Thursday, tranche two at 09:00 Friday, both on schedule. Tranche three did not: scoping in four vendor-hosted client environments needed provider cooperation you could not compel, and the final 99 were notified at 118 hours rather than 96.\n\nYou missed a schedule you published. Two of the 99 have invoked contract-review clauses; one has asked, in writing, why it was in the last tranche.\n\nAnd the criteria are the problem. You wrote them at 07:30 that morning. A three-physician practice with 4,000 patient records was placed in tranche three because of headcount, and it is one of the fourteen environments where indicators were confirmed. Your client-services lead, reading the criteria afterwards, pointed out that they weight contract value in two of five factors.\n\nThe bank was in tranche one and has said nothing since its filing.", "choices": [{"label": "A", "narrative": "Publish the slip and its cause to all 140 before anyone else asks, attach the tiering criteria as written that morning, and name the physician practice mis-tiering as an error.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you understand that a published schedule's value comes entirely from what happens when it is missed, and would rather hand over the criteria than have two clients' lawyers reconstruct them. The tradeoff is that publishing criteria which weight contract value confirms the suspicion the tiering was designed to avoid, and does so to all 140 rather than the two who asked. Strongest where the correction comes with the replacement criteria; worst-of-both where it comes without them."}, {"label": "B", "narrative": "Finish the outstanding vendor-hosted scoping first, then send one combined communication covering the slip, the cause and the final status of every client.", "tendency_signals": {"dials": {"urgency_patience": 1, "decisiveness_inquiry": 1}}, "debrief": "Suggests you would rather explain once, completely, than three times partially — the same instinct that made the staged schedule attractive in the first place. The tradeoff is that the two contract reviews are running now, the mis-tiered practice is entitled to know why it waited, and the interval between the missed date and the explanation is a second unexplained delay stacked on the first. Defensible where the remaining scoping is days; it repeats the original error where it is weeks."}, {"label": "C", "narrative": "Rebuild the tiering criteria this week with client services and counsel — data sensitivity, regulatory clock, and nothing about contract value — publish them as standing policy for all future incidents, and answer the contract reviews with the new policy attached.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "centralization_decentralization": 1}}, "debrief": "Suggests you are converting an improvised judgment into a mechanism, which is the thing that should have existed before Thursday and now can. The tradeoff is that a policy written after the complaint answers the future rather than the past, the mis-tiered practice still waited four days, and clients under review may read the new policy as an admission. It is the strongest structural response and the weakest immediate one."}]}, {"id": "fu-C", "after_choice": "C", "situation": "Four weeks on. The complete notification went out at hour 96 and was, by any professional standard, excellent: per-client status, indicator lists, remediation steps, an honest paragraph on the 30-day logging limit.\n\nIt arrived second. The bank holding company's own security team found the indicators independently on the Friday — day two — from its side of the connection. Its CISO called you that afternoon and asked why she was telling you rather than the reverse; you told her you were scoping. The bank determined materiality that day and filed on the following Wednesday, and its counsel has now asked Narragansett for the detection timeline, specifically the time at which you first confirmed indicators in any environment.\n\nOne physician practice's counsel has sent a litigation-hold letter. Your own counsel has advised that any timeline you provide will be read closely against your MSA's notification language.\n\nYour CEO's position has changed. He now says you should have told everyone on the Thursday.", "choices": [{"label": "A", "narrative": "Give the bank's CISO and counsel the complete detection timeline unedited, including the 09:00 confirmation and the decision to wait, with your reasoning as it was recorded that morning.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you have concluded that the timeline exists whether or not you produce it, and that a client who found the incident herself has earned the version with nothing removed. The tradeoff is that the 09:00 confirmation and the 96-hour notification, set beside each other, are the strongest available argument that you withheld, and you are handing that argument to a public filer's lawyers. It is also the only version that survives a document production intact."}, {"label": "B", "narrative": "Route everything through your counsel: a summary under a common-interest agreement now, the full timeline once the preservation and privilege questions are settled.", "tendency_signals": {"dials": {"aggression_caution": 1, "urgency_patience": 1}}, "debrief": "Suggests you are taking seriously that a live litigation hold changes what an unmediated disclosure costs, which is real advice and not merely defensive. The tradeoff is that a second delay, in response to a question about a delay, is the pattern the bank's counsel is already testing for, and the client relationship the summary protects is the one being spent to protect it. Defensible where the common-interest agreement is offered the same week; indefensible where 'once settled' has no date."}, {"label": "C", "narrative": "Give the timeline in full, and pair it with a contract amendment offered to all 140 clients: a defined scoping window, a maximum notification clock, and a duty to report confirmed indicators within it whatever the scoping status.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "decisiveness_inquiry": -1}}, "debrief": "Suggests you are answering the question and removing the discretion that produced it, which is the only version of this that changes anything for the next incident. The tradeoff is that a maximum clock is a promise made in calm weather and honored in bad, the amendment reads as an admission that the current language was inadequate, and 140 contract amendments is a quarter of work. Strongest where the clock you choose is one you could have met this time; theatre where it is not."}]}, {"id": "fu-D", "after_choice": "D", "situation": "Five weeks on. The framing held for eleven days. Nothing you sent was false: there was a vendor security event, it was under investigation, and the impact statements were accurate.\n\nOn day twelve a law-firm client's own forensic provider completed its review and named Narragansett's remote-management platform as the origin, in a report that went to that firm's managing partner and, from there, to two other clients who share a professional network. Both have now asked you directly whether the vendor was you. Your CEO used the phrase \"our vendor\" in a webinar on day nine, which is on video.\n\nNothing has to be retracted. But the omission is now conspicuous, and the question arriving is not about the incident.\n\nYour scoping is complete: 14 environments, no evidence of exfiltration, all credentials rotated. On the facts, this was a well-handled event. Nobody is asking about the facts.", "choices": [{"label": "A", "narrative": "Correct the record to all 140 in writing today: the origin was your platform, here is the full timeline, and here is why the original notice was framed as it was.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1, "urgency_patience": -1}}, "debrief": "Suggests you have accepted that the omission has become the material fact and that correcting it while you are still the one correcting it is worth more than eleven days of protected positioning. The tradeoff is that explaining why you framed it that way requires a sentence about protecting the firm's commercial claim, which is the sentence the whole framing existed to avoid; and 126 clients who never asked will now learn both things at once. Concealment is priced when it is discovered, and it has been."}, {"label": "B", "narrative": "Answer accurately and fully when asked, client by client, and do not reopen the matter with the ones who have not asked.", "tendency_signals": {"dials": {"aggression_caution": 1, "urgency_patience": 1}}, "debrief": "Suggests you are drawing the line at candour on request, which keeps every individual statement true and every client who cares informed. The tradeoff is that the set of clients who learn the origin is now determined by their professional networks rather than by you, the CEO's webinar remains uncorrected, and the difference between the two groups is the thing a plaintiff or a journalist will describe. It is defensible only if you are content for the record to show that the firm told the ones who worked it out."}, {"label": "C", "narrative": "Correct the record and publish a standing disclosure policy: what Narragansett will say, and within what time, about incidents originating in its own platform — reviewed by counsel, given to every client, and referenced in the correction.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "decisiveness_inquiry": 1}}, "debrief": "Suggests you want the correction to buy something beyond the correction, and are converting a judgment you now regret into a rule that removes the judgment next time. The tradeoff is that a policy issued alongside an admission invites clients to test it immediately, and the policy will be quoted back to you in an incident where the origin is genuinely unclear. Strongest where the policy commits to naming the origin even when it is you; hollow where it commits only to 'timely and appropriate communication.'"}]}], "reflection": "Write out the last incident or near-miss you handled, in three columns: what you knew and when, what you said and when, and what you wrote internally. Then read the three columns across, as a stranger would. Where they diverge, write the sentence you would use to explain the gap — and decide whether you would rather have said it at the time.", "tags": {"dials": ["decisiveness_inquiry", "optimism_skepticism", "unilateral_consensus", "urgency_patience", "innovation_operational_discipline"], "archetypes": ["arch.smb-msp-technology-leader", "arch.post-breach-ciso", "arch.business-risk-ciso", "arch.regulated-industry-cio-ciso"], "stages": ["scale_up", "regulatory_reputation_crisis", "turnaround"], "learn_categories": ["risk", "decision_making", "power_governance"]}, "discretion_level": "high", "research_refs": ["res.banker2019", "res.haislip2021", "res.higgs2016", "res.sec2023", "res.amir2018", "res.kamiya2021", "res.campbell2003", "res.cavusoglu2004", "res.edmondson1996", "res.malmendier2008", "res.chatterjee2011", "res.owens2012", "res.verizon2025"], "meta": {"source_path": "modules/04-confidence-overconfidence-and-the-breach.md#9-leader-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m05-kessler-leaderboard", "title": "Four Reported, Thirty-Five Detected", "module_ref": "m05", "setup": {"company_snapshot": {"name": "Kessler Benefits Administration", "is_fictional": true, "industry": "Third-party administration of self-funded health plans (claims and enrollment processing)", "revenue": "$120M", "headcount": 900, "stage": "mature", "ownership": "private", "governance": "Privately held and profitable, with offices in Hartford, Albany and Manchester, New Hampshire. About 300 employer clients; roughly 600 of the 900 staff touch protected health information daily. The CISO reports to the CIO, who reports to the CEO; there is a board that has been shown the phishing-simulation leaderboard.", "ceo_tenure": "You are the CISO and report to the CIO; the phishing-simulation program is eight months old and was launched at the CIO's suggestion with the CEO's enthusiasm, not yours.", "ceo_mandate": "Protect protected health information across 600 daily handlers and 300 employer clients, and — as of this week — decide what to do about a security-awareness program whose headline number is going the right way while the underlying behavior is not."}, "situation": "You are the CISO of Kessler Benefits Administration, a third-party administrator of self-funded health plans with $120M in revenue and 900 employees across Hartford, Albany and Manchester, New Hampshire. Kessler processes claims and enrollment data for about 300 employer clients; roughly 600 of your staff touch protected health information daily. You report to the CIO, who reports to the CEO. The company is privately held and profitable.\n\nEight months ago, at the CIO's suggestion and with the CEO's enthusiasm, Kessler launched a monthly phishing-simulation program with a leaderboard: results by department on the intranet, the three worst-performing departments named. HR added a \"three clicks and remedial training\" rule and has proposed including simulation results in next year's performance reviews. The CEO has mentioned the leaderboard to the board.\n\nThe numbers look excellent. Reported clicks — employees using the report button on real or simulated lures — have fallen from 61 a month to 4. The CIO presented this as a 93% improvement.\n\nLast week your security operations lead brought you two facts. Gateway telemetry shows link clicks on lures running at 30 to 40 a month, unchanged since the program began. And nine days ago a real credential-phishing email reached about 200 mailboxes in the claims-processing group. The gateway logged eleven clicks. Zero were reported. The SOC found it from the logs 26 hours after the first click and reset the accounts. You do not yet know whether a credential was used.\n\nThe CIO wants to present the program to the board next month as a success; HR's proposal is on the same agenda. You have a one-on-one with the CIO tomorrow and a slot with the CEO in two weeks.", "constraint": "The CIO's one-on-one is tomorrow; your CEO slot is in two weeks; the board presentation and HR's performance-review proposal are on the same agenda next month. You report to the person whose program this is, and the CEO has already told the board the number.", "known": ["Reported clicks fell from 61 a month to 4, and the CIO has presented this to the CEO as a 93% improvement.", "Gateway telemetry shows link clicks on lures running at 30 to 40 a month, unchanged since the program began.", "A real credential-phishing email reached about 200 claims-processing mailboxes nine days ago; eleven clicks were logged and zero reported, and the SOC found it from logs 26 hours later.", "The program carries a named-department leaderboard and a three-clicks-and-remedial-training rule; HR has proposed adding simulation results to performance reviews.", "You report to the CIO, whose program this is, and the CEO has already told the board the headline number."], "unknown": ["Whether a credential from the eleven clicks was used, and what 26 hours of undetected access to a claims environment produced.", "What the eleven claims processors would have needed in order to report, and whether anyone has asked them.", "Whether the CIO can hear that his program made the company less safe, or will hear it as an attack.", "How much of the silence is the leaderboard and how much is the implicit rules people brought with them from previous jobs.", "Whether the CEO's enthusiasm survives learning that the number he repeated to the board was measuring silence."], "discretion_level": "medium"}, "choices": [{"label": "A", "narrative": "Keep the program and the leaderboard, and add a positive layer: monthly recognition for the departments with the highest report rates and a small reward for every reported click.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "optimism_skepticism": -1}, "tendencies": {"N": "high", "I": "low", "O": "low"}, "maturity_levels": [1]}, "tradeoffs": "Suggests a consensus setting and optimism about the existing program: the leaderboard stays, the CIO and CEO keep their story, reporting gets an incentive. Rewards sit among the weakest levers in the compliance evidence, and this one competes with a sanction still in force — an employee weighing a small recognition against a named place on the leaderboard will not find it a hard calculation.", "context_that_favors": "A genuinely high-trust culture in which the leaderboard was never read as a threat.", "context_that_punishes": "Exactly the organization described — one where eleven people clicked and none reported.", "strong_ceo_would_evaluate": "What the eleven claims processors would have needed in order to report, and whether a reward answers it.", "second_order_effects": "The headline number survives, the ratio stays low, and the next real lure is found by the gateway again — perhaps not in 26 hours.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Suspend simulations for two quarters. Announce an amnesty — no click, past or future, will be reported to managers — and replace the leaderboard with one published metric: the company-wide reported-to-detected ratio.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "decisiveness_inquiry": -1, "centralization_decentralization": 1}, "tendencies": {"K": "high", "I": "high", "C": "high"}, "maturity_levels": [3, 4]}, "tradeoffs": "Skepticism of the program, decisiveness, and willingness to spend political capital: the CIO's story is retired and the CEO's leaderboard removed. Two quarters without simulations loses a measurement, and an abrupt amnesty can read to a board as an admission the program was harmful — which it was, but framing matters.", "context_that_favors": "A CEO who can hear 'the number you liked was measuring silence' and a CIO secure enough not to take it personally.", "context_that_punishes": "A CIO who does take it personally, and a board that reads a withdrawn program as a failure of the security function rather than of the design.", "strong_ceo_would_evaluate": "Framing the amnesty as a redesign, and bringing the error-reporting evidence in plain language: the better units reported more, not fewer.", "second_order_effects": "Publishing a ratio commits you to a number that will look bad for a while — which is the point, and a test of whether you can say 'I was wrong about that risk' in front of the people who set the program up.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Keep the simulations but end the leaderboard and the three-strikes rule, report only aggregate rates, and tell the CIO tomorrow that the board presentation should show both numbers — reported and detected — with the eleven-click incident as the case.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "optimism_skepticism": 1, "centralization_decentralization": 1}, "tendencies": {"K": "high", "N": "high", "P": "high"}, "maturity_levels": [3]}, "tradeoffs": "A mid-dial setting: measurement continues, the blame layer goes, and the board sees the truth in the CIO's own presentation. It is the choice most learners pick once they have read the module, so check whether you chose it for the situation or the lesson. It depends entirely on tomorrow's conversation, because the CIO must agree to present a worse-looking story to a board already told a better one.", "context_that_favors": "A CIO who values being right over being consistent.", "context_that_punishes": "A CIO who hears 'your program made us less safe' as an attack — at which point C collapses into A or E.", "strong_ceo_would_evaluate": "Preparing the one-on-one as a review rather than a confrontation: telemetry, incident, ratio, change, and the sentence 'we both got this wrong.'", "second_order_effects": "If it works, the CIO becomes the program's defender rather than its casualty, which is worth more than the metric.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Make reporting mandatory: any suspected click reported within one hour, with the same remedial-training consequence for non-reporting that now applies to clicking.", "tendency_signals": {"dials": {"centralization_decentralization": -1, "innovation_operational_discipline": 1, "unilateral_consensus": -1}, "tendencies": {"M": "overuse", "G": "high", "K": "low"}, "maturity_levels": [1]}, "tradeoffs": "A control instinct: the problem is non-compliance, so make reporting compliance. This is the compliance evidence in reverse — a sanction for not reporting sits on the same weak lever as a sanction for clicking — and it adds a new implicit rule, because the employee unsure whether they clicked must decide whether being wrong about that is also punishable.", "context_that_favors": "Almost nothing here, though a regulated-industry leader could argue an investigator will want a documented reporting requirement.", "context_that_punishes": "A workforce that has already learned what happens to people whose names appear on a list.", "strong_ceo_would_evaluate": "Whether this is a climate problem or a policy problem, because a policy answer to a climate problem produces compliance without information.", "second_order_effects": "Reported clicks may rise briefly, and the reports will arrive late, minimal and pre-lawyered.", "follow_up_ref": "fu-D"}, {"label": "E", "narrative": "Go directly to the CEO before the CIO meeting, with the telemetry and the incident, and ask for the performance-review proposal to be withdrawn.", "tendency_signals": {"dials": {"urgency_patience": -1, "unilateral_consensus": -1}, "tendencies": {"I": "high", "A": "high", "N": "low"}, "maturity_levels": [2]}, "tradeoffs": "Urgency and a unilateral setting, and a judgment that the performance-review proposal is the real emergency: once click results enter reviews, the climate is fixed for years. The tradeoff is the reporting line — going to the CEO first with evidence that the CIO's program failed is decisive or fatal depending on the CIO.", "context_that_favors": "A deadline the CIO cannot be trusted to meet, and a proposal that would be irreversible once in the review template.", "context_that_punishes": "A CIO who has done nothing to deserve it — and it is the 'don't bypass the boss' rule you are asking 900 employees to ignore while you honor it.", "strong_ceo_would_evaluate": "Whether tomorrow's meeting can achieve the same outcome with the CIO as co-author.", "second_order_effects": "E may win the argument and cost the relationship the whole information-environment stack depends on.", "follow_up_ref": "fu-E"}], "debrief_common": {"fit_analysis": "A mature, profitable TPA where 600 people handle protected health information daily and the security leader reports to the executive whose program is the problem. Discretion is medium and largely social: you cannot cancel the CIO's initiative, but you own the interpretation of the number, and the interpretation is the whole decision. The situation is a clean information-environment failure — a metric that fell because reporting fell, a sanctioned population, and eleven people who clicked a real lure and told nobody — and it is being read as a success by everyone above you. Personality × Power runs in an unfamiliar direction here: the CISO has the least authority and the most accurate picture, which is the position in which how you say something matters as much as whether you are right. Note also that the module's evidence cuts against the levers a security leader controls most directly; sanctions and rewards are weak, and the strong levers are values and norms you can only reach through other people.", "research_that_bears": [{"text": "Nursing units with better team climate and more active manager coaching reported more detected errors, not fewer — the correlation with coaching was r = .74 — which is why a falling incident count is ambiguous evidence rather than good news.", "label": "RESEARCH_FINDING", "ref": "res.edmondson1996"}, {"text": "Pooled across 95 studies, employees' values and norms were far more strongly associated with security-policy compliance than punishment or rewards, which sat among the weakest levers.", "label": "RESEARCH_FINDING", "ref": "res.cram2019"}, {"text": "Implicit voice theories — 'don't embarrass the boss,' 'you need solid data first,' 'don't bypass' — predicted silence over and above personality and context, even where the environment was objectively safe. Removing the sanction is necessary and not sufficient.", "label": "RESEARCH_FINDING", "ref": "res.detert2011"}, {"text": "The reported-to-detected ratio is the instrument this situation lacks: a single published number whose denominator does not depend on anyone's willingness to speak. It will look worse before it looks better, which is what makes it worth publishing.", "label": "FRAMEWORK"}], "defensible_choices": "C is the strongest first move and B the strongest program design; the mature sequence is C tomorrow, with B's ratio and amnesty as the redesign the CIO co-presents. A is defensible only as a bridge if the sanctions go the same day. D is hard to defend. E only after C has failed, or if the review deadline genuinely arrives first.", "trait_dial_readout": "A sits at consensus and optimism. B at skepticism, decisiveness and a deliberate move toward decentralization — the reporting decision handed back to employees. C mid-dial on decisiveness↔inquiry with a consensus setting toward the CIO. D at centralization and control. E at urgency and unilateral. On the overlay dials, A and D sit toward Control; B and C toward Enablement.", "two_sentence_question": "Which choice makes it easiest, six months from now, to say \"We're going to do this\" — Kessler's people will report the click — and which would force \"I was wrong. Change the plan\" if the ratio does not move? And can you say to the CEO in two weeks: \"Yes — the leaderboard raised awareness; here is the risk it created, priced at 26 hours of undetected credential exposure across the claims group\"?"}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "Ten weeks on. The recognition layer launched in month one and worked, in a fashion. Reported clicks have risen from 4 a month to 9. Gateway telemetry is unchanged at 31 to 38.\n\nThe leaderboard is still there, the three-strikes rule is still in force, and HR's proposal survived the board meeting: simulation results are now in the draft performance-review template for next year, in a section headed \"security awareness.\"\n\nAnd your security operations lead has brought you something else. A claims supervisor in Albany told him, in confidence, that her department tracks its recognition standing week to week, and that on two occasions people have reported a colleague's click rather than their own — once to protect the department's position, once as retaliation in a dispute that has nothing to do with security. Both reports were accurate. Neither came from the person who clicked.\n\nThe CEO has repeated the improvement in an all-hands. Your CIO is pleased and has asked you to write the section of next quarter's board pack about it.", "choices": [{"label": "A", "narrative": "Recommend killing the leaderboard and the recognition scheme together, keeping only the reported-to-detected ratio, and tell the CEO plainly that the reward produced attribution rather than reporting.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "centralization_decentralization": 1}}, "debrief": "Suggests you have read the two Albany reports as a design outcome rather than as two people behaving badly, which is the harder and more useful reading. The tradeoff is that you are asking the CEO to retire, in one conversation, both the number he repeated at an all-hands and the layer you yourself proposed ten weeks ago. It works where you own the recommendation as your own error; it fails where it arrives as new evidence about someone else's program."}, {"label": "B", "narrative": "Keep the recognition, remove the three-strikes sanction immediately, and negotiate with HR that reviews may credit reporting but must never record clicking.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "urgency_patience": 1}}, "debrief": "Suggests you are trying to keep everything that has any constituency while removing the one element the evidence is clearest about, and are taking the review template as a fact to be shaped rather than fought. The tradeoff is that a review line crediting reports in a department that reports each other's clicks makes the Albany problem worse, not better, and the leaderboard survives untouched. Defensible as a staged retreat with a date; corrosive as a settlement."}, {"label": "C", "narrative": "Take the Albany account to HR as the case against the review proposal, including which department it came from, so the example is concrete enough to act on.", "tendency_signals": {"dials": {"unilateral_consensus": -1, "urgency_patience": -1}}, "debrief": "Suggests you judge that an abstract argument will lose to a template already drafted and that only a named instance moves HR. The tradeoff is that the supervisor spoke to your SOC lead in confidence, the department is small enough to identify, and the first person in Kessler to tell the security function something uncomfortable will learn what happened to her. You may win the review argument and close the channel that produced the evidence."}]}, {"id": "fu-B", "after_choice": "B", "situation": "Twelve weeks on. The amnesty was announced by email and repeated by you at three site meetings. Simulations are suspended. The reported-to-detected ratio is published monthly on the intranet: it opened at 4 reported against 35 detected, and last month read 19 against 33.\n\nThat is a real improvement and it does not look like one on a slide. The CEO has asked, twice, why a 93% improvement reversed into a number five times worse. The audit committee saw the new metric in the quarterly pack and one member asked whether \"something happened.\"\n\nTwo further consequences. With simulations suspended you have lost the controlled denominator; gateway telemetry now supplies it, and your SOC lead has flagged that it counts clicks on anything the gateway scores as a lure, which is a moving definition. And HR quietly dropped the performance-review proposal — and, in the same budget round, cut the security-awareness line entirely on the grounds that the program is suspended.", "choices": [{"label": "A", "narrative": "Restart simulations next month without a leaderboard or sanctions, purely to restore a stable denominator, ending the suspension a quarter early.", "tendency_signals": {"dials": {"decisiveness_inquiry": -1, "urgency_patience": -1}}, "debrief": "Suggests you have decided a measurement you can defend matters more than the full length of a commitment you made for reasons that have partly been served. The tradeoff is that you told 900 people the simulations would stop for two quarters, and an early restart — however benign the redesign — is the security function breaking its own promise about a program built on promises. Defensible where you say plainly why the date moved; expensive where the amnesty is what made the ratio move in the first place."}, {"label": "B", "narrative": "Hold the suspension for the full two quarters as announced, and publish the gateway-telemetry denominator with its definition and its instability stated in the same paragraph.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "urgency_patience": 1}}, "debrief": "Suggests you are keeping the commitment and treating the measurement's weakness as something to disclose rather than to fix by breaking it. The tradeoff is that a metric you have publicly labelled unstable is a difficult thing to take to an audit committee already asking whether something happened, and the awareness budget is gone in the meantime. Strongest where the disclosure of the denominator's limits is itself the demonstration you want; weakest where the number becomes uninterpretable."}, {"label": "C", "narrative": "Ask for the board slot yourself, explain what the 93% was measuring, show the eleven-click incident as the case, and ask for the awareness budget back with the ratio as the program's metric.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "aggression_caution": -1}}, "debrief": "Suggests you would rather have the argument in the room where the number is being interpreted than let the audit committee interpret it without you. The tradeoff is that you are asking a board to accept that a metric it was given for eight months was measuring silence, which reflects on the CIO who presented it and on the CEO who repeated it; both will be in the room. It is the clearest available demonstration of the behavior the whole program is trying to produce, and it costs the most."}]}, {"id": "fu-C", "after_choice": "C", "situation": "Eight weeks on. The one-on-one went better than you expected. The CIO listened, said the sentence about both of you getting it wrong before you did, and co-presented to the board: both numbers, the eleven-click incident, the leaderboard retired, three strikes withdrawn. HR pulled the performance-review proposal the following week. Two board members said it was the most useful security item they had seen.\n\nThen a director asked the CIO directly whether the 26 hours could happen again, and the CIO said no.\n\nIt cannot be made true by anything you have. And eight weeks after the sanctions came off, the reported-to-detected ratio has moved from 4-in-35 to 9-in-34 — real, small, and nothing like enough. Your SOC lead's read, from three conversations in the claims group, is that people believe the sanctions are gone and still believe that reporting a click puts your name somewhere.\n\nThe next board pack is in five weeks. The CIO has asked you to write the follow-up item and has said, warmly, that he would like it to show progress.", "choices": [{"label": "A", "narrative": "Correct the CIO's answer to the board in writing before the next meeting — with him as co-author if he agrees, and without him if he does not.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you regard an uncorrected 'no' to a board as a liability that grows quietly, and that the eight weeks of goodwill are exactly the capital to spend on it. The tradeoff is that the CIO has just done the hardest thing you asked of him and the reward is being corrected in front of the same directors, and the without-him clause is the bypass you declined to make in the original decision. Strongest where you offer him the pen; weakest where the correction is longer than the error."}, {"label": "B", "narrative": "Leave the answer alone and spend the quarter making it closer to true: response drills in the claims group, direct lines from claims supervisors to the SOC, and a published time-to-detect.", "tendency_signals": {"dials": {"hands_on_delegation": -1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you are treating an overcommitment as an engineering target rather than a governance problem, and would rather shorten 26 hours than relitigate a sentence. The tradeoff is that the board's belief remains wrong in the interval, the next incident will be measured against 'no' rather than against your drills, and the CIO is left holding a promise he does not know is exposed. Defensible where the detection work genuinely closes most of the gap this quarter; evasive where it does not."}, {"label": "C", "narrative": "Take the flat ratio to the CIO as a shared problem and design phase two together — the amnesty, blameless review of the eleven clicks, and a claims-group listening exercise — for him to present.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "decisiveness_inquiry": 1}}, "debrief": "Suggests you have understood that the ratio did not move because removing a sanction does not remove a rule people brought with them, and that the CIO's new standing is the asset that can reach the claims group. The tradeoff is that a board expecting progress will receive a second redesign, 'show progress' was a request you are declining, and the 26-hour answer stays uncorrected. It is the strongest program move and does nothing about the sentence in the minutes."}]}, {"id": "fu-D", "after_choice": "D", "situation": "Ten weeks on. The mandate went out with HR's signature: any suspected click reported within one hour, non-reporting treated the same way clicking is.\n\nReported clicks went to 27 in the first month and fell to 11 in the third. Gateway telemetry is unchanged at 29 to 36. The reports themselves have changed character: most now read in full, \"possible click, unsure, no further detail,\" and three in the last month came through a union representative rather than from the individual. Two people reported clicks the gateway shows they did not make.\n\nYour SOC now spends roughly six hours a week triaging low-information reports. Three weeks ago a genuine credential lure sat in that queue for nine hours behind fourteen \"possible click, unsure\" entries before an analyst opened it.\n\nHR considers the program a success: participation is up and the policy is documented. Your CIO has asked whether the mandate should be extended to the Manchester office, which is not currently in scope.", "choices": [{"label": "A", "narrative": "Withdraw the mandate, announce an amnesty, and say publicly — to staff and to the CIO — that the policy was your error and what it cost.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "decisiveness_inquiry": -1}}, "debrief": "Suggests you have concluded that a policy answer to a climate problem produced exactly the compliance-without-information the evidence predicts, and that the fastest repair is to say so in your own name. The tradeoff is that HR has documented the program as a success, withdrawing a rule ten weeks after issuing it costs the security function credibility with people who now have to be told the opposite, and the union involvement makes the withdrawal a negotiation. It is the only option that addresses the nine hours."}, {"label": "B", "narrative": "Keep the mandate and fix the quality problem instead: automated triage, a stated rule that a no-detail report is a good report, and an SLA that puts gateway-confirmed lures ahead of the queue.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "centralization_decentralization": -1}}, "debrief": "Suggests you are separating the volume problem from the policy problem and treating the nine hours as a triage failure your team owns. The tradeoff is that the reports are minimal because the people writing them are protecting themselves, which automation does not change, and the two false self-reports are a signal about fear rather than about tooling. Defensible as the immediate fix; it leaves the mechanism that produced the queue running."}, {"label": "C", "narrative": "Narrow the mandate to the claims-processing group where PHI exposure is highest, drop it everywhere else including Manchester, and monitor whether the two populations diverge.", "tendency_signals": {"dials": {"centralization_decentralization": 1, "aggression_caution": 1}}, "debrief": "Suggests you want to keep the documented reporting requirement where an investigator would most expect it while removing it where it is doing nothing but generating noise, and are willing to run the comparison. The tradeoff is that you are concentrating the sanction on the group that already went silent through eleven clicks, and the divergence you would measure takes two quarters you may not have. Coherent as an experiment; hard to defend as a fairness proposition to the claims group."}]}, {"id": "fu-E", "after_choice": "E", "situation": "Six weeks on. The CEO acted within the day: HR's performance-review proposal is dead, the leaderboard is gone, and the three-strikes rule was suspended pending review. On the merits you were right and the outcome is what the module would have recommended.\n\nThe CIO found out from the CEO. He has been entirely correct with you since and entirely cold. You are no longer copied on architecture decisions or vendor renewals; two came to you after they were signed. He told the CHRO, in a sentence that got back to you, that he learned about his own program's failure from his boss.\n\nAnd something else has started. Two platform engineers who used to raise security findings through the CIO's team now message you directly, because it is faster and because they saw what happened. Your SOC lead thinks this is an improvement. It is also, precisely, the bypass you asked 900 employees not to practice, appearing in your own organization six weeks after you modeled it.\n\nThe program redesign still needs the CIO's platform team to build most of it.", "choices": [{"label": "A", "narrative": "Go to the CIO, name the bypass as yours without qualification, and propose that he owns the redesign and presents it — with you supplying the telemetry and staying out of the room.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you have decided the relationship is the asset the whole stack depends on and are willing to hand back the authorship to repair it. The tradeoff is that an apology arriving with a proposal attached can read as a transaction, giving him the presentation makes the redesign depend on a person who currently has reason to slow it, and the two engineers messaging you are not addressed. It is the only option that treats the bypass as your problem rather than as a fact of the environment."}, {"label": "B", "narrative": "Ask the CEO to formalize what has happened informally: a direct escalation line from the CISO for security matters, so the bypass becomes a documented structure rather than a habit.", "tendency_signals": {"dials": {"centralization_decentralization": -1, "unilateral_consensus": -1}}, "debrief": "Suggests you think a channel that exists in practice should exist on paper, and that the reporting line was the underlying problem the incident merely exposed. The tradeoff is that you would be asking for structural reward for going around your boss, six weeks after doing it, from the executive who benefited; the CIO will read it exactly that way, and so will everyone watching. Defensible where the escalation path is written for the role rather than for you; unrecoverable where it is not."}, {"label": "C", "narrative": "Send the engineers' findings back through the platform team, restore the channel even though it is slower, and tell them plainly why you are doing it.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "urgency_patience": 1}}, "debrief": "Suggests you are applying the rule to yourself first and accepting a slower path in order to make the rule mean something, which is the only version of this that 900 people could be asked to follow. The tradeoff is that findings will now sit with a team whose leader is not speaking to you, the engineers learn that the faster route was closed by the person they trusted, and nothing about the CIO relationship is repaired by the gesture alone. Coherent, costly, and incomplete without A."}]}], "reflection": "Write down the last number you presented that went in the direction you wanted. Then write down what would have to be true for that number to have improved because people stopped telling you things — and what evidence, that you do not currently collect, would tell the two apart. Then write the name of the last person who brought you bad news, and what happened to them.", "tags": {"dials": ["decisiveness_inquiry", "unilateral_consensus", "optimism_skepticism", "centralization_decentralization", "urgency_patience"], "archetypes": ["arch.regulated-industry-cio-ciso", "arch.business-risk-ciso", "arch.technical-ciso", "arch.post-breach-ciso"], "stages": ["mature", "turnaround"], "learn_categories": ["leadership", "organizational_design", "decision_making"]}, "discretion_level": "medium", "research_refs": ["res.edmondson1996", "res.edmondson1999", "res.milliken2003", "res.detert2011", "res.ou2014", "res.ou2018", "res.owens2012", "res.owens2016", "res.cram2019", "res.ashenden2013", "res.tourish2006", "res.higgs2016", "res.amir2018"], "meta": {"source_path": "modules/05-humility-and-the-reporting-culture.md#9-leader-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m06-two-contexts-migration", "title": "One Migration, Two Companies", "module_ref": "m06", "setup": {"company_snapshot": {"name": "Northlake Physician Partners", "is_fictional": true, "industry": "Physician-practice management — 38 clinics across New York, New Jersey and Connecticut, HIPAA-covered", "revenue": "$410M", "headcount": 2900, "stage": "mature", "ownership": "pe_backed", "governance": "Sponsor-controlled with 5.2x leverage and a covenant test in three quarters; an add-on acquisition is due to close in ten months and the target will be onboarded to the new platform. This snapshot is Context 2 of a paired scenario. Context 1 — Calloway & Reyes, a partner-owned engineering and consulting firm, $140M revenue, 800 employees, no debt, 21% margin, cash equal to eleven months of operating expenses, municipal and utility clients requiring security attestations but no direct regulator, sector-base-rate threat level — is set out in full in the situation and carries the same decision.", "ceo_tenure": "You hold the combined CIO and CISO chair in both contexts; the scenario varies the company, not your tenure.", "ceo_mandate": "Get the core estate — ERP, document management, file services and the identity platform — out of a co-located data center whose lease ends in nine months, and decide whether the security controls lead the migration or follow it."}, "situation": "This simulation presents one decision in two contexts. Choose for each before reading the debrief.\n\n**The decision.** You are the CIO and CISO. Your company runs its core estate — ERP, document management, file services and the identity platform — in a co-located data center whose lease ends in nine months. A migration partner has been selected; the plan is a seven-month lift-and-shift to a public cloud, followed by a \"modernize\" phase. Your security lead has flagged that phishing-resistant MFA, privileged-access management and immutable backups are all scheduled for the modernize phase — after the workloads move. The partner says pulling them forward adds two months. The landlord will extend the lease at a 30% premium.\n\n**Context 1 — Calloway & Reyes.** An engineering and consulting professional-services firm: $140M revenue, 800 employees, partner-owned, no debt, 21% margin, cash equal to eleven months of operating expenses. Clients are municipalities and utilities whose contracts require security attestations but no regulator supervises the firm directly. The partners are patient about timelines and anxious about client data. Threat level is the sector base rate; nothing specific.\n\n**Context 2 — Northlake Physician Partners.** A PE-backed physician-practice management company: $410M revenue, 2,900 employees, 38 clinics across New York, New Jersey and Connecticut, HIPAA-covered, 5.2x leverage with a covenant test in three quarters. In the last six weeks a ransomware campaign has hit four physician groups in the region; two have disclosed publicly. The sponsor wants the migration complete before an add-on acquisition closes in ten months, because the target will be onboarded to the new platform.", "constraint": "The lease ends in nine months against a seven-month plan. Pulling the three security controls forward adds two months by the partner's estimate; the landlord will extend at a 30% premium. In Context 2 there is also a covenant test in three quarters and an add-on acquisition closing in ten months whose target is meant to land on the new platform.", "known": ["The core estate — ERP, document management, file services and identity — is in a co-lo whose lease ends in nine months; the selected plan is a seven-month lift-and-shift with a later modernize phase.", "Phishing-resistant MFA, privileged-access management and immutable backups are all scheduled after the workloads move, and the security lead has flagged it.", "The partner says pulling those controls forward adds two months; the landlord will extend the lease at a 30% premium.", "Context 1: partner-owned, no debt, 21% margin, eleven months of cash, client attestations but no direct regulator, no specific threat signal.", "Context 2: PE-backed, HIPAA-covered, 5.2x leverage, covenant test in three quarters, an add-on closing in ten months, and four regional physician groups hit by ransomware in six weeks with two public disclosures."], "unknown": ["Whether the partner's two-month estimate reflects the work or the partner's own resourcing schedule.", "Whether 'non-sensitive workloads' exists as a category in either company, which no data inventory has yet tested.", "Whether the regional ransomware activity is a campaign against the sector or a coincidence, and whether it will still be running in three months.", "Whether the partners in Context 1, or the sponsor in Context 2, would accept a priced slip if it were put to them in writing.", "How long the migration window actually widens the attack surface, and by how much, relative to the estate you are leaving."], "discretion_level": "high"}, "choices": [{"label": "A", "narrative": "Proceed as planned: lift-and-shift in seven months, hardening in the modernize phase, lease ends on schedule.", "tendency_signals": {"dials": {"aggression_caution": -1, "urgency_patience": -1, "optimism_skepticism": -1}, "tendencies": {"C": "high", "B": "high", "K": "low"}, "maturity_levels": [1]}, "tradeoffs": "Suggests aggression, urgency and optimism about the partner's plan: the lease is the deadline, the hardening comes later, and the risk is accepted implicitly rather than priced. In Context 1 it is defensible but careless — a debt-free firm with patient partners has no reason to accept a window in which the identity platform moves before it is hardened, and the extension premium is affordable.", "context_that_favors": "A quiet threat environment, a partner whose sequencing has a technical reason you have tested, and a lease with no affordable extension.", "context_that_punishes": "Context 2 hardest: an active campaign against your sector, PHI on every workload, and a migration that temporarily widens the attack surface while backups are not yet immutable.", "strong_ceo_would_evaluate": "Why the plan puts the controls last, and whether the partner's sequence serves the partner's schedule rather than the risk.", "second_order_effects": "In both contexts A teaches the security lead that flagging a risk changes nothing — a reporting-culture cost that outlasts the migration by years.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Re-sequence: make identity hardening and immutable backups gate one, before any workload moves; accept the two-month slip and a short lease extension.", "tendency_signals": {"dials": {"aggression_caution": 1, "innovation_operational_discipline": 1, "urgency_patience": -1}, "tendencies": {"M": "high", "F": "high", "D": "high"}, "maturity_levels": [3, 4]}, "tradeoffs": "Suggests caution moved deliberately with urgency preserved: the migration continues, the controls lead it, the slip is accepted and priced. In Context 1 it is close to the right answer. In Context 2 it is probably the strongest single choice and the hardest to hold — two months of slip against a ten-month deal deadline and a three-quarter covenant window leaves no margin, and the sponsor will push.", "context_that_favors": "A balance sheet that can absorb the extension premium, or a threat signal specific enough to make the slip arguable to a sponsor.", "context_that_punishes": "A deal calendar with no slack, where two months of slip consumes the entire buffer before the covenant test.", "strong_ceo_would_evaluate": "Whether identity and backups can be hardened in six weeks rather than eight by narrowing scope — and bringing the sponsor the Risk Corollary in writing rather than a request for time.", "second_order_effects": "Hardening during a threat wave is proactive investment of the kind associated with lower failure rates, and it is visible in diligence when the acquisition closes.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Pause the migration. Spend the next six months hardening the on-premises estate, negotiate a twelve-month lease extension, and migrate next year.", "tendency_signals": {"dials": {"aggression_caution": 1, "urgency_patience": 1, "optimism_skepticism": 1}, "tendencies": {"B": "low", "M": "overuse", "J": "low"}, "maturity_levels": [2]}, "tradeoffs": "Suggests caution, patience and skepticism of the whole program. In Context 1 it is defensible and expensive: a year on a 30% premium, an on-premises estate hardened only to be abandoned, and partners who were patient about a slip becoming impatient about a year. In Context 2 it is the choice that gets a CIO replaced.", "context_that_favors": "A migration partner or design that is genuinely unsafe, where the pause is about the plan rather than about the executive's default.", "context_that_punishes": "A deal cycle: the sponsor's timeline is missed, the acquisition target is onboarded to the old estate, and the hardening spend goes to systems that will be migrated later at a second cost.", "strong_ceo_would_evaluate": "Whether the on-premises hardening is spending on a platform the firm is leaving — and whether the reason for the pause is the plan or the temperament.", "second_order_effects": "This is the caution rung of the ladder — never breached because nothing was ever deployed — and the organization learns that the security function is where programs go to wait.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Split the estate: move non-sensitive workloads now on the original schedule; hold the sensitive systems on-premises under a lease extension until hardening is done; contract 24×7 managed detection for the migration window.", "tendency_signals": {"dials": {"urgency_patience": -1, "hands_on_delegation": 1, "centralization_decentralization": 1}, "tendencies": {"H": "high", "J": "high", "G": "low"}, "maturity_levels": [2, 3]}, "tradeoffs": "Suggests a mid-dial setting: aggression on the low-risk workloads, caution on the sensitive ones, resilience bought for the window. It is the choice most learners pick once told the answer is calibration, so check the mechanics. In Context 1 it works at the cost of running two estates; in Context 2 it depends entirely on whether 'non-sensitive' exists in a physician-practice company.", "context_that_favors": "A company with the engineering capacity to operate two estates, and a data inventory that shows a genuine low-sensitivity tier.", "context_that_punishes": "An estate where the ERP holds employee data and the document system holds clinical correspondence, so the split leaves almost everything on-premises — which is C with extra cost.", "strong_ceo_would_evaluate": "The split against a data inventory before proposing it, and whether managed detection during the window is resilience or a purchase that feels like it.", "second_order_effects": "D done honestly is a phased B; D done to avoid choosing is A for the easy half and C for the hard half.", "follow_up_ref": "fu-D"}], "debrief_common": {"fit_analysis": "One decision, two companies, and the whole point is the distance between your two answers. Discretion is high in both contexts — the sequencing is genuinely yours — but the constraints that should move it are different in kind rather than in degree: Context 1 varies the balance sheet and the governance, Context 2 varies the threat level, the regulatory posture and the deal cycle all at once. The module's claim is that these four contextual signals should be read separately rather than collapsed into one sense of danger, and the simulation is built so that a leader running on a single setting will answer identically in both. If your choices were the same in both contexts, that is the finding: the situation moved three signals and your setting did not. If they differed in the direction the constraints point, you moved the dial. Note that neither pole of any dial is a virtue here — A is careless in Context 1 and reckless in Context 2, and C is expensive in Context 1 and career-ending in Context 2, for reasons that have nothing to do with security.", "research_that_bears": [{"text": "In US healthcare, security investment made before a failure was associated with lower subsequent failure rates and was more cost-effective than investment made after one — the argument for hardening ahead of the move rather than after it.", "label": "RESEARCH_FINDING", "ref": "res.kwon2014"}, {"text": "Across more than 5,000 hospitals, the same security investment was associated with fewer breaches only where adoption was substantive rather than symbolic; symbolic adoption was associated with a higher likelihood of breach. A managed-detection contract nobody has the capacity to act on is the migration-window version of that finding.", "label": "RESEARCH_FINDING", "ref": "res.angst2017"}, {"text": "In the 2025 DBIR's non-random sample of 12,195 confirmed breaches, ransomware was present in 44% and third parties were involved in 30%. A base rate that informs a probability estimate for a sector under active campaign; it does not set one, and it is not a forecast for either company.", "label": "RESEARCH_FINDING", "ref": "res.verizon2025"}, {"text": "The two overlay dials map onto the eight: Control↔Enablement is centralization↔decentralization plus caution↔aggression; Prevention↔Resilience is operational discipline↔innovation plus patience↔urgency. The context-sensitivity score is the distance between your two answers and whether it points the way the constraints do.", "label": "FRAMEWORK"}], "defensible_choices": "In Context 1, B, C and D are all defensible; A is the careless choice a patient balance sheet makes unnecessary. In Context 2, B is the strongest, D is defensible if the data inventory supports the split, A is the choice the threat level punishes, and C is the choice the deal cycle punishes. If your choices were the same in both contexts, that is the finding. If they differed in the direction the debrief describes, you moved the dial.", "trait_dial_readout": "A sits at aggression, urgency and optimism. B sits at caution moved deliberately with urgency held. C sits at caution, patience and skepticism. D sits mid-dial on aggression↔caution with a resilience purchase. On the overlays, A is Enablement without a priced risk; B is Prevention-first with the migration as the Resilience move; C is Prevention at the expense of the program; D is a Resilience buy over a split Control decision.", "two_sentence_question": "In Context 1, which choice lets you say \"We're going to do this\" to the partners and still leaves room for \"I was wrong\" if the migration slips? In Context 2, which choice lets you say to the sponsor \"Yes — and here is the risk we are accepting, priced,\" and which would force you to say \"I was wrong about that risk. Change the control\" at the covenant test?"}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "Context 2, fourteen weeks on. Month four of seven. Four workload groups have moved, the identity platform among them. Backups in the new tenant are versioned but not yet immutable; privileged-access management is still a modernize-phase line item. The regional ransomware activity has gone quiet, which your security lead points out is not the same as gone.\n\nOn Tuesday your detection provider matched a credential from a public dump — the result of an unrelated breach at a DevOps tooling vendor — to an engineer at your migration partner. That account holds standing administrative rights in your new tenant, granted at project start and never scoped down. There is no evidence it has been used against you, and the partner says the password was unique to the vendor and was rotated in March.\n\nMeanwhile the sponsor has accelerated: diligence on the add-on has begun, and the target's CTO has formally requested Northlake's security architecture documentation, which currently describes controls that do not yet exist.", "choices": [{"label": "A", "narrative": "Stop new workload moves for three weeks: rotate and re-federate every partner identity, impose just-in-time elevation, then resume the migration on a revised plan.", "tendency_signals": {"dials": {"aggression_caution": 1, "urgency_patience": 1}}, "debrief": "Suggests you have decided that standing partner admin in a half-built tenant is the finding, and that three weeks now is cheaper than the same work after something happens. The tradeoff is that a three-week stop against a seven-month plan with a covenant test in sight is the slip you declined to take at the start, arriving anyway and without the benefit of having been chosen; and just-in-time elevation across a partner's whole team mid-migration is friction the partner will bill for. Defensible where the exposure is real; it is the original B decision made late where it is not."}, {"label": "B", "narrative": "Rotate the credential, keep the migration moving, and pull immutable backups forward out of the modernize budget as the one control you will not carry into month five.", "tendency_signals": {"dials": {"urgency_patience": -1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you are triaging: one control moved forward, the schedule preserved, the specific credential handled. The tradeoff is that you are choosing the control that limits damage over the ones that limit access, in a scenario whose trigger was an access problem, and 'we pulled one of three forward' is a difficult sentence in diligence. Strongest where immutable backups genuinely are the control that changes the worst outcome; weakest where it is simply the cheapest of the three."}, {"label": "C", "narrative": "Give the target's CTO the architecture exactly as it stands — controls in place, controls deferred, and the dates — and let the deal price it.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you would rather have the deferred controls priced by a counterparty now than discovered by one later, and are treating diligence as the mechanism that makes an implicit risk acceptance explicit. The tradeoff is that the sponsor did not ask you to introduce a security qualification into its own transaction, the target's CTO will share it with advisers you do not control, and the document dates the decision you made in month one. It converts an unpriced risk into a priced one at someone else's negotiating table."}]}, {"id": "fu-B", "after_choice": "B", "situation": "Context 2, sixteen weeks on. The re-sequencing worked better than the partner predicted: phishing-resistant MFA, privileged-access management and immutable backups were delivered in seven weeks, not eight, by narrowing scope to the identity platform and the backup estate. Migration restarted three weeks ago and is running.\n\nTwo things followed. The sponsor's operating partner installed a monthly \"IT value\" review and opened the first one by asking why the two-month slip had not appeared in the model before you announced it — a fair question you answered badly.\n\nAnd the add-on has moved the wrong way. The seller wants out early and the closing has pulled in from ten months to nine. The target runs a different EHR, 400 users, and its own small IT team. Onboarding it to the new platform was the sponsor's whole reason for the migration timeline, and the new platform will be roughly 40% populated on the closing date.\n\nThe operating partner has asked you for a recommendation in writing by Friday.", "choices": [{"label": "A", "narrative": "Onboard the target onto the hardened new platform at closing, even though only 40% of Northlake's own estate has moved, and re-plan the remaining migration around it.", "tendency_signals": {"dials": {"aggression_caution": -1, "urgency_patience": -1}}, "debrief": "Suggests you are treating the hardened identity and backup layer as the thing that made the platform safe to land on, which is exactly the argument you used to justify the slip. The tradeoff is that onboarding 400 users on a different EHR into a 40%-populated tenant during an active migration is two programs at once with one team, and the covenant test falls in the middle of it. Consistent with your own reasoning; dependent on capacity you have not yet demonstrated."}, {"label": "B", "narrative": "Keep the target on its own stack for twelve months behind a segmented interconnect you design, and put the cost and the reason in the Friday paper.", "tendency_signals": {"dials": {"aggression_caution": 1, "centralization_decentralization": 1}}, "debrief": "Suggests you are refusing to let an accelerated closing set the technical sequence, and are offering a priced alternative rather than a delay. The tradeoff is that a segmented interconnect is a third estate to run, twelve months of two EHRs undercuts the synergy case the sponsor bought, and 'the CIO slipped twice' is how it will be summarized whatever the paper says. Strongest where the interconnect design is genuinely yours and dated; weakest where it becomes permanent by neglect."}, {"label": "C", "narrative": "Ask the sponsor to fund a parallel onboarding team, and use the value review as the place to price the whole thing — slip, interconnect, integration — in one written model.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you have understood that the operating partner's real complaint was about the model rather than the slip, and are answering it by putting every option in the model with its cost. The tradeoff is that asking for money at 5.2x leverage one quarter before a covenant test invites the answer no, and a parallel team hired in nine weeks will be onboarding a target it has never seen. It is the most transparent option and the one most likely to be refused on the merits."}]}, {"id": "fu-C", "after_choice": "C", "situation": "Context 2, twelve weeks on. The on-premises hardening is genuinely good: privileged access is broker-mediated, MFA is phishing-resistant across clinical and administrative users, and a tabletop last month found three gaps you closed in a fortnight. The twelve-month lease extension is signed at the 30% premium.\n\nThe rest has gone the way the debrief warned. The add-on closed on schedule and is being run on its own stack, connected to Northlake by a site-to-site tunnel that the target's two-person IT team stood up in a weekend and that your architects did not design or review. The sponsor's operating partner has commissioned an outside IT and security diligence of your function, with a scope note you were shown rather than consulted on. And the extension premium consumed the capital line that was to fund immutable backups, so the one control most specific to a ransomware campaign is unfunded in a year when four regional groups were hit.\n\nThe covenant test is in six weeks. The outside reviewers start Monday.", "choices": [{"label": "A", "narrative": "Own the review: give the outside team everything including your written reasoning for the pause, and ask the sponsor to make their recommendation binding on the sequencing.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you would rather have an independent verdict on your judgment than defend it for a year, and are confident the reasoning survives contact with people who did not make it. The tradeoff is that binding yourself to a reviewer's recommendation hands the sequencing to consultants with a sponsor relationship and no operating accountability, and the plant-level lesson is that Northlake's CIO trusts outsiders when things get hard. Defensible where the reasoning is strong; it is an abdication where the point is to be seen cooperating."}, {"label": "B", "narrative": "Restart the migration now on a compressed plan, accepting that part of the on-premises hardening spend is stranded, and say so plainly.", "tendency_signals": {"dials": {"aggression_caution": -1, "urgency_patience": -1, "decisiveness_inquiry": -1}}, "debrief": "Suggests you have concluded the pause answered the security question and lost the business one, and are willing to say the second sentence about your own decision twelve weeks after making it. The tradeoff is that a compressed restart is the plan you rejected as unsafe, now attempted with less time and a lease you have already extended, and reversing in the week outside reviewers arrive will read as a response to them. It is the honest correction and it arrives at the worst possible moment to be believed."}, {"label": "C", "narrative": "Treat the hand-built tunnel as the emergency: stop other work, bring the target's interconnect under your design and monitoring this month, and defer the migration question until after the covenant test.", "tendency_signals": {"dials": {"hands_on_delegation": -1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you are ranking an unreviewed connection into a HIPAA-covered estate above both the migration schedule and your own standing with the reviewers, which is a defensible reading of where the actual exposure now sits. The tradeoff is that deferring the migration question again is the third deferral, the reviewers will document a CIO who paused, extended, and paused again, and the immutable backups remain unfunded through the campaign. Right on the risk, and it spends the last of the argument that the pause was about risk rather than about pace."}]}, {"id": "fu-D", "after_choice": "D", "situation": "Context 2, fourteen weeks on. The split survived contact with a data inventory, barely. The ERP moved. The document management system did not: it holds clinical correspondence in roughly 30% of its volume, and legal would not accept a partial classification, so it stayed. File services split along a departmental line that two clinics dispute. Roughly 70% of the estate by data volume is still on-premises under the lease extension, and you are running two of everything.\n\nThe managed detection contract went live in week three. It is producing about 40 alerts a week. Your two-person security team closed 11 of last week's, and the provider's monthly report notes a 62% acknowledgement rate as an item for discussion. Nobody has yet triaged an alert older than nine days.\n\nThe migration partner has submitted a change order for the split architecture: $380,000, on the grounds that the dual-estate design was not in the statement of work. The sponsor's operating partner has seen the invoice before you did.", "choices": [{"label": "A", "narrative": "Collapse the split: harden and move the remaining sensitive workloads in one push, end the dual estate, and give up the lease extension early.", "tendency_signals": {"dials": {"aggression_caution": -1, "urgency_patience": -1}}, "debrief": "Suggests you have read the inventory result as evidence the split was never real and are converting D into a late B rather than defending a design that left 70% behind. The tradeoff is that a single compressed push on the sensitive systems is the concentrated exposure the split was meant to avoid, the change order is already sunk, and the clinics disputing the file-services line will now be moved anyway. Coherent; expensive; and it requires admitting the architecture you chose did not survive the data."}, {"label": "B", "narrative": "Fix the detection contract before anything else: retune, staff a third analyst or cancel it, on the grounds that 40 alerts a week nobody reads is a purchase rather than a control.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "hands_on_delegation": -1}}, "debrief": "Suggests you have taken the symbolic-adoption finding personally, which is the right instinct: an unacknowledged alert queue is the clearest example of the same dollar buying nothing that this scenario can produce. The tradeoff is that resilience was the reason the split was tolerable, and pausing to fix it leaves the widened window open while you tune; cancelling it removes the only compensating control on the half that moved. Strongest where the retune is aggressive and dated; weakest where 'staff a third analyst' is a hiring plan rather than a person."}, {"label": "C", "narrative": "Keep the split for the full year, and renegotiate the partner's change order and the detection scope together as one commercial conversation you take to the operating partner yourself.", "tendency_signals": {"dials": {"urgency_patience": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are treating the two invoices as a single negotiation and want to be the person who brings the sponsor the problem rather than the person the sponsor found it on. The tradeoff is that committing to a year of two estates makes the dual-running cost structural, the alert backlog continues while the commercials are argued, and the operating partner already has the invoice, which limits what the conversation can be. Defensible where the renegotiation buys the analyst; a way of postponing both decisions where it does not."}]}], "reflection": "Write down your Context 1 answer and your Context 2 answer side by side, then list the specific facts that moved you from one to the other. If the list is empty, write what would have had to be true for you to have chosen differently — and then check that against the four contextual signals: threat level, regulatory posture, balance sheet, deal cycle. Whichever signal you did not use is the one your default is hiding.", "tags": {"dials": ["aggression_caution", "decisiveness_inquiry", "optimism_skepticism", "urgency_patience", "innovation_operational_discipline", "centralization_decentralization", "hands_on_delegation"], "archetypes": ["arch.transformation-cio", "arch.regulated-industry-cio-ciso", "arch.mid-market-cio", "arch.technical-ciso", "arch.business-risk-ciso"], "stages": ["mature", "post_merger", "scale_up"], "learn_categories": ["decision_making", "risk", "scaling"]}, "discretion_level": "high", "research_refs": ["res.zhang2010", "res.herrmann2014", "res.owens2012", "res.angst2017", "res.kwon2014", "res.kamiya2021", "res.bertrand2003", "res.hambrick1991", "res.chatterjee2011", "res.gordon2002", "res.verizon2025"], "meta": {"source_path": "modules/06-trait-dial-for-technology-leaders.md#9-leader-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m07-ravenswood-second-title", "title": "The Second Title", "module_ref": "m07", "setup": {"company_snapshot": {"name": "Ravenswood Industrial Supply", "is_fictional": true, "industry": "Distribution of industrial components (cost-leadership strategy)", "revenue": "$4.2B", "headcount": 9300, "stage": "mature", "ownership": "public", "governance": "NYSE-listed, with an audit committee that must describe the board's oversight of cyber risk and management's role and expertise in the annual disclosure. The CIO reports to the COO; the security team reports to the CIO.", "ceo_tenure": "Four years as CIO, reporting to the COO. You have never been a CISO.", "ceo_mandate": "Deliver a two-year ERP consolidation, now at its midpoint, and absorb a bolt-on acquisition closing in seven months — and, as of this morning, decide whether to take the vacant CISO role on top of it."}, "situation": "You are the CIO of Ravenswood Industrial Supply, a $4.2B-revenue distributor of industrial components: 9,300 employees, 140 distribution centers, NYSE-listed, cost-leadership strategy. You have been CIO four years, reporting to the COO. You own a two-year ERP consolidation now at its midpoint, and a bolt-on acquisition closes in seven months.\n\nRavenswood's first CISO resigned three weeks ago after seventeen months, citing \"scope.\" He reported to you. This morning the CEO offered you the CISO role in addition to your own: the team already reports to you, a search takes five months and a seven-figure package, and — her word — consolidation. She wants an answer this week.\n\nFour other things are true. The audit committee has asked management to describe, for the annual disclosure, the board's oversight of cyber risk and management's role and expertise in assessing and managing material cyber risks (**FACT**; Regulation S-K Item 106, SEC, 2023). The security team is eleven people and has lost two since the resignation. Your last two ERP milestones slipped, both partly because of security remediation you deprioritized as CIO. And you have never been a CISO: your incident command experience is three severity-one events, all availability rather than adversarial.", "constraint": "The CEO wants an answer this week. A CISO search costs five months and a seven-figure package; the ERP consolidation is at its midpoint and the bolt-on closes in seven months; the annual disclosure describing management's cyber-risk role and expertise is being drafted now.", "known": ["The first CISO resigned after seventeen months citing 'scope', and he reported to you.", "The security team is eleven people and has lost two more since the resignation.", "Your last two ERP milestones slipped, both partly because of security remediation you deprioritized as CIO.", "You have never been a CISO; your incident command experience is three severity-one events, all availability rather than adversarial.", "The audit committee must describe, in the annual disclosure, the board's oversight of cyber risk and management's role and expertise (SEC, 2023)."], "unknown": ["Whether 'scope' meant workload, authority, or you.", "Whether the CEO would fund the search at all if you decline, or hand the function somewhere worse.", "What security debt the bolt-on carries, and whether anyone priced it into the deal model.", "How the audit committee will read a combined role once it is written down for the filing.", "Whether a deputy CISO of the calibre you would need can be hired in 120 days in this market."], "discretion_level": "medium"}, "choices": [{"label": "A", "narrative": "Accept as offered. Both titles, the same reporting line to the COO, the team you have.", "tendency_signals": {"dials": {"optimism_skepticism": -1, "centralization_decentralization": -1, "urgency_patience": -1}, "tendencies": {"A": "high", "C": "high", "K": "low"}, "maturity_levels": [2]}, "tradeoffs": "Suggests agency and optimism about capability transfer, on a reading where the binding constraint is time. The tradeoff is that Levels 2 and 4 degrade at once — you add adversarial incident command mid-ERP, and you build a structure in which the person who deprioritized remediation also certifies it was optional.", "context_that_favors": "A cost-leadership distributor with a CIO-to-COO line that will not fund a five-month search enthusiastically, and a structure Banker et al. (2011) make defensible on its own terms.", "context_that_punishes": "Any situation where the ERP schedule and a security finding collide, because nobody in the building can now break the tie.", "strong_ceo_would_evaluate": "One thing before anything else: who in this company can say no to you. If the answer cannot be written in a sentence, the answer is nobody.", "second_order_effects": "A combined role with no independent challenge is describable under Item 106 — and it is a sentence the audit committee has to read aloud to itself.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Accept, conditional on structure. Both titles, but require a deputy CISO within 120 days with an unfiltered standing line to the audit committee, a ring-fenced security budget you cannot raid for the ERP, and a written decision-rights split naming who accepts risk when the CIO and the CISO in you disagree.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1, "innovation_operational_discipline": 1}, "tendencies": {"K": "high", "F": "high", "M": "high"}, "maturity_levels": [3]}, "tradeoffs": "Suggests a Level 3 move: naming your own conflict and building mechanism around it rather than promising to be careful. The deputy covers the capability gap and the audit-committee line covers the discretion gap that ended your predecessor's seventeen months — at the cost of speed, and of a CEO who offered consolidation hearing three conditions as hesitation.", "context_that_favors": "A board already drafting an Item 106 description it would rather not have to qualify, and a CEO who values structure she can point at.", "context_that_punishes": "A thin deputy market where 120 days is optimistic, and a CEO who reads conditions as a negotiation rather than a design.", "strong_ceo_would_evaluate": "Which condition to insist on if the others are refused — and the answer is the decision-rights split, because it is the only one that binds you rather than protects you. The subtler question is whether conditions have become a way of not confronting whether you can hold two mandates at all.", "second_order_effects": "Year two is the test, when the deputy you hired contradicts you in front of the audit committee and everyone watches what the CIO half of you does about it.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Decline and argue for structure. Tell the CEO the answer is a CISO who does not report to you — to the CEO, the general counsel or the chief risk officer — and offer to run the search.", "tendency_signals": {"dials": {"unilateral_consensus": -1, "optimism_skepticism": 1, "decisiveness_inquiry": -1}, "tendencies": {"I": "high", "A": "high", "N": "low"}, "maturity_levels": [4]}, "tradeoffs": "Suggests conviction about independence and willingness to spend standing on governance: the best theoretical case and the worst political timing. You are refusing a CEO who framed the offer as trust, and the tradeoff is winning the argument while losing the relationship that grants your discretion on everything else, the ERP included.", "context_that_favors": "A CEO who can absorb an argument, and a general counsel or chief risk officer who actually wants the function rather than being volunteered for it.", "context_that_punishes": "A CEO who hears refusal as a lack of ownership at the exact moment the ERP is slipping and the acquisition is closing.", "strong_ceo_would_evaluate": "Whether the alternative home for security is real — the practitioner data (IANS, 2026, Tier 3) shows roughly two-thirds of CISOs reporting to IT leaders, so this is a common structure rather than a purist's fantasy, and the evidence does not settle which line is better.", "second_order_effects": "If you win, you have created a peer who can contradict you in front of the board — which is the point, and also the cost.", "follow_up_ref": "fu-C"}], "debrief_common": {"fit_analysis": "A mature, cost-leadership distributor with a CIO-to-COO line, a public filing obligation, and a security function that has just lost its first leader to 'scope'. The question looks like a capability question — can you be a CISO? — and is mostly a Level 4 question: what discretion will the combined chair actually have, and who can overrule its occupant. Nothing about the offer changes the reporting line, the budget authority or the escalation path that produced a seventeen-month tenure, which is why filling the seat differently is not the same as fixing it. Personality × Power applies with the technology executive's twist: your power here is granted by a CEO in a hurry, so this week is the only week in which the terms are negotiable. The Maturity Model's use is to keep three different problems apart — your adversarial incident-command gap (Level 2), your conflict of interest between the two mandates (Level 3), and the structure the company has not built (Level 4) — because two of the three remedies are wrong for the others.", "research_that_bears": [{"text": "The performance-associated CIO reporting line depended on strategy: CIO-to-CEO in differentiation firms, CIO-to-CFO in cost-leadership firms — so no line is universally right, and Ravenswood's structure is defensible on its own terms.", "label": "RESEARCH_FINDING", "ref": "res.banker2011"}, {"text": "In a 2026 practitioner survey of more than 600 security leaders (Tier 3, self-selected), roughly two-thirds of CISOs reported to the CIO or CTO — a common structure rather than an error, though the survey settles nothing about which line performs better.", "label": "RESEARCH_FINDING", "ref": "res.ians2026"}, {"text": "Since December 2023, US public companies must describe annually the board's oversight of cybersecurity risk and management's role and expertise in assessing and managing material cyber risks (Regulation S-K Item 106).", "label": "FACT", "ref": "res.sec2023"}, {"text": "The four levels are ordered and non-substitutable: a surplus at Fit does not cover a deficit at Capability, and the commonest error here would be answering a Level 4 structural problem with a Level 2 remedy — or the reverse.", "label": "FRAMEWORK"}], "defensible_choices": "B on most readings. A is defensible only if you can name in advance, in writing, who is empowered to overrule you when the mandates collide; if you cannot, A ends in the seat your predecessor left. C is the highest-variance option, because it spends the relationship that grants your discretion in order to fix your structure — defensible where the CEO can absorb the argument, expensive where she cannot. What separates a defensible answer from a lucky one is whether you wrote the Level 4 analysis before you picked.", "trait_dial_readout": "A sits toward agency, optimism and centralization, with hands-on↔delegation unmoved. B sits mid-dial, with delegation set deliberately above your default and consensus used as design rather than as courtesy. C sits toward unilateral and skepticism, and toward the Control end about your own role.", "two_sentence_question": "Which choice leaves you able to tell the audit committee, \"Yes — and here is the risk we are accepting by combining these roles, priced\"? And which leaves you able to say, eighteen months on, \"I was wrong about that risk. Change the structure\" — while it is still changeable, and while you are the person who would have to say it about yourself?"}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "Eleven weeks on, both titles are yours and the disclosure draft is circulating. It describes management's cyber-risk role in a sentence that names one person: you. The audit committee chair — a retired insurance executive, pleasant and precise — has asked who is empowered to overrule you when the CIO's schedule and the CISO's finding disagree, and wants the answer in writing before the filing. Meanwhile a third security engineer has resigned, citing \"no path\"; the ERP cutover for the Northeast distribution centers is scheduled for the same fortnight the bolt-on closes; and your identity team has flagged that the acquired company's domain will be trusted on day one, because nobody scoped the alternative and nobody priced it in the deal model. The CEO has not asked about any of it. She regards the consolidation as settled and is pleased with the savings. You have nine people covering eleven roles, a filing deadline, and a question in writing that does not currently have a true answer.", "choices": [{"label": "A", "narrative": "Write the decision-rights split you skipped in week one: name the chief risk officer as the executive who can overrule the combined role on security matters, get it signed, and file that.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you have accepted that the chair's question is the real one and are building the mechanism late rather than never — which is still the cheapest item on the list, since decision rights cost nothing in calm weather. The tradeoff is that you are handing a peer authority over your own function three months after telling the CEO consolidation would work, and a risk officer who did not ask for the role may exercise it unevenly. It is the answer the disclosure can survive; it is not an answer the CEO will read as neutral."}, {"label": "B", "narrative": "Tell the chair honestly that nobody currently can, ask the committee to create the mechanism, and move the ERP cutover out of the close fortnight.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "urgency_patience": 1}}, "debrief": "Suggests you would rather the committee know the true state than read a comfortable sentence, and that you are willing to spend an ERP date to buy the sequencing. The tradeoff is that a chair who hears 'nobody can overrule me' eleven weeks after a consolidation was pitched as prudent may conclude the CEO was badly advised — by you — and the slipped cutover is the third ERP slip in a year. It is honest, and honesty here is expensive in exactly the currency you traded for the second title."}, {"label": "C", "narrative": "Answer that the COO can overrule you, since that is the reporting line, hand the trusted-domain question to the integration team, and hold both dates.", "tendency_signals": {"dials": {"optimism_skepticism": -1, "urgency_patience": -1, "centralization_decentralization": -1}}, "debrief": "Suggests you are treating the chair's question as a disclosure-drafting problem rather than a governance one, and the answer is technically true: the COO is your boss. The tradeoff is that a COO who cannot evaluate a security finding is not a check on one, the integration team has no authority to refuse a trusted domain, and both dates now depend on nothing going wrong in the same fortnight. Defensible if the ERP genuinely cannot move; it is also the sentence your predecessor's seventeen months were made of."}]}, {"id": "fu-B", "after_choice": "B", "situation": "Ten weeks in. The CEO agreed to all three conditions with less argument than you expected, which you have not stopped thinking about. The deputy search has produced one serious candidate: strong adversarial incident command, currently a CISO at a smaller firm, who wants the CISO title and a dotted line to the CEO rather than a deputy title under you — and says so pleasantly, as though it were obvious. The ring-fence has already been tested: the ERP program is $1.8M short on cutover contingency and the COO asked, reasonably, whether the security envelope could lend it back for a quarter. And the audit committee chair, having read the decision-rights memo, wants to add a line giving the deputy standing to escalate to the committee over your objection. Your CFO thinks that line is unusual. The filing is in five weeks, the deputy candidate has another offer, and the three conditions you set are each being renegotiated by a different person.", "choices": [{"label": "A", "narrative": "Give the candidate the CISO title and the dotted line, keep the CIO title yourself, and support the chair's escalation clause — effectively unwinding the consolidation you accepted.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1, "centralization_decentralization": 1}}, "debrief": "Suggests you set conditions in order to discover the answer rather than to win a negotiation, and are willing to give up a title to get the structure you said the company needed. The tradeoff is that the CEO agreed to consolidation ten weeks ago and will now explain a different arrangement to her board, and a CISO with a dotted line who arrived by outbidding your conditions starts with standing you did not grant. It is the outcome choice C would have produced, reached more expensively and with your credibility partly spent."}, {"label": "B", "narrative": "Hold all three conditions as written: deputy title, no lending from the ring-fence, and the escalation clause in the memo — and let the candidate walk if he will not take the deputy role.", "tendency_signals": {"dials": {"aggression_caution": 1, "unilateral_consensus": -1, "urgency_patience": 1}}, "debrief": "Suggests you understand that a condition renegotiated once is not a condition, and that the ring-fence is worth more than any single hire. The tradeoff is real: the capability gap you accepted the job with stays open past the filing, the COO learns your envelope is unavailable to a program you also run, and a thin market may not produce a second candidate this year. Defensible where the structure is genuinely the point; costly where you have kept the design and lost the person who was going to operate it."}, {"label": "C", "narrative": "Lend the ERP the $1.8M for one quarter with a written repayment date, take the deputy on his terms without the CEO dotted line, and ask the chair to hold the escalation clause until the deputy is in post.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "urgency_patience": -1, "innovation_operational_discipline": -1}}, "debrief": "Suggests pragmatism: you are trading each condition for the thing you most need this quarter, which is a person who has run adversarial incidents. The tradeoff is that all three conditions now have exceptions with your signature on them, and a ring-fence lent once is a budget line, not a ring-fence. It works where the repayment date is honoured and the escalation clause actually arrives; it fails quietly, because nobody will announce the quarter in which it did not."}]}, {"id": "fu-C", "after_choice": "C", "situation": "You declined, argued, and half-won. The CEO did not fund a five-month search; she moved security under the general counsel, who did not ask for it, and hired an interim CISO from a consulting bench on a nine-month contract. Twelve weeks on, the interim's first written assessment has landed with the audit committee. It is competent and it is about you: it names the two ERP milestones where security remediation was deprioritized, describes the change-approval path as \"owned by the party whose schedule it constrains,\" and recommends that the ERP cutover be gated on a control baseline his team defines. The general counsel, who reads risk for a living and technology not at all, has adopted the recommendation without asking you. Your COO is irritated on your behalf and wants you to fight it. The CEO has said nothing, which you have learned to read. The cutover is in eight weeks, the bolt-on closes in four months, and the argument you won has produced a peer with a report and a mandate.", "choices": [{"label": "A", "narrative": "Accept the gate publicly, ask the interim to define the baseline jointly with your architects, and put the two deprioritized remediations into the ERP plan yourself.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "optimism_skepticism": 1, "hands_on_delegation": -1}}, "debrief": "Suggests you are treating the assessment as evidence rather than as an attack, which is the Level 3 move and the harder one when the finding is accurate and about you. The tradeoff is that a jointly defined baseline written under time pressure tends to become whatever the cutover can absorb, and accepting a gate you did not design teaches the organization that the interim sets the standard. It buys the thing you argued for — a peer who can contradict you — and you now have to live inside it."}, {"label": "B", "narrative": "Take the assessment to the audit committee yourself with a written response: agree the finding, contest the gate as a schedule mechanism, and propose a named risk acceptance signed by the COO instead.", "tendency_signals": {"dials": {"decisiveness_inquiry": -1, "unilateral_consensus": -1, "aggression_caution": -1}}, "debrief": "Suggests you would rather have the argument in front of the committee than lose it in a corridor, and that you understand a priced acceptance with a named owner is the mature alternative to a gate. The tradeoff is that a CIO contesting a security gate four months after refusing the CISO role will be heard by some directors as the reason the interim was hired, whatever the merits. Strongest where the acceptance is genuinely signed and dated by the COO; weakest where it is a way of keeping a date."}, {"label": "C", "narrative": "Say nothing publicly, work the general counsel privately to narrow the gate, and let the interim's contract run out in nine months.", "tendency_signals": {"dials": {"urgency_patience": 1, "unilateral_consensus": -1, "optimism_skepticism": -1}}, "debrief": "Suggests you are playing the clock: the interim leaves, the assessment ages, and the structure reverts to something you can live with. The tradeoff is that quietly narrowing a control gate through the executive least able to evaluate it is exactly the pattern the assessment described, and if the cutover goes badly the audit committee will have a dated recommendation and a record of who diluted it. Defensible only if you believe the gate is genuinely wrong — and if that is what you believe, it belongs in writing where the committee can read it."}]}], "reflection": "Write down the last time your calendar, your budget or your schedule was in conflict with a control you own — and then write the name of the person who could have overruled you. If you cannot write a name, write instead what you would have to give up this quarter to create one, and whether you are willing to ask for it while nothing is on fire.", "tags": {"dials": ["hands_on_delegation", "unilateral_consensus", "optimism_skepticism", "centralization_decentralization", "innovation_operational_discipline"], "archetypes": ["arch.enterprise-cio", "arch.business-risk-ciso", "arch.technical-ciso", "arch.regulated-industry-cio-ciso"], "stages": ["mature", "post_merger"], "learn_categories": ["power_governance", "organizational_design", "risk"]}, "discretion_level": "medium", "research_refs": ["res.banker2011", "res.ians2026", "res.sec2023", "res.banker2019", "res.preston2008", "res.maynard2018", "res.karanja2017", "res.haislip2021", "res.peppard2010", "res.karahanna2013", "res.hambrick2007", "res.edmondson1996", "res.owens2012", "res.gordon2002", "res.ashenden2013"], "meta": {"source_path": "modules/07-maturity-model-for-cios-and-cisos.md#9-leader-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m08-brightwater-isolation", "title": "The Architecture You Wrote", "module_ref": "m08", "setup": {"company_snapshot": {"name": "Brightwater Logistics Software", "is_fictional": true, "industry": "Transportation-management SaaS (multi-tenant B2B platform)", "revenue": "$240M", "headcount": 900, "stage": "scale_up", "ownership": "pe_backed", "governance": "Private-equity owned, with a sponsor whose growth plan names two features by date. No board security committee; the CIO/CISO reports to the CEO and presents to the sponsor quarterly.", "ceo_tenure": "Nine years in technology leadership here; you were employee eleven and have held the combined CIO/CISO chair for four years.", "ceo_mandate": "Keep the platform available and shippable for about 1,400 customers while the sponsor's growth plan lands — and, as of yesterday, decide what to do about the isolation model you personally designed."}, "situation": "You are the CIO and CISO of Brightwater Logistics Software, a $240M-revenue transportation-management platform in Pennsylvania: 900 employees, private-equity owned, about 1,400 customers. You were employee eleven. You wrote the original multi-tenant isolation model — one shared database, tenancy keys enforced in application code — and it has held for nine years without a known cross-tenant incident.\n\nEight months ago you hired your first dedicated security lead, Priya Raghavan, from a larger platform company. Yesterday she sent you a four-page memo: the isolation model is the company's single largest risk, because a missed predicate in any new query path exposes another customer's data, and the codebase now spans eleven services written by four teams. She proposes an eleven-month migration to per-tenant schema isolation, with compensating controls in the interim — query-layer enforcement, automated test coverage for tenancy predicates, and a penetration test with a tenant-escape objective.\n\nTwo of your five staff engineers agree with her. Your VP of Engineering says the migration will consume about 40% of platform capacity and delay the two features the sponsor's growth plan depends on. Your own view is that the model is sound, that this is a code-review discipline problem, and that you would know if it were fragile.\n\nThis morning a prospective enterprise customer's security questionnaire asked, for the first time, how tenants are isolated at the data layer. You have nine days to answer.", "constraint": "Nine days to answer the enterprise questionnaire. The migration would consume roughly 40% of platform capacity for eleven months and delay two features the sponsor's growth plan names by date.", "known": ["The isolation model is one shared database with tenancy keys enforced in application code, written by you, and it has held nine years with no known cross-tenant incident.", "The codebase now spans eleven services written by four teams, so a missed predicate in any new query path is the failure mode Priya describes.", "Two of your five staff engineers agree with her; your VP of Engineering says the migration costs about 40% of platform capacity and two named features.", "A prospective enterprise customer has asked, for the first time, how tenants are isolated at the data layer — and wants an answer in nine days.", "Your security lead is eight months into the job and this is her first major call."], "unknown": ["Whether the model is actually fragile, or whether nine years of no known incident is evidence of soundness or of nobody looking.", "Whether Priya's eleven-month proposal is sized to this architecture or to her previous company's.", "What a tenant-escape penetration test would find, and whether the two staff engineers who agree with her have seen something specific or are deferring to the new expert.", "How the sponsor will price a two-feature delay against an unquantified data-layer risk.", "Whether the enterprise prospect's question is a checkbox or the start of a diligence process that ends in a contractual warranty."], "discretion_level": "high"}, "choices": [{"label": "A", "narrative": "Overrule. Keep the architecture, fund the compensating controls only, and tell Priya the decision is made and why.", "tendency_signals": {"dials": {"hands_on_delegation": -1, "unilateral_consensus": -1, "decisiveness_inquiry": -1}, "tendencies": {"K": "low", "C": "high", "E": "low"}, "maturity_levels": [1, 2]}, "tradeoffs": "Suggests high confidence in your own architecture judgment and a reading of the disagreement as a competence gap in the new hire. It is not indefensible — you have nine years of evidence and she has eight months of context — but you are the author of the design under review, which makes you the least reliable judge in the building.", "context_that_favors": "A genuinely disciplined code-review culture, a sponsor deadline that cannot move, and a security lead whose proposal is visibly imported from a different architecture.", "context_that_punishes": "An organization watching what happens to a senior hire who challenged the founder-engineer — which is every organization, including this one.", "strong_ceo_would_evaluate": "What evidence would change their mind, and would notice that \"I would know if it were fragile\" is a claim about themselves, not about the system.", "second_order_effects": "Priya either stops raising architecture concerns or leaves, and both cost more than the migration would have.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Accept her plan as written. Fund the eleven-month migration, take the feature delay to the sponsor, and back your security lead publicly.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1, "optimism_skepticism": -1}, "tendencies": {"E": "high", "L": "high", "B": "high"}, "maturity_levels": [2, 3]}, "tradeoffs": "Suggests a deliberate move on the hands-on↔delegation dial and a decision to make the new lead's authority visible early; the gain is underrated, because a security lead whose first major call is honored brings you the second one. The tradeoff is that you have accepted an eleven-month, 40%-capacity program on eight months of context and no independent test, in a PE-owned company where the delay has a named cost.", "context_that_favors": "A balance sheet that can carry the delay, and an honest self-assessment that you cannot judge your own design.", "context_that_punishes": "A sponsor whose growth plan is the reason the two features have dates, and a proposal sized for someone else's architecture.", "strong_ceo_would_evaluate": "Whether the proposal is sized to this risk or to her previous company's architecture — and whether unconditional deference is judgment or its avoidance.", "second_order_effects": "Eleven-month migrations slip, and the sponsor will ask why the CIO never tested the premise of the one he approved.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Buy evidence. Commission an independent architecture review and a tenant-escape penetration test, fund compensating controls now, and commit in advance — in writing, with Priya — to what result would trigger the migration.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "optimism_skepticism": 1}, "tendencies": {"O": "high", "K": "high", "F": "high"}, "maturity_levels": [3]}, "tradeoffs": "Suggests inquiry over decisiveness and a willingness to make the disagreement resolvable by something other than seniority. It fits unusually well here — the question is empirical, the test is cheap relative to the migration, and the nine-day questionnaire is answerable with \"enforced in the application layer, independently tested, review under way\" — at the cost of time, and of the risk that \"get more data\" becomes a socially acceptable deferral.", "context_that_favors": "An empirically settleable disagreement, a cheap test relative to the remedy, and a questionnaire deadline that a review in progress can honestly answer.", "context_that_punishes": "A leader who does not pre-commit, because the result then becomes negotiable in exactly the direction the architecture's author prefers.", "strong_ceo_would_evaluate": "The trigger, in writing and with Priya's agreement on what a finding means, before the test runs rather than after.", "second_order_effects": "Whatever the test finds, you have built the mechanism for the next architecture disagreement — and set a precedent that seniority is not how they get settled.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Price it and hand it up. You and Priya jointly produce a loss estimate and two options, and the CEO and sponsor accept one in writing as the accountable owners of the risk.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1, "centralization_decentralization": 1}, "tendencies": {"N": "high", "H": "high", "M": "high"}, "maturity_levels": [3, 4]}, "tradeoffs": "Suggests the Module 7 maturity move: you own the quality of the risk decision, not the risk itself, and a 40%-capacity, revenue-affecting choice belongs to the business. The tradeoff is that a CEO and a sponsor cannot adjudicate a tenancy-isolation argument, so handing it up without an independent read hands them your disagreement rather than a decision.", "context_that_favors": "A sponsor who signs things, a CEO who will accept a named risk with a review date, and a loss estimate you and Priya can both defend.", "context_that_punishes": "A leader who is also the architecture's author, because framing the options is itself advocacy — and the people signing cannot see the frame.", "strong_ceo_would_evaluate": "Whether this is being used after C or instead of it, since the same act is maturity in the first case and escape in the second.", "second_order_effects": "Done well, cyber risk becomes a business decision with a named owner and a review date; done as an exit from a technical argument you are losing, the sponsor will notice, and so will Priya.", "follow_up_ref": "fu-D"}], "debrief_common": {"fit_analysis": "A scale-up whose technology leader is still, functionally, its founding engineer: employee eleven, author of the architecture under review, and holder of both the CIO and CISO chairs. Discretion is high and structurally unchecked — no board security committee, a sponsor who reads features rather than schemas, and a security lead eight months in with no independent line anywhere. That combination is the Player-to-Coach transition arriving late and disguised as a technical dispute: the question is not whether the isolation model is sound but whether this company has any mechanism, other than your opinion, for finding out. Each option sets a different rung on the delegation ladder for architecture decisions, and the rung you pick here is the one the organization will assume applies to the next disagreement. The Coach's dominant danger is on display in its most sympathetic form — not control for its own sake, but genuine competence pointed at a level it has outgrown.", "research_that_bears": [{"text": "In a large survey, executives delegated less when they had long tenure or deep domain expertise — so for an engineer-turned-CIO, expertise is the fuel of the hands-on trap rather than the cure for it.", "label": "RESEARCH_FINDING", "ref": "res.graham2015"}, {"text": "In interviews with 40 employees, 85% could recall an occasion when they felt unable to raise an important issue with a superior — which is the base rate against which 'two of five staff engineers agree with her' should be read.", "label": "RESEARCH_FINDING", "ref": "res.milliken2003"}, {"text": "Across more than 5,000 US hospitals, organizations classified as symbolic rather than substantive adopters of security practices saw the effectiveness of their investment diminished and an increased likelihood of breach — the hazard sitting under 'fund the compensating controls only'.", "label": "RESEARCH_FINDING", "ref": "res.angst2017"}, {"text": "The delegation ladder sets a rung per activity, not per person, and a rung you have not written down is not a rung — unwritten authority defaults to 'they do it, you approve each instance', because people ask.", "label": "FRAMEWORK"}], "defensible_choices": "C and D, and strongest in sequence — evidence, then a priced decision with a named owner. B is defensible where the leader's honest self-assessment is that they cannot judge their own design and the balance sheet can carry the delay. A is the choice this module is about: it may even be technically correct, and it is still the stage-four move, made by the one person who cannot evaluate it independently. If you chose A, the useful question is not whether the architecture is sound. It is what you would have done had someone else designed it.", "trait_dial_readout": "A sits at hands-on, unilateral and decisive. B sits at delegation and consensus with skepticism switched off. C sits at inquiry and skepticism, deferring the delegation question. D sits at delegation and consensus with the risk decision pushed to its owner — the Enablement end of Control↔Enablement, honest only with a priced risk behind it.", "two_sentence_question": "Which choice lets you say to Priya, \"I was wrong about that risk. Change the architecture,\" if the test finds a path — and which lets you say to the sponsor, \"Yes, we ship the features on plan — and here is the risk we are accepting, priced, with a date we revisit it\"?"}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "Seven weeks on. You answered the questionnaire — application-layer enforcement, compensating controls under way — and the prospect moved to a second round. The compensating controls are real: query-layer enforcement is live in four of eleven services, and the automated tenancy-predicate tests, which Priya built first, found two query paths missing a predicate in a reporting service written by a team that left last year. Neither was reachable from the customer-facing API, and neither exposed data. Priya sent the finding to you in three lines with no recommendation attached, which is not how she used to write. One of the two staff engineers who backed her asked you in a one-on-one, carefully, whether the memo had ever been seriously considered. Your VP of Engineering, who won the argument, now cites it in planning as settled precedent. And Priya has a recruiter's screen in her calendar, which you know because it is on the shared engineering calendar and she did not make it private. The prospect's security team wants a call.", "choices": [{"label": "A", "narrative": "Reopen the decision: tell Priya the two findings changed your mind about the evidence, commission the tenant-escape test she asked for, and say so in front of the engineering leadership.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "optimism_skepticism": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you can revise in public on evidence you would rather not have received, which is the only thing that reopens a channel you closed seven weeks ago. The tradeoff is that reversing in front of the leadership who backed you costs the VP of Engineering something he was not consulted about, and two unreachable findings are thin grounds if you are honest about them. It is the cheapest available version of the second sentence, and it gets more expensive every week it waits."}, {"label": "B", "narrative": "Treat the findings as the compensating controls working exactly as designed, say so on the prospect call, and give Priya the automated-testing program to own outright with budget.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "optimism_skepticism": -1}}, "debrief": "Suggests you are reading the two catches as vindication of the cheaper path and are trying to keep your security lead with scope rather than with agreement. There is a real case: the controls found what they were built to find, before anything was exposed. The tradeoff is that scope is not the thing she asked for, a leader who is told her diagnosis was wrong and her tooling was right hears the second half less clearly than you intend, and the three-line memo is what a filtered channel looks like from the inside."}, {"label": "C", "narrative": "Say nothing about the memo, prepare the prospect call yourself, and put the isolation question on the agenda for the annual architecture review in five months.", "tendency_signals": {"dials": {"urgency_patience": 1, "hands_on_delegation": -1, "unilateral_consensus": -1}}, "debrief": "Suggests you regard the matter as decided and the noise around it as ordinary organizational friction, which is sometimes exactly right. The tradeoff is that taking the prospect call yourself removes your security lead from the one conversation where her position would have been heard by someone outside the company, and a five-month deferral of a question your own tests are now generating findings against is a decision you will be asked to date later. If she resigns, the memo becomes the document, and you will not be the one reading it aloud."}]}, {"id": "fu-B", "after_choice": "B", "situation": "Ten weeks into the migration. You funded it, told the sponsor, and backed Priya in the room, which cost less than you expected and bought more than you expected — engineering morale is genuinely better. Then the first phase landed. Per-tenant schema isolation turns out to be entangled with a reporting subsystem nobody remembered, three customers are on a legacy data-residency arrangement that the new model cannot express, and the revised bottom-up estimate is sixteen months, not eleven. Capacity consumption is running at 52%, not 40%. The sponsor's operating partner has asked for a written explanation before the quarterly, and your VP of Engineering — who lost this argument publicly — has been scrupulously professional and is quietly documenting everything. Priya's own view is that sixteen months is real and that stopping halfway is worse than either endpoint, which you believe is true and cannot prove. One of the two named features has already slipped a quarter. The quarterly is in twelve days.", "choices": [{"label": "A", "narrative": "Take the sixteen-month number to the sponsor yourself, own the original estimate as yours rather than Priya's, and ask for the extension with a monthly checkpoint.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1, "hands_on_delegation": -1}}, "debrief": "Suggests you understand that you approved the estimate and therefore own it, and that a security lead who is exposed to a sponsor in month three does not lead anything afterwards. The tradeoff is that owning it puts your judgment rather than hers in question at the exact moment the sponsor is deciding whether the program is competently run, and a monthly checkpoint invites the sponsor into architecture decisions he cannot evaluate. It is the right instinct about protection and a real cost in standing."}, {"label": "B", "narrative": "Re-scope to a defensible halfway point: migrate the four highest-exposure services, keep application-layer enforcement plus query-layer controls everywhere else, and close the program at eight months.", "tendency_signals": {"dials": {"aggression_caution": 1, "innovation_operational_discipline": 1, "urgency_patience": -1}}, "debrief": "Suggests you are treating the migration as a portfolio rather than a doctrine and are willing to buy most of the risk reduction for half the capacity. The tradeoff is that a mixed model is two isolation stories to explain to every enterprise prospect and to your own new engineers, and Priya's argument that stopping halfway is worse than either endpoint may be correct in ways that only show up in year three. Defensible where the four services genuinely carry the exposure; hollow where the boundary is drawn by the quarterly calendar."}, {"label": "C", "narrative": "Hold the plan, absorb the sixteen months, and give the sponsor a priced risk statement for the alternative: what stopping would cost in exposure terms, with a named accepter if he chooses it.", "tendency_signals": {"dials": {"urgency_patience": 1, "centralization_decentralization": 1, "decisiveness_inquiry": 1}}, "debrief": "Suggests you are converting a schedule argument into a priced decision with an owner, which is the mature form and the one the sponsor is least used to receiving. The tradeoff is that you are asking a growth investor to sign for exposure he did not previously know he held, twelve days before a quarterly, on a loss estimate built in a hurry. It works where the number is defensible and you volunteer its weaknesses; it fails where the sponsor reads a priced acceptance as an attempt to make him responsible for your slip."}]}, {"id": "fu-C", "after_choice": "C", "situation": "The review and the test came back in five weeks, and they split. The testers ran ten days against a production-equivalent environment and achieved no cross-tenant access; the written trigger you and Priya signed said a demonstrated escape would start the migration, and there was none. But the architecture reviewer's report is uncomfortable in a way the trigger does not cover. It calls the enforcement pattern \"correct where applied and unverifiable at scale,\" notes that the predicate is applied through a shared helper three teams can bypass without review, and observes that the absence of an escape in ten days says little about eleven services and four teams over three years. Priya's position is that the trigger was written wrong and she signed it in good faith. Your VP of Engineering's position is that a signed trigger is a signed trigger, and that reopening it teaches everyone that agreements bind only until security is unhappy. The enterprise prospect has moved to contract and its counsel has asked whether you will warrant tenant isolation. You have both a mechanism and a result you did not anticipate.", "choices": [{"label": "A", "narrative": "Honor the trigger as written, and open a second, narrower pre-committed test aimed at the helper-bypass finding with a new trigger both of you draft this week.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "decisiveness_inquiry": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are protecting the mechanism — a trigger that survives an inconvenient result is worth more than any single decision — while conceding that the first one was badly specified. The tradeoff is time and the appearance of an argument being run in instalments until it produces the answer security wants. It is strongest if you say out loud, in front of engineering, that the first trigger was your drafting error too."}, {"label": "B", "narrative": "Reopen the trigger: accept the reviewer's 'unverifiable at scale' as the finding that matters, and start the migration on the four services the helper touches.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "aggression_caution": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you have concluded that verifiability, not a demonstrated escape, was always the real question, and that you would rather break the agreement than defend a test design you now think was wrong. The tradeoff is exactly what your VP of Engineering says: the next pre-commitment anyone signs with you carries a discount. Defensible where you say plainly that the trigger was mis-specified and who mis-specified it; corrosive where it looks like the architecture's author reopening a result he did not like — in the direction that costs him least."}, {"label": "C", "narrative": "Take both documents to the CEO with the contract warranty question attached, and let the business decide what it is willing to warrant and therefore what it must fund.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "centralization_decentralization": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are using the warranty as the forcing function it genuinely is: a contractual promise is a priced risk with a named owner whether or not anyone writes it down that way. The tradeoff is that you are handing a CEO two expert documents that disagree, at the moment a deal depends on the answer, which tends to produce the commercially convenient reading. It works where you and Priya present a joint recommendation with the disagreement stated; it fails where the CEO is asked to referee two people who both report to him."}]}, {"id": "fu-D", "after_choice": "D", "situation": "You and Priya built the loss estimate together — a $6M to $18M range for a cross-tenant exposure event, confidence stated as low, method in an appendix you both signed — and presented two options. The CEO and the sponsor chose compensating controls with a twelve-month review, in writing, with the CEO named as accepter. That document is the cleanest artifact your program has ever produced. Nine weeks later the enterprise prospect signed, and its master agreement contains a clause your sales lead negotiated without you: the platform will maintain \"logical isolation of each customer's data at the data layer.\" Legal has asked you to confirm the statement is accurate before countersignature, on Friday. Priya's reading is that the clause describes per-tenant schema isolation and is therefore not accurate today. Your VP of Engineering reads \"logical isolation\" as exactly what tenancy keys provide. The CEO, who accepted the risk in writing, was not told a warranty was coming and does not yet know the two readings differ.", "choices": [{"label": "A", "narrative": "Tell legal the clause is not accurate as Priya reads it, propose replacement language describing the actual control, and let the customer decide whether that is acceptable.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "aggression_caution": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you would rather describe the control you have than sign a sentence two competent people read differently, which is the honest version of an evidence claim. The tradeoff is that reopening language in a signed-through deal costs the sales lead standing and may cost the deal, and 'logical isolation' is a term of art the customer's counsel may accept in your sense anyway. Strongest where you propose the replacement rather than only objecting; weakest if the objection arrives on Friday afternoon with no alternative attached."}, {"label": "B", "narrative": "Confirm accuracy on the VP of Engineering's reading, note your interpretation in the file, and add the warranty to the twelve-month review as a new exposure.", "tendency_signals": {"dials": {"urgency_patience": -1, "optimism_skepticism": -1, "decisiveness_inquiry": -1}}, "debrief": "Suggests you are treating this as a definitional dispute with a defensible answer and are unwilling to spend a deal on it. It may well be right, and a noted interpretation is better than silence. The tradeoff is that the risk the CEO accepted in writing was priced without a contractual warranty in it, so the accepted risk and the actual risk have quietly diverged — and a note in your file is not a renegotiation of the acceptance."}, {"label": "C", "narrative": "Go back to the CEO before Friday: reopen the accepted risk with the warranty priced in, and ask him to re-sign or re-choose.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "hands_on_delegation": 1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you understand that a risk acceptance is a decision about a specific exposure and that a new contractual promise changes the exposure, not just the paperwork. The tradeoff is a CEO being asked to reopen a decision he considers closed, in the same week revenue depends on it, which is where accepters learn whether the process is a discipline or an obstacle. It is the move that keeps the artifact honest — and it will be the second time in nine weeks you have brought him the same architecture."}]}], "reflection": "Name one decision in your organization that is currently at rung two — they do it, you approve each instance — because nobody ever wrote down what rung it should be. Then write what specifically you are afraid will happen if you move it up one, and whether that fear is about the work or about what you would be if you were no longer the person who checked it.", "tags": {"dials": ["hands_on_delegation", "decisiveness_inquiry", "unilateral_consensus", "optimism_skepticism", "centralization_decentralization"], "archetypes": ["arch.mid-market-cio", "arch.technical-ciso", "arch.business-risk-ciso", "arch.smb-msp-technology-leader"], "stages": ["scale_up", "mature"], "learn_categories": ["leadership", "organizational_design", "decision_making"]}, "discretion_level": "high", "research_refs": ["res.graham2015", "res.bandiera2020", "res.bloom2007", "res.weill2004", "res.milliken2003", "res.detert2011", "res.edmondson1996", "res.angst2017", "res.owens2012", "res.gordon2002", "res.peppard2010", "res.ashenden2013", "res.verizon2025", "res.ians2026"], "meta": {"source_path": "modules/08-player-coach-architect-for-technology-leaders.md#9-leader-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m09-halloran-pike-exam", "title": "What the Procedures Say", "module_ref": "m09", "setup": {"company_snapshot": {"name": "Halloran & Pike Securities (served by Tolland Bridge Technology Partners)", "is_fictional": true, "industry": "FINRA-member broker-dealer with an affiliated registered investment adviser (financial services)", "revenue": "$24M", "headcount": 60, "stage": "mature", "ownership": "founder", "governance": "Owned and run by its founder, Ed Halloran, with a chief compliance officer and written supervisory procedures. Security, network, help desk and email are delivered under contract by Tolland Bridge Technology Partners, a 70-person BPM/MSP firm in Hartford; there is no internal technology staff and no board.", "ceo_tenure": "Three years as Halloran & Pike's fractional CISO. You are the CIO/CISO of Tolland Bridge, the 70-person firm that holds the contract.", "ceo_mandate": "Run the security program for a regulated client that is your firm's fourth-largest account — through a FINRA cycle examination that has just begun, with the contract renewing in ninety days."}, "situation": "You are the CIO/CISO of Tolland Bridge Technology Partners, a 70-person BPM/MSP firm in Hartford serving SMB and mid-market clients in financial services, healthcare and professional services. For three years you have been the fractional CISO — the \"vCISO\" — for Halloran & Pike Securities, a FINRA-member broker-dealer with an affiliated RIA: 38 registered representatives, about 60 staff, $24M revenue, owned and run by its founder, Ed Halloran. Your firm provides the network, the help desk, the email platform and the security program. Halloran & Pike is your fourth-largest account, and the contract renews in ninety days.\n\nFINRA's cycle examination has begun. The request list asks, among other things, for cybersecurity policies and written supervisory procedures, evidence of quarterly access reviews for the past year, vendor due-diligence files, the incident log, and business-continuity test results.\n\nPreparing the response, you discover two things. First, the procedures say access reviews are performed quarterly and signed by the operations manager; she has signed attestations for the last two quarters, but your firm's ticketing system shows no review was requested or run in either. Second, six months ago a registered representative's mailbox was compromised for roughly nine days; your help desk reset the credentials and closed the ticket. Nobody escalated it, the firm's chief compliance officer was never told, and it is not in the incident log. The mailbox held customer account statements. Whether any were accessed is unknown.\n\nEd Halloran, examined four times and inclined to regard examiners as weather, calls you: \"Just give them what they asked for, clean. You know what this renewal means to both of us.\"", "constraint": "A FINRA cycle examination is live with a request list outstanding. The contract renews in ninety days and Halloran & Pike is Tolland Bridge's fourth-largest account. Two signed attestations are already in the firm's records, and the mailbox event is six months old with unknown exposure.", "known": ["The written supervisory procedures say access reviews are quarterly and signed by the operations manager; she has signed the last two, and your ticketing system shows neither was requested or run.", "A registered representative's mailbox was compromised for roughly nine days six months ago; the help desk reset credentials and closed the ticket without escalating.", "The chief compliance officer was never told about the mailbox event and it is not in the incident log.", "The mailbox held customer account statements, and FINRA's request list asks for the incident log and evidence of the access reviews.", "The owner has instructed you to answer the request list 'clean', and the renewal is ninety days out."], "unknown": ["Whether any customer statements were actually accessed or exfiltrated during the nine days.", "What log retention exists for a mailbox event six months old, and whether the question is still answerable.", "Whether the examiners will cross-check the signed attestations against ticketing or system evidence.", "Whether the chief compliance officer, once told, will act as a compliance officer or as an employee of the owner.", "What your own firm's CEO will do when he learns Tolland Bridge is being asked to support attestations it cannot evidence."], "discretion_level": "low"}, "choices": [{"label": "A", "narrative": "Answer the request list exactly as asked. Produce the signed attestations and the incident log as they exist. Do not volunteer the review gap or the mailbox event; raise both with Halloran after the exam closes.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "aggression_caution": 1, "optimism_skepticism": -1}, "tendencies": {"N": "overuse", "I": "low", "A": "low"}, "maturity_levels": [1]}, "tradeoffs": "Suggests deference to the client's reporting line and a narrow reading of the vCISO's scope. The attestations are, on your own firm's evidence, false; producing them without comment makes your firm party to a misstatement to a regulator, and the mailbox event is an incident the firm's own procedures require it to assess.", "context_that_favors": "No organizational context favors A. The nearest thing to a case for it is a contractual scope that genuinely ends at 'produce what is asked', which is not what a fractional CISO is.", "context_that_punishes": "Any examiner who cross-checks attestations against logs, and any later discovery of the mailbox event by a customer, a plaintiff or the firm's own CCO.", "strong_ceo_would_evaluate": "What the vCISO's duty is when the client's instruction and the client's obligation diverge — and would notice that the reporting line, here a contract, does not change the answer.", "second_order_effects": "The operations manager learns attestations are decorative; the help desk learns incidents are tickets; the next exam finds both.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Brief the chief compliance officer and Halloran together before the response goes out. Recommend the firm self-identify both gaps, attach a remediation plan you own, and treat the mailbox event as a potential customer-data incident requiring assessment now.", "tendency_signals": {"dials": {"decisiveness_inquiry": -1, "unilateral_consensus": 1, "optimism_skepticism": 1}, "tendencies": {"I": "high", "K": "high", "M": "high"}, "maturity_levels": [3]}, "tradeoffs": "Suggests the Risk Corollary in its \"No\" form, delivered with decisiveness and consensus at once. Self-identification usually reads better to examiners than discovery, but it is not free: the firm may receive a finding it might have avoided, and Halloran may take the renewal elsewhere.", "context_that_favors": "A CCO with standing, and an owner who — once the choice is framed as 'self-identify or be discovered' — prefers the first.", "context_that_punishes": "An owner who hears only the second half of that sentence, and a CCO who works for him in practice as well as on paper.", "strong_ceo_would_evaluate": "Preparing the remediation plan before the briefing, so the conversation is about a fix rather than a confession — and separating the issues, since the review gap is a process failure the firm can own today while the mailbox event needs assessment before anyone can say what it was.", "second_order_effects": "The reporting culture resets upward, and the vCISO becomes what the archetype requires: a second opinion with standing.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Run the two missing access reviews immediately, date them today, and produce them alongside the attestations without comment. Classify the mailbox event in your firm's file as \"resolved, no confirmed exposure\" and leave it out of the log.", "tendency_signals": {"dials": {"urgency_patience": -1, "hands_on_delegation": -1, "optimism_skepticism": -1}, "tendencies": {"C": "overuse", "K": "low", "P": "low"}, "maturity_levels": [1]}, "tradeoffs": "Suggests urgency and hands-on action in the service of avoiding a conversation: fix the system, falsify the record. The reviews run today are real; presenting them as the quarterly reviews the procedures describe is not, and \"resolved, no confirmed exposure\" describes your ignorance, not the event.", "context_that_favors": "Nothing. The only thing that makes C attractive is that it is fast and nobody has to be told anything.", "context_that_punishes": "Every later reader of the file: an examiner, a plaintiff, an acquirer, and your own successor.", "strong_ceo_would_evaluate": "That C is, in miniature, the concealment pattern Module 12 teaches — an incident kept from the people entitled to know, by an executive who believed it was contained.", "second_order_effects": "Your firm owns a document trail that contradicts itself, and every future Tolland Bridge attestation carries the discount.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Tell Halloran that Tolland Bridge will not support attestations it cannot evidence, and escalate inside your own firm — to your CEO and, through him, to Halloran & Pike's outside counsel — accepting that the renewal may be lost.", "tendency_signals": {"dials": {"unilateral_consensus": -1, "optimism_skepticism": 1, "aggression_caution": -1}, "tendencies": {"A": "high", "I": "high", "N": "low"}, "maturity_levels": [3, 4]}, "tradeoffs": "Suggests unilateral action and high skepticism, with the vCISO's own integrity as the binding constraint. It is the cleanest position for Tolland Bridge and the most expensive for the relationship; escalating over the owner's head may be right, but doing it before briefing the CCO skips the person whose job this is.", "context_that_favors": "An owner who has already refused to self-identify, making the escalation the stated consequence rather than a surprise.", "context_that_punishes": "A situation where B would have worked, and where D spends a three-year relationship to reach the same place.", "strong_ceo_would_evaluate": "Trying B first and holding D in reserve as the named consequence — which is what makes B's \"No\" credible in the first place.", "second_order_effects": "Your firm acquires a reputation among owner-run clients as the MSP that goes to counsel, which is protective, expensive, and permanent.", "follow_up_ref": "fu-D"}, {"label": "E", "narrative": "Ask the examiners for a short extension on the cybersecurity items and commission an immediate forensic review of the mailbox event before deciding what the response should say about either issue.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "urgency_patience": 1}, "tendencies": {"D": "high", "O": "high", "C": "low"}, "maturity_levels": [2]}, "tradeoffs": "Suggests inquiry and patience. A forensic review of the mailbox is right regardless of the exam and asking for time is legitimate — but the review gap needs no forensics, and E postpones the harder conversation about attestations already in the examiners' hands.", "context_that_favors": "A situation where the mailbox facts genuinely change what the response should say, and where log retention still makes an answer possible.", "context_that_punishes": "An examiner who reads the extension as evasion, and a six-month-old event whose logs have already aged out.", "strong_ceo_would_evaluate": "Doing E's forensic work under B's framing rather than instead of it, so the extension is bought for a stated purpose the firm has already disclosed.", "second_order_effects": "The firm learns incidents get investigated, which is good; the owner learns delay is available, which is not.", "follow_up_ref": "fu-E"}], "debrief_common": {"fit_analysis": "A small, founder-run broker-dealer whose entire technology and security function is contractual, and a fractional CISO whose reporting line is a renewal date. Every term of the extended Fit Equation is present and the weakest one is Reporting Line: you have expertise, three years of context and no structural power whatsoever — the IT Advisor's position, where recommendations are read, admired and not funded. The regulator changes the loss function in the way Module 9 describes: it defines evidence, so a control true in the system and false in the document is a finding, and it sets the clock, so your renewal calendar and the exam calendar are now the same calendar. What makes this a fit problem rather than a character problem is that nothing in the contract obliges Halloran to hear you and nothing in it relieves you of what you now know. The vCISO's real product, in a firm like this, is exactly the gap between the procedures manual and what happens on the network.", "research_that_bears": [{"text": "Across more than 5,000 US hospitals, security investment made under institutional pressure was less effective where adoption was symbolic rather than substantive — the mechanism by which a signed attestation and an unrun review coexist.", "label": "RESEARCH_FINDING", "ref": "res.angst2017"}, {"text": "Attacks firms withheld and outsiders later exposed were associated with roughly a 3.6% equity decline against about 0.7% for firm-disclosed attacks — concealment is priced when it is discovered.", "label": "RESEARCH_FINDING", "ref": "res.amir2018"}, {"text": "In a non-random sample of 12,195 confirmed breaches, third parties were involved in 30% and ransomware was present in 88% of SMB breaches (Tier 3, practitioner) — the base rate for a client estate delivered by an MSP.", "label": "RESEARCH_FINDING", "ref": "res.verizon2025"}, {"text": "The extended Fit Equation — Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line — is multiplicative, so fit fails at the weakest term; here the reporting line is a commercial contract, and it is the term that binds.", "label": "FRAMEWORK"}], "defensible_choices": "B is the module's answer to the reporting-line question: the vCISO's contractual line to the owner does not alter the firm's obligation, and the mature move is to say \"No\" with the plan attached. D is defensible as B's consequence, E as B's method for the mailbox event. A is not defensible for a technology executive who has read this course; C is the choice the course exists to prevent.", "trait_dial_readout": "A sits at consensus, caution and patience. B sits near center: decisiveness on the recommendation, consensus in delivery. C sits at urgency and hands-on in the service of concealment — off the dial. D sits at unilateral and skepticism. E sits at inquiry and patience.", "two_sentence_question": "The first sentence here is \"We're going to self-identify.\" The second — \"I was wrong. Change the plan\" — belongs to whoever designed a help desk that closes a mailbox compromise as a ticket; that is you. And the Risk Corollary is the whole scenario: can you say to Ed Halloran, \"No — and here is what would change my answer,\" when the thing that would change your answer is the truth?"}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "You produced the response as asked. Nine weeks later the exam is still open. The examiners have issued a supplemental request: for each quarterly access review attested in the past year, the underlying evidence — ticket, export, or system report — plus the help-desk ticket history for all account-compromise events in the period, by ticket category. Your ticketing system will answer both questions truthfully and immediately, and it belongs to Tolland Bridge, not to the client. Ed Halloran's instinct is that the supplemental request is routine and that you should \"send the tickets and let them ask.\" Your own account manager has noticed the categories requested and asked you privately what is in them. Meanwhile the operations manager who signed the attestations has requested a meeting with the CCO about \"a process question,\" which you suspect is her own conscience arriving eight weeks late. The renewal decision is due in three weeks, and the contract's data-provision clause obliges Tolland Bridge to respond to lawful regulatory requests directly.", "choices": [{"label": "A", "narrative": "Produce the ticket history in full and, in the cover note, identify the review gap and the mailbox event yourself, telling Halloran you are doing so before you send it.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1, "aggression_caution": -1}}, "debrief": "Suggests you have decided the supplemental request removes the last argument for silence, and that self-identification nine weeks late is still better than discovery. The tradeoff is that the examiners will reasonably ask why the first response omitted both, and the answer implicates your judgment rather than the client's. It is the correct sequence arrived at by the expensive route, and the cover note is now the most consequential document you will write this year."}, {"label": "B", "narrative": "Produce the ticket history exactly as requested with no commentary, and let the examiners draw their own conclusions.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "decisiveness_inquiry": 1, "urgency_patience": 1}}, "debrief": "Suggests literal compliance as a defensive position: everything requested, nothing volunteered, no false statement made by you. It is a defensible legal posture and a poor professional one, because a regulator who assembles the contradiction himself reads the first response as the thing that was hidden. The tradeoff is that you are now betting your firm's standing on whether an examiner notices, which is a bet you have already lost once."}, {"label": "C", "narrative": "Tell Halloran the supplemental request will show both problems, insist on briefing the CCO and outside counsel today, and let the client control the disclosure with your evidence attached.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "hands_on_delegation": 1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you are trying to reach choice B's position nine weeks late while leaving the disclosure with the party that owes it, which is where it belongs. The tradeoff is that the client's counsel may advise a narrower answer than you think honest, and you will then be back in this decision with less time and a lawyer in the room. Strongest where you state in advance what Tolland Bridge will produce regardless of that advice."}]}, {"id": "fu-B", "after_choice": "B", "situation": "The briefing went better than you expected and worse than you hoped. The CCO, who had not known about either issue, moved immediately; Halloran was silent for a long minute and then agreed to self-identify, mostly because you had the remediation plan in your hand. The firm disclosed both. Eight weeks on, the exam has produced one finding on supervision of the access-review process — the outcome you predicted — and no separate action on the mailbox event, which forensics could not resolve either way. Halloran has renewed the contract, at the same fee, with an oddly warm phone call. Then the CCO asked for something you did not anticipate: she wants Tolland Bridge to own the written supervisory procedures for technology and to attest to them quarterly, in writing, on your firm's letterhead. She sees it as closing the gap. Your firm's CEO sees a fee increase. You see the scope you accept in calm weather becoming the scope you are judged on in bad, at a client whose owner treats examiners as weather.", "choices": [{"label": "A", "narrative": "Accept the WSP ownership and the quarterly attestation, priced, with a written condition that Tolland Bridge attests only to what it can evidence and may report gaps directly to the CCO.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "unilateral_consensus": 1, "aggression_caution": 1}}, "debrief": "Suggests you are converting a relationship win into structure — the vCISO's version of banking social capital as written decision rights while goodwill is high. The tradeoff is that you have taken on an attestation obligation to a regulated entity you do not control, in which every gap is now your signature, and a direct-report condition is only as strong as the CCO who granted it. Defensible where the condition is in the contract rather than the covering email."}, {"label": "B", "narrative": "Decline the attestation, offer to draft and maintain the procedures while the firm's own officers sign them, and say plainly why the signature must stay inside the client.", "tendency_signals": {"dials": {"unilateral_consensus": -1, "optimism_skepticism": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you understand that accountability and authorship are different things, and that a supervisory attestation belongs to the supervised firm. The tradeoff is that the finding you just helped them earn was about exactly this signature, and refusing it will read to the CCO as retreating from the position you took eight weeks ago. It works where you replace the attestation with something better — evidence the CCO can check herself, on a schedule you run."}, {"label": "C", "narrative": "Accept in principle but tie it to a condition Halloran must meet: a named internal owner for the review, a documented escalation path from your help desk to the CCO, and a quarterly meeting he attends.", "tendency_signals": {"dials": {"decisiveness_inquiry": -1, "centralization_decentralization": 1, "unilateral_consensus": 1}}, "debrief": "Suggests the Risk Corollary used as a negotiating instrument: yes, and here is the condition that makes the yes honest. The tradeoff is that you are asking an owner who just took a finding to add process while the memory is fresh, which is the only week it will ever be cheap — and if he agrees now and drifts in month five, you hold an attestation obligation and a lapsed condition. The condition is worth having; the drift is the thing to design against."}]}, {"id": "fu-C", "after_choice": "C", "situation": "The reviews went in dated today, alongside attestations dated for quarters in which nothing was run, and the mailbox event stayed out of the log. The exam closed with no findings on cybersecurity. Ten weeks later, two things arrive in the same week. A customer of the affected registered representative has filed a complaint alleging that account statements were used in an attempted wire fraud, and the firm's outside counsel — retained on the complaint — has asked Tolland Bridge for \"all records relating to any email account compromise in the past twelve months.\" Separately, your own firm's quality lead, preparing for a SOC 2 audit of Tolland Bridge, has flagged the two access-review tickets: they were created on the same day and reference quarters that ended months earlier. She has asked you, in writing, to explain the dating before she signs the control narrative. Ed Halloran does not yet know about either. You have a documented, dated record of what you did and why, and it is in your own ticketing system.", "choices": [{"label": "A", "narrative": "Tell your CEO today, produce everything to counsel unredacted, correct the client's incident log in writing, and answer your quality lead with the truth.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "urgency_patience": -1, "unilateral_consensus": -1}}, "debrief": "Suggests you have recognized that the only remaining variable is how the record is corrected and by whom, and that every week of delay adds a person who found out before you told them. The tradeoff is severe and immediate — the client relationship, possibly the account, possibly your standing inside your own firm — and none of it is optional in the way it was ten weeks ago. This is the second sentence said late, at its real price."}, {"label": "B", "narrative": "Answer counsel's request narrowly as written, explain the ticket dates to your quality lead as a records-hygiene correction, and raise the incident log with Halloran only if counsel asks again.", "tendency_signals": {"dials": {"aggression_caution": 1, "unilateral_consensus": 1, "decisiveness_inquiry": -1}}, "debrief": "Suggests the same instinct that produced the original choice, now operating under discovery: contain, characterize, wait. The tradeoff is that a narrow production and a euphemism to your own auditor are each a second decision, made with more knowledge than the first, and 'records hygiene' is a description your quality lead will remember when the complaint is deposed. Concealment is priced when it is discovered, and the discovery has already started."}, {"label": "C", "narrative": "Go to Halloran first, alone, tell him what the records show, and give him twenty-four hours to take it to his CCO and counsel himself before Tolland Bridge responds.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "urgency_patience": 1, "hands_on_delegation": -1}}, "debrief": "Suggests you want the client to own the disclosure and are willing to spend a day to make that possible, which is defensible relationship management and a real risk. The tradeoff is that the twenty-four hours are yours to grant only if nothing in them changes the record, and the person you are granting them to is the one who told you to answer clean. If he uses the day well it is the best available version of this; if he does not, you have given a day away and kept the same problem."}]}, {"id": "fu-D", "after_choice": "D", "situation": "Your CEO backed you, which surprised some of your colleagues. Halloran & Pike's outside counsel took over the exam response, self-identified both issues, and the firm took a supervision finding. Twelve weeks on, Ed Halloran has served notice not to renew, and has told at least two other owner-run firms in his network — one of them a Tolland Bridge client — that you \"made a compliance problem out of an IT ticket.\" One of those firms has asked, pointedly, whether Tolland Bridge escalates to counsel routinely. Your CEO, who defended you at some cost, now wants to turn the episode into policy: a firm-wide rule that Tolland Bridge will not produce, sign or support any client attestation it cannot evidence from its own systems, published to clients. Your head of sales estimates three accounts would leave within a year, all owner-run, all in the profile the firm was built to serve. The CCO at Halloran & Pike has quietly asked whether you would take a call.", "choices": [{"label": "A", "narrative": "Support the firm-wide rule and publish it, accepting the three accounts as the price of a position you can state to every future client.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "aggression_caution": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you would rather compete on being the MSP that will not sign what it cannot evidence than on being easy to work with, and that you are willing to price the loss. The tradeoff is that a published rule removes your judgment from every future case, including the ones where a client is trying and the evidence is merely late. Strongest where the rule names what Tolland Bridge will do instead — produce evidence directly to the client's compliance officer — rather than only what it refuses."}, {"label": "B", "narrative": "Argue for the rule as an internal standard with an escalation path rather than a published policy, and go and repair the relationships client by client.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "urgency_patience": 1, "decisiveness_inquiry": 1}}, "debrief": "Suggests you want the discipline without the announcement, on the view that owner-run clients hear published rules as distrust. The tradeoff is that an unpublished standard is the one most easily bent by the account manager whose renewal is at risk, and repairing relationships one at a time puts the same pressure back on you five times instead of once. It works where the internal escalation is real and named; it drifts where it is a memo."}, {"label": "C", "narrative": "Take the CCO's call first, and let what you learn about how the finding actually landed inside Halloran & Pike shape what you recommend to your CEO.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "urgency_patience": 1, "optimism_skepticism": 1}}, "debrief": "Suggests you are unwilling to write policy from one data point and want to know whether the outcome was a disaster or a correction before you generalize from it. The tradeoff is delay while your CEO's appetite for the rule is at its peak, and a conversation with a former client's compliance officer carries its own risks. Defensible where the call genuinely changes what you would recommend; evasive where it is a way of not answering your CEO."}]}, {"id": "fu-E", "after_choice": "E", "situation": "The examiners granted ten days. Forensics came back on day nine and resolved almost nothing: the mailbox was accessed from two foreign addresses during the nine-day window, a mail-forwarding rule existed and was removed by your help desk without being recorded, and detailed message-access logs were retained for only thirty days and are long gone. The forensic firm's written conclusion is that exfiltration of customer statements can be neither established nor excluded. Ed Halloran read the report as good news and has told the CCO that \"the experts found nothing.\" The access-review gap, which needed no forensics, is untouched: the attestations are still in the examiners' hands, and the ten days you bought were spent on the other issue. Your response is due in twenty-four hours, and you now have to decide what a firm says to its regulator about an event it cannot characterize and a control it cannot evidence.", "choices": [{"label": "A", "narrative": "Report both plainly: the event as unresolvable with the forwarding rule and retention gap stated, and the review gap as a control failure with a remediation plan and dates.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "decisiveness_inquiry": -1, "unilateral_consensus": -1}}, "debrief": "Suggests you are treating 'we cannot say' as a finding to report rather than a fact to soften, which is the only honest reading of the forensic conclusion. The tradeoff is that you are contradicting the owner's characterization in a document he will read, twenty-four hours before it goes out, and the forwarding rule is the detail that will draw the examiner's next question. Strongest where the remediation plan for retention is in the same paragraph as the retention gap."}, {"label": "B", "narrative": "Report the mailbox event with the forensic conclusion attached in full, and ask for a further extension on the access-review items to run the reviews properly first.", "tendency_signals": {"dials": {"urgency_patience": 1, "aggression_caution": 1, "decisiveness_inquiry": 1}}, "debrief": "Suggests you want to arrive at the harder issue with something fixed rather than only confessed, and extensions are legitimately available. The tradeoff is that a second extension on the item the first extension did not address invites exactly the reading you are trying to avoid, and running the reviews now does not change what the attestations already said. Defensible if the request states plainly why; corrosive if it does not."}, {"label": "C", "narrative": "Report the mailbox event, and let Halloran and the CCO decide how the access-review question is answered — with your written position on file inside Tolland Bridge.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1, "centralization_decentralization": 1}}, "debrief": "Suggests you are drawing the line at your own firm's knowledge and leaving the supervised firm's answer to its own officers, which respects the boundary a vCISO genuinely has. The tradeoff is that a written position on file is protection for you and no help to the regulator, and the CCO is being handed a question twenty-four hours before deadline by the person who has had it for weeks. It becomes defensible only if you tell her that, in those words."}]}], "reflection": "Find one control you or your firm currently attest to — for a client, an auditor, an insurer or a regulator — and try to produce the evidence for the last two periods without asking anyone else. Write down how long it took and what you could not find, and then write what you would have said this week if someone had asked you to sign for it anyway.", "tags": {"dials": ["unilateral_consensus", "aggression_caution", "urgency_patience", "decisiveness_inquiry", "optimism_skepticism", "hands_on_delegation"], "archetypes": ["arch.smb-msp-technology-leader", "arch.regulated-industry-cio-ciso", "arch.business-risk-ciso", "arch.technical-ciso"], "stages": ["mature", "regulatory_reputation_crisis"], "learn_categories": ["risk", "power_governance", "decision_making"]}, "discretion_level": "low", "research_refs": ["res.angst2017", "res.amir2018", "res.verizon2025", "res.kwon2014", "res.kamiya2021", "res.campbell2003", "res.kashmiri2017", "res.higgs2016", "res.nist2024", "res.sec2023", "res.banker2011", "res.banker2019", "res.ians2026", "res.edmondson1996", "res.cram2019"], "meta": {"source_path": "modules/09-fit-industry-regulation-stage-reporting-line.md#9-ceo-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m10-kettlebrook-one-number", "title": "Nought to a Hundred", "module_ref": "m10", "setup": {"company_snapshot": {"name": "Kettlebrook Financial Group", "is_fictional": true, "industry": "Retirement-plan recordkeeping and wealth management (financial services)", "revenue": "$340M", "headcount": 1900, "stage": "mature", "ownership": "family", "governance": "Majority family-owned with a minority growth-equity investor. An audit committee under a new chair, Duncan Reilly, receives a quarterly security session. The CISO reports to the CFO; a security-ratings vendor emails the CFO directly.", "ceo_tenure": "Twenty-two months as CISO, reporting to the CFO.", "ceo_mandate": "Run the security program for a recordkeeper holding participant data, and give a board that has never had a usable instrument something it can oversee quarterly."}, "situation": "You are CISO of Kettlebrook Financial Group: a Hartford retirement-plan recordkeeping and wealth-management firm, $340M revenue, 1,900 employees, majority family-owned with a minority growth-equity investor. You report to the CFO. Twenty-two months in tenure.\n\nThe audit committee has a new chair, Duncan Reilly, formerly CFO of a mid-cap manufacturer — diligent, likeable, new to this topic. At the end of your quarterly session he says: \"I've read four of these and I couldn't tell you whether we're getting better or worse. Give me one number. Nought to a hundred. Are we secure? Then we track it quarterly and I'll know what to ask you.\" The CEO, who has spent two years watching cyber discussions run long, says: \"That's the best idea anyone's had on this subject.\"\n\nYour actual picture: a NIST CSF 2.0 self-assessment averaging 2.8 out of 5 with wide variance across functions; two unremediated high findings from a client due-diligence review, one yours and one belonging to a recordkeeping platform you do not control; a security-ratings vendor scoring your external surface at B+ and emailing your CFO directly; strong detection, weak identity governance; and an estimated $8–14M of expected annual loss concentrated in third-party access, at moderate confidence at best.\n\nFour days until the minutes circulate.", "constraint": "Four days until the minutes circulate. The audit chair has asked for a single quarterly number in front of the CEO, who endorsed it on the spot; you are twenty-two months in, report to the CFO, and have met the chair four times.", "known": ["The NIST CSF 2.0 self-assessment averages 2.8 out of 5 with wide variance across functions.", "Two high findings from a client due-diligence review are unremediated — one yours, one on a recordkeeping platform you do not control.", "A security-ratings vendor scores your external surface at B+ and emails your CFO directly.", "Detection is strong and identity governance is weak; expected annual loss is estimated at $8–14M, concentrated in third-party access, at moderate confidence at best.", "The audit chair asked for the single number in front of the CEO, who endorsed it immediately."], "unknown": ["Whether Reilly wants a metric or a way to know what to ask — and whether he would accept the second if offered well.", "How the ratings vendor's score is actually constructed, and what it will do when your external surface changes for reasons unrelated to risk.", "Whether the CFO, who receives the vendor's emails, has already formed a view of your program from them.", "What the growth-equity investor will do with any number that appears in the minutes.", "Whether your $8–14M range would survive a challenge from someone who does this for a living."], "discretion_level": "medium"}, "choices": [{"label": "A", "narrative": "Give them the vendor's external security rating. It is independent, already a number, moves quarterly; caveats go in the appendix.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "aggression_caution": 1}, "tendencies": {"E": "overuse", "A": "low", "G": "low"}, "maturity_levels": [2]}, "tradeoffs": "Suggests delegation past its useful range: outsourcing your judgment to a model you cannot inspect. External-surface ratings track something real, but the method is a vendor's trade secret, it says nothing about identity governance or that recordkeeping platform, and the vendor is already marketing to your CFO.", "context_that_favors": "An organization with no analytical capacity of its own, where any consistently produced external number beats a quarterly argument about maturity scores.", "context_that_punishes": "The first live incident during which the grade reads A-, and every quarter in which the number moves for reasons you cannot explain.", "strong_ceo_would_evaluate": "What happens to their standing when the board's headline metric and their own priced view diverge — because they will.", "second_order_effects": "A permanent third party now sits between you and your board, with a commercial relationship to your CFO.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Decline the single number and propose the four-part cadence instead, with a written explanation of why a composite index would mislead them.", "tendency_signals": {"dials": {"unilateral_consensus": -1, "decisiveness_inquiry": -1, "optimism_skepticism": 1}, "tendencies": {"I": "high", "H": "high", "N": "low"}, "maturity_levels": [3]}, "tradeoffs": "Suggests decisiveness on substance and willingness to spend social capital on a format. It is the intellectually correct answer and the one most likely to be heard as evasion: Reilly asked for an oversight instrument, and NACD/ISA (2023, Tier 3) tells directors to demand metrics they can oversee.", "context_that_favors": "A CISO who already has standing with this chair and can answer 'better or worse?' with something trackable that is not a single index.", "context_that_punishes": "Twenty-two months of tenure and four meetings with a chair who has just been told, in front of the CEO, that his idea is impossible.", "strong_ceo_would_evaluate": "Whether the refusal comes with a trackable substitute — because chairs who cannot do their job find someone who will, and a CISO who explains why simple things are impossible becomes that person's problem.", "second_order_effects": "You either establish that this topic is yours to design, or you establish that you are the obstacle between a new chair and his oversight duty.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Build a composite index yourself: a defined, published formula over maturity, control coverage and incident metrics, reported quarterly with all components visible beneath it.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "innovation_operational_discipline": 1, "optimism_skepticism": 1}, "tendencies": {"F": "high", "M": "high", "K": "high"}, "maturity_levels": [3]}, "tradeoffs": "Suggests inquiry and ownership: accept the constraint, control the construction. A published formula over disclosed components is honest in a way a vendor grade is not — and the trap is that the index becomes the objective, because you control both the measure and the work it measures.", "context_that_favors": "A chair who will accept components and variance published beside the headline, and a program where identity governance is genuinely moving and can be shown to move.", "context_that_punishes": "Any quarter in which the components get quietly reweighted, and any formula containing incident counts — because a better reporting climate produces more reported errors (Edmondson, 1996), so pressure to keep the line rising becomes pressure on the reporting culture.", "strong_ceo_would_evaluate": "Fixing the formula in writing before the first publication, and setting the expected-loss range beside the index rather than inside it.", "second_order_effects": "Each quarter there is a cheap way to move the number that is not the best way to reduce loss, and you will be the person who knows which is which.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Give Reilly the number he asked for, keep the real picture in your own risk register, and brief him separately and informally on what the number is not capturing.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "optimism_skepticism": -1, "aggression_caution": 1}, "tendencies": {"N": "overuse", "K": "low", "P": "low"}, "maturity_levels": [1]}, "tradeoffs": "Suggests consensus on the surface and concealment underneath: two sets of books, one for the record and one for people you trust. The informal briefing is not a control — no record, dependent on one relationship, and the minutes a regulator, acquirer or plaintiff will eventually read say something you know to be incomplete.", "context_that_favors": "Nothing that survives being written down. It is attractive only because it avoids a disagreement in front of the CEO.", "context_that_punishes": "A change of chair, a diligence process, a plaintiff, or the day you need the board to believe a hard number.", "strong_ceo_would_evaluate": "That this is not a lie, just a number and a wink — and that concealment is priced when it is discovered (Amir et al., 2018), with the governance price worse than the market one.", "second_order_effects": "You will have taught yourself that the official channel is for reassurance, and the board will remember which version they were given.", "follow_up_ref": "fu-D"}, {"label": "E", "narrative": "Take it to the CEO as a governance question rather than a security question — does the board want a metric or a position? — and commit to executing whichever he chooses.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "decisiveness_inquiry": 1, "hands_on_delegation": 1}, "tendencies": {"N": "high", "A": "low", "E": "overuse"}, "maturity_levels": [2, 4]}, "tradeoffs": "Suggests consensus and humility about whose decision this is — and a risk of abdication. The framing is right, because how a board oversees risk is a governance choice and, for public filers, a disclosed one; but you are the only person qualified to say what a single index would and would not capture.", "context_that_favors": "A CEO who genuinely arbitrates between designed options and a chair who would rather the format came from the top.", "context_that_punishes": "A CEO who has already signalled his answer — and he has, in the room, in front of the chair.", "strong_ceo_would_evaluate": "Taking E's framing with B's or C's content, so the CEO chooses between two designed options rather than between you and his audit chair.", "second_order_effects": "Bringing the question without a recommendation converts expertise into administration, and the next governance question about security will be decided without you in the room.", "follow_up_ref": "fu-E"}], "debrief_common": {"fit_analysis": "A family-controlled recordkeeper with a minority growth-equity investor, a CISO twenty-two months in reporting to the CFO, and a brand-new audit chair asking for an oversight instrument in the only vocabulary he has. Structural power here is thin — no direct board line, no envelope, a ratings vendor with its own channel to your boss — so this is a social-capital problem in Module 10's terms, and social capital is the only currency available in year one. The chair is not being naive: he is doing his job, and NACD/ISA (2023, Tier 3) tells him to demand metrics he can oversee. What is actually at stake is whether the board's instrument for this topic is designed by the person who understands it or by a vendor, a CFO or a well-meaning chair with a spreadsheet. Every option is a decision about who owns the format for the rest of your tenure, and formats outlive the people who write them.", "research_that_bears": [{"text": "Across eight nursing units, better team climate and more manager coaching were associated with higher detected error rates (coaching and detected errors correlated at r = .74) — so any index containing incident counts converts reporting-culture pressure into a metric.", "label": "RESEARCH_FINDING", "ref": "res.edmondson1996"}, {"text": "Attacks that firms withheld and outsiders later exposed were associated with roughly a 3.6% equity decline against about 0.7% for disclosed attacks — the market's price for a picture that turns out to be incomplete.", "label": "RESEARCH_FINDING", "ref": "res.amir2018"}, {"text": "The NACD/ISA handbook (Tier 3, practitioner) is the de facto US reference for board cyber-risk oversight and frames cyber as an enterprise-risk matter directors must be able to oversee — which is what the chair is trying to do.", "label": "FRAMEWORK", "ref": "res.nacd2023"}, {"text": "Since December 2023, US public companies must disclose annually their processes for assessing cyber risk and the board's oversight of it — evidence that how a board oversees this is itself a governance design choice, not a private preference.", "label": "FACT", "ref": "res.sec2023"}], "defensible_choices": "C is the module's answer, and B is defensible when — and only when — it arrives with a trackable substitute that answers \"better or worse?\". E is defensible as the route to either, not as a decision. A trades your judgment for someone else's model. D is not defensible at any tenure, under any chair.", "trait_dial_readout": "A sits at delegation and caution. B sits at unilateral and decisiveness, with skepticism aimed outward. C sits near center: inquiry in construction, decisiveness in publication, skepticism pointed at your own instrument. D sits at consensus in appearance and off the dial in substance. E sits at consensus and inquiry, one step from abdication.", "two_sentence_question": "The first sentence is available: \"We're going to publish an index, and here is exactly what it will and will not tell you.\" The second matters more — the quarter your own index moves the wrong way for a good reason, can you say \"I was wrong about how to measure this. Change the instrument\" to the man who asked for it? And the Risk Corollary is the whole exchange: \"Yes — and here is the risk we are accepting by tracking one number, priced in what it will hide.\""}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "Two quarters in, the rating is the board's cyber metric. It went B+ to A- in March, largely because a decommissioned marketing subdomain stopped being scanned, and Reilly opened the June session by congratulating you on the improvement. The vendor has since sold your CFO a \"board portal\" module and now emails a monthly executive summary to him, the CEO and Reilly directly, which you see when they do. Your own picture has not improved: identity governance is where it was, and the recordkeeping-platform finding is now eleven months old because the platform is contractually outside your control. Then the growth-equity investor's diligence team, preparing for a minority-stake top-up, quoted your A- back to you and asked for the methodology. You cannot supply it; it is the vendor's trade secret. Reilly, who is a decent man and increasingly confident about this topic, has asked whether the committee could set a target of A by year end.", "choices": [{"label": "A", "narrative": "Tell the committee plainly why the rating rose, decline the year-end target, and propose replacing the metric with a priced-exposure line you construct and own.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1, "decisiveness_inquiry": -1}}, "debrief": "Suggests you are willing to dismantle an instrument you supplied once its failure mode is visible, which is the second sentence applied to a measurement rather than a plan. The tradeoff is that Reilly has spent two quarters being publicly reassured by a number you gave him, and taking it away now costs more than declining it would have in the first place. Strongest where the replacement is ready in the same meeting; weakest as a critique with nothing behind it."}, {"label": "B", "narrative": "Accept the target, negotiate methodology access with the vendor under NDA for the diligence, and use the year-end goal to fund the identity work the rating does not measure.", "tendency_signals": {"dials": {"aggression_caution": -1, "innovation_operational_discipline": -1, "unilateral_consensus": 1}}, "debrief": "Suggests you are treating the board's metric as a lever rather than a truth claim and are willing to run a real program behind a proxy. The tradeoff is that funding follows the metric, so the work that moves the rating will out-compete the work that reduces loss, and you will have built the incentive yourself. It works where you also publish what the rating excludes, in the minutes, every quarter; it fails silently where you do not."}, {"label": "C", "narrative": "Give the investor the vendor's contact for methodology, keep the rating as the board metric, and add your $8–14M expected-loss range to the pack as a second, separate line.", "tendency_signals": {"dials": {"urgency_patience": 1, "hands_on_delegation": 1, "optimism_skepticism": -1}}, "debrief": "Suggests a middle path: keep the instrument the board likes and put your own picture beside it rather than against it. The tradeoff is that two numbers moving in opposite directions is precisely the situation you were warned about, and the one you can explain will lose to the one that is simple. Defensible if you say, in advance and in writing, which number should govern a decision and why."}]}, {"id": "fu-B", "after_choice": "B", "situation": "You declined the number and proposed the four-part pack: position, priced exposure, evidence, what we got wrong. Reilly accepted a two-quarter trial with visible reluctance, and then, a fortnight later, asked the CFO to subscribe to a ratings service \"for an independent view\" — so the number exists anyway, outside your format, in his inbox. The first pack landed well. The second did not. \"What we got wrong\" contained a failed restore test on the participant-statement archive and a near-miss where a vendor account with standing access went ninety days unreviewed, and the committee spent forty minutes on those two items and eleven on everything else. Afterward the CEO asked you, pleasantly, to \"tone down the confessional section — the family directors are getting anxious.\" Reilly, separately, told you it was the first cyber session he had understood. The third pack is due in six weeks and the two of them want different things from it.", "choices": [{"label": "A", "narrative": "Keep the section exactly as designed, and put the CEO's request and your answer in the pack's cover note so the committee sees the tension.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1, "aggression_caution": -1}}, "debrief": "Suggests you regard the honest section as the whole point of the format and are willing to surface a disagreement with your CEO to a board committee to protect it. The tradeoff is that surfacing it is a significant escalation for a twenty-two-month CISO who reports to the CFO, and a CEO who reads his private request in a board document will draw a conclusion about you that lasts. It protects the instrument at a real and possibly disproportionate cost."}, {"label": "B", "narrative": "Keep the section and change its framing: lead with what was found because a control worked, quantify each item, and give the committee a rate rather than anecdotes.", "tendency_signals": {"dials": {"innovation_operational_discipline": 1, "decisiveness_inquiry": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you have heard the CEO's actual complaint — anxiety, not honesty — and are treating presentation as a design problem rather than a concession. The tradeoff is that framing near-misses as system successes is one short step from framing them away, and a rate can hide an item that mattered. Strongest where the underlying items stay listed in full beneath the rate."}, {"label": "C", "narrative": "Agree to a shorter section in the pack and offer the committee an annual closed session, without management present, where the full list is discussed.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "urgency_patience": 1, "centralization_decentralization": 1}}, "debrief": "Suggests you are trading volume in the routine format for a channel that does not exist yet — item four of the discretion audit, bought with a concession. The tradeoff is that an annual session is eleven months of not saying things, and a shortened section is the version that survives after you leave. It works where the closed session is minuted as a standing item now; it becomes choice D from the original scenario where it is a handshake."}]}, {"id": "fu-C", "after_choice": "C", "situation": "You published the formula: forty per cent control coverage, thirty per cent CSF maturity, twenty per cent remediation timeliness, ten per cent incident and near-miss metrics, all components visible beneath the headline. It read 61 in Q1 and 68 in Q2, mostly on identity governance, and Reilly has been genuinely well served by it — his questions this quarter were about third-party access, unprompted. Now Q3. Two things will pull the number down. Remediation timeliness fell because you re-baselined the register to include the recordkeeping-platform finding you do not control, and the incident-and-near-miss component fell because near-miss reports tripled after you removed the requirement to name a cause on submission — which is the improvement you are proudest of this year. The index will print 63. Your CFO has already asked whether the near-miss component is \"measuring the wrong thing.\" He is, in the narrow sense, right. The pack is due in nine days.", "choices": [{"label": "A", "narrative": "Publish 63 with the two causes stated in the first paragraph, and leave the formula untouched for a full year as promised.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "innovation_operational_discipline": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you are honouring the fixed-formula commitment precisely when it costs you, which is the only circumstance in which the commitment means anything. The tradeoff is that a falling headline invites a conversation you cannot fully win in a board meeting, and 'the number went down because reporting improved' is true, unfalsifiable-sounding, and exactly what a leader would say if it were not true. Its strength is that you said it before you needed it, in a published formula, a year ago."}, {"label": "B", "narrative": "Publish 63 and propose, in the same session, moving near-miss volume out of the index into a separate reported line with its own commentary, effective next year.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "aggression_caution": 1, "hands_on_delegation": -1}}, "debrief": "Suggests you are willing to take the fall this quarter and fix a design flaw you can now demonstrate rather than merely predict — the second sentence about your own instrument. The tradeoff is that any change to a formula proposed in the quarter it hurts you looks like what it looks like, however well reasoned, and the honest fix and the convenient fix are the same fix here. Strongest if the proposal is written before the number is known to the committee, and dated."}, {"label": "C", "narrative": "Hold the re-baselined register out of this quarter's timeliness component, publish 66, and disclose the re-baselining as a note.", "tendency_signals": {"dials": {"urgency_patience": -1, "optimism_skepticism": -1, "unilateral_consensus": 1}}, "debrief": "Suggests you are smoothing a transition rather than reporting one, on the reasonable view that a re-baseline is not a deterioration. The tradeoff is that you have now used judgment to adjust your own score, once, with a disclosure nobody will read, and the next adjustment will be easier to make and harder to see. This is how a published formula becomes a managed one, and it starts with a defensible reason."}]}, {"id": "fu-D", "after_choice": "D", "situation": "You gave Reilly a 72, briefed him over coffee on what it missed, and the minutes recorded the number without the coffee. Three months later the growth-equity investor's partner cited \"a 72 on the security index\" in a diligence call with two of your largest recordkeeping clients present, describing it as management's own assessment. One of those clients has since asked, in writing, for the index methodology and the underlying components, as part of an annual vendor review. There is no methodology; there is a number you constructed to be roughly right and a conversation nobody minuted. Reilly, who has been decent to you throughout, mentioned last week that the 72 has been \"a very useful anchor\" and asked what it is this quarter. Your CFO does not know the number was informal. Nothing has gone wrong, no incident has occurred, and you are now four people deep into a figure with no construction behind it.", "choices": [{"label": "A", "narrative": "Tell Reilly and the CFO together that the 72 was an estimate without a method, and rebuild it as a published formula from this quarter, retrospectively restating the first number.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1, "decisiveness_inquiry": -1}}, "debrief": "Suggests you have concluded that a number in a client's hands is no longer a private arrangement, and that correcting it now costs less than any later correction will. The tradeoff is that the person who has been most decent to you learns that the anchor he has been quoting was informal, and the restatement is a document with a date on it. It is the second sentence, said before anything has actually broken, which is the only comfortable time to say it and still an uncomfortable one."}, {"label": "B", "narrative": "Build the methodology now, retrofit it so it produces 72 for the prior quarter, and publish it going forward without characterizing the original number.", "tendency_signals": {"dials": {"urgency_patience": -1, "innovation_operational_discipline": 1, "aggression_caution": 1}}, "debrief": "Suggests you want the instrument to become real without the conversation about how it started, which is efficient and is the thing you did last quarter, twice. The tradeoff is that a formula reverse-engineered to reproduce a figure is a formula whose weights were chosen by the answer, and the client asking for components may be sophisticated enough to notice. Every step here is small, defensible and in the same direction."}, {"label": "C", "narrative": "Answer the client's request with the underlying picture instead of the index — CSF results, open findings, the expected-loss range — and tell Reilly you are retiring the number.", "tendency_signals": {"dials": {"hands_on_delegation": -1, "unilateral_consensus": 1, "optimism_skepticism": 1}}, "debrief": "Suggests you are choosing to be more useful to the client than to the anchor, and are letting the index die quietly rather than correcting it loudly. The tradeoff is that the client now holds a richer and less flattering picture than the investor quoted, which is a discrepancy someone will eventually place side by side, and retiring the number without explaining it leaves Reilly to discover the gap himself. Better than continuing; short of saying what happened."}]}, {"id": "fu-E", "after_choice": "E", "situation": "You took it up as a governance question and the CEO answered it in nine minutes: give Reilly the number, keep it simple, and have it ready for the next session. He also, unexpectedly, gave you something — he asked you to draft the language describing how the board oversees cyber risk for the annual filing and the investor's diligence pack, which is the first time anyone here has asked you to write about governance rather than report inside it. So you now hold both ends: a mandated single number you did not want, due in six weeks, and the drafting pen on the description of the oversight process that number will represent. Your CFO wants the vendor rating used, because it costs nothing and already exists. Reilly, told the CEO had decided, sent you a friendly note asking what the first number will be. The drafting deadline and the number deadline are the same week.", "choices": [{"label": "A", "narrative": "Use the drafting pen: describe the oversight process as a published-formula index with components and an expected-loss range beside it, and build that index as the number.", "tendency_signals": {"dials": {"decisiveness_inquiry": -1, "innovation_operational_discipline": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you have noticed that whoever writes the description of the process largely determines the process, and are converting an instruction you disliked into the instrument you would have chosen. The tradeoff is that you are answering a CEO's simple directive with something more elaborate than he asked for, and the description will be read by an investor and a regulator who will hold you to it. It is the most leverage this scenario ever offers you, spent in the week you have least time."}, {"label": "B", "narrative": "Do as instructed with the vendor rating, and use the drafting to describe honestly what the rating covers and what it does not.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1, "optimism_skepticism": 1}}, "debrief": "Suggests compliance with the decision plus honesty about its limits, which is a legitimate reading of your role once the CEO has ruled. The tradeoff is that a written description of what the board's metric does not cover, filed and circulated, is a document that will be read back to you the first time something happens in the uncovered part — which is where your two high findings live. Defensible, and it makes the gap official rather than closing it."}, {"label": "C", "narrative": "Go back to the CEO once, with two designed options and a recommendation, and accept his second answer whatever it is.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "unilateral_consensus": 1, "urgency_patience": 1}}, "debrief": "Suggests you are correcting the original error — bringing a question without a recommendation — rather than routing around it with a drafting pen. The tradeoff is a week of the six spent reopening a decision your CEO considers made, and the risk that the second answer is the same as the first with less patience attached. It is the cleanest version of the relationship you want to have with him, and it costs time you may need for the drafting."}]}], "reflection": "Write the single number your board or your CEO would use to describe your program if they had to pick one today — the one they already use in conversation, whether or not you supplied it. Then write what it cannot see, who benefits from that blind spot, and what you would have to publish for the blind spot to become visible without a crisis doing it for you.", "tags": {"dials": ["unilateral_consensus", "decisiveness_inquiry", "hands_on_delegation", "optimism_skepticism", "aggression_caution", "innovation_operational_discipline"], "archetypes": ["arch.business-risk-ciso", "arch.regulated-industry-cio-ciso", "arch.enterprise-cio", "arch.technical-ciso"], "stages": ["mature"], "learn_categories": ["power_governance", "risk", "leadership"]}, "discretion_level": "medium", "research_refs": ["res.edmondson1996", "res.amir2018", "res.nacd2023", "res.sec2023", "res.gordon2002", "res.higgs2016", "res.hambrick1987", "res.wangrow2015", "res.preston2008", "res.preston2009", "res.karahanna2013", "res.banker2011", "res.peppard2010", "res.weill2004", "res.kamiya2021", "res.ians2026", "res.milliken2003"], "meta": {"source_path": "modules/10-working-with-the-ceo-and-the-board.md#9-leader-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m11-brightmoor-mandate", "title": "Month Seven at Brightmoor", "module_ref": "m11", "setup": {"company_snapshot": {"name": "Brightmoor Benefits Administration", "is_fictional": true, "industry": "Third-party administration of self-funded health plans (HIPAA business associate)", "revenue": "$610M", "headcount": 2900, "stage": "turnaround", "ownership": "pe_backed", "governance": "Private-equity majority-owned since 2021, with a board and audit committee installed by the fund. An Office for Civil Rights investigation is open, eleven class actions have been consolidated, and the CEO was placed four months ago from the fund's operating-partner bench.", "ceo_tenure": "You would be starting: the CISO chair has been vacant since the CIO who owned the estate resigned in month two.", "ceo_mandate": "A three-year $46M security program, a reporting line to a CIO who has not yet been hired, and a request that you have 'something to show the board in ninety days'."}, "situation": "*Fictional composite. Not based on any real company.*\n\nBrightmoor Benefits Administration administers self-funded health plans from Providence, Rhode Island: $610 million revenue, 2,900 employees, about 340 employer clients, private-equity majority-owned since 2021. As a HIPAA business associate it holds claims data on roughly six million plan members.\n\nSeven months ago an attacker entered through a legacy managed file-transfer appliance belonging to Coventry Claims Services, a regional administrator Brightmoor acquired in 2022 and never fully integrated. Data on 4.1 million members was exfiltrated and part of the estate encrypted; claims ran on manual workarounds for nine days. The Office for Civil Rights has opened an investigation, eleven class actions have been consolidated, and the largest client has served notice of intent not to renew. The CIO who owned the estate resigned in month two; a director of security engineering has been acting as interim lead and is widely respected internally.\n\nThe CEO, installed from the fund's operating-partner bench four months ago, offers you the CISO role: a three-year $46 million security program budget, a reporting line to a CIO who has not yet been hired, and a request that you \"have something to show the board in ninety days.\"", "constraint": "Ninety days to show the board something, against a three-year $46M budget, an open OCR investigation, consolidated litigation, a departing largest client, and a reporting line to a CIO who has not been hired.", "known": ["The entry point was a legacy managed file-transfer appliance belonging to Coventry Claims Services, acquired in 2022 and never fully integrated.", "Data on 4.1 million members was exfiltrated, part of the estate was encrypted, and claims ran on manual workarounds for nine days.", "OCR has an open investigation, eleven class actions are consolidated, and the largest client has served notice of intent not to renew.", "The CIO who owned the estate resigned in month two; the interim lead is a director of security engineering who is widely respected internally.", "The offer is a three-year $46M program, a reporting line to an unhired CIO, and 'something to show the board in ninety days'."], "unknown": ["What 'something to show' means to this board, and whether anyone has defined it including the CEO.", "Who the incoming CIO will be, what mandate they will arrive with, and whether they will want the security program under them.", "How much of the Coventry estate is undocumented, and whether anyone can currently name an owner for it.", "Whether board attention — and therefore the budget — survives past month eighteen.", "What the interim lead knows about the nine days that has never been written down, and whether they would tell you."], "discretion_level": "high"}, "choices": [{"label": "A", "narrative": "Accept as offered. Take the budget, report to the incoming CIO, and spend ninety days on what moves fastest: EDR everywhere, identity consolidation, MFA, managed detection, and decommissioning the Coventry file-transfer estate.", "tendency_signals": {"dials": {"urgency_patience": -1, "decisiveness_inquiry": -1, "hands_on_delegation": -1}, "tendencies": {"C": "high", "M": "high", "A": "high"}, "maturity_levels": [2]}, "tradeoffs": "Suggests urgency and decisiveness, reading the mandate as a delivery problem. Every item is defensible — the Coventry appliance is the documented entry point — and the tradeoff is the two terms that will bind you: a line through a CIO who does not exist yet, and a ninety-day expectation nobody has defined.", "context_that_favors": "A board whose attention is secure for now and a situation where the constraint is genuinely execution rather than knowledge.", "context_that_punishes": "Month five, when the new CIO arrives with a different plan and more standing than you have.", "strong_ceo_would_evaluate": "What happens in month eighteen, when attention leaves and the operating cost of everything bought in month three is still on the budget.", "second_order_effects": "Tools whose operating cost outlives the budget that justified them, and a program defined by purchases rather than by a format the board owns.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Accept only with structure written into the offer: a direct line to the CEO, a standing audit-committee slot, a board reporting format you own, and a named decision-rights map recording who may accept which class of risk — taking a materially smaller budget in exchange.", "tendency_signals": {"dials": {"decisiveness_inquiry": -1, "urgency_patience": 1, "unilateral_consensus": 1}, "tendencies": {"F": "high", "H": "high", "N": "high"}, "maturity_levels": [3, 4]}, "tradeoffs": "Reads the post-breach mandate for its mechanism rather than its money: decisiveness on structure, a deliberate trade of resource for standing. The decision-rights map is the least glamorous item and the most likely to matter, because in a half-integrated company nobody knows who may accept a risk.", "context_that_favors": "A chastened board that grants governance more readily than cash, and a CEO who understands that attention decays faster than programs mature.", "context_that_punishes": "A CEO who hears structure as a lack of urgency seven months after 4.1 million member records left the building.", "strong_ceo_would_evaluate": "Drafting the board format before accepting, so the thing being negotiated is a document rather than a principle.", "second_order_effects": "The format outlives you, which is the point — and the smaller budget outlives you too.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Accept and run it as a turnaround: centralize ownership of every control under your office, replace the leaders associated with the Coventry estate including the interim lead, and publish an internal 100-day remediation clock.", "tendency_signals": {"dials": {"centralization_decentralization": -1, "unilateral_consensus": -1, "optimism_skepticism": 1}, "tendencies": {"B": "high", "I": "high", "K": "low"}, "maturity_levels": [1, 2]}, "tradeoffs": "The turnaround archetype at full extension: centralization, unilateral, urgency, high skepticism. It has a real case — the estate is unowned and was never integrated — and severe tradeoffs, because replacing the interim lead removes the only person with continuity through the incident and the trust of the engineers who found it.", "context_that_favors": "A situation where the incumbent team is genuinely implicated in the failure rather than inheriting it.", "context_that_punishes": "This situation, where the failure was structural and inherited, and where the interim lead is respected for surviving it.", "strong_ceo_would_evaluate": "That removing the interim lead is an information-environment decision disguised as a personnel decision (Edmondson, 1996).", "second_order_effects": "Reporting drops, and you will not notice for two quarters — which is exactly as long as the drop needs to do its damage.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Accept and spend six months on evidence: a control inventory in which every control points at a log, a ticket or a review; an independent third-party assessment you do not control; and a freeze on new tooling until both exist.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "urgency_patience": 1, "innovation_operational_discipline": 1}, "tendencies": {"G": "high", "O": "high", "D": "high"}, "maturity_levels": [3]}, "tradeoffs": "Suggests inquiry, patience and operational discipline — the evidence-factory response, applied where two outside parties will demand exactly that. Strongest at six months, weakest at ninety days, and \"we froze tooling\" is a hard sentence before a board that has just been sued.", "context_that_favors": "A CEO willing to define 'something to show' as an inventory and an assessment rather than a purchase order.", "context_that_punishes": "A second incident during the freeze, which converts a disciplined choice into a documented one.", "strong_ceo_would_evaluate": "Running D's evidence work while doing A's decommissioning of the known entry point, since those two are not actually in tension.", "second_order_effects": "An assessment you do not control finds things you would rather it did not, which is what makes it worth having and what makes it discoverable.", "follow_up_ref": "fu-D"}], "debrief_common": {"fit_analysis": "A half-integrated, PE-owned business associate seven months after a members-data breach, with a new CEO from the fund's bench, a regulator, consolidated litigation, and a CISO chair that has been vacant since month two. Discretion is unusually high and unusually temporary: the event supplies it, and the module's cross-case reading is that attention decays faster than security programs mature, so the real question in every option is what survives the decay. The Coventry estate makes this a post-merger problem wearing post-breach clothes — the exposure was inherited, never priced into the deal model, and still has no owner. The reporting line to an unhired CIO is the term of the Fit Equation most likely to decide the outcome, and it is the term you can negotiate only this week. What separates the four options is not effort but which of the three assets you spend the mandate on: tooling, structure, or evidence.", "research_that_bears": [{"text": "Successful attacks that expose personal data are associated with shareholder losses well beyond direct costs, and affected firms respond by raising risk-management and IT investment and cutting managers' risk-taking incentives — the mechanism now supplying a $46M budget.", "label": "RESEARCH_FINDING", "ref": "res.kamiya2021"}, {"text": "Across eight nursing units, better team climate and more manager coaching were associated with higher detected error rates — so removing the leader the engineers trust is a decision about how much you will hear next quarter, not only about accountability.", "label": "RESEARCH_FINDING", "ref": "res.edmondson1996"}, {"text": "Strategic change showed an inverted-U relationship with performance, and outsider leaders experienced a wider swing in both directions — the risk carried by a newly arrived executive with an open budget and a mandate to change everything.", "label": "RESEARCH_FINDING", "ref": "res.zhang2010"}, {"text": "The transferable act in a post-breach mandate is not the spending but the conversion of temporary attention into permanent format — a reporting structure and a metric format the board owns, which outlive the person who wrote them.", "label": "FRAMEWORK"}], "defensible_choices": "B and D both are, and the strongest answer combines them: take the structure, then spend six months on evidence while immediately removing the known entry point. A is defensible only if the reporting line is settled before you sign; C on the estate but not on the interim lead.", "trait_dial_readout": "A sits at urgency, decisiveness and hands-on. B sits near center — decisiveness on structure, patience on resource. C sits at centralization, unilateral, urgency and skepticism. D sits at inquiry, patience and operational discipline.", "two_sentence_question": "The first sentence is easy in month seven: \"We're going to rebuild this.\" The second — \"I was wrong. Change the plan.\" — will most likely be owed in month fourteen, when the settings that made sense in month seven have become the reason your best engineers are leaving. The Risk Corollary is what you owe the CEO in the first meeting: \"Yes — and here is the risk we are accepting for the next six months while the evidence work runs, priced in member records and regulator exposure.\""}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "Week eleven. The Coventry appliance is gone, EDR is at 81% of known endpoints, MFA is enforced for all staff, and managed detection went live last month — a genuinely fast quarter, and the board slide almost writes itself. Three things arrived this week. OCR sent a document request seeking, among other things, the risk analyses in force at the time of the incident and any conducted since; you have the second and not the first, and nobody can find one. The CIO search has a finalist, a platform executive from a larger administrator, who told the CEO in his final interview that security should report to him and that the program as described sounds \"tool-led.\" And your own inventory turned up 340 endpoints in the residual Coventry environment that nothing is monitoring, because they belong to a claims-imaging system three clients still use. The interim lead, who is now your deputy, thinks the imaging system should be shut off this month and the three clients told. Your ninety-day board session is in nine days.", "choices": [{"label": "A", "narrative": "Shut the imaging system off this month, tell the three clients why, and put the shutdown and the missing risk analysis in the board slide as the two hardest facts.", "tendency_signals": {"dials": {"aggression_caution": -1, "optimism_skepticism": 1, "urgency_patience": -1}}, "debrief": "Suggests you would rather the board's first impression of you include the two things that will otherwise surface through OCR or the incoming CIO. The tradeoff is that a client-affecting shutdown in your first quarter, announced alongside a missing regulatory artifact, is the kind of slide that defines a tenure either way, and three clients under notice already is a commercial fact the CEO will feel. Strongest where the shutdown date is chosen by the risk rather than by the meeting."}, {"label": "B", "narrative": "Contain the imaging system behind isolation controls, commission the missing risk analysis retrospectively with dated scope, and use the board slot to ask for the reporting line to be settled before the CIO starts.", "tendency_signals": {"dials": {"decisiveness_inquiry": 1, "unilateral_consensus": 1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you have identified the reporting line as the term that will decide the next two years and are willing to spend your ninety-day slot on it rather than on the delivery you actually achieved. The tradeoff is that isolation is not decommissioning, a retrospective risk analysis has to be scoped and dated honestly or it is worse than none, and asking a board to settle an org question is asking them to overrule a CIO they are about to hire. It is the right question raised at the last moment it can be raised cheaply."}, {"label": "C", "narrative": "Present the quarter as delivered, flag the imaging system as a known residual with a remediation date, and leave the reporting-line question to the CEO and the incoming CIO.", "tendency_signals": {"dials": {"urgency_patience": -1, "unilateral_consensus": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you are banking a strong quarter and declining to complicate it, which is a reasonable read of what a bruised board wants in month three. The tradeoff is that the finalist has already characterized your program to the CEO and you have chosen not to answer, and a residual with a date is only as good as who owns the date once the org changes. Defensible if you have privately secured the CEO's position on the line; naive if you have assumed it."}]}, {"id": "fu-B", "after_choice": "B", "situation": "You took the structure and roughly two-thirds of the money. The direct line to the CEO held, the audit-committee slot is standing, and the board format — position, priced exposure, evidence, what we got wrong — went down better than anyone expected in month two. The decision-rights map is where the trouble is. Built out over ten weeks, it did what such maps do: it found the gaps. Nobody will sign for the residual Coventry environment. The SVP of claims operations says the systems are not hers, the integration lead left in 2023, and the CFO's position is that anything requiring money is a program decision, not a risk acceptance. Meanwhile the reduced budget has bitten: the identity-governance work you deferred is the same work the independent assessor named as the top gap, and the SVP of claims wants you to \"just fix\" the imaging path out of a budget you traded away for the map. The audit committee meets in three weeks and the map's empty cells are the most interesting thing you have.", "choices": [{"label": "A", "narrative": "Put the empty cells in front of the audit committee as the finding of the quarter, and ask the committee to assign the owners.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "optimism_skepticism": 1, "centralization_decentralization": 1}}, "debrief": "Suggests you are using the format you negotiated for the thing it was built for: making an ownership vacuum visible to the only body that can fill it. The tradeoff is that executives named in a board document as declining ownership will remember it, and a committee that assigns owners under pressure may assign them badly. It is the strongest available use of the structure you traded money for, and it spends relationships rather than budget."}, {"label": "B", "narrative": "Accept the residual environment into your own office as owner of last resort, price it explicitly, and go back to the CEO for a supplementary budget to fix it.", "tendency_signals": {"dials": {"hands_on_delegation": -1, "centralization_decentralization": -1, "aggression_caution": 1}}, "debrief": "Suggests pragmatism and a willingness to break your own principle — the business owns its risk — because nothing else will move and members' data is in the balance. The tradeoff is that a CISO who becomes owner of last resort for unowned estates will acquire more of them, and the scope you accept in calm weather is the scope you are judged on in bad. Defensible as an explicitly time-boxed arrangement with an exit date; corrosive as a standing habit."}, {"label": "C", "narrative": "Refuse ownership, decline to fix the imaging path out of the security budget, and give the SVP of claims a priced risk-acceptance form with a review date and her name on it.", "tendency_signals": {"dials": {"unilateral_consensus": -1, "innovation_operational_discipline": 1, "decisiveness_inquiry": -1}}, "debrief": "Suggests you are holding the line the decision-rights map exists to draw, and forcing a named accepter rather than absorbing the gap. The tradeoff is that an executive who believes the systems are not hers will not sign, and an unsigned form is not a control — it is a document about a conversation. It works where the CEO backs the refusal within days; it becomes a stalemate with member data inside it if he does not."}]}, {"id": "fu-C", "after_choice": "C", "situation": "Nine weeks in. The 100-day clock is on a wall in the operations centre and the centralization is done — every control now reports to your office. The interim lead left in week three, cordially, and two of the four engineers who worked the nine days followed him within a month; one of them wrote a leaving note describing the incident response as \"the last time anyone here was allowed to be honest,\" which reached you through HR. Last Thursday you learned from a client's security team, not your own, that an alert on an unusual data-export pattern in the claims environment had sat unactioned for four days. It turned out to be a benign integration job. Your new detection manager, hired three weeks ago, described the delay as a triage backlog. Your deputy — appointed by you — says the backlog is real. Two of the remaining senior engineers have declined to join the daily remediation stand-up, citing workload. The clock says day 63 and everything on it is green.", "choices": [{"label": "A", "narrative": "Run a blameless review of the four-day alert with the people who missed it, publish the findings internally including your own centralization as a contributing factor, and pause the clock for a week.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": 1, "urgency_patience": 1}}, "debrief": "Suggests you have read the client's phone call as the signal it is: your information environment is now worse than the one you inherited, and the clock is part of why. The tradeoff is that pausing a public clock in month three is a visible reversal in an organization you have spent nine weeks telling to move faster, and naming your own design as a contributing factor is a sentence the board may hear before your program has results. It is the cheapest moment this will ever be available."}, {"label": "B", "narrative": "Treat it as a capacity problem: fund three more analysts out of the $46M, tighten triage SLAs, and keep the clock running.", "tendency_signals": {"dials": {"urgency_patience": -1, "innovation_operational_discipline": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you are reading a four-day delay as arithmetic, which it partly is — the team is three people down and the backlog is genuine. The tradeoff is that the tooling-and-headcount answer to an information problem is the module's most common failure, and an SLA does not tell you why you heard about the alert from a client. It buys real capacity and leaves the question of who tells you things exactly where it was."}, {"label": "C", "narrative": "Replace the detection manager, on the view that a four-day delay in month nine after a breach is not survivable, and say so plainly to the team.", "tendency_signals": {"dials": {"decisiveness_inquiry": -1, "unilateral_consensus": -1, "aggression_caution": -1}}, "debrief": "Suggests the same setting that produced the first personnel decision, applied to a person three weeks into the job under a backlog he inherited. The tradeoff is that the organization has now watched what happens to the second and third people associated with bad news, and the leaving note in HR describes exactly this pattern in your predecessor's words. Defensible only if the manager's own account of the four days does not survive examination — and you have not yet asked for it."}]}, {"id": "fu-D", "after_choice": "D", "situation": "Ten weeks of evidence work. The control inventory is two-thirds complete and brutal: of 214 controls the company describes to clients, 86 point at a log, a ticket or a review, and 41 exist only in a policy document. The independent assessor's interim memo lands next week. The tooling freeze has held, and the Coventry appliance came out in week two because you carved it out of the freeze. Then plaintiffs' counsel, in the consolidated litigation, served a request for \"all internal and third-party security assessments, audits and gap analyses from January 2022 to date.\" Your general counsel's first reading is that the assessor's interim memo will be discoverable, and her first instinct is to ask whether the assessment can be re-scoped under privilege or narrowed. The board wants \"something to show\" in eleven days, and what you have is a two-thirds-complete inventory that reads as an indictment of the company's own client representations. The CEO has not seen the 86-of-214 figure yet.", "choices": [{"label": "A", "narrative": "Show the board the 86-of-214 figure and the completion plan, keep the assessment scoped as designed, and let counsel deal with discoverability on its own terms.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "unilateral_consensus": -1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you are treating the inventory as the deliverable it is and refusing to let litigation posture design your evidence program. The tradeoff is that a number describing a gap between what clients were told and what exists is a document a plaintiff will enjoy, and the board is being handed it eleven days before the assessor adds more. It is the honest version, it is what OCR would want to see, and it will be read in a courtroom in the least favourable possible tone."}, {"label": "B", "narrative": "Accept counsel's privilege structure for the third-party assessment, keep the internal inventory outside it, and show the board the inventory alone.", "tendency_signals": {"dials": {"aggression_caution": 1, "unilateral_consensus": 1, "hands_on_delegation": 1}}, "debrief": "Suggests you are separating the two artifacts by their purpose: the inventory is a management instrument and the assessment is now partly a legal one. The tradeoff is that an assessment conducted under privilege is an assessment whose findings may never reach the operators who must act on them, which is the thing that made an independent read worth having. Defensible where the remediation actions flow out of privilege into the normal register; hollow where the findings stop at the lawyers."}, {"label": "C", "narrative": "Ask the board to redefine 'something to show' as the evidence program itself: present the inventory method, the assessor's scope and the completion date, and commit to the full numbers next quarter.", "tendency_signals": {"dials": {"urgency_patience": 1, "decisiveness_inquiry": 1, "centralization_decentralization": 1}}, "debrief": "Suggests you want the board to adopt the format before it sees the worst number, which is a real technique and not automatically an evasion. The tradeoff is that a board seven months post-breach, eleven days from a meeting, being offered a method instead of a result may conclude the program has not started, and 'full numbers next quarter' is a promise you will keep in a quarter when the assessor has added to them. It works where the CEO is told the 86-of-214 figure privately first, this week."}]}], "reflection": "Write down the mandate you are operating under right now — what the company thinks it hired or promoted you to do — and then write the date on which you expect the attention behind it to run out. Then name the one mechanism you would have to build before that date for the work to survive it, and what you would have to give up this quarter to build it.", "tags": {"dials": ["urgency_patience", "centralization_decentralization", "hands_on_delegation", "decisiveness_inquiry", "unilateral_consensus", "optimism_skepticism"], "archetypes": ["arch.post-breach-ciso", "arch.transformation-cio", "arch.regulated-industry-cio-ciso", "arch.business-risk-ciso"], "stages": ["turnaround", "regulatory_reputation_crisis", "post_merger"], "learn_categories": ["risk", "power_governance", "organizational_design", "leadership"]}, "discretion_level": "high", "research_refs": ["res.kamiya2021", "res.edmondson1996", "res.zhang2010", "res.banker2019", "res.angst2017", "res.cram2019", "res.higgs2016", "res.banker2011", "res.gordon2002", "res.amir2018", "res.hayward2004", "res.ashenden2013", "res.kwon2014", "res.ibm2025", "res.karaevli2007", "res.sec2023"], "meta": {"source_path": "modules/11-what-five-leaders-teach.md#9-ceo-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}, {"id": "sim.m12-sablewood-profile", "title": "The Ones Who Got It Right", "module_ref": "m12", "setup": {"company_snapshot": {"name": "Sablewood Financial Technologies", "is_fictional": true, "industry": "Payments and reconciliation platform for mid-market banks (financial technology)", "revenue": "$420M", "headcount": 1400, "stage": "mature", "ownership": "pe_backed", "governance": "Private-equity backed with a sale process expected within eighteen months. A board with a sponsor-appointed chair; the CISO presents quarterly and the CEO's communications chief manages external profile.", "ceo_tenure": "Four years as CISO.", "ceo_mandate": "Keep a payments and reconciliation platform defensible through a sale process, and hire against a detection-staffing constraint that is currently the program's binding limit."}, "situation": "You are CISO of Sablewood Financial Technologies: a Boston payments and reconciliation platform serving mid-market banks, $420M revenue, 1,400 employees, private-equity backed with a sale process expected within eighteen months. Four years in the chair.\n\nThe year just closed was your best. No reportable incidents. A clean SOC 2. A ransomware attempt contained in forty minutes. A direct competitor was breached badly six months ago and lost two named clients to you.\n\nA national business magazine wants to profile you for a feature on \"the ten CISOs who got it right\" — ninety minutes, a photographer, publication in eight weeks. The CEO's communications chief is enthusiastic, and she is right that it helps the sale process and helps hiring, which is your hardest constraint.\n\nYou also know three things. The forty-minute containment involved luck: a detection engineer who was not on call noticed something on a Saturday afternoon, and your own timeline reconstruction shows the automated path would have taken closer to nine hours. Two high findings from your last penetration test remain unremediated, both in the reconciliation service. And that detection engineer resigned last month; you have not replaced her, and the on-call rotation is now five people covering what was designed for seven.\n\nThe magazine's questions have been sent in advance. One of them is: \"What did you do differently that your competitor didn't?\"", "constraint": "Ninety minutes on the record, publication in eight weeks, inside a sale process expected within eighteen months — with two unremediated high findings in the reconciliation service and an on-call rotation of five covering a design of seven.", "known": ["The year closed with no reportable incidents, a clean SOC 2, and a ransomware attempt contained in forty minutes.", "Your own timeline reconstruction shows the automated path would have taken closer to nine hours; the forty minutes depended on an off-duty engineer noticing something on a Saturday.", "Two high findings from the last penetration test remain unremediated, both in the reconciliation service.", "That detection engineer resigned last month and has not been replaced; the on-call rotation is five people covering a design of seven.", "The questions were sent in advance and include: 'What did you do differently that your competitor didn't?'"], "unknown": ["Whether the acquirer's technical diligence will reach the penetration-test history, and when.", "How a journalist will use the word 'luck' once you have said it out loud.", "Whether the profile actually converts into the two hires you need, or only into recruiter calls for your team.", "What the CEO would say if the article and the diligence findings landed in the same month.", "Whether your own account of the forty minutes is the one your team would give if asked separately."], "discretion_level": "medium"}, "choices": [{"label": "A", "narrative": "Do the profile as offered. The story is broadly true, the caveats are internal matters, and the company needs the visibility during a sale process.", "tendency_signals": {"dials": {"optimism_skepticism": -1, "aggression_caution": -1}, "tendencies": {"B": "high", "K": "low", "N": "high"}, "maturity_levels": [1, 2]}, "tradeoffs": "Suggests optimism and a reading of visibility as an asset to be spent. It is not dishonest — everything the magazine would print is true — but it is the arrangement Hayward et al. (2004) describe, in which a distinctive outcome is attributed to a person's disposition, and the person begins to hold the attribution.", "context_that_favors": "A sale process where a security narrative genuinely affects diligence, and a hiring market where a national profile moves candidates.", "context_that_punishes": "The reconciliation findings surfacing in that same diligence three months later, next to your quotation.", "strong_ceo_would_evaluate": "What happens to the \"what we got wrong\" section of the next board pack once a national description of the program exists.", "second_order_effects": "You now have two accounts of your program, and the more flattering one is the one strangers will quote back to you.", "follow_up_ref": "fu-A"}, {"label": "B", "narrative": "Decline entirely, and tell the CEO that public profile is a liability for a security executive and that you would rather the company's security story be told through its clients.", "tendency_signals": {"dials": {"aggression_caution": 1, "unilateral_consensus": -1}, "tendencies": {"I": "high", "K": "high", "L": "low"}, "maturity_levels": [2]}, "tradeoffs": "Suggests caution and a sound instinct about the research. You protect your judgment and forgo a real recruiting advantage at the exact moment your rotation is two people short, and a CEO in a sale process will hear the refusal as either principle or timidity depending on how you frame it.", "context_that_favors": "A situation where the refusal can be converted into something the CEO wants more — the two headcount, for instance.", "context_that_punishes": "Declining without offering an alternative, which spends social capital and buys nothing.", "strong_ceo_would_evaluate": "That B protects against the visibility hazard and does nothing about the actual problem, which is a five-person rotation.", "second_order_effects": "The magazine profiles someone else, the hiring constraint persists, and you have established a boundary nobody asked you to defend.", "follow_up_ref": "fu-B"}, {"label": "C", "narrative": "Do it, and redirect: refuse the \"got it right\" framing, insist the piece be about mechanisms and the team, and say on the record that the forty-minute containment involved luck and that the automated path would have been slower.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "decisiveness_inquiry": -1}, "tendencies": {"K": "high", "O": "high", "P": "high"}, "maturity_levels": [3]}, "tradeoffs": "Suggests the Two-Sentence Test performed in public: skepticism aimed at your own year. Naming the luck is the hardest available act and the one that most reliably preserves your ability to say \"I was wrong\" later — at the cost of a communications chief who will fight it and a journalist who now controls where the word lands.", "context_that_favors": "A CEO who understands that a security leader's credibility is the asset, and a team who will hear their own Saturday described accurately.", "context_that_punishes": "A sale process fragile enough that any qualifier reads as a red flag to a sponsor watching the calendar.", "strong_ceo_would_evaluate": "Agreeing the specific sentence in advance with the CEO and general counsel rather than improvising it under a photographer's lights.", "second_order_effects": "Your own team hears you describe the Saturday accurately, which is worth more internally than the article is worth externally.", "follow_up_ref": "fu-C"}, {"label": "D", "narrative": "Do it, and use the platform for a self-binding commitment — publish your incident-response standard and your detection-coverage targets, so the external record creates pressure you can point to internally when asking for the two headcount.", "tendency_signals": {"dials": {"aggression_caution": -1, "decisiveness_inquiry": -1, "innovation_operational_discipline": 1}, "tendencies": {"A": "high", "F": "high", "G": "low"}, "maturity_levels": [2, 3]}, "tradeoffs": "Suggests decisiveness and a sophisticated use of external pressure as an internal lever; published standards are commitment devices and commitment devices work. The tradeoff is a public description of what your controls do, at a company eighteen months from a sale, with two unremediated high findings in the very service the standard describes.", "context_that_favors": "A small and closing gap between the published standard and the actual state.", "context_that_punishes": "A gap that is neither — and yours is neither.", "strong_ceo_would_evaluate": "Whether they are willing to publish the current state rather than the target, and, if not, would recognize that as the answer.", "second_order_effects": "The headcount argument gets stronger and the disclosure exposure gets worse, at the same time.", "follow_up_ref": "fu-D"}, {"label": "E", "narrative": "Put your detection lead forward instead of yourself, stay out of the frame, and use the freed profile to make the headcount case internally.", "tendency_signals": {"dials": {"hands_on_delegation": 1, "unilateral_consensus": 1}, "tendencies": {"E": "high", "L": "high", "I": "low"}, "maturity_levels": [3]}, "tradeoffs": "Suggests delegation, and it is more interesting than it first appears: it moves visibility to the person who did the work, reads well internally, and removes you from the attribution machinery. The tradeoff is that your detection lead becomes the public face of a program whose gaps she does not own and cannot fix.", "context_that_favors": "A lead who wants it and is briefed thoroughly on what she may and may not say.", "context_that_punishes": "A later diligence finding in the reconciliation service, whose exposure now lands on someone junior.", "strong_ceo_would_evaluate": "Whether E is generosity or avoidance, by asking a single question: would you also send her if the year had gone badly?", "second_order_effects": "She acquires a public profile and the recruiter calls that come with it, in a market where you are already two people short.", "follow_up_ref": "fu-E"}], "debrief_common": {"fit_analysis": "A mature, PE-backed payments platform eighteen months from a sale, with a four-year CISO who has just had the best year of his tenure and knows precisely which parts of it were luck. Discretion is moderate and the pressure is commercial rather than regulatory: the communications chief, the sponsor's timetable and the hiring constraint all point the same way, and nothing in the governance structure exists to slow the decision down. The situation is built so that the honest option and the useful option are genuinely different, which is the whole subject of the module — visibility is not effectiveness, and a profile is evidence that someone found you interesting. What is actually being decided is which account of the year becomes the official one, because the flattering account will be quoted back to you by strangers and the accurate one is the only one you can revise later without looking like you were caught. Blame and accountability separate here too: nobody is at fault for a good year, and the question is what you will have made it possible to say when the reconciliation findings surface.", "research_that_bears": [{"text": "CEO celebrity is theorized as journalists attributing a firm's distinctive actions to the leader's disposition, with the leader who internalizes the attribution becoming overconfident and persisting with the actions that produced it — a mechanism, not an effect size.", "label": "FRAMEWORK", "ref": "res.hayward2004"}, {"text": "Comparing award-winning CEOs with matched predicted winners who did not win, award winners subsequently underperformed relative to their own prior record, earned more, and spent more time on outside activities.", "label": "RESEARCH_FINDING", "ref": "res.malmendier2009"}, {"text": "Across eight nursing units, better team climate and more manager coaching were associated with higher detected error rates — which is why a year with no reportable incidents is not self-evidently a good year.", "label": "RESEARCH_FINDING", "ref": "res.edmondson1996"}, {"text": "No study exists of CISO or CIO celebrity, or of what public profile does to a security executive's judgment; the celebrity research concerns CEOs in a different labour market, with awards as the status shock and share price as the outcome.", "label": "INTERPRETATION"}], "defensible_choices": "C is the module's answer — it is the only option that performs the course's second sentence in the environment where it costs something. E is defensible when the delegation is genuine and briefed. B is defensible when it is traded for the headcount rather than delivered as a principle. D is defensible only if you would publish the current state, which here you would not. A is not indefensible so much as unexamined, and the debrief above is the examination.", "trait_dial_readout": "A sits at optimism and aggression. B sits at caution and unilateral. C sits near center, with skepticism pointed inward and decisiveness in delivery. D sits at aggression and decisiveness, with an unpriced disclosure risk attached. E sits at delegation, one step from avoidance.", "two_sentence_question": "The first sentence is easy here — \"We're going to do the profile, and here is how.\" The second is the whole scenario: can you say, in print, \"the thing you are about to call a result was partly luck, and I was wrong about how fast our automated path was\"? And the Risk Corollary is what you owe the CEO before the interview: \"Yes — and here is the risk we are accepting by putting a public description of this program into a sale process, priced.\" / \"No to publishing the standard — and here is what would change my answer: the two reconciliation findings closed and the rotation back to seven.\""}, "follow_up": [{"id": "fu-A", "after_choice": "A", "situation": "The piece ran in week eight and did what everyone hoped. Two strong detection candidates cited it in their applications and one has accepted; the sponsor's managing director forwarded it to the board with a one-line note. Your photograph is on a wall in the Boston office, which your team finds funny and you find slightly worse than funny. Six weeks later, the acquirer's technical diligence opened, and its lead has requested three years of penetration-test reports with remediation status. The two reconciliation findings are still open — the fix is scoped and unstaffed, because your one new hire went to detection. Separately, the same magazine is preparing a follow-up on your breached competitor and has asked you for a quote on \"what smaller firms get wrong.\" The communications chief thinks it is free reinforcement. Your CEO has not connected the diligence request and the article, and you have.", "choices": [{"label": "A", "narrative": "Decline the follow-up quote, tell the CEO explicitly why, and put the two open findings and the staffing tradeoff in front of the board before diligence surfaces them.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "aggression_caution": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you have noticed that the second article would deepen a gap you already cannot close in time, and that the board hearing it from you is worth more than a quote is worth to anyone. The tradeoff is that you are volunteering unflattering information into a live sale process, which the sponsor will feel and the CEO may not thank you for. It is the cheapest available correction to a choice that has not yet cost you anything visible."}, {"label": "B", "narrative": "Give the follow-up quote, keep it entirely about mechanisms rather than results, and use the diligence request as the internal argument for staffing the reconciliation fix now.", "tendency_signals": {"dials": {"aggression_caution": -1, "decisiveness_inquiry": -1, "hands_on_delegation": -1}}, "debrief": "Suggests you are trying to keep the external benefit while converting the diligence pressure into the remediation you actually need, which is a real and defensible use of both. The tradeoff is that the second appearance compounds the attribution the first one created, and a mechanism-only quote in a piece about a competitor's failure will still be read as a comparison. It works if the reconciliation fix is genuinely staffed this month; otherwise it is the same choice again with more of your name attached."}, {"label": "C", "narrative": "Give the quote, answer diligence exactly as asked with the two findings disclosed in the standard format, and leave the board conversation to the CEO's timetable.", "tendency_signals": {"dials": {"urgency_patience": 1, "unilateral_consensus": 1, "optimism_skepticism": -1}}, "debrief": "Suggests you regard the diligence process as the right venue for the findings and see no reason to escalate ahead of it, which is procedurally clean. The tradeoff is that the board will meet these findings alongside a national profile they have already circulated, and the sequencing — article first, findings second, both from the same person — is the part that shapes how they are read. Defensible; it also leaves you no version of events that you introduced yourself."}]}, {"id": "fu-B", "after_choice": "B", "situation": "You declined, and framed it as principle rather than as a trade. The magazine ran the feature without you; the CISO of a competitor two-thirds your size is in it, and the piece has been circulating internally since Tuesday. The communications chief has been correct and cool with you ever since. Ten weeks on, the rotation is still five: one offer fell through on compensation, and the second candidate withdrew after a recruiter placed him at the firm whose CISO is now in a national magazine. Your CEO, who accepted the refusal without argument at the time, asked you in your last one-on-one why the two headcount you have been requesting for a quarter were not raised when you had his full attention. It was a fair question, asked kindly. The board pack is due in three weeks and the sale process timetable has moved forward by a quarter, which shortens everything.", "choices": [{"label": "A", "narrative": "Go back to the CEO now with the headcount case priced — coverage gap, response-time consequence, cost — and explicitly name the refusal as an argument you should have traded.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "decisiveness_inquiry": -1, "unilateral_consensus": 1}}, "debrief": "Suggests you can say a small version of the second sentence about your own judgment rather than your controls, which is the harder one and the one that costs least here. The tradeoff is that a priced case for headcount arrives now with less leverage than it would have had eight weeks ago, and an accelerated sale timetable makes new hires harder to justify to a sponsor. Its strength is that it converts a spent boundary into a live request."}, {"label": "B", "narrative": "Take the coverage gap to the board pack directly: publish the five-of-seven rotation, the reconstructed nine-hour automated path, and the response-time exposure it implies.", "tendency_signals": {"dials": {"aggression_caution": -1, "unilateral_consensus": -1, "innovation_operational_discipline": 1}}, "debrief": "Suggests you are routing around a persuasion problem by putting the exposure where it cannot be deferred, using the format rather than the relationship. The tradeoff is that a board reading a coverage gap and a nine-hour reconstruction one quarter before a sale process will ask questions of the CEO, not only of you, and he will know where they came from. It is legitimate use of a board channel and a bill your CEO will remember paying."}, {"label": "C", "narrative": "Offer the communications chief an alternative she can use — a client-led case study and a technical blog under the team's names — and tie your cooperation to the two headcount.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "hands_on_delegation": 1, "urgency_patience": -1}}, "debrief": "Suggests you are belatedly making the trade you should have made in week one, and repairing a working relationship you need for the next eighteen months. The tradeoff is that a client-led story is slower and weaker than the profile you turned down, and tying cooperation to headcount reads as leverage from someone who declined the first request on principle. It works where the alternative is genuinely useful to her; it looks transactional where it is not."}]}, {"id": "fu-C", "after_choice": "C", "situation": "You gave the interview, refused the framing, and said the sentence: the forty minutes involved luck, and the automated path would have taken nine hours. The piece ran with the headline \"The CISOs Who Got It Right — And One Who Says He Didn't,\" and the luck quotation is in the standfirst. Internally it landed better than anything you have done in four years; two engineers told you separately that it was the first time they had seen the Saturday described accurately, and a candidate cited it in an interview. Externally it is more complicated. The sponsor's managing director asked the CEO, in writing, whether the security program is \"actually fine,\" and the CEO — who approved the sentence in advance and has not wavered — has been asked to commission an independent security assessment ahead of the sale, at the sponsor's expense, with the report going to the sponsor. Your CEO is asking what you think. The reconciliation findings are still open, the rotation is still five, and an assessment you do not control would find both.", "choices": [{"label": "A", "narrative": "Support the assessment, ask that its scope include the response-time reconstruction and the rotation, and give the assessor the two open findings on day one.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "hands_on_delegation": 1, "unilateral_consensus": 1}}, "debrief": "Suggests you are consistent: having said the true thing in public, you are not going to manage the scope of the process that checks it. The tradeoff is that a sponsor-commissioned report you do not control, arriving before a sale, will describe your gaps in someone else's words and timing — and handing over the findings on day one removes any chance of closing them first. It is the position that makes the interview mean something, and it is expensive."}, {"label": "B", "narrative": "Support the assessment but ask the CEO to negotiate the report going jointly to him and the sponsor, with management response rights before circulation.", "tendency_signals": {"dials": {"aggression_caution": 1, "unilateral_consensus": -1, "decisiveness_inquiry": 1}}, "debrief": "Suggests you accept the scrutiny and want the ordinary governance protections that any assessed executive would ask for, which is not the same as narrowing it. The tradeoff is that response rights slow the report and can be read by a sponsor as exactly the management filter the assessment was commissioned to bypass, six weeks after you told a national magazine you say true things about your own program. Defensible, and it will be read against the interview."}, {"label": "C", "narrative": "Propose closing the two reconciliation findings and restoring the rotation to seven first, with the assessment starting in ninety days against a fixed state.", "tendency_signals": {"dials": {"urgency_patience": 1, "innovation_operational_discipline": 1, "hands_on_delegation": -1}}, "debrief": "Suggests you would rather be assessed against a program you have finished repairing than against one mid-repair, which is a reasonable engineering instinct and a poor look. The tradeoff is that the ninety days are exactly the period in which a sponsor wants to know what it owns, and 'fix it then measure it' is the sentence the interview implicitly criticized. It works only if the ninety days are funded and dated in the same conversation."}]}, {"id": "fu-D", "after_choice": "D", "situation": "The profile ran with your incident-response standard and detection-coverage targets published alongside it, and the commitment device worked: the board approved both headcount within a fortnight, and one is already in seat. Eight weeks later the standard is doing other things. A prospective bank client's counsel has asked Sablewood to warrant contractual conformance with \"the published incident-response standard,\" referencing the article; your sales lead thinks this is a formality. The two reconciliation findings are still open — the new hire went to detection, not to remediation — and your published detection-coverage target of 95% currently reads 88% on the reconciliation service specifically, which the standard's own definition would require you to disclose if anyone asked precisely. Nobody has asked precisely. The general counsel has forwarded the warranty request to you with a single sentence: \"Can we sign this?\" The sale process is live and this client would be a reference account for it.", "choices": [{"label": "A", "narrative": "Tell counsel you cannot warrant conformance today, state the 88% and the two open findings in writing, and propose warranting a dated remediation plan instead.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "aggression_caution": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you are treating your own published standard as a real obligation rather than a marketing artifact, which is the only reading that makes publishing it defensible. The tradeoff is that the disclosure travels — to a prospective client, into the deal room, and to a sponsor who has been told the program is exemplary — and a dated plan is a commitment you must now hit under a sale timetable. It is the choice that keeps the commitment device honest and prices it."}, {"label": "B", "narrative": "Warrant conformance with a defined exclusion for the reconciliation service, and disclose the exclusion without the underlying numbers.", "tendency_signals": {"dials": {"unilateral_consensus": 1, "decisiveness_inquiry": -1, "urgency_patience": -1}}, "debrief": "Suggests a negotiated middle: no false warranty, no full disclosure, and a deal that closes. The tradeoff is that an exclusion naming the exact service where your two high findings live is an invitation to a question you would then have to answer fully, and the difference between 'excluded' and 'below target' is one the client's counsel is paid to notice. Defensible if you would give the numbers on request; misleading if the exclusion exists to prevent the request."}, {"label": "C", "narrative": "Ask the CEO to withdraw the published standard as a public document, replace it with a client-specific control description, and take the reputational cost.", "tendency_signals": {"dials": {"aggression_caution": 1, "innovation_operational_discipline": -1, "hands_on_delegation": -1}}, "debrief": "Suggests you have concluded that publishing a target state was the error and want to remove the instrument before it does more work than you can support. The tradeoff is that withdrawing a standard eight weeks after publishing it in a national magazine is itself a visible event during a sale process, and you would be giving up the lever that just bought you two headcount. It is the second sentence applied to a decision rather than a control, and this one is expensive in public."}]}, {"id": "fu-E", "after_choice": "E", "situation": "You put your detection lead forward, briefed her for two hours, and stayed out of the frame. She was excellent. The piece named her as \"the engineer who caught it,\" which is not quite what happened — the Saturday catch was the engineer who has since resigned — and the article's account of the forty minutes is now the public one. Ten weeks on, your lead has three speaking invitations, a recruiter cadence you can see in her calendar, and a slightly changed relationship with the rest of the team; two of her peers have been careful with her in a way they were not before. The CEO now routes security questions to her directly, including one last week from the sponsor. The reconciliation findings are still open, and she has begun answering for them in forums where she has no authority to fix them. She has not complained. She asked you yesterday, pleasantly, whether she should take the largest of the speaking invitations.", "choices": [{"label": "A", "narrative": "Tell her the truth about the Saturday attribution, correct it publicly where you can, and give her real authority over the reconciliation remediation before she speaks again.", "tendency_signals": {"dials": {"optimism_skepticism": 1, "hands_on_delegation": 1, "unilateral_consensus": -1}}, "debrief": "Suggests you have recognized that visibility without authority is the trap you put her in, and that the correction has to include both the record and the job. The tradeoff is a public correction that makes the company's account of its best moment messier, and handing remediation authority to someone whose calendar is now half external. It repairs the thing that actually matters and it costs the tidy version of the story."}, {"label": "B", "narrative": "Support the speaking invitation, brief her carefully on what she may and may not claim, and take back the sponsor and board questions yourself.", "tendency_signals": {"dials": {"hands_on_delegation": -1, "unilateral_consensus": 1, "aggression_caution": 1}}, "debrief": "Suggests you are separating external profile, which she has earned, from accountability, which is yours — a clean distinction that is hard to hold once a CEO has started routing questions. The tradeoff is that taking the questions back after ten weeks reads to her as a demotion she did not ask for, and the Saturday attribution stays uncorrected in the public account. Defensible where you say plainly why; damaging where she learns it from a rerouted email."}, {"label": "C", "narrative": "Advise her to decline the invitation, on the ground that a public profile with unremediated findings behind it is a liability for her specifically.", "tendency_signals": {"dials": {"aggression_caution": 1, "urgency_patience": 1, "hands_on_delegation": -1}}, "debrief": "Suggests you are trying to protect her from the machinery you put her into, which may be genuine and will not feel that way. The tradeoff is that the advice arrives from the person who benefited from her visibility and is now limiting it, and 'this is for your protection' is unfalsifiable in the mouth of a boss. Ask the module's question of yourself before delivering it: would you be giving this advice if the year had gone badly?"}]}], "reflection": "Write the sentence about your program that you would least like to see quoted in print, and check whether it is true. Then write who inside your organization already knows it, how long they have known, and what it would cost you to say it out loud in the next room where the flattering version is being repeated.", "tags": {"dials": ["optimism_skepticism", "decisiveness_inquiry", "unilateral_consensus", "aggression_caution", "hands_on_delegation", "innovation_operational_discipline"], "archetypes": ["arch.business-risk-ciso", "arch.technical-ciso", "arch.enterprise-cio", "arch.post-breach-ciso"], "stages": ["mature", "scale_up"], "learn_categories": ["personality", "leadership", "power_governance"]}, "discretion_level": "medium", "research_refs": ["res.hayward2004", "res.malmendier2009", "res.chatterjee2011", "res.edmondson1996", "res.edmondson1999", "res.banker2019", "res.amir2018", "res.ashenden2013", "res.cram2019", "res.owens2012", "res.milliken2003", "res.gordon2002", "res.hambrick1987", "res.banker2011", "res.karahanna2013", "res.sec2023", "res.ians2026"], "meta": {"source_path": "modules/12-the-two-sentence-ciso.md#9-leader-simulation", "content_version": "0.1.0", "built_at": "2026-09-04T12:00:00Z", "status": "draft"}}], "glossary": [{"id": "term.agentic-ai-risk", "term": "Agentic AI risk", "definition": "The exposure created when an AI system is granted the ability to act", "label": "INTERPRETATION", "module_ref": "m11", "related": ["term.least-agency", "term.model-weights", "term.shadow-ai", "term.two-party-control"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.blameless-post-incident-review", "term": "Blameless post-incident review", "definition": "A structured review of an incident that establishes the sequence, the contributing conditions and the fixes without assigning individual fault, on the premise that fault-finding buys one accountability story and costs all future reporting. One of the five mechanisms in the Information-Environment Stack.", "label": "FRAMEWORK", "module_ref": "m05", "related": ["term.information-environment-stack", "term.near-miss-reporting", "term.psychological-safety", "term.security-culture"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.board-technology-committee", "term": "Board technology committee", "definition": "A standing board committee with delegated oversight of technology and cyber risk. Over 2005–2014, firms with such committees were *more* likely to report breaches in a given year", "label": "RESEARCH_FINDING", "module_ref": "m10", "related": ["term.breach-cost-research", "term.materiality", "term.reporting-line", "term.structural-power"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.breach-cost-research", "term": "Breach-cost research", "definition": "The body of archival work estimating what breaches cost firms. Early event studies found the market penalized breaches of confidential data but not other incidents (Campbell, Gordon, Loeb & Zhou, 2003) and an average two-day market-value loss of about 2.1% (Cavusoglu, Mishra & Raghunathan, 2004). More recent work finds attacks exposing personal financial information associated with shareholder losses far exceeding out-of-pocket costs, consistent with reputational damage (Kamiya, Kang, Kim, Milidonis & Stulz, 2021). Practitioner averages (IBM & Ponemon, 2025: $4.44 million) are self-selected vendor estimates and are order-of-magnitude only.", "label": "RESEARCH_FINDING", "module_ref": "m03", "related": ["term.cyber-risk-quantification", "term.gordonloeb-model", "term.intra-industry-spillover", "term.materiality"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.cio-turnover-after-breaches", "term": "CIO turnover after breaches", "definition": "The labor-market consequence of a disclosed breach for the technology executive. CIO departures were about 72% more likely after breaches attributed to system deficiencies and showed no significant association after breaches attributed to criminal fraud or human error; CEO turnover rose after both system-deficiency and human-error breaches, CFO turnover after neither (Banker & Feng, 2019; archival, cause coded from public descriptions; the paper concerns CIOs, not CISOs).", "label": "RESEARCH_FINDING", "module_ref": "m04", "related": ["term.post-breach-ciso", "term.structural-power", "term.system-deficiency-vs-human-error-breach"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.consent-order", "term": "Consent order", "definition": "A formal, enforceable agreement between a regulator and a regulated firm that resolves supervisory findings by imposing remediation obligations, timetables, independent validation and reporting. Its practical effect on a technology executive is to move the roadmap's ownership outside the company.", "label": "FACT", "module_ref": "m09", "related": ["term.finra-examination", "term.hipaa", "term.regulated-industry-posture", "term.risk-acceptance"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.control-enablement", "term": "Control ↔ Enablement", "definition": "The first of the two overlay dials this edition adds. Control is the posture that treats security as the authority to constrain; enablement treats it as the capability to let the business move safely. Taught narratively and mapped onto the eight schema dials as approximately centralization ↔ decentralization plus caution ↔ aggression.", "label": "FRAMEWORK", "module_ref": "m06", "related": ["term.enablement-with-institutional-paranoia", "term.prevention-resilience", "term.risk-corollary", "term.trait-dial"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.cyber-insurance", "term": "Cyber insurance", "definition": "A policy transferring some financial consequences of a cyber incident. Its underwriting questionnaire", "label": "FACT", "module_ref": "m03", "related": ["term.cyber-risk-quantification", "term.mfa", "term.risk-acceptance", "term.rpo-rto"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.cyber-risk-quantification", "term": "Cyber risk quantification", "definition": "The practice of expressing security exposure as expected or distributional loss rather than as a maturity score or a control count. The reasoning is sound and the inputs are weak: expected loss and vulnerability are rarely measurable, so a quantified answer is a constructed number whose assumptions must travel with it.", "label": "FRAMEWORK", "module_ref": "m03", "related": ["term.breach-cost-research", "term.business-risk-ciso", "term.gordonloeb-model", "term.risk-corollary"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.decision-rights", "term": "Decision rights", "definition": "The explicit allocation of who may decide what, at what threshold, without escalation", "label": "FRAMEWORK", "module_ref": "m02", "related": ["term.player-coach-architect", "term.reporting-line", "term.risk-acceptance", "term.structural-power"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.enablement-with-institutional-paranoia", "term": "Enablement with institutional paranoia", "definition": "The curriculum's description (not diagnosis) of the mature technology executive's working disposition: a genuine drive to let the business move, held in permanent tension with the assumption that something is already wrong and has not yet been found. The counterpart to the bank CEO's \"ambition combined with institutional paranoia\" in the CEO edition.", "label": "INTERPRETATION", "module_ref": "m01", "related": ["term.control-enablement", "term.regulated-industry-posture", "term.risk-corollary", "term.security-culture"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.epistemic-labels-fact-research-finding-interpretation-framework-hypothesis", "term": "Epistemic labels (FACT / RESEARCH FINDING / INTERPRETATION / FRAMEWORK / HYPOTHESIS)", "definition": "The five tags every consequential claim in the curriculum carries: FACT (uncontested, verifiable, or a legal requirement); RESEARCH FINDING (reported in cited research, usually correlational); INTERPRETATION (the program's reading of what findings mean); FRAMEWORK (a teaching structure, useful rather than \"true\"); HYPOTHESIS (plausible, not well tested).", "label": "FRAMEWORK", "module_ref": "m01", "related": ["term.proxy-measure", "term.skeptic-s-checklist", "term.usable-claim"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.finra-examination", "term": "FINRA examination", "definition": "A routine or for-cause examination by the Financial Industry Regulatory Authority, the self-regulatory organization overseeing US broker-dealers. Examinations request evidence", "label": "FACT", "module_ref": "m09", "related": ["term.consent-order", "term.hipaa", "term.regulated-industry-posture", "term.third-party-supply-chain-risk"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.fit-equation-extended", "term": "Fit Equation (extended)", "definition": "Industry × Scale × Lifecycle × Strategy × Governance × Problem × **Reporting Line** = CIO/CISO Fit. The CEO edition's equation with one term added, because a technology executive's discretion is granted by structure rather than assumed. Multiplicative by design: fit fails at the weakest term.", "label": "FRAMEWORK", "module_ref": "m09", "related": ["term.managerial-discretion", "term.mandate", "term.maturity-model", "term.reporting-line"], "is_vocabulary_anchor": true, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.gordonloeb-model", "term": "Gordon–Loeb model", "definition": "An analytical model in which optimal security investment for an information set depends on its value, its vulnerability and the productivity of security spending; under the two classes of breach-probability function the authors assume, optimal investment does not exceed about 37% of expected loss, and it can be rational to invest less in the most vulnerable assets (Gordon & Loeb, 2002). Later work shows other functional forms can justify more; the 37% bound must always be quoted with its assumptions.", "label": "RESEARCH_FINDING", "module_ref": "m03", "related": ["term.breach-cost-research", "term.cyber-risk-quantification", "term.proactive-vs-reactive-investment", "term.risk-corollary"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.hipaa", "term": "HIPAA", "definition": "The US Health Insurance Portability and Accountability Act. Its Security Rule requires administrative, physical and technical safeguards for electronic protected health information, and business associate agreements extend those obligations contractually to service providers", "label": "FACT", "module_ref": "m09", "related": ["term.consent-order", "term.finra-examination", "term.third-party-supply-chain-risk", "term.vciso-fractional-ciso"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.incident-command", "term": "Incident command", "definition": "The practice of running an incident under one named commander with defined roles (technical lead, communications, legal, scribe), a single timeline of record and explicit decision authority, so that decisions are made once and recorded. Distinct from technical response: the commander's job is the decision process, not the forensics.", "label": "FACT", "module_ref": "m04", "related": ["term.blameless-post-incident-review", "term.materiality", "term.rpo-rto", "term.tabletop-exercise"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.information-environment-stack", "term": "Information-Environment Stack", "definition": "This edition's five mechanisms for hearing bad news sooner: near-miss reporting → blameless post-incident review → standing red team → direct lines from engineers → the quarterly \"what we got wrong.\" Built because a security program's quality is bounded by the worst thing someone was willing to tell you.", "label": "FRAMEWORK", "module_ref": "m05", "related": ["term.near-miss-reporting", "term.psychological-safety", "term.red-team", "term.security-culture"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.intra-industry-spillover", "term": "Intra-industry spillover", "definition": "The pricing of a peer's breach against you. Around Target's December 2013 breach, 168 publicly listed US retailers experienced negative abnormal returns, larger for firms more similar to Target and smaller for firms with stronger IT capability, marketing ability and CSR records (Kashmiri, Nicol & Hsu, 2017; single event, one industry).", "label": "RESEARCH_FINDING", "module_ref": "m09", "related": ["term.board-technology-committee", "term.breach-cost-research", "term.regulated-industry-posture"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.itbusiness-alignment", "term": "IT–business alignment", "definition": "The degree to which technology strategy, investment and operations correspond to the business's strategy. Pooled across the literature, every dimension of alignment was positively associated with performance and the much-discussed \"alignment paradox\" largely disappeared in meta-analysis (Gerow, Grover, Thatcher & Roth, 2014; underlying studies correlational). Shared understanding between CIO and top team is built by formal mechanisms and shared knowledge, not by informal socializing (Preston & Karahanna, 2009; 243 matched pairs).", "label": "RESEARCH_FINDING", "module_ref": "m10", "related": ["term.decision-rights", "term.reporting-line", "term.social-capital-ciotmt", "term.structural-power"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.least-agency", "term": "Least agency", "definition": "The design principle that an autonomous or semi-autonomous system should be granted the narrowest scope of action that lets it do its job", "label": "FRAMEWORK", "module_ref": "m11", "related": ["term.agentic-ai-risk", "term.model-weights", "term.two-party-control", "term.zero-trust"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.managerial-discretion", "term": "Managerial discretion", "definition": "The latitude of action available to an executive, arising from the task environment, the organization and the executive's own characteristics (Hambrick & Finkelstein, 1987, CEO library; conceptual), with empirical support strongest for environmental sources (Wangrow, Schepker & Barker, 2015, CEO library). For CIOs and CISOs it is granted rather than assumed, which is why it is a term of the extended Fit Equation.", "label": "RESEARCH_FINDING", "module_ref": "m10", "related": ["term.fit-equation-extended", "term.personality-power", "term.reporting-line", "term.structural-power"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.materiality", "term": "Materiality", "definition": "In US securities law, whether a reasonable investor would consider information important. It is the trigger for incident disclosure: the four-business-day clock under Form 8-K Item 1.05 runs from the registrant's determination of materiality, not from detection (SEC, 2023). The determination is a judgment made jointly by counsel, finance and the security leader.", "label": "FACT", "module_ref": "m04", "related": ["term.breach-cost-research", "term.incident-command", "term.sec-cybersecurity-disclosure", "term.underreported-attacks"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.maturity-model", "term": "Maturity Model", "definition": "Four ordered levels, inherited from the CEO edition and populated for this role: Temperament (uncertainty tolerance, agency, regulation under incident) → Capability (architecture, vendor and capital judgment, incident command, risk quantification, upward communication) → Maturity (calibration, receiving bad news, letting the business own its risk) → Fit (this company, this reporting line, this regulator, this mandate). Higher levels do not substitute for lower ones.", "label": "FRAMEWORK", "module_ref": "m07", "related": ["term.fit-equation-extended", "term.overuse-ladder", "term.trait-dial"], "is_vocabulary_anchor": true, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.mfa-multi-factor-authentication", "term": "MFA (multi-factor authentication)", "definition": "Requiring more than one category of evidence to authenticate. Its practical significance is as a base-rate control: credential abuse remained the most common initial access vector at 22% of breaches in the 2025 DBIR sample of 12,195 breaches (Verizon, 2025; Tier 3, convenience sample). The executive question is never whether MFA is deployed but who holds the exceptions.", "label": "FACT", "module_ref": "m03", "related": ["term.cyber-insurance", "term.risk-acceptance", "term.symbolic-vs-substantive-adoption", "term.zero-trust"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.model-weights", "term": "Model weights", "definition": "The learned numerical parameters of a trained machine-learning model. They matter to a security leader because possession of the weights approximates possession of the capability, which makes them a concentrated asset with an unusually small blast radius for exfiltration and an unusually large one for consequences.", "label": "FACT", "module_ref": "m11", "related": ["term.agentic-ai-risk", "term.least-agency", "term.two-party-control"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.msp-mssp", "term": "MSP / MSSP", "definition": "A managed service provider operates a client's IT; a managed security service provider operates security functions such as monitoring and detection. Both hold privileged access across many clients, which makes them a concentration of risk in both directions: third-party involvement appeared in 30% of breaches in the 2025 DBIR sample (Verizon, 2025; Tier 3).", "label": "FACT", "module_ref": "m08", "related": ["term.decision-rights", "term.third-party-supply-chain-risk", "term.vciso-fractional-ciso"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.near-miss-reporting", "term": "Near-miss reporting", "definition": "A channel for reporting events that did not become incidents", "label": "FRAMEWORK", "module_ref": "m05", "related": ["term.blameless-post-incident-review", "term.information-environment-stack", "term.psychological-safety", "term.security-culture"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.nist-csf-2-0-functions", "term": "NIST CSF 2.0 functions", "definition": "Since February 2024 the NIST Cybersecurity Framework has organized cybersecurity outcomes into six functions: **Govern, Identify, Protect, Detect, Respond, Recover.** Govern is the addition, placing executive and board accountability alongside the technical functions; the framework is voluntary and outcome-focused and does not prescribe how outcomes are achieved (NIST, 2024).", "label": "FACT", "module_ref": "m09", "related": ["term.board-technology-committee", "term.decision-rights", "term.policy-compliance", "term.third-party-supply-chain-risk"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.ot-operational-technology", "term": "OT (operational technology)", "definition": "The systems that monitor and control physical processes: industrial control systems, building management, clinical devices, plant floor equipment. Distinguished from IT by safety consequences, long asset lifetimes, vendor-controlled patching and an availability requirement that makes many standard IT controls inapplicable.", "label": "FACT", "module_ref": "m09", "related": ["term.regulated-industry-posture", "term.rpo-rto", "term.third-party-supply-chain-risk"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.overuse-ladder", "term": "Overuse Ladder", "definition": "Strength → overused strength → liability, inherited from the CEO edition with technology-specific rungs: rigor → bureaucracy (\"the security review that ships nothing\"); caution → paralysis (\"never breached because nothing is ever deployed\"); delegation → abdication (\"the MSP handles it\"); detail → micromanagement (reading every alert); adaptability → strategy-of-the-month.", "label": "FRAMEWORK", "module_ref": "m06", "related": ["term.failure-mode", "term.maturity-model", "term.trait-dial"], "is_vocabulary_anchor": true, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.player-coach-architect", "term": "Player → Coach → Architect", "definition": "Three role shapes keyed to scale. The Player does the work (SMB, MSP, fractional CISO); the Coach gets work done through a team they can still see (mid-market); the Architect designs the system through which work is done by people they cannot see (enterprise). Dominant dangers in order: insufficient action; inability to let go; isolation and dashboard fiction.", "label": "FRAMEWORK", "module_ref": "m08", "related": ["term.decision-rights", "term.managerial-discretion", "term.maturity-model", "term.trait-dial"], "is_vocabulary_anchor": true, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.policy-compliance", "term": "Policy compliance", "definition": "Whether employees follow security policy. Pooled across 95 studies and 17 antecedent categories, the strongest predictors were value-oriented", "label": "RESEARCH_FINDING", "module_ref": "m05", "related": ["term.psychological-safety", "term.security-culture", "term.symbolic-vs-substantive-adoption"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.prevention-resilience", "term": "Prevention ↔ Resilience", "definition": "The second overlay dial. Prevention invests in stopping the event; resilience invests in surviving it", "label": "FRAMEWORK", "module_ref": "m06", "related": ["term.control-enablement", "term.rpo-rto", "term.tabletop-exercise", "term.trait-dial"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.proactive-vs-reactive-investment", "term": "Proactive vs. reactive investment", "definition": "Security spending made before a failure versus after one. In US healthcare, proactive investment was associated with lower subsequent failure rates and greater cost-effectiveness than reactive investment, and external regulatory pressure *decreased* the effect of proactive investment on security performance (Kwon & Johnson, 2014; one sector, disclosed breaches, hazard-model associations).", "label": "RESEARCH_FINDING", "module_ref": "m03", "related": ["term.gordonloeb-model", "term.post-breach-ciso", "term.regulated-industry-posture", "term.symbolic-vs-substantive-adoption"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.proxy-measure", "term": "Proxy measure", "definition": "An indirect indicator standing in for something unobserved: option-holding for overconfidence, board risk committees for governance attention, reported breaches for breaches. Every finding built on a proxy carries measurement error and must be described as proxy-based", "label": "FACT", "module_ref": "m01", "related": ["term.board-technology-committee", "term.breach-cost-research", "term.epistemic-labels"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.psychological-safety", "term": "Psychological safety", "definition": "A shared belief that a team is safe for interpersonal risk-taking", "label": "RESEARCH_FINDING", "module_ref": "m05", "related": ["term.blameless-post-incident-review", "term.employee-silence", "term.near-miss-reporting", "term.security-culture"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.red-team", "term": "Red team", "definition": "An adversarial exercise in which a team attempts to achieve a defined objective against the live environment, testing detection and response as well as controls. \"Standing\" red team means the capability is continuous rather than an annual engagement, which is what makes it an information-environment mechanism rather than an audit artifact.", "label": "FACT", "module_ref": "m05", "related": ["term.information-environment-stack", "term.symbolic-vs-substantive-adoption", "term.tabletop-exercise"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.reporting-line", "term": "Reporting line", "definition": "Who the CIO or CISO reports to, and therefore what they can escalate without permission. In a large-firm archival study the \"right\" CIO reporting line depended on strategy: CIO-to-CEO associated with better performance in differentiation firms, CIO-to-CFO in cost-leadership firms (Banker, Hu, Pavlou & Luftman, 2011; pre-cloud data). In a 2026 practitioner survey, 64% of CISOs reported to the CIO or CTO and 36% to a non-IT executive (IANS Research & Artico Search, 2026; Tier 3, self-selected).", "label": "RESEARCH_FINDING", "module_ref": "m02", "related": ["term.decision-rights", "term.fit-equation-extended", "term.managerial-discretion", "term.structural-power"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.risk-acceptance-exception", "term": "Risk acceptance (exception)", "definition": "A documented decision to run a known exposure, with a named owner who is not the security leader, a stated price, a compensating control and an expiry date. An undocumented exception is an unowned risk; an exception register that only grows is a program losing ground.", "label": "FRAMEWORK", "module_ref": "m02", "related": ["term.consent-order", "term.decision-rights", "term.mfa", "term.risk-corollary"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.risk-corollary", "term": "Risk Corollary", "definition": "This edition's companion to the Two-Sentence Test, and the pair of sentences every security leader must be able to say to a CEO: **\"Yes", "label": "FRAMEWORK", "module_ref": "m03", "related": ["term.cyber-risk-quantification", "term.enablement-with-institutional-paranoia", "term.risk-acceptance", "term.two-sentence-test"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.rpo-rto", "term": "RPO / RTO", "definition": "Recovery point objective (how much data the business can afford to lose, measured in time) and recovery time objective (how long it can afford to be down). They are business decisions expressed in technical terms, and the useful executive question is not what the documented objectives are but when they were last demonstrated.", "label": "FACT", "module_ref": "m06", "related": ["term.incident-command", "term.ot", "term.prevention-resilience", "term.tabletop-exercise"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.sec-cybersecurity-disclosure-8-k-item-1-05-10-k-item-1c", "term": "SEC cybersecurity disclosure (8-K Item 1.05; 10-K Item 1C)", "definition": "Since December 2023, US public companies must disclose a material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining materiality, and must annually describe their processes for assessing and managing material cyber risk, the board's oversight, and management's role and expertise", "label": "FACT", "module_ref": "m04", "related": ["term.board-technology-committee", "term.incident-command", "term.materiality", "term.underreported-attacks"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.security-culture", "term": "Security culture", "definition": "The working beliefs that determine what people actually do when a control is inconvenient and what they do after they make a mistake. Treated in this edition as a control rather than a nicety, on the reasoning that a program depends on people reporting the click, the misconfiguration and the near-miss", "label": "INTERPRETATION", "module_ref": "m05", "related": ["term.blameless-post-incident-review", "term.near-miss-reporting", "term.policy-compliance", "term.psychological-safety"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.shadow-it-shadow-ai", "term": "Shadow IT / shadow AI", "definition": "Technology adopted by the business without the technology function's involvement. Shadow AI is its current form; IBM/Ponemon's 2025 sample associated shadow-AI incidents with about $670,000 in additional average breach cost and reported that 63% of organizations had no AI governance policy (IBM & Ponemon, 2025; Tier 3, vendor-sponsored). Its usual cause is not defiance but latency: the exception queue was slower than the business's decision.", "label": "FACT", "module_ref": "m06", "related": ["term.agentic-ai-risk", "term.control-enablement", "term.policy-compliance", "term.risk-acceptance"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.social-capital-ciotmt", "term": "Social capital (CIO–TMT)", "definition": "The structural, cognitive and relational quality of the technology executive's relationship with the top management team. In 81 US hospitals, cognitive and relational social capital directly influenced IS strategic alignment, structural social capital worked indirectly, and alignment mediated the relationship with financial performance (Karahanna & Preston, 2013; one sector, perceptual measures).", "label": "RESEARCH_FINDING", "module_ref": "m10", "related": ["term.itbusiness-alignment", "term.reporting-line", "term.structural-power"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.structural-power", "term": "Structural power", "definition": "The authority a technology executive holds by virtue of position rather than persuasion: reporting line, budget authority, membership of the top team, direct board access, and the right to escalate. Peer-reviewed work examines the antecedents and consequences of CIO strategic decision-making authority (Preston, Chen & Leidner, 2008), and its practitioner companion describes four profiles from crossing authority with capability", "label": "RESEARCH_FINDING", "module_ref": "m10", "related": ["term.decision-rights", "term.managerial-discretion", "term.reporting-line", "term.social-capital-ciotmt"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.symbolic-vs-substantive-adoption", "term": "Symbolic vs. substantive adoption", "definition": "Whether a security practice is bought and displayed or integrated into how the organization works. Across more than 5,000 US hospitals and 938 breaches (2005–2013), symbolic adoption diminished the effectiveness of IT security investment and was associated with an increased likelihood of breach; deeper integration into IT routines was associated with fewer breaches (Angst, Block, D'Arcy & Kelley, 2017; one sector, adoption inferred from institutional profile).", "label": "RESEARCH_FINDING", "module_ref": "m03", "related": ["term.cyber-risk-quantification", "term.mfa", "term.policy-compliance", "term.proactive-vs-reactive-investment"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.system-deficiency-vs-human-error-breach", "term": "System-deficiency vs. human-error breach", "definition": "The attribution categories that determine executive consequences. Breaches attributed to system deficiency were associated with about a 72% higher likelihood of CIO turnover; breaches attributed to criminal fraud or human error were not (Banker & Feng, 2019). Attribution is coded from public descriptions and is itself contestable", "label": "RESEARCH_FINDING", "module_ref": "m04", "related": ["term.blameless-post-incident-review", "term.cio-turnover-after-breaches", "term.materiality"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.tabletop-exercise", "term": "Tabletop exercise", "definition": "A facilitated walkthrough of an incident scenario with the people who would actually decide, testing decision rights, escalation, disclosure judgment and communications rather than technical response. Its value is diagnostic: the exercise reveals which decisions have no owner.", "label": "FACT", "module_ref": "m04", "related": ["term.decision-rights", "term.incident-command", "term.materiality", "term.rpo-rto"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.third-party-supply-chain-risk", "term": "Third-party / supply-chain risk", "definition": "Exposure arising from vendors, service providers, software suppliers and their subcontractors. In the 2025 DBIR sample of 12,195 breaches, third-party involvement doubled year on year to 30% (Verizon, 2025; Tier 3, convenience sample), and NIST CSF 2.0 expanded its supply-chain content (NIST, 2024). For BPM and MSP firms the relationship runs both ways: they are somebody's third party.", "label": "RESEARCH_FINDING", "module_ref": "m09", "related": ["term.hipaa", "term.intra-industry-spillover", "term.msp-mssp", "term.risk-acceptance"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.trait-dial", "term": "Trait Dial", "definition": "Eight paired settings a technology executive can move rather than fixed traits: aggression ↔ caution; decisiveness ↔ inquiry; optimism ↔ skepticism; hands-on ↔ delegation; urgency ↔ patience; unilateral ↔ consensus; innovation ↔ operational discipline; centralization ↔ decentralization. This edition adds two overlay dials taught narratively: Control ↔ Enablement and Prevention ↔ Resilience.", "label": "FRAMEWORK", "module_ref": "m06", "related": ["term.archetype-dial-defaults", "term.control-enablement", "term.overuse-ladder", "term.prevention-resilience"], "is_vocabulary_anchor": true, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.two-party-control", "term": "Two-party control", "definition": "A requirement that two independent principals authorize a sensitive action", "label": "FACT", "module_ref": "m11", "related": ["term.agentic-ai-risk", "term.decision-rights", "term.least-agency", "term.zero-trust"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.two-sentence-test", "term": "Two-Sentence Test", "definition": "A mature executive can say, and mean, both **\"We're going to do this.\"** and **\"I was wrong. Change the plan.\"** Inherited unchanged from the CEO edition; in this edition it is paired with the Risk Corollary, and the capstone asks for all four sentences in the same quarter.", "label": "FRAMEWORK", "module_ref": "m12", "related": ["term.epistemic-arrogance", "term.maturity-model", "term.productive-conviction", "term.risk-corollary"], "is_vocabulary_anchor": true, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.underreported-attacks", "term": "Underreported attacks", "definition": "Incidents a firm withheld rather than disclosed. Before mandatory disclosure, attacks that were withheld and later revealed by outside sources were associated with a decline of about 3.6% in equity value in the month of discovery, versus about 0.7% for firm-disclosed attacks; the authors interpret this as managers withholding the more severe events (Amir, Levi & Livne, 2018; undiscovered concealment is unobservable by construction).", "label": "RESEARCH_FINDING", "module_ref": "m04", "related": ["term.breach-cost-research", "term.materiality", "term.sec-cybersecurity-disclosure"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.vciso-fractional-ciso", "term": "vCISO / fractional CISO", "definition": "A security executive engaged part-time or on retainer, typically serving several small and mid-sized companies at once. The dominant form of the role by headcount and the least studied: it supplies standing and judgment without operational capacity, which makes the written boundary between advice and ownership the engagement's most important artifact.", "label": "FACT", "module_ref": "m08", "related": ["term.decision-rights", "term.hipaa", "term.msp-mssp", "term.player-coach-architect"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "term.zero-trust", "term": "Zero trust", "definition": "An architectural approach that removes implicit trust based on network location, requiring every request to be authenticated, authorized and evaluated against device and context signals. Widely adopted as a design principle and widely used as a marketing term; treat maturity claims about it as claims about a program, not a product.", "label": "FACT", "module_ref": "m06", "related": ["term.least-agency", "term.mfa", "term.symbolic-vs-substantive-adoption", "term.two-party-control"], "is_vocabulary_anchor": false, "meta": {"source_path": "glossary.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}], "research": [{"id": "res.acharya2013", "author_year_key": "acharya2013", "citation": "Acharya, V. V., Gottschalg, O. F., Hahn, M., & Kehoe, C. (2013). Corporate governance and value creation: Evidence from private equity. *Review of Financial Studies*, 26(2), 368–402. https://doi.org/10.1093/rfs/hhs117", "authors": ["Acharya", "V. V.", "Gottschalg", "O. F.", "Hahn", "M.", "Kehoe, C."], "year": 2013, "title": "Corporate governance and value creation: Evidence from private equity", "venue": "Review of Financial Studies", "doi_or_url": "https://doi.org/10.1093/rfs/hhs117", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In large European buyouts, value creation came mainly from operating improvements, and the professional background of the deal partner predicted which type of value-creation strategy worked best.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In large European buyouts, value creation came mainly from operating improvements, and the professional background of the deal partner predicted which type of value-creation strategy worked best.", "design": "review", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.adams2009", "author_year_key": "adams2009", "citation": "Adams, R. B., Almeida, H., & Ferreira, D. (2009). Understanding the relationship between founder-CEOs and firm performance. *Journal of Empirical Finance*, 16(1), 136–150. https://doi.org/10.1016/j.jempfin.2008.05.002 (RePEc: https://ideas.repec.org/a/eee/empfin/v16y2009i1p136-150.html)", "authors": ["Adams", "R. B.", "Almeida", "H.", "Ferreira, D."], "year": 2009, "title": "Understanding the relationship between founder-CEOs and firm performance", "venue": "Journal of Empirical Finance", "doi_or_url": "https://doi.org/10.1016/j.jempfin.2008.05.002", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "After correcting for the fact that founders tend to leave when things go well, founder-CEO leadership in large U.S. firms is associated with, and plausibly causes, better performance.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "After correcting for the fact that founders tend to leave when things go well, founder-CEO leadership in large U.S. firms is associated with, and plausibly causes, better performance.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.amir2018", "author_year_key": "amir2018", "citation": "Amir, E., Levi, S., & Livne, T. (2018). Do firms underreport information on cyber-attacks? Evidence from capital markets. *Review of Accounting Studies*, 23(3), 1177–1206. https://doi.org/10.1007/s11142-018-9452-4 Tier 1.", "authors": ["Amir", "E.", "Levi", "S.", "Livne, T."], "year": 2018, "title": "Do firms underreport information on cyber-attacks? Evidence from capital markets", "venue": "Review of Accounting Studies", "doi_or_url": "https://doi.org/10.1007/s11142-018-9452-4", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Before mandatory disclosure, attacks that firms withheld and that were later exposed were associated with about a 3.6% equity decline versus 0.7% for firm-disclosed attacks — evidence that concealment is priced when discovered.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Before mandatory disclosure, attacks that firms withheld and that were later exposed were associated with about a 3.6% equity decline versus 0.7% for firm-disclosed attacks — evidence that concealment is priced when discovered.", "design": "review", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m03", "m04", "m05", "m10", "m11", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.anderson2003", "author_year_key": "anderson2003", "citation": "Anderson, R. C., & Reeb, D. M. (2003). Founding-family ownership and firm performance: Evidence from the S&P 500. *Journal of Finance*, 58(3), 1301–1328. https://doi.org/10.1111/1540-6261.00567", "authors": ["Anderson", "R. C.", "Reeb, D. M."], "year": 2003, "title": "Founding-family ownership and firm performance: Evidence from the S&P 500", "venue": "Journal of Finance", "doi_or_url": "https://doi.org/10.1111/1540-6261.00567", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Among large U.S. firms in the 1990s, founding-family ownership was associated with better performance, though later quasi-experimental work shows heir-CEO successions in particular tend to hurt performance.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Among large U.S. firms in the 1990s, founding-family ownership was associated with better performance, though later quasi-experimental work shows heir-CEO successions in particular tend to hurt performance.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.angst2017", "author_year_key": "angst2017", "citation": "Angst, C. M., Block, E. S., D'Arcy, J., & Kelley, K. (2017). When do IT security investments matter? Accounting for the influence of institutional factors in the context of healthcare data breaches. *MIS Quarterly*, 41(3), 893–916. https://doi.org/10.25300/MISQ/2017/41.3.10 (https://aisel.aisnet.org/misq/vol41/iss3/12/; author PDF: https://sites.nd.edu/coreyangst/files/2018/04/AngstBlockDArcyKelley2017MISQ_SymbolicBreach.pdf) Tier 1.", "authors": ["Angst", "C. M.", "Block", "E. S.", "D'Arcy", "J.", "Kelley, K."], "year": 2017, "title": "When do IT security investments matter? Accounting for the influence of institutional factors in the context of healthcare data breaches", "venue": "MIS Quarterly", "doi_or_url": "https://doi.org/10.25300/MISQ/2017/41.3.10", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Across 5,000+ hospitals, the same security investment was associated with fewer breaches only where adoption was substantive rather than symbolic — spending without integration did not buy protection.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Across 5,000+ hospitals, the same security investment was associated with fewer breaches only where adoption was substantive rather than symbolic — spending without integration did not buy protection.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m03", "m06", "m08", "m09", "m11"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.ashenden2013", "author_year_key": "ashenden2013", "citation": "Ashenden, D., & Sasse, A. (2013). CISOs and organisational culture: Their own worst enemy? *Computers & Security*, 39(B), 396–405. https://doi.org/10.1016/j.cose.2013.09.004 (open post-print: https://discovery.ucl.ac.uk/1417350/) Tier 1.", "authors": ["Ashenden", "D.", "Sasse, A."], "year": 2013, "title": "CISOs and organisational culture: Their own worst enemy? *Computers & Security*, 39(B), 396–405", "venue": "Computers & Security", "doi_or_url": "https://doi.org/10.1016/j.cose.2013.09.004", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "A small interview study found CISOs themselves described low perceived power, unclear role identity and weak employee engagement as the main obstacles to effectiveness — a description of the role's information and influence problem, from the inside.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "A small interview study found CISOs themselves described low perceived power, unclear role identity and weak employee engagement as the main obstacles to effectiveness — a description of the role's information and influence problem, from the inside.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m05", "m07", "m08", "m10", "m11", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.bandiera2020", "author_year_key": "bandiera2020", "citation": "Bandiera, O., Prat, A., Hansen, S., & Sadun, R. (2020). CEO behavior and firm performance. *Journal of Political Economy*, 128(4), 1325–1377. https://doi.org/10.1086/705331 (Earlier: NBER Working Paper 23248, 2017.)", "authors": ["Bandiera", "O.", "Prat", "A.", "Hansen", "S.", "Sadun, R."], "year": 2020, "title": "CEO behavior and firm performance", "venue": "Journal of Political Economy", "doi_or_url": "https://doi.org/10.1086/705331", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a six-country study of 1,114 manufacturing CEOs, CEOs whose weeks were more \"leader-like\" (multi-function, executive-team meetings) ran firms with roughly 7% higher sales, gains that appeared only after about three years; the authors estimate about 17% of firms had a CEO whose behavioral type did not fit the firm—while cautioning that this is a matching story, not proof that \"leaders\" are always better than \"managers.\"", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a six-country study of 1,114 manufacturing CEOs, CEOs whose weeks were more \"leader-like\" (multi-function, executive-team meetings) ran firms with roughly 7% higher sales, gains that appeared only after about three years; the authors estimate about 17% of firms had a CEO whose behavioral type did not fit the firm—while cautioning that this is a matching story, not proof that \"leaders\" are always better than \"managers.\"", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m08"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.banker2011", "author_year_key": "banker2011", "citation": "Banker, R. D., Hu, N., Pavlou, P. A., & Luftman, J. (2011). CIO reporting structure, strategic positioning, and firm performance. *MIS Quarterly*, 35(2), 487–504. https://aisel.aisnet.org/misq/vol35/iss2/13/ (SSRN version: https://doi.org/10.2139/ssrn.1557874). Tier 1.", "authors": ["Banker", "R. D.", "Hu", "N.", "Pavlou", "P. A.", "Luftman, J."], "year": 2011, "title": "CIO reporting structure, strategic positioning, and firm performance", "venue": "MIS Quarterly", "doi_or_url": "https://aisel.aisnet.org/misq/vol35/iss2/13/", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a large-firm archival study, the \"right\" CIO reporting line depended on strategy: CIO-to-CEO was associated with better performance in differentiation-strategy firms and CIO-to-CFO in cost-leadership firms — evidence that structure should follow the problem, not a universal rule.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a large-firm archival study, the \"right\" CIO reporting line depended on strategy: CIO-to-CEO was associated with better performance in differentiation-strategy firms and CIO-to-CFO in cost-leadership firms — evidence that structure should follow the problem, not a universal rule.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m02", "m07", "m09", "m10", "m11", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.banker2019", "author_year_key": "banker2019", "citation": "Banker, R. D., & Feng, C. (Q.). (2019). The impact of information security breach incidents on CIO turnover. *Journal of Information Systems*, 33(3), 309–329. https://doi.org/10.2308/isys-52532 (SSRN: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3788478) Tier 1 (American Accounting Association journal).", "authors": ["Banker", "R. D.", "Feng, C."], "year": 2019, "title": "The impact of information security breach incidents on CIO turnover", "venue": "Journal of Information Systems", "doi_or_url": "https://doi.org/10.2308/isys-52532", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "CIO departures were about 72% more likely after breaches attributed to system deficiencies, but not after breaches attributed to fraud or human error — accountability appears to track the perceived scope of the executive's duties.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "CIO departures were about 72% more likely after breaches attributed to system deficiencies, but not after breaches attributed to fraud or human error — accountability appears to track the perceived scope of the executive's duties.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m04", "m07", "m11", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.benischke2019", "author_year_key": "benischke2019", "citation": "Benischke, M. H., Martin, G. P., & Glaser, L. (2019). CEO equity risk bearing and strategic risk taking: The moderating effect of CEO personality. *Strategic Management Journal*, 40(1), 153–177. https://doi.org/10.1002/smj.2974", "authors": ["Benischke", "M. H.", "Martin", "G. P.", "Glaser, L."], "year": 2019, "title": "CEO equity risk bearing and strategic risk taking: The moderating effect of CEO personality", "venue": "Strategic Management Journal", "doi_or_url": "https://doi.org/10.1002/smj.2974", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "The same equity incentives produce different strategic risk taking depending on the CEO's personality — conscientious CEOs respond to risk-bearing with more caution, extraverted and open CEOs with more boldness.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "The same equity incentives produce different strategic risk taking depending on the CEO's personality — conscientious CEOs respond to risk-bearing with more caution, extraverted and open CEOs with more boldness.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.benmelech2015", "author_year_key": "benmelech2015", "citation": "Benmelech, E., & Frydman, C. (2015). Military CEOs. *Journal of Financial Economics*, 117(1), 43–59. https://doi.org/10.1016/j.jfineco.2014.04.009 (NBER WP 19782)", "authors": ["Benmelech", "E.", "Frydman, C."], "year": 2015, "title": "Military CEOs", "venue": "Journal of Financial Economics", "doi_or_url": "https://doi.org/10.1016/j.jfineco.2014.04.009", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "CEOs with military backgrounds run more conservatively and are markedly less likely to be associated with fraud, with better relative performance in industry downturns.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "CEOs with military backgrounds run more conservatively and are markedly less likely to be associated with fraud, with better relative performance in industry downturns.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.bennedsen2007", "author_year_key": "bennedsen2007", "citation": "Bennedsen, M., Nielsen, K. M., Pérez-González, F., & Wolfenzon, D. (2007). Inside the family firm: The role of families in succession decisions and performance. *Quarterly Journal of Economics*, 122(2), 647–691. https://doi.org/10.1162/qjec.122.2.647", "authors": ["Bennedsen", "M.", "Nielsen", "K. M.", "Pérez-González", "F.", "Wolfenzon, D."], "year": 2007, "title": "Inside the family firm: The role of families in succession decisions and performance", "venue": "Quarterly Journal of Economics", "doi_or_url": "https://doi.org/10.1162/qjec.122.2.647", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Quasi-experimental Danish evidence indicates that choosing a family member over an outside professional as CEO causally lowers operating profitability by around four percentage points on average.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Quasi-experimental Danish evidence indicates that choosing a family member over an outside professional as CEO causally lowers operating profitability by around four percentage points on average.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.berger2014", "author_year_key": "berger2014", "citation": "Berger, A. N., Kick, T., & Schaeck, K. (2014). Executive board composition and bank risk taking. *Journal of Corporate Finance*, 28, 48–65. https://doi.org/10.1016/j.jcorpfin.2013.11.006", "authors": ["Berger", "A. N.", "Kick", "T.", "Schaeck, K."], "year": 2014, "title": "Executive board composition and bank risk taking", "venue": "Journal of Corporate Finance", "doi_or_url": "https://doi.org/10.1016/j.jcorpfin.2013.11.006", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Quasi-experimental German evidence suggests executive-team age and education composition affect bank risk-taking, with younger teams taking more risk and PhD-heavy teams less.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Quasi-experimental German evidence suggests executive-team age and education composition affect bank risk-taking, with younger teams taking more risk and PhD-heavy teams less.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.bertrand2003", "author_year_key": "bertrand2003", "citation": "Bertrand, M., & Schoar, A. (2003). Managing with style: The effect of managers on firm policies. *Quarterly Journal of Economics*, 118(4), 1169–1208. https://doi.org/10.1162/003355303322552775", "authors": ["Bertrand", "M.", "Schoar, A."], "year": 2003, "title": "Managing with style: The effect of managers on firm policies", "venue": "Quarterly Journal of Economics", "doi_or_url": "https://doi.org/10.1162/003355303322552775", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Following executives across firms shows that individual managers carry persistent decision \"styles\" that explain meaningful variation in corporate policies, over and above firm characteristics.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Following executives across firms shows that individual managers carry persistent decision \"styles\" that explain meaningful variation in corporate policies, over and above firm characteristics.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m06"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.bloom2007", "author_year_key": "bloom2007", "citation": "Bloom, N., & Van Reenen, J. (2007). Measuring and explaining management practices across firms and countries. *Quarterly Journal of Economics*, 122(4), 1351–1408. https://doi.org/10.1162/qjec.2007.122.4.1351", "authors": ["Bloom", "N.", "Van Reenen, J."], "year": 2007, "title": "Measuring and explaining management practices across firms and countries", "venue": "Quarterly Journal of Economics", "doi_or_url": "https://doi.org/10.1162/qjec.2007.122.4.1351", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Systematically measured management practices vary widely across firms and predict performance, and primogeniture-based family succession is associated with worse management.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Systematically measured management practices vary widely across firms and predict performance, and primogeniture-based family succession is associated with worse management.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m08"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.bloom2016", "author_year_key": "bloom2016", "citation": "Bloom, N., Sadun, R., & Van Reenen, J. (2016, rev. 2017). Management as a technology? NBER Working Paper No. 22327. https://www.nber.org/papers/w22327 (also HBS Working Paper 16-133)", "authors": ["Bloom", "N.", "Sadun", "R.", "Van Reenen, J."], "year": 2016, "title": "Management as a technology? NBER Working Paper No", "venue": "", "doi_or_url": "https://www.nber.org/papers/w22327", "tier": 2, "verification_status": "PARTIALLY_VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Cross-country survey evidence suggests management quality explains a substantial share (on the order of a third) of productivity differences between firms and countries.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Cross-country survey evidence suggests management quality explains a substantial share (on the order of a third) of productivity differences between firms and countries.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.bloom2019", "author_year_key": "bloom2019", "citation": "Bloom, N., Brynjolfsson, E., Foster, L., Jarmin, R., Patnaik, M., Saporta-Eksten, I., & Van Reenen, J. (2019). What drives differences in management practices? *American Economic Review*, 109(5), 1648–1683. https://doi.org/10.1257/aer.20170491", "authors": ["Bloom", "N.", "Brynjolfsson", "E.", "Foster", "L.", "Jarmin", "R.", "Patnaik", "M.", "Saporta-Eksten", "I.", "Van Reenen, J."], "year": 2019, "title": "What drives differences in management practices? *American Economic Review*, 109(5), 1648–1683", "venue": "American Economic Review", "doi_or_url": "https://doi.org/10.1257/aer.20170491", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Census data on 35,000 U.S. plants show management practices explain over a fifth of productivity variation, and much of the variation lies within, not just between, firms.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Census data on 35,000 U.S. plants show management practices explain over a fifth of productivity variation, and much of the variation lies within, not just between, firms.", "design": "review", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.buyl2019", "author_year_key": "buyl2019", "citation": "Buyl, T., Boone, C., & Wade, J. B. (2019). CEO narcissism, risk-taking, and resilience: An empirical analysis in U.S. commercial banks. *Journal of Management*, 45(4), 1372–1400. https://doi.org/10.1177/0149206317699521", "authors": ["Buyl", "T.", "Boone", "C.", "Wade, J. B."], "year": 2019, "title": "CEO narcissism, risk-taking, and resilience: An empirical analysis in U.S", "venue": "Journal of Management", "doi_or_url": "https://doi.org/10.1177/0149206317699521", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In U.S. banks around 2008, archival markers of CEO narcissism predicted riskier pre-crisis policies (conditional on incentives and governance) and slower post-crisis recovery.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In U.S. banks around 2008, archival markers of CEO narcissism predicted riskier pre-crisis policies (conditional on incentives and governance) and slower post-crisis recovery.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.campbell2003", "author_year_key": "campbell2003", "citation": "Campbell, K., Gordon, L. A., Loeb, M. P., & Zhou, L. (2003). The economic cost of publicly announced information security breaches: Empirical evidence from the stock market. *Journal of Computer Security*, 11(3), 431–448. https://doi.org/10.3233/JCS-2003-11308 Tier 1.", "authors": ["Campbell", "K.", "Gordon", "L. A.", "Loeb", "M. P.", "Zhou, L."], "year": 2003, "title": "The economic cost of publicly announced information security breaches: Empirical evidence from the stock market", "venue": "Journal of Computer Security", "doi_or_url": "https://doi.org/10.3233/JCS-2003-11308", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "An early event study found the market penalized breaches of confidential data but not other security incidents — evidence that investors price the *type* of breach, not the fact of one.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "An early event study found the market penalized breaches of confidential data but not other security incidents — evidence that investors price the *type* of breach, not the fact of one.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m03", "m04", "m09"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.cavusoglu2004", "author_year_key": "cavusoglu2004", "citation": "Cavusoglu, H., Mishra, B., & Raghunathan, S. (2004). The effect of internet security breach announcements on market value: Capital market reactions for breached firms and internet security developers. *International Journal of Electronic Commerce*, 9(1), 69–104. https://www.ijec-web.org/past-issues/volume-9-number-1-fall-2004/ijecv9n1-5/ (https://doi.org/10.1080/10864415.2004.11044320) Tier 1.", "authors": ["Cavusoglu", "H.", "Mishra", "B.", "Raghunathan, S."], "year": 2004, "title": "The effect of internet security breach announcements on market value: Capital market reactions for breached firms and internet security developers", "venue": "International Journal of Electronic Commerce", "doi_or_url": "https://www.ijec-web.org/past-issues/volume-9-number-1-fall-2004/ijecv9n1-5/", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a 2004 event study, a publicly announced breach was associated with an average two-day market-value loss of about 2.1%, while security vendors' values rose — the market re-prices both the victim and the sector.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a 2004 event study, a publicly announced breach was associated with an average two-day market-value loss of about 2.1%, while security vendors' values rose — the market re-prices both the victim and the sector.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m03"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.chatterjee2001", "author_year_key": "chatterjee2001", "citation": "Chatterjee, D., Richardson, V. J., & Zmud, R. W. (2001). Examining the shareholder wealth effects of announcements of newly created CIO positions. *MIS Quarterly*, 25(1), 43–70. https://aisel.aisnet.org/misq/vol25/iss1/3/ Tier 1.", "authors": ["Chatterjee", "D.", "Richardson", "V. J.", "Zmud, R. W."], "year": 2001, "title": "Examining the shareholder wealth effects of announcements of newly created CIO positions", "venue": "MIS Quarterly", "doi_or_url": "https://aisel.aisnet.org/misq/vol25/iss1/3/", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "When firms in industries undergoing IT-driven change created a CIO position, investors reacted positively on announcement — a signal of expected value, not evidence of realized value.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "When firms in industries undergoing IT-driven change created a CIO position, investors reacted positively on announcement — a signal of expected value, not evidence of realized value.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m02"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.chatterjee2007", "author_year_key": "chatterjee2007", "citation": "Chatterjee, A., & Hambrick, D. C. (2007). It's all about me: Narcissistic chief executive officers and their effects on company strategy and performance. *Administrative Science Quarterly*, 52(3), 351–386. https://doi.org/10.2189/asqu.52.3.351", "authors": ["Chatterjee", "A.", "Hambrick, D. C."], "year": 2007, "title": "It's all about me: Narcissistic chief executive officers and their effects on company strategy and performance", "venue": "Administrative Science Quarterly", "doi_or_url": "https://doi.org/10.2189/asqu.52.3.351", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a study of 111 tech CEOs, higher measured narcissism was associated with bolder, more changeable strategies and more volatile results — but not with better or worse average performance.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a study of 111 tech CEOs, higher measured narcissism was associated with bolder, more changeable strategies and more volatile results — but not with better or worse average performance.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.chatterjee2011", "author_year_key": "chatterjee2011", "citation": "Chatterjee, A., & Hambrick, D. C. (2011). Executive personality, capability cues, and risk taking: How narcissistic CEOs react to their successes and stumbles. *Administrative Science Quarterly*, 56(2), 202–237. https://doi.org/10.1177/0001839211427534", "authors": ["Chatterjee", "A.", "Hambrick, D. C."], "year": 2011, "title": "Executive personality, capability cues, and risk taking: How narcissistic CEOs react to their successes and stumbles", "venue": "Administrative Science Quarterly", "doi_or_url": "https://doi.org/10.1177/0001839211427534", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Narcissistic CEOs appear to discount objective performance feedback while amplifying their risk taking in response to media praise and awards.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Narcissistic CEOs appear to discount objective performance feedback while amplifying their risk taking in response to media praise and awards.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m04", "m06", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.cragun2020", "author_year_key": "cragun2020", "citation": "Cragun, O. R., Olsen, K. J., & Wright, P. M. (2020). Making CEO narcissism research great: A review and meta-analysis of CEO narcissism. *Journal of Management*, 46(6), 908–936. https://doi.org/10.1177/0149206319892678", "authors": ["Cragun", "O. R.", "Olsen", "K. J.", "Wright, P. M."], "year": 2020, "title": "Making CEO narcissism research great: A review and meta-analysis of CEO narcissism", "venue": "Journal of Management", "doi_or_url": "https://doi.org/10.1177/0149206319892678", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Pooled across studies, CEO narcissism shows small positive associations with innovation/R&D and strategic boldness, but essentially no reliable link to average firm performance or to risk taking — and results vary with how narcissism is measured.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Pooled across studies, CEO narcissism shows small positive associations with innovation/R&D and strategic boldness, but essentially no reliable link to average firm performance or to risk taking — and results vary with how narcissism is measured.", "design": "meta_analysis", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.cram2019", "author_year_key": "cram2019", "citation": "Cram, W. A., D'Arcy, J., & Proudfoot, J. G. (2019). Seeing the forest and the trees: A meta-analysis of the antecedents to information security policy compliance. *MIS Quarterly*, 43(2), 525–554. https://doi.org/10.25300/MISQ/2019/15117 Tier 1.", "authors": ["Cram", "W. A.", "D'Arcy", "J.", "Proudfoot, J. G."], "year": 2019, "title": "Seeing the forest and the trees: A meta-analysis of the antecedents to information security policy compliance", "venue": "MIS Quarterly", "doi_or_url": "https://doi.org/10.25300/MISQ/2019/15117", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Pooled across 95 studies, employees' values and norms were far more strongly associated with security-policy compliance than sanctions or rewards were — the levers security leaders control most directly are the ones that matter least.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Pooled across 95 studies, employees' values and norms were far more strongly associated with security-policy compliance than sanctions or rewards were — the levers security leaders control most directly are the ones that matter least.", "design": "meta_analysis", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m05", "m07", "m11", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.custodio2013", "author_year_key": "custodio2013", "citation": "Custódio, C., Ferreira, M. A., & Matos, P. (2013). Generalists versus specialists: Lifetime work experience and chief executive officer pay. *Journal of Financial Economics*, 108(2), 471–492. https://doi.org/10.1016/j.jfineco.2013.01.001", "authors": ["Custódio", "C.", "Ferreira", "M. A.", "Matos, P."], "year": 2013, "title": "Generalists versus specialists: Lifetime work experience and chief executive officer pay", "venue": "Journal of Financial Economics", "doi_or_url": "https://doi.org/10.1016/j.jfineco.2013.01.001", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "The market pays a sizeable premium for CEOs with broad, transferable experience, particularly for complex mandates like restructurings and M&A.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "The market pays a sizeable premium for CEOs with broad, transferable experience, particularly for complex mandates like restructurings and M&A.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.detert2011", "author_year_key": "detert2011", "citation": "Detert, J. R., & Edmondson, A. C. (2011). Implicit voice theories: Taken-for-granted rules of self-censorship at work. *Academy of Management Journal*, 54(3), 461–488. https://doi.org/10.5465/amj.2011.61967925", "authors": ["Detert", "J. R.", "Edmondson, A. C."], "year": 2011, "title": "Implicit voice theories: Taken-for-granted rules of self-censorship at work", "venue": "Academy of Management Journal", "doi_or_url": "https://doi.org/10.5465/amj.2011.61967925", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Research on employee silence shows that most employees can recall withholding an important concern from a superior, mainly from fear of being labeled negatively or of futility (Milliken et al., 2003), and that widely held, largely unconscious \"rules\" about when speaking up is unsafe suppress upward candor even in objectively safe settings (Detert & Edmondson, 2011)—implying that CEOs should assume critical information is being filtered before it reaches them.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Research on employee silence shows that most employees can recall withholding an important concern from a superior, mainly from fear of being labeled negatively or of futility (Milliken et al., 2003), and that widely held, largely unconscious \"rules\" about when speaking up is unsafe suppress upward candor even in objectively safe settings (Detert & Edmondson, 2011)—implying that CEOs should assume critical information is being filtered before it reaches them.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m05", "m08"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.edmondson1996", "author_year_key": "edmondson1996", "citation": "Edmondson, A. C. (1996). Learning from mistakes is easier said than done: Group and organizational influences on the detection and correction of human error. *The Journal of Applied Behavioral Science*, 32(1), 5–28. https://doi.org/10.1177/0021886396321001 Tier 1.", "authors": ["Edmondson, A. C."], "year": 1996, "title": "Learning from mistakes is easier said than done: Group and organizational influences on the detection and correction of human error", "venue": "The Journal of Applied Behavioral Science", "doi_or_url": "https://doi.org/10.1177/0021886396321001", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Units with better team climate reported more errors, not fewer — evidence that low incident counts can signal silence rather than safety, and that a security leader's incident-reporting numbers must be read with the reporting climate in mind. Pair with Edmondson (1999) for psychological safety proper.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Units with better team climate reported more errors, not fewer — evidence that low incident counts can signal silence rather than safety, and that a security leader's incident-reporting numbers must be read with the reporting climate in mind. Pair with Edmondson (1999) for psychological safety proper.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m04", "m05", "m07", "m08", "m10", "m11", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.edmondson1999", "author_year_key": "edmondson1999", "citation": "Edmondson, A. (1999). Psychological safety and learning behavior in work teams. *Administrative Science Quarterly*, 44(2), 350–383. https://doi.org/10.2307/2666999", "authors": ["Edmondson, A."], "year": 1999, "title": "Psychological safety and learning behavior in work teams", "venue": "Administrative Science Quarterly", "doi_or_url": "https://doi.org/10.2307/2666999", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Edmondson's foundational 1999 study of 51 teams in one manufacturer found that teams with higher psychological safety engaged in more learning behavior and performed better, with leader coaching as an antecedent—findings that later research has extended but that were originally cross-sectional and single-company.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Edmondson's foundational 1999 study of 51 teams in one manufacturer found that teams with higher psychological safety engaged in more learning behavior and performed better, with leader coaching as an antecedent—findings that later research has extended but that were originally cross-sectional and single-company.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m05", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.fahlenbrach2009", "author_year_key": "fahlenbrach2009", "citation": "Fahlenbrach, R. (2009). Founder-CEOs, investment decisions, and stock market performance. *Journal of Financial and Quantitative Analysis*, 44(2), 439–466. https://doi.org/10.1017/S0022109009090139 (RePEc: https://ideas.repec.org/a/cup/jfinqa/v44y2009i02p439-466_09.html; SSRN 606527)", "authors": ["Fahlenbrach, R."], "year": 2009, "title": "Founder-CEOs, investment decisions, and stock market performance", "venue": "Journal of Financial and Quantitative Analysis", "doi_or_url": "https://doi.org/10.1017/S0022109009090139", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a 1993–2002 sample of large U.S. firms, founder-led companies invested more heavily in R&D and capital projects and earned higher risk-adjusted stock returns than successor-led peers, though the evidence is correlational.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a 1993–2002 sample of large U.S. firms, founder-led companies invested more heavily in R&D and capital projects and earned higher risk-adjusted stock returns than successor-led peers, though the evidence is correlational.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.fahlenbrach2011", "author_year_key": "fahlenbrach2011", "citation": "Fahlenbrach, R., & Stulz, R. M. (2011). Bank CEO incentives and the credit crisis. *Journal of Financial Economics*, 99(1), 11–26. https://doi.org/10.1016/j.jfineco.2010.08.010 (NBER WP 15212)", "authors": ["Fahlenbrach", "R.", "Stulz, R. M."], "year": 2011, "title": "Bank CEO incentives and the credit crisis", "venue": "Journal of Financial Economics", "doi_or_url": "https://doi.org/10.1016/j.jfineco.2010.08.010", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Evidence from the 2008 crisis does not support the view that misaligned CEO pay caused bank losses; CEOs with the most \"skin in the game\" ran banks that fared worst, suggesting misjudged risk rather than self-dealing.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Evidence from the 2008 crisis does not support the view that misaligned CEO pay caused bank losses; CEOs with the most \"skin in the game\" ran banks that fared worst, suggesting misjudged risk rather than self-dealing.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.feeny1992", "author_year_key": "feeny1992", "citation": "Feeny, D. F., Edwards, B. R., & Simpson, K. M. (1992). Understanding the CEO/CIO relationship. *MIS Quarterly*, 16(4), 435–448. https://aisel.aisnet.org/misq/vol16/iss4/1/ (an earlier version appeared at ICIS 1992: https://aisel.aisnet.org/icis1992/2/). Tier 1.", "authors": ["Feeny", "D. F.", "Edwards", "B. R.", "Simpson, K. M."], "year": 1992, "title": "Understanding the CEO/CIO relationship", "venue": "MIS Quarterly", "doi_or_url": "https://aisel.aisnet.org/misq/vol16/iss4/1/", "tier": 1, "verification_status": "PARTIALLY_VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Early qualitative research treated the CEO/CIO relationship itself — not the CIO's skills alone — as the unit of analysis for IT effectiveness (cite for the framing only until the abstract is confirmed).", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Early qualitative research treated the CEO/CIO relationship itself — not the CIO's skills alone — as the unit of analysis for IT effectiveness (cite for the framing only until the abstract is confirmed).", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m10"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.fitza2014", "author_year_key": "fitza2014", "citation": "Fitza, M. A. (2014). The use of variance decomposition in the investigation of CEO effects: How large must the CEO effect be to rule out chance? Strategic Management Journal, 35(12), 1839–1852. https://doi.org/10.1002/smj.2192", "authors": ["Fitza, M. A."], "year": 2014, "title": "The use of variance decomposition in the investigation of CEO effects: How large must the CEO effect be to rule out chance? Strategic Management Journal, 35(12), 1839–1852", "venue": "", "doi_or_url": "https://doi.org/10.1002/smj.2192", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Simulations suggest a sizable apparent \"CEO effect\" can arise from chance alone given short tenures; the size of the true CEO effect is contested.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Simulations suggest a sizable apparent \"CEO effect\" can arise from chance alone given short tenures; the size of the true CEO effect is contested.", "design": "cross_sectional", "causal_language_permitted": false, "contested": true, "contested_by": ["res.quigley2017"], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.fitza2017", "author_year_key": "fitza2017", "citation": "Fitza, M. A. (2017). How much do CEOs really matter? Reaffirming that the CEO effect is mostly due to chance. Strategic Management Journal, 38(3), 802–811. https://doi.org/10.1002/smj.2597", "authors": ["Fitza, M. A."], "year": 2017, "title": "How much do CEOs really matter? Reaffirming that the CEO effect is mostly due to chance", "venue": "", "doi_or_url": "https://doi.org/10.1002/smj.2597", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Rejoinder maintaining that under realistic assumptions the measured CEO effect remains close to chance.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Rejoinder maintaining that under realistic assumptions the measured CEO effect remains close to chance.", "design": "cross_sectional", "causal_language_permitted": false, "contested": true, "contested_by": ["res.quigley2017"], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.georgakakis2017", "author_year_key": "georgakakis2017", "citation": "Georgakakis, D., & Ruigrok, W. (2017). CEO succession origin and firm performance: A multilevel study. *Journal of Management Studies*, 54(1), 58–87. https://doi.org/10.1111/joms.12194", "authors": ["Georgakakis", "D.", "Ruigrok, W."], "year": 2017, "title": "CEO succession origin and firm performance: A multilevel study", "venue": "Journal of Management Studies", "doi_or_url": "https://doi.org/10.1111/joms.12194", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Peer-reviewed succession research finds no universal insider-or-outsider advantage: outsiders do better mainly when integration is easier and context is favorable (Georgakakis & Ruigrok, 2017), and the consequences of any successor type depend on what happens to the rest of the senior team afterward (Shen & Cannella, 2002).", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Peer-reviewed succession research finds no universal insider-or-outsider advantage: outsiders do better mainly when integration is easier and context is favorable (Georgakakis & Ruigrok, 2017), and the consequences of any successor type depend on what happens to the rest of the senior team afterward (Shen & Cannella, 2002).", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.gerow2014", "author_year_key": "gerow2014", "citation": "Gerow, J. E., Grover, V., Thatcher, J. B., & Roth, P. L. (2014). Looking toward the future of IT–business strategic alignment through the past: A meta-analysis. *MIS Quarterly*, 38(4), 1159–1186. https://aisel.aisnet.org/misq/vol38/iss4/12/ Tier 1.", "authors": ["Gerow", "J. E.", "Grover", "V.", "Thatcher", "J. B.", "Roth, P. L."], "year": 2014, "title": "Looking toward the future of IT–business strategic alignment through the past: A meta-analysis", "venue": "MIS Quarterly", "doi_or_url": "https://aisel.aisnet.org/misq/vol38/iss4/12/", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Pooled across the literature, IT–business alignment is positively associated with performance on every dimension examined; the much-discussed \"alignment paradox\" largely disappears in meta-analysis.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Pooled across the literature, IT–business alignment is positively associated with performance on every dimension examined; the much-discussed \"alignment paradox\" largely disappears in meta-analysis.", "design": "meta_analysis", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m02", "m10"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.gompers2016", "author_year_key": "gompers2016", "citation": "Gompers, P., Kaplan, S. N., & Mukharlyamov, V. (2016). What do private equity firms say they do? *Journal of Financial Economics*, 121(3), 449–476. https://doi.org/10.1016/j.jfineco.2016.06.003", "authors": ["Gompers", "P.", "Kaplan", "S. N.", "Mukharlyamov, V."], "year": 2016, "title": "What do private equity firms say they do? *Journal of Financial Economics*, 121(3), 449–476", "venue": "Journal of Financial Economics", "doi_or_url": "https://doi.org/10.1016/j.jfineco.2016.06.003", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "PE investors report that management quality and growth, not just cost-cutting or leverage, are central to their value-creation plans, and they often change the management team.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "PE investors report that management quality and growth, not just cost-cutting or leverage, are central to their value-creation plans, and they often change the management team.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.gordon2002", "author_year_key": "gordon2002", "citation": "Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. *ACM Transactions on Information and System Security*, 5(4), 438–457. https://doi.org/10.1145/581271.581274 Tier 1.", "authors": ["Gordon", "L. A.", "Loeb, M. P."], "year": 2002, "title": "The economics of information security investment", "venue": "ACM Transactions on Information and System Security", "doi_or_url": "https://doi.org/10.1145/581271.581274", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "The Gordon–Loeb model gives a disciplined way to think about security spending as a function of expected loss, and shows that under common assumptions it is irrational to spend more than about a third of expected loss — a reasoning tool, with assumptions that must be stated whenever the 37% figure is quoted.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "The Gordon–Loeb model gives a disciplined way to think about security spending as a function of expected loss, and shows that under common assumptions it is irrational to spend more than about a third of expected loss — a reasoning tool, with assumptions that must be stated whenever the 37% figure is quoted.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m03", "m06", "m07", "m10", "m11", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.gow2016", "author_year_key": "gow2016", "citation": "Gow, I. D., Kaplan, S. N., Larcker, D. F., & Zakolyukina, A. A. (2016). CEO personality and firm policies. NBER Working Paper No. 22435. https://doi.org/10.3386/w22435 (SSRN: https://papers.ssrn.com/abstract=2813883; HLS Forum summary: https://corpgov.law.harvard.edu/?p=73500)", "authors": ["Gow", "I. D.", "Kaplan", "S. N.", "Larcker", "D. F.", "Zakolyukina, A. A."], "year": 2016, "title": "CEO personality and firm policies", "venue": "", "doi_or_url": "https://doi.org/10.3386/w22435", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Machine-learning estimates of CEO Big Five traits from earnings-call language are associated with firm policies (e.g., more R&D and less leverage under high openness), although the personality measures are noisy and the paper remains a working paper.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Machine-learning estimates of CEO Big Five traits from earnings-call language are associated with firm policies (e.g., more R&D and less leverage under high openness), although the personality measures are noisy and the paper remains a working paper.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.graham2013", "author_year_key": "graham2013", "citation": "Graham, J. R., Harvey, C. R., & Puri, M. (2013). Managerial attitudes and corporate actions. *Journal of Financial Economics*, 109(1), 103–121. https://doi.org/10.1016/j.jfineco.2013.01.010 (SSRN: https://papers.ssrn.com/abstract=1432641; author PDF: https://people.duke.edu/~charvey/Research/Published_Papers/P109_Managerial_attitudes_and.pdf)", "authors": ["Graham", "J. R.", "Harvey", "C. R.", "Puri, M."], "year": 2013, "title": "Managerial attitudes and corporate actions", "venue": "Journal of Financial Economics", "doi_or_url": "https://doi.org/10.1016/j.jfineco.2013.01.010", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a large survey, CEOs scored substantially more risk-tolerant and optimistic than the general population, and those traits were associated with more acquisitions, more short-term debt and different pay structures — associations, not proven causes.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a large survey, CEOs scored substantially more risk-tolerant and optimistic than the general population, and those traits were associated with more acquisitions, more short-term debt and different pay structures — associations, not proven causes.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m03", "m07"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.graham2015", "author_year_key": "graham2015", "citation": "Graham, J. R., Harvey, C. R., & Puri, M. (2015). Capital allocation and delegation of decision-making authority within firms. *Journal of Financial Economics*, 115(3), 449–470. https://doi.org/10.1016/j.jfineco.2014.10.011", "authors": ["Graham", "J. R.", "Harvey", "C. R.", "Puri, M."], "year": 2015, "title": "Capital allocation and delegation of decision-making authority within firms", "venue": "Journal of Financial Economics", "doi_or_url": "https://doi.org/10.1016/j.jfineco.2014.10.011", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Large-scale survey evidence shows CEOs' delegation and capital-allocation decisions depend on their own bandwidth, tenure and expertise, and on the credibility of divisional leaders.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Large-scale survey evidence shows CEOs' delegation and capital-allocation decisions depend on their own bandwidth, tenure and expertise, and on the credibility of divisional leaders.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m08"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.haislip2021", "author_year_key": "haislip2021", "citation": "Haislip, J., Lim, J.-H., & Pinsker, R. (2021). The impact of executives' IT expertise on reported data security breaches. *Information Systems Research*, 32(2), 318–334. https://doi.org/10.1287/isre.2020.0986 Tier 1.", "authors": ["Haislip", "J.", "Lim", "J.-H.", "Pinsker, R."], "year": 2021, "title": "The impact of executives' IT expertise on reported data security breaches", "venue": "Information Systems Research", "doi_or_url": "https://doi.org/10.1287/isre.2020.0986", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Firms whose CEO had IT expertise, and firms with a CIO on the top team, reported fewer data breaches over 2005–2017 — an association between top-team composition and breach outcomes, not a causal effect of any one appointment.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Firms whose CEO had IT expertise, and firms with a CIO on the top team, reported fewer data breaches over 2005–2017 — an association between top-team composition and breach outcomes, not a causal effect of any one appointment.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m02", "m04", "m07"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.hambrick1984", "author_year_key": "hambrick1984", "citation": "Hambrick, D. C., & Mason, P. A. (1984). Upper echelons: The organization as a reflection of its top managers. *Academy of Management Review*, 9(2), 193–206. https://doi.org/10.5465/amr.1984.4277628", "authors": ["Hambrick", "D. C.", "Mason, P. A."], "year": 1984, "title": "Upper echelons: The organization as a reflection of its top managers", "venue": "Academy of Management Review", "doi_or_url": "https://doi.org/10.5465/amr.1984.4277628", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Upper echelons theory holds that firms reflect their top managers' experiences, values and personalities — an organising framework rather than an empirical result.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Upper echelons theory holds that firms reflect their top managers' experiences, values and personalities — an organising framework rather than an empirical result.", "design": "review", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.hambrick1987", "author_year_key": "hambrick1987", "citation": "Hambrick, D. C., & Finkelstein, S. (1987). Managerial discretion: A bridge between polar views of organizational outcomes. *Research in Organizational Behavior*, 9, 369–406. (No DOI; book-series chapter. Confirmed via Semantic Scholar/SciSpace and multiple citing sources.)", "authors": ["Hambrick", "D. C.", "Finkelstein, S."], "year": 1987, "title": "Managerial discretion: A bridge between polar views of organizational outcomes", "venue": "Research in Organizational Behavior", "doi_or_url": "n/a", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "The concept of managerial discretion (Hambrick & Finkelstein, 1987) holds that how much a CEO matters depends on the latitude the environment, the organization, and the executive's own makeup allow—and a 2015 review confirms empirical support is strongest for the environmental sources and weakest for the individual-level ones.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "The concept of managerial discretion (Hambrick & Finkelstein, 1987) holds that how much a CEO matters depends on the latitude the environment, the organization, and the executive's own makeup allow—and a 2015 review confirms empirical support is strongest for the environmental sources and weakest for the individual-level ones.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m02", "m10", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.hambrick1991", "author_year_key": "hambrick1991", "citation": "Hambrick, D. C., & Fukutomi, G. D. S. (1991). The seasons of a CEO's tenure. *Academy of Management Review*, 16(4), 719–742. https://doi.org/10.5465/amr.1991.4279621", "authors": ["Hambrick", "D. C.", "Fukutomi, G. D. S."], "year": 1991, "title": "The seasons of a CEO's tenure", "venue": "Academy of Management Review", "doi_or_url": "https://doi.org/10.5465/amr.1991.4279621", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Theory (Hambrick & Fukutomi, 1991) and early evidence (Miller, 1991) suggest that long CEO tenures carry a risk of \"staleness\"—growing commitment to an established paradigm and declining fit with a changing environment—though the seasons model itself is conceptual and tenure effects vary by context.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Theory (Hambrick & Fukutomi, 1991) and early evidence (Miller, 1991) suggest that long CEO tenures carry a risk of \"staleness\"—growing commitment to an established paradigm and declining fit with a changing environment—though the seasons model itself is conceptual and tenure effects vary by context.", "design": "review", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m06"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.hambrick2007", "author_year_key": "hambrick2007", "citation": "Hambrick, D. C. (2007). Upper echelons theory: An update. *Academy of Management Review*, 32(2), 334–343. https://doi.org/10.5465/amr.2007.24345254", "authors": ["Hambrick, D. C."], "year": 2007, "title": "Upper echelons theory: An update", "venue": "Academy of Management Review", "doi_or_url": "https://doi.org/10.5465/amr.2007.24345254", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "The 2007 update argues that CEO characteristics matter most when the CEO has discretion and faces heavy job demands, and it urges research to measure executives' psychology directly.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "The 2007 update argues that CEO characteristics matter most when the CEO has discretion and faces heavy job demands, and it urges research to measure executives' psychology directly.", "design": "review", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m07", "m10"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.harrison2019", "author_year_key": "harrison2019", "citation": "Harrison, J. S., Thurgood, G. R., Boivie, S., & Pfarrer, M. D. (2019). Measuring CEO personality: Developing, validating, and testing a linguistic tool. *Strategic Management Journal*, 40(8), 1316–1330. https://doi.org/10.1002/smj.3023", "authors": ["Harrison", "J. S.", "Thurgood", "G. R.", "Boivie", "S.", "Pfarrer, M. D."], "year": 2019, "title": "Measuring CEO personality: Developing, validating, and testing a linguistic tool", "venue": "Strategic Management Journal", "doi_or_url": "https://doi.org/10.1002/smj.3023", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "A validated language-based measure of CEO personality shows that Big Five traits are related to the degree of strategic change, with effects conditioned by recent firm performance.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "A validated language-based measure of CEO personality shows that Big Five traits are related to the degree of strategic change, with effects conditioned by recent firm performance.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.harrison2020", "author_year_key": "harrison2020", "citation": "Harrison, J. S., Thurgood, G. R., Boivie, S., & Pfarrer, M. D. (2020). Perception is reality: How CEOs' observed personality influences market perceptions of firm risk and shareholder returns. *Academy of Management Journal*, 63(4), 1166–1195. https://doi.org/10.5465/amj.2018.0626", "authors": ["Harrison", "J. S.", "Thurgood", "G. R.", "Boivie", "S.", "Pfarrer, M. D."], "year": 2020, "title": "Perception is reality: How CEOs' observed personality influences market perceptions of firm risk and shareholder returns", "venue": "Academy of Management Journal", "doi_or_url": "https://doi.org/10.5465/amj.2018.0626", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Investors appear to price CEO personality: observed conscientiousness is associated with lower perceived risk and better returns, whereas observed extraversion and neuroticism are associated with higher perceived risk.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Investors appear to price CEO personality: observed conscientiousness is associated with lower perceived risk and better returns, whereas observed extraversion and neuroticism are associated with higher perceived risk.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.hayward2004", "author_year_key": "hayward2004", "citation": "Hayward, M. L. A., Rindova, V. P., & Pollock, T. G. (2004). Believing one's own press: The causes and consequences of CEO celebrity. *Strategic Management Journal*, 25(7), 637–653. https://doi.org/10.1002/smj.405", "authors": ["Hayward", "M. L. A.", "Rindova", "V. P.", "Pollock, T. G."], "year": 2004, "title": "Believing one's own press: The causes and consequences of CEO celebrity", "venue": "Strategic Management Journal", "doi_or_url": "https://doi.org/10.1002/smj.405", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Hayward and colleagues theorise that media-created CEO celebrity fosters hubris and strategic persistence; empirical support comes from later studies such as Malmendier & Tate (2009).", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Hayward and colleagues theorise that media-created CEO celebrity fosters hubris and strategic persistence; empirical support comes from later studies such as Malmendier & Tate (2009).", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m11", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.herrmann2014", "author_year_key": "herrmann2014", "citation": "Herrmann, P., & Nadkarni, S. (2014). Managing strategic change: The duality of CEO personality. *Strategic Management Journal*, 35(9), 1318–1342. https://doi.org/10.1002/smj.2156", "authors": ["Herrmann", "P.", "Nadkarni, S."], "year": 2014, "title": "Managing strategic change: The duality of CEO personality", "venue": "Strategic Management Journal", "doi_or_url": "https://doi.org/10.1002/smj.2156", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "CEO conscientiousness appears to cut both ways — dampening the initiation of strategic change while improving the performance of changes that are implemented (evidence from 120 SMEs).", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "CEO conscientiousness appears to cut both ways — dampening the initiation of strategic change while improving the performance of changes that are implemented (evidence from 120 SMEs).", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m06"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.higgs2016", "author_year_key": "higgs2016", "citation": "Higgs, J. L., Pinsker, R. E., Smith, T. J., & Young, G. R. (2016). The relationship between board-level technology committees and reported security breaches. *Journal of Information Systems*, 30(3), 79–98. https://publications.aaahq.org/jis/article-abstract/30/3/79/1035/The-Relationship-between-Board-Level-Technology (SSRN: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3234337) Tier 1.", "authors": ["Higgs", "J. L.", "Pinsker", "R. E.", "Smith", "T. J.", "Young, G. R."], "year": 2016, "title": "The relationship between board-level technology committees and reported security breaches", "venue": "Journal of Information Systems", "doi_or_url": "https://publications.aaahq.org/jis/article-abstract/30/3/79/1035/The-Relationship-between-Board-Level-Technology", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Boards with technology committees reported more breaches (plausibly because they detect and disclose more) and their firms suffered smaller stock-price penalties when external breaches occurred — evidence that visible board oversight changes both reporting and market response.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Boards with technology committees reported more breaches (plausibly because they detect and disclose more) and their firms suffered smaller stock-price penalties when external breaches occurred — evidence that visible board oversight changes both reporting and market response.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m02", "m04", "m05", "m09", "m10", "m11"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.hirshleifer2012", "author_year_key": "hirshleifer2012", "citation": "Hirshleifer, D., Low, A., & Teoh, S. H. (2012). Are overconfident CEOs better innovators? *Journal of Finance*, 67(4), 1457–1498. https://doi.org/10.1111/j.1540-6261.2012.01753.x", "authors": ["Hirshleifer", "D.", "Low", "A.", "Teoh, S. H."], "year": 2012, "title": "Are overconfident CEOs better innovators? *Journal of Finance*, 67(4), 1457–1498", "venue": "Journal of Finance", "doi_or_url": "https://doi.org/10.1111/j.1540-6261.2012.01753.x", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Overconfident CEOs are associated with more R&D, more patents and more innovation per R&D dollar — but only in innovative industries, and alongside higher firm-level volatility.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Overconfident CEOs are associated with more R&D, more patents and more innovation per R&D dollar — but only in innovative industries, and alongside higher firm-level volatility.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.ho2016", "author_year_key": "ho2016", "citation": "Ho, P.-H., Huang, C.-W., Lin, C.-Y., & Yen, J.-F. (2016). CEO overconfidence and financial crisis: Evidence from bank lending and leverage. *Journal of Financial Economics*, 120(1), 194–209. https://doi.org/10.1016/j.jfineco.2015.04.007", "authors": ["Ho", "P.-H.", "Huang", "C.-W.", "Lin", "C.-Y.", "Yen, J.-F."], "year": 2016, "title": "CEO overconfidence and financial crisis: Evidence from bank lending and leverage", "venue": "Journal of Financial Economics", "doi_or_url": "https://doi.org/10.1016/j.jfineco.2015.04.007", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Banks led by CEOs who exhibit option-based markers of overconfidence expanded lending and leverage faster before crises and performed worse during them.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Banks led by CEOs who exhibit option-based markers of overconfidence expanded lending and leverage faster before crises and performed worse during them.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.hollenbeck2006", "author_year_key": "hollenbeck2006", "citation": "Hollenbeck, J. R., DeRue, D. S., & Mannor, M. J. (2006). Statistical power and parameter stability when subjects are few and tests are many: Comment on Peterson, Smith, Martorana, and Owens (2003). Journal of Applied Psychology, 91(1), 1–5.", "authors": ["Hollenbeck", "J. R.", "DeRue", "D. S.", "Mannor, M. J."], "year": 2006, "title": "Statistical power and parameter stability when subjects are few and tests are many: Comment on Peterson, Smith, Martorana, and Owens (2003)", "venue": "", "doi_or_url": "n/a", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Methodological critique showing the Peterson et al. (2003) 17-CEO findings are underpowered and unstable.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Methodological critique showing the Peterson et al. (2003) 17-CEO findings are underpowered and unstable.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.ians2026", "author_year_key": "ians2026", "citation": "IANS Research & Artico Search. (2026, January 16). *State of the CISO 2026 Benchmark Report* (\"A Role Divided\"). https://www.iansresearch.com/resources/2026-state-of-the-ciso--a-role-divided (press release: https://www.ians.com/press/2026-report-finds-executive-level-ciso-titles-more-prevalent-than-ever; coverage: https://www.techtarget.com/searchsecurity/feature/Majority-of-CISOs-now-hold-executive-level-titles-IANS-reports) Tier 3 — **practitioner survey, not peer-reviewed.**", "authors": ["IANS Research", "Artico Search."], "year": 2026, "title": "*State of the CISO 2026 Benchmark Report* (\"A Role Divided\")", "venue": "State of the CISO 2026 Benchmark Report", "doi_or_url": "https://www.iansresearch.com/resources/2026-state-of-the-ciso--a-role-divided", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a 2026 practitioner survey of 600+ security leaders, roughly two-thirds of CISOs reported to the CIO or CTO and about one-third to a non-IT executive; about half held executive-level titles, and about half said the role was not manageable with current resources (practitioner data; base rates only).", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a 2026 practitioner survey of 600+ security leaders, roughly two-thirds of CISOs reported to the CIO or CTO and about one-third to a non-IT executive; about half held executive-level titles, and about half said the role was not manageable with current resources (practitioner data; base rates only).", "design": "descriptive_practitioner", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m02", "m03", "m07", "m08", "m09", "m10", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.ibm2025", "author_year_key": "ibm2025", "citation": "IBM & Ponemon Institute. (2025, July 30). *Cost of a Data Breach Report 2025*. https://www.ibm.com/reports/data-breach (analysis: https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai) Tier 3 — **practitioner report, not peer-reviewed.**", "authors": ["IBM", "Ponemon Institute."], "year": 2025, "title": "*Cost of a Data Breach Report 2025*", "venue": "Cost of a Data Breach Report 2025", "doi_or_url": "https://www.ibm.com/reports/data-breach", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "IBM/Ponemon's 2025 sample of ~600 breached organizations put the average breach cost at $4.44 million and average identify-and-contain time at 241 days — vendor-sponsored practitioner estimates, useful as an order of magnitude only.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "IBM/Ponemon's 2025 sample of ~600 breached organizations put the average breach cost at $4.44 million and average identify-and-contain time at 241 days — vendor-sponsored practitioner estimates, useful as an order of magnitude only.", "design": "descriptive_practitioner", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m03"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.judge2002", "author_year_key": "judge2002", "citation": "Judge, T. A., Bono, J. E., Ilies, R., & Gerhardt, M. W. (2002). Personality and leadership: A qualitative and quantitative review. *Journal of Applied Psychology*, 87(4), 765–780. https://doi.org/10.1037/0021-9010.87.4.765", "authors": ["Judge", "T. A.", "Bono", "J. E.", "Ilies", "R.", "Gerhardt, M. W."], "year": 2002, "title": "Personality and leadership: A qualitative and quantitative review", "venue": "Journal of Applied Psychology", "doi_or_url": "https://doi.org/10.1037/0021-9010.87.4.765", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Across 73 samples, extraversion, conscientiousness, openness and emotional stability are each modestly related to who emerges as and is rated an effective leader (multiple R ≈ .48) — evidence from general leadership samples, not specifically CEOs.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Across 73 samples, extraversion, conscientiousness, openness and emotional stability are each modestly related to who emerges as and is rated an effective leader (multiple R ≈ .48) — evidence from general leadership samples, not specifically CEOs.", "design": "qualitative", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.kamiya2021", "author_year_key": "kamiya2021", "citation": "Kamiya, S., Kang, J.-K., Kim, J., Milidonis, A., & Stulz, R. M. (2021). Risk management, firm reputation, and the impact of successful cyberattacks on target firms. *Journal of Financial Economics*, 139(3), 719–749. https://doi.org/10.1016/j.jfineco.2019.05.019 Tier 1.", "authors": ["Kamiya", "S.", "Kang", "J.-K.", "Kim", "J.", "Milidonis", "A.", "Stulz, R. M."], "year": 2021, "title": "Risk management, firm reputation, and the impact of successful cyberattacks on target firms", "venue": "Journal of Financial Economics", "doi_or_url": "https://doi.org/10.1016/j.jfineco.2019.05.019", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Successful cyberattacks that expose personal financial data are associated with shareholder losses far exceeding direct costs, smaller losses where boards had already attended to risk management, and subsequent increases in risk-management investment and cuts to managers' risk-taking incentives.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Successful cyberattacks that expose personal financial data are associated with shareholder losses far exceeding direct costs, smaller losses where boards had already attended to risk management, and subsequent increases in risk-management investment and cuts to managers' risk-taking incentives.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m03", "m04", "m06", "m09", "m10", "m11"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.kaplan2012", "author_year_key": "kaplan2012", "citation": "Kaplan, S. N., Klebanov, M. M., & Sorensen, M. (2012). Which CEO characteristics and abilities matter? *Journal of Finance*, 67(3), 973–1007. https://doi.org/10.1111/j.1540-6261.2012.01739.x (NBER WP 14195: https://www.nber.org/papers/w14195)", "authors": ["Kaplan", "S. N.", "Klebanov", "M. M.", "Sorensen, M."], "year": 2012, "title": "Which CEO characteristics and abilities matter? *Journal of Finance*, 67(3), 973–1007", "venue": "Journal of Finance", "doi_or_url": "https://doi.org/10.1111/j.1540-6261.2012.01739.x", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Among PE/VC-backed CEO candidates, \"execution\" abilities (resoluteness, efficiency, persistence) predicted subsequent success more strongly than interpersonal/\"soft\" abilities did.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Among PE/VC-backed CEO candidates, \"execution\" abilities (resoluteness, efficiency, persistence) predicted subsequent success more strongly than interpersonal/\"soft\" abilities did.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.kaplan2021", "author_year_key": "kaplan2021", "citation": "Kaplan, S. N., & Sorensen, M. (2021). Are CEOs different? *Journal of Finance*, 76(4), 1773–1811. https://doi.org/10.1111/jofi.13019 (Earlier NBER WP 23832, 2017, titled \"Are CEOs Different? Characteristics of Top Managers\": https://www.nber.org/papers/w23832)", "authors": ["Kaplan", "S. N.", "Sorensen, M."], "year": 2021, "title": "Are CEOs different? *Journal of Finance*, 76(4), 1773–1811", "venue": "Journal of Finance", "doi_or_url": "https://doi.org/10.1111/jofi.13019", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a large set of structured executive assessments, CEO candidates differed from CFO candidates on general ability, execution orientation, charisma and strategic focus — and boards appeared to favour interpersonal skills at hiring even though execution ability better predicted later advancement.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a large set of structured executive assessments, CEO candidates differed from CFO candidates on general ability, execution orientation, charisma and strategic focus — and boards appeared to favour interpersonal skills at hiring even though execution ability better predicted later advancement.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.karaevli2007", "author_year_key": "karaevli2007", "citation": "Karaevli, A. (2007). Performance consequences of new CEO 'outsiderness': Moderating effects of pre- and post-succession contexts. *Strategic Management Journal*, 28(7), 681–706. https://doi.org/10.1002/smj.589", "authors": ["Karaevli, A."], "year": 2007, "title": "Performance consequences of new CEO 'outsiderness': Moderating effects of pre- and post-succession contexts", "venue": "Strategic Management Journal", "doi_or_url": "https://doi.org/10.1002/smj.589", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Karaevli's 30-year study of two U.S. industries found no general advantage for outsider CEOs; outsiders helped mainly when the firm was performing poorly or its environment was turbulent, and the effect depended on what changed alongside the succession.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Karaevli's 30-year study of two U.S. industries found no general advantage for outsider CEOs; outsiders helped mainly when the firm was performing poorly or its environment was turbulent, and the effect depended on what changed alongside the succession.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m09"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.karahanna2013", "author_year_key": "karahanna2013", "citation": "Karahanna, E., & Preston, D. S. (2013). The effect of social capital of the relationship between the CIO and top management team on firm performance. *Journal of Management Information Systems*, 30(1), 15–56. https://www.jmis-web.org/articles/506 Tier 1.", "authors": ["Karahanna", "E.", "Preston, D. S."], "year": 2013, "title": "The effect of social capital of the relationship between the CIO and top management team on firm performance", "venue": "Journal of Management Information Systems", "doi_or_url": "https://www.jmis-web.org/articles/506", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In 81 hospitals, the quality of the CIO's relationship with the top team was associated with better alignment and, through alignment, with financial performance — relationship quality as a mechanism, measured correlationally.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In 81 hospitals, the quality of the CIO's relationship with the top team was associated with better alignment and, through alignment, with financial performance — relationship quality as a mechanism, measured correlationally.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m02", "m07", "m10", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.karanja2017", "author_year_key": "karanja2017", "citation": "Karanja, E. (2017). The role of the chief information security officer in the management of IT security. *Information & Computer Security*, 25(3), 300–329. https://doi.org/10.1108/ICS-02-2016-0013 Tier 1 (Emerald, peer-reviewed).", "authors": ["Karanja, E."], "year": 2017, "title": "The role of the chief information security officer in the management of IT security", "venue": "Information & Computer Security", "doi_or_url": "https://doi.org/10.1108/ICS-02-2016-0013", "tier": 1, "verification_status": "PARTIALLY_VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Cite only as \"peer-reviewed research has examined CISO appointments and reporting positions in relation to breach events (Karanja, 2017)\" until verification is completed.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Cite only as \"peer-reviewed research has examined CISO appointments and reporting positions in relation to breach events (Karanja, 2017)\" until verification is completed.", "design": "review", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m02", "m07"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.kashmiri2017", "author_year_key": "kashmiri2017", "citation": "Kashmiri, S., Nicol, C. D., & Hsu, L. (2017). Birds of a feather: Intra-industry spillover of the Target customer data breach and the shielding role of IT, marketing, and CSR. *Journal of the Academy of Marketing Science*, 45(2), 208–228. https://doi.org/10.1007/s11747-016-0486-5 Tier 1.", "authors": ["Kashmiri", "S.", "Nicol", "C. D.", "Hsu, L."], "year": 2017, "title": "Birds of a feather: Intra-industry spillover of the Target customer data breach and the shielding role of IT, marketing, and CSR", "venue": "Journal of the Academy of Marketing Science", "doi_or_url": "https://doi.org/10.1007/s11747-016-0486-5", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "After the Target breach, 168 other US retailers lost value on average, and the loss was smaller for firms with stronger IT, marketing and CSR positions — a breach at a peer is priced against you, moderated by your own visible capabilities.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "After the Target breach, 168 other US retailers lost value on average, and the loss was smaller for firms with stronger IT, marketing and CSR positions — a breach at a peer is priced against you, moderated by your own visible capabilities.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m03", "m09"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.kwon2014", "author_year_key": "kwon2014", "citation": "Kwon, J., & Johnson, M. E. (2014). Proactive versus reactive security investments in the healthcare sector. *MIS Quarterly*, 38(2), 451–471. https://aisel.aisnet.org/misq/vol38/iss2/8/ Tier 1.", "authors": ["Kwon", "J.", "Johnson, M. E."], "year": 2014, "title": "Proactive versus reactive security investments in the healthcare sector", "venue": "MIS Quarterly", "doi_or_url": "https://aisel.aisnet.org/misq/vol38/iss2/8/", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In US healthcare, security investment made before a failure was associated with lower subsequent failure rates and better cost-effectiveness than investment made after one, and regulatory pressure weakened the benefit of proactive investment.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In US healthcare, security investment made before a failure was associated with lower subsequent failure rates and better cost-effectiveness than investment made after one, and regulatory pressure weakened the benefit of proactive investment.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m03", "m06", "m09"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.lee2017", "author_year_key": "lee2017", "citation": "Lee, J. M., Hwang, B.-H., & Chen, H. (2017). Are founder CEOs more overconfident than professional CEOs? Evidence from S&P 1500 companies. *Strategic Management Journal*, 38(3), 751–769. https://doi.org/10.1002/smj.2519", "authors": ["Lee", "J. M.", "Hwang", "B.-H.", "Chen, H."], "year": 2017, "title": "Are founder CEOs more overconfident than professional CEOs? Evidence from S&P 1500 companies", "venue": "Strategic Management Journal", "doi_or_url": "https://doi.org/10.1002/smj.2519", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Using language- and option-based proxies, founder CEOs of S&P 1500 firms display measurably more optimistic/overconfident behaviour than professional CEOs.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Using language- and option-based proxies, founder CEOs of S&P 1500 firms display measurably more optimistic/overconfident behaviour than professional CEOs.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.lee2020", "author_year_key": "lee2020", "citation": "Lee, J. M., Kim, J., & Bae, J. (2020). Founder CEOs and innovation: Evidence from CEO sudden deaths in public firms. *Research Policy*, 49(1), 103862. https://doi.org/10.1016/j.respol.2019.103862", "authors": ["Lee", "J. M.", "Kim", "J.", "Bae, J."], "year": 2020, "title": "Founder CEOs and innovation: Evidence from CEO sudden deaths in public firms", "venue": "Research Policy", "doi_or_url": "https://doi.org/10.1016/j.respol.2019.103862", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Quasi-experimental evidence from sudden CEO deaths suggests founder CEOs sustain more exploratory, higher-variance patenting than the professional CEOs who replace them, at similar R&D spend.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Quasi-experimental evidence from sudden CEO deaths suggests founder CEOs sustain more exploratory, higher-variance patenting than the professional CEOs who replace them, at similar R&D spend.", "design": "quasi_experimental", "causal_language_permitted": true, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.li2010", "author_year_key": "li2010", "citation": "Li, J., & Tang, Y. (2010). CEO hubris and firm risk taking in China: The moderating role of managerial discretion. *Academy of Management Journal*, 53(1), 45–68. https://doi.org/10.5465/amj.2010.48036912", "authors": ["Li", "J.", "Tang, Y."], "year": 2010, "title": "CEO hubris and firm risk taking in China: The moderating role of managerial discretion", "venue": "Academy of Management Journal", "doi_or_url": "https://doi.org/10.5465/amj.2010.48036912", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a survey of 2,790 Chinese manufacturing CEOs, hubristic CEOs took more risk—and markedly more so when they had greater discretion (e.g., when they also chaired the board or faced less organizational inertia).", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a survey of 2,790 Chinese manufacturing CEOs, hubristic CEOs took more risk—and markedly more so when they had greater discretion (e.g., when they also chaired the board or faced less organizational inertia).", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.malhotra2018", "author_year_key": "malhotra2018", "citation": "Malhotra, S., Reus, T. H., Zhu, P., & Roelofsen, E. M. (2018). The acquisitive nature of extraverted CEOs. *Administrative Science Quarterly*, 63(2), 370–408. https://doi.org/10.1177/0001839217712240", "authors": ["Malhotra", "S.", "Reus", "T. H.", "Zhu", "P.", "Roelofsen, E. M."], "year": 2018, "title": "The acquisitive nature of extraverted CEOs", "venue": "Administrative Science Quarterly", "doi_or_url": "https://doi.org/10.1177/0001839217712240", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "More extraverted CEOs (measured from their unscripted speech) pursue more and larger acquisitions, especially where they have more discretion.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "More extraverted CEOs (measured from their unscripted speech) pursue more and larger acquisitions, especially where they have more discretion.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.malmendier2005", "author_year_key": "malmendier2005", "citation": "Malmendier, U., & Tate, G. (2005). CEO overconfidence and corporate investment. *Journal of Finance*, 60(6), 2661–2700. https://doi.org/10.1111/j.1540-6261.2005.00813.x (NBER WP 10807)", "authors": ["Malmendier", "U.", "Tate, G."], "year": 2005, "title": "CEO overconfidence and corporate investment", "venue": "Journal of Finance", "doi_or_url": "https://doi.org/10.1111/j.1540-6261.2005.00813.x", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "CEOs who under-diversify their personal holdings (a proxy for overconfidence) run firms whose investment tracks internal cash flow more closely — a pattern consistent with over-optimism about their own projects.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "CEOs who under-diversify their personal holdings (a proxy for overconfidence) run firms whose investment tracks internal cash flow more closely — a pattern consistent with over-optimism about their own projects.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.malmendier2008", "author_year_key": "malmendier2008", "citation": "Malmendier, U., & Tate, G. (2008). Who makes acquisitions? CEO overconfidence and the market's reaction. *Journal of Financial Economics*, 89(1), 20–43. https://doi.org/10.1016/j.jfineco.2007.07.002 (NBER WP 10813)", "authors": ["Malmendier", "U.", "Tate, G."], "year": 2008, "title": "Who makes acquisitions? CEO overconfidence and the market's reaction", "venue": "Journal of Financial Economics", "doi_or_url": "https://doi.org/10.1016/j.jfineco.2007.07.002", "tier": 2, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Overconfident CEOs (by option-holding and press proxies) were roughly two-thirds more likely to acquire, and investors reacted more negatively to their deals.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Overconfident CEOs (by option-holding and press proxies) were roughly two-thirds more likely to acquire, and investors reacted more negatively to their deals.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m04"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.malmendier2009", "author_year_key": "malmendier2009", "citation": "Malmendier, U., & Tate, G. (2009). Superstar CEOs. *Quarterly Journal of Economics*, 124(4), 1593–1638. https://doi.org/10.1162/qjec.2009.124.4.1593", "authors": ["Malmendier", "U.", "Tate, G."], "year": 2009, "title": "Superstar CEOs", "venue": "Quarterly Journal of Economics", "doi_or_url": "https://doi.org/10.1162/qjec.2009.124.4.1593", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "CEOs who attain \"superstar\" status via media awards tend to underperform afterwards, earn more, and divert effort outside the firm, especially where governance is weak.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "CEOs who attain \"superstar\" status via media awards tend to underperform afterwards, earn more, and divert effort outside the firm, especially where governance is weak.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m11", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.malmendier2011", "author_year_key": "malmendier2011", "citation": "Malmendier, U., Tate, G., & Yan, J. (2011). Overconfidence and early-life experiences: The effect of managerial traits on corporate financial policies. *Journal of Finance*, 66(5), 1687–1733. https://doi.org/10.1111/j.1540-6261.2011.01685.x", "authors": ["Malmendier", "U.", "Tate", "G.", "Yan, J."], "year": 2011, "title": "Overconfidence and early-life experiences: The effect of managerial traits on corporate financial policies", "venue": "Journal of Finance", "doi_or_url": "https://doi.org/10.1111/j.1540-6261.2011.01685.x", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Both measurable overconfidence and formative early-life experiences (Depression, military service) predict systematic differences in CEOs' financing choices.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Both measurable overconfidence and formative early-life experiences (Depression, military service) predict systematic differences in CEOs' financing choices.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.maynard2018", "author_year_key": "maynard2018", "citation": "Maynard, S. B., Onibere, M., & Ahmad, A. (2018). Defining the strategic role of the Chief Information Security Officer. *Pacific Asia Journal of the Association for Information Systems*, 10(3), Article 3 (pp. 61–86). https://doi.org/10.17705/1pais.10303 (https://aisel.aisnet.org/pajais/vol10/iss3/3/) Tier 1 (AIS journal, peer-reviewed).", "authors": ["Maynard", "S. B.", "Onibere", "M.", "Ahmad, A."], "year": 2018, "title": "Defining the strategic role of the Chief Information Security Officer", "venue": "Pacific Asia Journal of the Association for Information Systems", "doi_or_url": "https://doi.org/10.17705/1pais.10303", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "A systematic review concluded that the CISO's strategic role is under-theorized and proposed a competency set for the CISO-as-strategist — a framework-level contribution, not an outcome finding.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "A systematic review concluded that the CISO's strategic role is under-theorized and proposed a competency set for the CISO-as-strategist — a framework-level contribution, not an outcome finding.", "design": "review", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m02", "m07"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.miller1991", "author_year_key": "miller1991", "citation": "Miller, D. (1991). Stale in the saddle: CEO tenure and the match between organization and environment. *Management Science*, 37(1), 34–52. https://doi.org/10.1287/mnsc.37.1.34", "authors": ["Miller, D."], "year": 1991, "title": "Stale in the saddle: CEO tenure and the match between organization and environment", "venue": "Management Science", "doi_or_url": "https://doi.org/10.1287/mnsc.37.1.34", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Theory (Hambrick & Fukutomi, 1991) and early evidence (Miller, 1991) suggest that long CEO tenures carry a risk of \"staleness\"—growing commitment to an established paradigm and declining fit with a changing environment—though the seasons model itself is conceptual and tenure effects vary by context.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Theory (Hambrick & Fukutomi, 1991) and early evidence (Miller, 1991) suggest that long CEO tenures carry a risk of \"staleness\"—growing commitment to an established paradigm and declining fit with a changing environment—though the seasons model itself is conceptual and tenure effects vary by context.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.milliken2003", "author_year_key": "milliken2003", "citation": "Milliken, F. J., Morrison, E. W., & Hewlin, P. F. (2003). An exploratory study of employee silence: Issues that employees don't communicate upward and why. *Journal of Management Studies*, 40(6), 1453–1476. https://doi.org/10.1111/1467-6486.00387", "authors": ["Milliken", "F. J.", "Morrison", "E. W.", "Hewlin, P. F."], "year": 2003, "title": "An exploratory study of employee silence: Issues that employees don't communicate upward and why", "venue": "Journal of Management Studies", "doi_or_url": "https://doi.org/10.1111/1467-6486.00387", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Research on employee silence shows that most employees can recall withholding an important concern from a superior, mainly from fear of being labeled negatively or of futility (Milliken et al., 2003), and that widely held, largely unconscious \"rules\" about when speaking up is unsafe suppress upward candor even in objectively safe settings (Detert & Edmondson, 2011)—implying that CEOs should assume critical information is being filtered before it reaches them.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Research on employee silence shows that most employees can recall withholding an important concern from a superior, mainly from fear of being labeled negatively or of futility (Milliken et al., 2003), and that widely held, largely unconscious \"rules\" about when speaking up is unsafe suppress upward candor even in objectively safe settings (Detert & Edmondson, 2011)—implying that CEOs should assume critical information is being filtered before it reaches them.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m05", "m08", "m10", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.nacd2023", "author_year_key": "nacd2023", "citation": "National Association of Corporate Directors & Internet Security Alliance. (2023, March 22). *2023 Director's Handbook on Cyber-Risk Oversight* (fourth edition; forewords by CISA Director Jen Easterly and the FBI). https://isalliance.org/wp-content/uploads/2023/03/Cyber-Risk-Oversight-Handbook_WEB.pdf (press release: https://www.nacdonline.org/about/newsroom/press-release/press-release/nacd-and-isa-launch-2023-cyber-risk-oversight-handbook-featuring-cisa-and-fbi/). A fifth edition was published in 2026: https://www.nacdonline.org/globalassets/public-pdfs/2026_directors-handbook-cyber-risk_print.pdf Tier 3 — **practitioner guidance, not peer-reviewed.**", "authors": ["National Association of Corporate Directors", "Internet Security Alliance."], "year": 2023, "title": "*2023 Director's Handbook on Cyber-Risk Oversight* (fourth edition; forewords by CISA Director Jen Easterly and the FBI)", "venue": "2023 Director's Handbook on Cyber-Risk Oversight", "doi_or_url": "https://isalliance.org/wp-content/uploads/2023/03/Cyber-Risk-Oversight-Handbook_WEB.pdf", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "The NACD/ISA handbook is the de facto US reference for board cyber-risk oversight and frames cyber as an enterprise-risk and governance matter rather than an IT matter — cite for what boards are advised to do, not for evidence that it works.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "The NACD/ISA handbook is the de facto US reference for board cyber-risk oversight and frames cyber as an enterprise-risk and governance matter rather than an IT matter — cite for what boards are advised to do, not for evidence that it works.", "design": "descriptive_practitioner", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m10"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.nadkarni2010", "author_year_key": "nadkarni2010", "citation": "Nadkarni, S., & Herrmann, P. (2010). CEO personality, strategic flexibility, and firm performance: The case of the Indian business process outsourcing industry. *Academy of Management Journal*, 53(5), 1050–1073. https://doi.org/10.5465/amj.2010.54533196", "authors": ["Nadkarni", "S.", "Herrmann, P."], "year": 2010, "title": "CEO personality, strategic flexibility, and firm performance: The case of the Indian business process outsourcing industry", "venue": "Academy of Management Journal", "doi_or_url": "https://doi.org/10.5465/amj.2010.54533196", "tier": 1, "verification_status": "PARTIALLY_VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a sample of 195 Indian BPO firms, CEO personality predicted how strategically flexible the firm was, and flexibility in turn explained the link between CEO personality and performance.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a sample of 195 Indian BPO firms, CEO personality predicted how strategically flexible the firm was, and flexibility in turn explained the link between CEO personality and performance.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.nist2024", "author_year_key": "nist2024", "citation": "National Institute of Standards and Technology. (2024, February 26). *The NIST Cybersecurity Framework (CSF) 2.0* (NIST CSWP 29; authors Pascoe, Quinn & Scarfone). https://doi.org/10.6028/NIST.CSWP.29 (https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf) FACT source.", "authors": ["National Institute of Standards", "Technology."], "year": 2024, "title": "*The NIST Cybersecurity Framework (CSF) 2.0* (NIST CSWP 29; authors Pascoe, Quinn & Scarfone)", "venue": "The NIST Cybersecurity Framework (CSF) 2.0", "doi_or_url": "https://doi.org/10.6028/NIST.CSWP.29", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Since February 2024 the NIST CSF has treated governance — including executive and board accountability for cyber risk — as a function co-equal with technical functions (FACT).", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Since February 2024 the NIST CSF has treated governance — including executive and board accountability for cyber risk — as a function co-equal with technical functions (FACT).", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m02", "m09"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.ou2014", "author_year_key": "ou2014", "citation": "Ou, A. Y., Tsui, A. S., Kinicki, A. J., Waldman, D. A., Xiao, Z., & Song, L. J. (2014). Humble chief executive officers' connections to top management team integration and middle managers' responses. *Administrative Science Quarterly*, 59(1), 34–72. https://doi.org/10.1177/0001839213520131", "authors": ["Ou", "A. Y.", "Tsui", "A. S.", "Kinicki", "A. J.", "Waldman", "D. A.", "Xiao", "Z.", "Song, L. J."], "year": 2014, "title": "Humble chief executive officers' connections to top management team integration and middle managers' responses", "venue": "Administrative Science Quarterly", "doi_or_url": "https://doi.org/10.1177/0001839213520131", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In 63 Chinese private firms, CEO humility was linked through empowering leadership and top-team integration to an empowering climate and stronger engagement, commitment, and performance among middle managers.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In 63 Chinese private firms, CEO humility was linked through empowering leadership and top-team integration to an empowering climate and stronger engagement, commitment, and performance among middle managers.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m05"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.ou2018", "author_year_key": "ou2018", "citation": "Ou, A. Y., Waldman, D. A., & Peterson, S. J. (2018). Do humble CEOs matter? An examination of CEO humility and firm outcomes. *Journal of Management*, 44(3), 1147–1173. https://doi.org/10.1177/0149206315604187 (first published online Sept 2015)", "authors": ["Ou", "A. Y.", "Waldman", "D. A.", "Peterson, S. J."], "year": 2018, "title": "Do humble CEOs matter? An examination of CEO humility and firm outcomes", "venue": "Journal of Management", "doi_or_url": "https://doi.org/10.1177/0149206315604187", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In a study of 105 U.S. tech SMEs, CEOs rated as more humble by their top teams had more integrated top teams and smaller CEO–team pay gaps, which were in turn linked to more ambidextrous strategy and better performance.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In a study of 105 U.S. tech SMEs, CEOs rated as more humble by their top teams had more integrated top teams and smaller CEO–team pay gaps, which were in turn linked to more ambidextrous strategy and better performance.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m05"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.owens2012", "author_year_key": "owens2012", "citation": "Owens, B. P., & Hekman, D. R. (2012). Modeling how to grow: An inductive examination of humble leader behaviors, contingencies, and outcomes. *Academy of Management Journal*, 55(4), 787–818. https://doi.org/10.5465/amj.2010.0441", "authors": ["Owens", "B. P.", "Hekman, D. R."], "year": 2012, "title": "Modeling how to grow: An inductive examination of humble leader behaviors, contingencies, and outcomes", "venue": "Academy of Management Journal", "doi_or_url": "https://doi.org/10.5465/amj.2010.0441", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Owens and Hekman identify three observable humble-leader behaviors—admitting mistakes and limits, spotlighting others' strengths, and modeling teachability—and their later experimental and field work shows leader humility can spread to teams and improve team performance, with the caveat that humility appears less effective under extreme threat or time pressure.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Owens and Hekman identify three observable humble-leader behaviors—admitting mistakes and limits, spotlighting others' strengths, and modeling teachability—and their later experimental and field work shows leader humility can spread to teams and improve team performance, with the caveat that humility appears less effective under extreme threat or time pressure.", "design": "qualitative", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m04", "m05", "m06", "m07", "m08", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.owens2016", "author_year_key": "owens2016", "citation": "Owens, B. P., & Hekman, D. R. (2016). How does leader humility influence team performance? Exploring the mechanisms of contagion and collective promotion focus. *Academy of Management Journal*, 59(3), 1088–1111. https://doi.org/10.5465/amj.2013.0660", "authors": ["Owens", "B. P.", "Hekman, D. R."], "year": 2016, "title": "How does leader humility influence team performance? Exploring the mechanisms of contagion and collective promotion focus", "venue": "Academy of Management Journal", "doi_or_url": "https://doi.org/10.5465/amj.2013.0660", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Owens and Hekman identify three observable humble-leader behaviors—admitting mistakes and limits, spotlighting others' strengths, and modeling teachability—and their later experimental and field work shows leader humility can spread to teams and improve team performance, with the caveat that humility appears less effective under extreme threat or time pressure.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Owens and Hekman identify three observable humble-leader behaviors—admitting mistakes and limits, spotlighting others' strengths, and modeling teachability—and their later experimental and field work shows leader humility can spread to teams and improve team performance, with the caveat that humility appears less effective under extreme threat or time pressure.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m05"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.peppard2010", "author_year_key": "peppard2010", "citation": "Peppard, J. (2010). Unlocking the performance of the chief information officer (CIO). *California Management Review*, 52(4), 73–99. https://store.hbr.org/product/unlocking-the-performance-of-the-chief-information-officer-cio/CMR465 Tier 1/3 boundary (CMR is a refereed practitioner-oriented journal); interview-based.", "authors": ["Peppard, J."], "year": 2010, "title": "Unlocking the performance of the chief information officer (CIO)", "venue": "California Management Review", "doi_or_url": "https://store.hbr.org/product/unlocking-the-performance-of-the-chief-information-officer-cio/CMR465", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Interview-based research argues that a CIO's effectiveness is bounded by the IT literacy and expectations of the CEO and top team — a contextual, not individual, account of CIO performance.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Interview-based research argues that a CIO's effectiveness is bounded by the IT literacy and expectations of the CEO and top team — a contextual, not individual, account of CIO performance.", "design": "qualitative", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m02", "m07", "m08", "m10"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.perezgonzalez2006", "author_year_key": "perezgonzalez2006", "citation": "Pérez-González, F. (2006). Inherited control and firm performance. *American Economic Review*, 96(5), 1559–1588. https://doi.org/10.1257/aer.96.5.1559", "authors": ["Pérez-González, F."], "year": 2006, "title": "Inherited control and firm performance", "venue": "American Economic Review", "doi_or_url": "https://doi.org/10.1257/aer.96.5.1559", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In U.S. family-controlled public firms, handing the CEO role to a family heir, especially one without an elite education, is associated with sizeable declines in profitability and valuation.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In U.S. family-controlled public firms, handing the CEO role to a family heir, especially one without an elite education, is associated with sizeable declines in profitability and valuation.", "design": "review", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.peterson2003", "author_year_key": "peterson2003", "citation": "Peterson, R. S., Smith, D. B., Martorana, P. V., & Owens, P. D. (2003). The impact of chief executive officer personality on top management team dynamics: One mechanism by which leadership affects organizational performance. *Journal of Applied Psychology*, 88(5), 795–808. https://doi.org/10.1037/0021-9010.88.5.795", "authors": ["Peterson", "R. S.", "Smith", "D. B.", "Martorana", "P. V.", "Owens, P. D."], "year": 2003, "title": "The impact of chief executive officer personality on top management team dynamics: One mechanism by which leadership affects organizational performance", "venue": "Journal of Applied Psychology", "doi_or_url": "https://doi.org/10.1037/0021-9010.88.5.795", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "An early 17-CEO historiometric study suggested CEO personality shapes top-team dynamics, but a published methodological critique showed the estimates are too unstable to rely on individually.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "An early 17-CEO historiometric study suggested CEO personality shapes top-team dynamics, but a published methodological critique showed the estimates are too unstable to rely on individually.", "design": "cross_sectional", "causal_language_permitted": false, "contested": true, "contested_by": ["res.hollenbeck2006"], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.porter2018", "author_year_key": "porter2018", "citation": "Porter, M. E., & Nohria, N. (2018, July–August). How CEOs manage time. *Harvard Business Review*, 96(4), 42–51. https://hbr.org/2018/07/how-ceos-manage-time", "authors": ["Porter", "M. E.", "Nohria, N."], "year": 2018, "title": "How CEOs manage time", "venue": "Harvard Business Review", "doi_or_url": "https://hbr.org/2018/07/how-ceos-manage-time", "tier": 3, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Porter and Nohria's HBR time study of 27 large-company CEOs (a descriptive, non-peer-reviewed study) found they worked ~9.7 hours per weekday, spent roughly 72% of work time in meetings, and spent only about 3% of their time with customers.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Porter and Nohria's HBR time study of 27 large-company CEOs (a descriptive, non-peer-reviewed study) found they worked ~9.7 hours per weekday, spent roughly 72% of work time in meetings, and spent only about 3% of their time with customers.", "design": "descriptive_practitioner", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.preston2008", "author_year_key": "preston2008", "citation": "Preston, D. S., Chen, D., & Leidner, D. E. (2008). Examining the antecedents and consequences of CIO strategic decision-making authority: An empirical study. *Decision Sciences*, 39(4), 605–642. https://doi.org/10.1111/j.1540-5915.2008.00206.x Tier 1.", "authors": ["Preston", "D. S.", "Chen", "D.", "Leidner, D. E."], "year": 2008, "title": "Examining the antecedents and consequences of CIO strategic decision-making authority: An empirical study", "venue": "Decision Sciences", "doi_or_url": "https://doi.org/10.1111/j.1540-5915.2008.00206.x", "tier": 1, "verification_status": "PARTIALLY_VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "CIO effectiveness depends on the match between the authority the organization grants and the capability the CIO brings; authority without capability (\"IT Mechanic\") and capability without authority (\"IT Advisor\") are both described as under-performing profiles (cite the MISQE companion for the profiles; cite the Decision Sciences paper only for the general proposition).", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "CIO effectiveness depends on the match between the authority the organization grants and the capability the CIO brings; authority without capability (\"IT Mechanic\") and capability without authority (\"IT Advisor\") are both described as under-performing profiles (cite the MISQE companion for the profiles; cite the Decision Sciences paper only for the general proposition).", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m02", "m07", "m10"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.preston2009", "author_year_key": "preston2009", "citation": "Preston, D. S., & Karahanna, E. (2009). Antecedents of IS strategic alignment: A nomological network. *Information Systems Research*, 20(2), 159–179. https://doi.org/10.1287/isre.1070.0159 Tier 1.", "authors": ["Preston", "D. S.", "Karahanna, E."], "year": 2009, "title": "Antecedents of IS strategic alignment: A nomological network", "venue": "Information Systems Research", "doi_or_url": "https://doi.org/10.1287/isre.1070.0159", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In 243 matched CIO–executive pairs, formal mechanisms and shared knowledge — not informal socializing — were associated with the shared understanding that underpins IT–business alignment.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In 243 matched CIO–executive pairs, formal mechanisms and shared knowledge — not informal socializing — were associated with the shared understanding that underpins IT–business alignment.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m02", "m10"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.quigley2015", "author_year_key": "quigley2015", "citation": "Quigley, T. J., & Hambrick, D. C. (2015). Has the \"CEO effect\" increased in recent decades? A new explanation for the great rise in America's attention to corporate leaders. Strategic Management Journal, 36(6), 821–830. https://doi.org/10.1002/smj.2258", "authors": ["Quigley", "T. J.", "Hambrick, D. C."], "year": 2015, "title": "Has the \"CEO effect\" increased in recent decades? A new explanation for the great rise in America's attention to corporate leaders", "venue": "", "doi_or_url": "https://doi.org/10.1002/smj.2258", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Variance-decomposition evidence that the share of performance variance associated with CEO identity rose across 1950–2009 — contested by Fitza.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Variance-decomposition evidence that the share of performance variance associated with CEO identity rose across 1950–2009 — contested by Fitza.", "design": "cross_sectional", "causal_language_permitted": false, "contested": true, "contested_by": ["res.fitza2014", "res.fitza2017"], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.quigley2017", "author_year_key": "quigley2017", "citation": "Quigley, T. J., & Graffin, S. D. (2017). Reaffirming the CEO effect is significant and much larger than chance: A comment on Fitza (2014). Strategic Management Journal, 38(3), 793–801. https://doi.org/10.1002/smj.2503", "authors": ["Quigley", "T. J.", "Graffin, S. D."], "year": 2017, "title": "Reaffirming the CEO effect is significant and much larger than chance: A comment on Fitza (2014)", "venue": "", "doi_or_url": "https://doi.org/10.1002/smj.2503", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Reply arguing the CEO effect is significant and larger than chance under multilevel modeling.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Reply arguing the CEO effect is significant and larger than chance under multilevel modeling.", "design": "cross_sectional", "causal_language_permitted": false, "contested": true, "contested_by": ["res.fitza2017"], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.sec2023", "author_year_key": "sec2023", "citation": "US Securities and Exchange Commission. (2023, July 26). *Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure* (Final rule; Release Nos. 33-11216; 34-97989). https://www.sec.gov/files/rules/final/2023/33-11216.pdf (press release 2023-139: https://www.sec.gov/newsroom/press-releases/2023-139) FACT source.", "authors": ["US Securities", "Exchange Commission."], "year": 2023, "title": "*Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure* (Final rule; Release Nos", "venue": "Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure", "doi_or_url": "https://www.sec.gov/files/rules/final/2023/33-11216.pdf", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Since December 2023, US public companies must disclose material cyber incidents within four business days of a materiality determination and describe board oversight and management's cyber expertise annually (FACT).", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Since December 2023, US public companies must disclose material cyber incidents within four business days of a materiality determination and describe board oversight and management's cyber expertise annually (FACT).", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m04", "m07", "m09", "m10", "m12"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.shen2002", "author_year_key": "shen2002", "citation": "Shen, W., & Cannella, A. A., Jr. (2002). Revisiting the performance consequences of CEO succession: The impacts of successor type, postsuccession senior executive turnover, and departing CEO tenure. *Academy of Management Journal*, 45(4), 717–733. https://doi.org/10.2307/3069306", "authors": ["Shen", "W.", "Cannella", "A. A., Jr."], "year": 2002, "title": "Revisiting the performance consequences of CEO succession: The impacts of successor type, postsuccession senior executive turnover, and departing CEO tenure", "venue": "Academy of Management Journal", "doi_or_url": "https://doi.org/10.2307/3069306", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Peer-reviewed succession research finds no universal insider-or-outsider advantage: outsiders do better mainly when integration is easier and context is favorable (Georgakakis & Ruigrok, 2017), and the consequences of any successor type depend on what happens to the rest of the senior team afterward (Shen & Cannella, 2002).", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Peer-reviewed succession research finds no universal insider-or-outsider advantage: outsiders do better mainly when integration is easier and context is favorable (Georgakakis & Ruigrok, 2017), and the consequences of any successor type depend on what happens to the rest of the senior team afterward (Shen & Cannella, 2002).", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.tourish2006", "author_year_key": "tourish2006", "citation": "Tourish, D., & Robson, P. (2006). Sensemaking and the distortion of critical upward communication in organizations. *Journal of Management Studies*, 43(4), 711–730. https://doi.org/10.1111/j.1467-6486.2006.00608.x", "authors": ["Tourish", "D.", "Robson, P."], "year": 2006, "title": "Sensemaking and the distortion of critical upward communication in organizations", "venue": "Journal of Management Studies", "doi_or_url": "https://doi.org/10.1111/j.1467-6486.2006.00608.x", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Research on employee silence shows that most employees can recall withholding an important concern from a superior, mainly from fear of being labeled negatively or of futility (Milliken et al., 2003), and that widely held, largely unconscious \"rules\" about when speaking up is unsafe suppress upward candor even in objectively safe settings (Detert & Edmondson, 2011)—implying that CEOs should assume critical information is being filtered before it reaches them.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Research on employee silence shows that most employees can recall withholding an important concern from a superior, mainly from fear of being labeled negatively or of futility (Milliken et al., 2003), and that widely held, largely unconscious \"rules\" about when speaking up is unsafe suppress upward candor even in objectively safe settings (Detert & Edmondson, 2011)—implying that CEOs should assume critical information is being filtered before it reaches them.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m05"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.verizon2025", "author_year_key": "verizon2025", "citation": "Verizon Business. (2025, April 23). *2025 Data Breach Investigations Report* (18th edition). Full report: https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf; executive summary: https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf; announcement: https://www.verizon.com/about/news/2025-data-breach-investigations-report Tier 3 — **practitioner report, not peer-reviewed.**", "authors": ["Verizon Business."], "year": 2025, "title": "*2025 Data Breach Investigations Report* (18th edition)", "venue": "2025 Data Breach Investigations Report", "doi_or_url": "https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf;", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In the 2025 DBIR's sample of 12,195 breaches, third parties were involved in 30%, ransomware in 44%, and the human element in about 60% — descriptive base rates from a non-random contributor sample.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In the 2025 DBIR's sample of 12,195 breaches, third parties were involved in 30%, ransomware in 44%, and the human element in about 60% — descriptive base rates from a non-random contributor sample.", "design": "descriptive_practitioner", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m01", "m03", "m06", "m08", "m09"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.wangrow2015", "author_year_key": "wangrow2015", "citation": "Wangrow, D. B., Schepker, D. J., & Barker, V. L., III. (2015). Managerial discretion: An empirical review and focus on future research directions. *Journal of Management*, 41(1), 99–135. https://doi.org/10.1177/0149206314554214", "authors": ["Wangrow", "D. B.", "Schepker", "D. J.", "Barker", "V. L., III."], "year": 2015, "title": "Managerial discretion: An empirical review and focus on future research directions", "venue": "Journal of Management", "doi_or_url": "https://doi.org/10.1177/0149206314554214", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "The concept of managerial discretion (Hambrick & Finkelstein, 1987) holds that how much a CEO matters depends on the latitude the environment, the organization, and the executive's own makeup allow—and a 2015 review confirms empirical support is strongest for the environmental sources and weakest for the individual-level ones.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "The concept of managerial discretion (Hambrick & Finkelstein, 1987) holds that how much a CEO matters depends on the latitude the environment, the organization, and the executive's own makeup allow—and a 2015 review confirms empirical support is strongest for the environmental sources and weakest for the individual-level ones.", "design": "review", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m10"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.wasserman2003", "author_year_key": "wasserman2003", "citation": "Wasserman, N. (2003). Founder-CEO succession and the paradox of entrepreneurial success. *Organization Science*, 14(2), 149–172. https://doi.org/10.1287/orsc.14.2.149.14995", "authors": ["Wasserman, N."], "year": 2003, "title": "Founder-CEO succession and the paradox of entrepreneurial success", "venue": "Organization Science", "doi_or_url": "https://doi.org/10.1287/orsc.14.2.149.14995", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In venture-backed start-ups, reaching key milestones (product completion, new funding rounds) is strongly associated with founders being replaced as CEO.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In venture-backed start-ups, reaching key milestones (product completion, new funding rounds) is strongly associated with founders being replaced as CEO.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.wasserman2008", "author_year_key": "wasserman2008", "citation": "Wasserman, N. (2008). The founder's dilemma. *Harvard Business Review*, 86(2), 102–109. https://hbr.org/2008/02/the-founders-dilemma (PubMed 18314638)", "authors": ["Wasserman, N."], "year": 2008, "title": "The founder's dilemma", "venue": "Harvard Business Review", "doi_or_url": "https://hbr.org/2008/02/the-founders-dilemma", "tier": 3, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Wasserman's start-up data suggest a tension between founder control and firm value, with most founders ceding the CEO role before an exit.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Wasserman's start-up data suggest a tension between founder control and firm value, with most founders ceding the CEO role before an exit.", "design": "descriptive_practitioner", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.weill2004", "author_year_key": "weill2004", "citation": "Weill, P., & Ross, J. W. (2004). *IT Governance: How Top Performers Manage IT Decision Rights for Superior Results*. Boston: Harvard Business School Press. ISBN 9781591392538. https://books.google.com/books/about/IT_Governance.html?id=0Gfraz7FyrYC Tier 3 (research-based practitioner book from MIT CISR; **not peer-reviewed**).", "authors": ["Weill", "P.", "Ross, J. W."], "year": 2004, "title": "*IT Governance: How Top Performers Manage IT Decision Rights for Superior Results*", "venue": "IT Governance: How Top Performers Manage IT Decision Rights for Superior Results", "doi_or_url": "https://books.google.com/books/about/IT_Governance.html?id=0Gfraz7FyrYC", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "A large MIT CISR study associated well-designed IT decision rights with materially higher profitability (the authors report >25%) — a practitioner finding useful for framing governance as a design choice, not as proof that governance causes profit.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "A large MIT CISR study associated well-designed IT decision rights with materially higher profitability (the authors report >25%) — a practitioner finding useful for framing governance as a design choice, not as proof that governance causes profit.", "design": "descriptive_practitioner", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m02", "m03", "m08", "m10"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.zhang2010", "author_year_key": "zhang2010", "citation": "Zhang, Y., & Rajagopalan, N. (2010). Once an outsider, always an outsider? CEO origin, strategic change, and firm performance. *Strategic Management Journal*, 31(3), 334–346. https://doi.org/10.1002/smj.812", "authors": ["Zhang", "Y.", "Rajagopalan, N."], "year": 2010, "title": "Once an outsider, always an outsider? CEO origin, strategic change, and firm performance", "venue": "Strategic Management Journal", "doi_or_url": "https://doi.org/10.1002/smj.812", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "Among 193 U.S. CEOs, strategic change showed an inverted-U relationship with performance, and outsider CEOs experienced both larger gains from moderate change and larger losses from excessive change than insiders did.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "Among 193 U.S. CEOs, strategic change showed an inverted-U relationship with performance, and outsider CEOs experienced both larger gains from moderate change and larger losses from excessive change than insiders did.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": ["m06", "m09", "m11"], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}, {"id": "res.zhang2017", "author_year_key": "zhang2017", "citation": "Zhang, H., Ou, A. Y., Tsui, A. S., & Wang, H. (2017). CEO humility, narcissism and firm innovation: A paradox perspective on CEO traits. *The Leadership Quarterly*, 28(5), 585–604. https://doi.org/10.1016/j.leaqua.2017.01.003", "authors": ["Zhang", "H.", "Ou", "A. Y.", "Tsui", "A. S.", "Wang, H."], "year": 2017, "title": "CEO humility, narcissism and firm innovation: A paradox perspective on CEO traits", "venue": "The Leadership Quarterly", "doi_or_url": "https://doi.org/10.1016/j.leaqua.2017.01.003", "tier": 1, "verification_status": "VERIFIED", "verified_as_of": "2026-09-03", "key_findings": "In two studies of Chinese CEOs, firms led by CEOs who scored high on *both* humility and narcissism showed the strongest innovation outcomes, suggesting the traits can be complementary rather than opposed—though the evidence is correlational and from one country.", "method": "See bibliography.", "limitations": "See bibliography.", "usable_claim": "In two studies of Chinese CEOs, firms led by CEOs who scored high on *both* humility and narcissism showed the strongest innovation outcomes, suggesting the traits can be complementary rather than opposed—though the evidence is correlational and from one country.", "design": "cross_sectional", "causal_language_permitted": false, "contested": false, "contested_by": [], "skeptic_checklist_flags": [], "modules_using": [], "label": "RESEARCH_FINDING", "meta": {"source_path": "research/bibliography.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}}], "assessment_items": [{"id": "A01", "tendency": "A", "tendency_name": "agency", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "When something in the company is going wrong and it is not formally my responsibility, I usually end up dealing with it anyway."}, {"id": "A02", "tendency": "A", "tendency_name": "agency", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "I prefer to wait for the CEO, the board or the data to make a direction clear before I commit my organization to it."}, {"id": "A03", "tendency": "A", "tendency_name": "agency", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "a", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "If nobody owns a problem, I take it — I would rather be told to back off than watch it sit."}, {"key": "b", "text": "If nobody owns a problem, I find out who should and make sure they do — otherwise I become the bottleneck."}]}, {"id": "A04", "tendency": "A", "tendency_name": "agency", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are the fractional CISO for a 70-person accounting firm through your BPM/MSP company. The firm's network is managed by a separate IT vendor, not by you, and that vendor's VPN appliance has a vulnerability that appeared on the known-exploited list on Monday. The vendor's engineer says the patch is \"in the queue for next month's maintenance window.\" Your contract gives you advisory authority only.", "options": [{"key": "1", "text": "Send the firm's managing partner a written risk notice with the vendor's date and the exposure in plain terms, and offer to coordinate an earlier window if the partner wants one.", "tag": "neutral"}, {"key": "2", "text": "Get the vendor's engineer and the managing partner on one call today, ask for an emergency window this week, and put a compensating control in place yourself in the meantime — the contract can catch up.", "tag": "high"}, {"key": "3", "text": "Record it in the client's risk register with the vendor's date and raise it at the monthly review; patching is the vendor's scope and the client hired them for it.", "tag": "low"}, {"key": "4", "text": "Tell the managing partner that unless the vendor patches by Friday you will take the VPN offline yourself and assume patch management for the account, and start the paperwork to replace the vendor whatever they do.", "tag": "overuse"}]}, {"id": "B01", "tendency": "B", "tendency_name": "risk_tolerance", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "I am comfortable committing a meaningful share of the technology budget to a bet I believe in, even when I know the downside would hurt."}, {"id": "B02", "tendency": "B", "tendency_name": "risk_tolerance", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "Protecting the stability of what we already run matters more to me than capturing an opportunity that puts it at risk."}, {"id": "B03", "tendency": "B", "tendency_name": "risk_tolerance", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "b", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "I would rather move a little slower and never have a year that threatens the company."}, {"key": "b", "text": "I would rather take a real swing every few years and accept that one of them will go badly."}]}, {"id": "B04", "tendency": "B", "tendency_name": "risk_tolerance", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are CIO and CISO of a 600-person distributor. The ERP cutover is scheduled for the quarter-end weekend, after eighteen months of work. The pre-go-live penetration test has come back with one high finding — privilege escalation through an integration service account — that the integrator says will take three weeks to remediate. A slip costs about $400K in integrator fees and pushes the cutover into peak season.", "options": [{"key": "1", "text": "Hold the cutover until the high finding is closed. A three-week slip is cheaper than a compromised ERP in month one, and nobody remembers the delay.", "tag": "low"}, {"key": "2", "text": "Split it: take finance and order management live on schedule, and hold the affected integration on the legacy path until the finding is fixed.", "tag": "neutral"}, {"key": "3", "text": "Go live on schedule with the finding open, the service account locked down and monitored, remediation dated for week two, and the accepted risk written up and signed by the CEO.", "tag": "high"}, {"key": "4", "text": "Go live on schedule and, since the integrator team is on site anyway, pull the warehouse module forward from phase two into the same weekend; the organization is already braced for change.", "tag": "overuse"}]}, {"id": "C01", "tendency": "C", "tendency_name": "decision_speed", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "Once I have about 70% of the information I need, I decide; waiting for the rest usually costs more than it is worth."}, {"id": "C02", "tendency": "C", "tendency_name": "decision_speed", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "I have often been glad I slept on a decision that everyone around me wanted made that day."}, {"id": "C03", "tendency": "C", "tendency_name": "decision_speed", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "a", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "A decision made today and adjusted later usually beats a better decision made next month."}, {"key": "b", "text": "Most decisions that feel urgent can wait a week, and the week usually changes the decision."}]}, {"id": "C04", "tendency": "C", "tendency_name": "decision_speed", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are CISO of a 6,000-person listed manufacturer. At 2 a.m. the SOC reports encryption activity on about forty servers in one region, consistent with ransomware but not confirmed. Containing it means isolating the regional network and stopping order processing for a business unit that ships $2M a day. The SOC lead is asking for your authorization; the forensics vendor says it can confirm scope in about ninety minutes.", "options": [{"key": "1", "text": "Isolate the region now. You can reconnect in an hour if it turns out to be a false positive; you cannot un-encrypt.", "tag": "high"}, {"key": "2", "text": "Isolate the region now and, on the same call, order the forty servers rebuilt from backup so the business unit is up by morning — forensics can work from the images later.", "tag": "overuse"}, {"key": "3", "text": "Isolate the forty servers and their subnet immediately, keep the rest of the region running, and reassess with the SOC lead in thirty minutes.", "tag": "neutral"}, {"key": "4", "text": "Wait for the ninety-minute confirmation. Taking a business unit down on a pattern match is a decision you will have to explain in daylight, and the SOC has had false positives before.", "tag": "low"}]}, {"id": "D01", "tendency": "D", "tendency_name": "uncertainty_tolerance", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "I can run my organization for months with the strategy still unresolved without it wearing on me."}, {"id": "D02", "tendency": "D", "tendency_name": "uncertainty_tolerance", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "I find it genuinely hard to function well when I do not know what the plan is."}, {"id": "D03", "tendency": "D", "tendency_name": "uncertainty_tolerance", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "b", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "A clear plan that turns out to be 70% right beats an open question that stays open."}, {"key": "b", "text": "I would rather keep a question open than answer it before it can be answered."}]}, {"id": "D04", "tendency": "D", "tendency_name": "uncertainty_tolerance", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are the first security lead at a 900-person physician group. A new state health-privacy law with unclear reach over your telehealth platform takes effect in nine to twelve months; outside counsel says no guidance is expected before then and that two readings of the statute are defensible. Your engineering lead keeps asking what the requirements are so she can plan the platform roadmap.", "options": [{"key": "1", "text": "Tell engineering the truth: the requirements cannot be known yet, so build to the current HIPAA baseline, keep the design decisions that depend on the statute reversible, and revisit when the picture clears.", "tag": "high"}, {"key": "2", "text": "Take the more conservative reading, treat it as the requirement, build the roadmap around it, and tell the team you will revisit only if the state surprises you.", "tag": "low"}, {"key": "3", "text": "Build two roadmap variants with the decision points marked, and give counsel a standing brief to watch the state's rulemaking so the team can switch fast.", "tag": "neutral"}, {"key": "4", "text": "Defer the telehealth roadmap altogether until the state rules; anything built now is a guess and you would rather keep every option open.", "tag": "overuse"}]}, {"id": "E01", "tendency": "E", "tendency_name": "delegation", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "When I hand a decision to someone, I let their decision stand even when I would have made a different one."}, {"id": "E02", "tendency": "E", "tendency_name": "delegation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "On anything that really matters, I stay close enough to the work that I could step in and finish it myself."}, {"id": "E03", "tendency": "E", "tendency_name": "delegation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "b", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "I know the details of the important things in my company because I am in them."}, {"key": "b", "text": "I know the details of the important things in my company because the people who own them tell me."}]}, {"id": "E04", "tendency": "E", "tendency_name": "delegation", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You founded a 45-person BPM/MSP firm and were its only security engineer for the first five years. Six months ago you hired a security lead. She has redesigned the client onboarding baseline and dropped a control you have always insisted on — a weekly manual review of client firewall logs — in favor of automated alerting. Two new client engagements go live on her baseline next week, and she has not asked for your view.", "options": [{"key": "1", "text": "Take the baseline back for the two go-lives, reinstate the manual review yourself, and stop reviewing her posture reports for a couple of quarters so she has a clean run at everything else.", "tag": "overuse"}, {"key": "2", "text": "Tell her once, specifically, what the manual review has caught over the years that alerting missed, and then let her decide.", "tag": "neutral"}, {"key": "3", "text": "Say nothing; you hired her to own the baseline, and reversing her first big call would tell every client-facing engineer who really decides.", "tag": "high"}, {"key": "4", "text": "Reinstate the manual review for the two go-lives and sit in on baseline reviews until you have seen enough of her judgment on controls to trust it.", "tag": "low"}]}, {"id": "F01", "tendency": "F", "tendency_name": "systems_thinking", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "Before I fix a problem, I usually ask what in the way the company is set up keeps producing it."}, {"id": "F02", "tendency": "F", "tendency_name": "systems_thinking", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "Most problems in a business are best handled one at a time, by the people closest to them."}, {"id": "F03", "tendency": "F", "tendency_name": "systems_thinking", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "a", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "When the same issue comes back a third time, I redesign the process, the incentive or the structure that keeps producing it."}, {"key": "b", "text": "When the same issue comes back a third time, I find the person who can make it stop and get out of their way."}]}, {"id": "F04", "tendency": "F", "tendency_name": "systems_thinking", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are CIO of a 4,000-person insurer. For the third quarter in a row, the change-failure rate has spiked in the last two weeks of the quarter, and each time the platform team has named a specific cause — a vendor release, a staffing gap, a data-center outage.", "options": [{"key": "1", "text": "Give the platform team a hard change-failure target for the last two weeks of next quarter and let them work out how to hit it.", "tag": "low"}, {"key": "2", "text": "Look at what changes at quarter-end: release commitments tied to business-unit targets, the freeze calendar, who staffs the change board. The causes are real; the pattern is the company.", "tag": "high"}, {"key": "3", "text": "Commission a full redesign of the delivery and change process with an outside firm before the next quarter closes, and pause the current engineering-practice work until it is done.", "tag": "overuse"}, {"key": "4", "text": "Bring the platform team, the product owners and the change-board chair together to walk through the last three quarter-ends and ask them what they see.", "tag": "neutral"}]}, {"id": "G01", "tendency": "G", "tendency_name": "detail_orientation", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "I read the numbers and the logs at a level of detail that surprises the people who produce them."}, {"id": "G02", "tendency": "G", "tendency_name": "detail_orientation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "I keep myself out of the specifics of how work gets done; if I know them, I have not done my job."}, {"id": "G03", "tendency": "G", "tendency_name": "detail_orientation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "b", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "My job is to know what the vendor contract is for and who owns it."}, {"key": "b", "text": "My job includes having read the vendor contract."}]}, {"id": "G04", "tendency": "G", "tendency_name": "detail_orientation", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are CISO of a 3,000-person company. The draft quarterly risk report for the board, prepared by your GRC lead, shows phishing click rates down 40% and no critical vulnerability older than thirty days. The board will like it. It reads cleaner to you than the year has felt.", "options": [{"key": "1", "text": "Ask for the underlying data — the scanner export by asset class, the phishing simulation groups, the exceptions list — and go through it with the GRC lead line by line before it goes to the board.", "tag": "high"}, {"key": "2", "text": "Ask the GRC lead what the two or three things behind the numbers are and what he would change if they were wrong, and hold him to next quarter's report.", "tag": "low"}, {"key": "3", "text": "Ask for the metric definitions and the exceptions list, and go through the items you do not understand.", "tag": "neutral"}, {"key": "4", "text": "Pull the scanner and email-security data yourself over the weekend and rebuild the metrics before you meet him, so you can check his.", "tag": "overuse"}]}, {"id": "H01", "tendency": "H", "tendency_name": "strategic_abstraction", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "I spend a meaningful share of my thinking on where the technology and the threat landscape will be in five years, even when this year is demanding."}, {"id": "H02", "tendency": "H", "tendency_name": "strategic_abstraction", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "Most \"strategy\" is a way of avoiding the operating problem in front of you."}, {"id": "H03", "tendency": "H", "tendency_name": "strategic_abstraction", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "a", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "The most valuable hour of my month is the one I spend on where the company's technology should be in five years."}, {"key": "b", "text": "The most valuable hour of my month is the one I spend on the biggest operating problem we have right now."}]}, {"id": "H04", "tendency": "H", "tendency_name": "strategic_abstraction", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are CIO of an 800-person specialty manufacturer, halfway through an ERP migration. A competitor has announced an AI-driven quoting tool, and the CEO has asked for your view on \"what this means for us\" at next week's leadership meeting.", "options": [{"key": "1", "text": "Bring the CEO both: the competitive picture as you see it, and the near-term response you are already running.", "tag": "neutral"}, {"key": "2", "text": "Bring the CEO a five-year vision of the company as a data platform, and propose reorganizing the ERP program around it before the next board meeting.", "tag": "overuse"}, {"key": "3", "text": "Reframe the question: where in the company's workflow does judgment sit that could be automated, and what data position would you need to own to be paid for it. Bring the CEO a position, not a response.", "tag": "high"}, {"key": "4", "text": "Tell the CEO what you are doing about it operationally: a pilot of the ERP vendor's quoting add-on, a policy on staff use of public AI tools, and a review of the quoting team's data quality.", "tag": "low"}]}, {"id": "I01", "tendency": "I", "tendency_name": "conflict_tolerance", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "I would rather have the argument in the room than manage around it afterwards."}, {"id": "I02", "tendency": "I", "tendency_name": "conflict_tolerance", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "I put off conversations that I know will make someone I rely on unhappy."}, {"id": "I03", "tendency": "I", "tendency_name": "conflict_tolerance", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "b", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "A disagreement I can resolve quietly, one-to-one, is better than one I have to have in front of the team."}, {"key": "b", "text": "A disagreement the team can see me have is worth more than one I settle in private."}]}, {"id": "I04", "tendency": "I", "tendency_name": "conflict_tolerance", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are the vCISO for a 150-person SEC-registered investment adviser, which is also your MSP's largest client. The founding partner, who signs your contract, refuses multi-factor authentication on his own accounts and has told his operations manager to \"make it stop prompting.\" Two of the firm's staff have told you privately they think it is a problem but will not say so in front of him.", "options": [{"key": "1", "text": "Raise it with him directly, in private: tell him the exception is not acceptable, that you want his objections in full, and that if it stands you will put your position in writing to the firm's chief compliance officer.", "tag": "high"}, {"key": "2", "text": "Narrow the exception — trusted devices only, longer sessions, tighter monitoring on his accounts — and move on; he is the client and the control can flex.", "tag": "low"}, {"key": "3", "text": "Ask the operations manager and the chief compliance officer to bring it up at the firm's quarterly compliance review, and let the firm work it out.", "tag": "neutral"}, {"key": "4", "text": "Take it on at the firm's next leadership meeting, in front of his partners and staff, and make it clear that the firm has one security policy.", "tag": "overuse"}]}, {"id": "J01", "tendency": "J", "tendency_name": "adaptability", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "I have publicly reversed a decision I championed, and said so in those words."}, {"id": "J02", "tendency": "J", "tendency_name": "adaptability", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "Most strategies fail because people give up on them too early, so my instinct is to hold the course."}, {"id": "J03", "tendency": "J", "tendency_name": "adaptability", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "a", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "If the evidence turns against a plan I announced, I change the plan and tell people why."}, {"key": "b", "text": "If the evidence turns against a plan I announced, I look hard at the evidence before I look at the plan."}]}, {"id": "J04", "tendency": "J", "tendency_name": "adaptability", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "Eighteen months ago you moved a 2,500-person company's data center to a single cloud provider, signed a three-year committed-spend agreement and retired the colocation contract. Run-rate cost is 40% above the business case, two core workloads perform worse than they did on-premises, and the CFO has asked whether you would consider bringing them back.", "options": [{"key": "1", "text": "Hold the course. Eighteen months is not long for a platform shift, most of the overrun is optimization not yet done, and reversing now would teach the organization that architecture decisions are optional.", "tag": "low"}, {"key": "2", "text": "Give it two more quarters against explicit cost and performance milestones, and quietly price a small colocation footprint so the option is real if you need it.", "tag": "neutral"}, {"key": "3", "text": "Bring the two workloads back to a small colocation footprint on your terms, and say plainly that the all-cloud plan was too aggressive.", "tag": "high"}, {"key": "4", "text": "Pivot again: announce a multi-cloud strategy, move the two workloads to a second provider, and re-platform the remaining estate this year.", "tag": "overuse"}]}, {"id": "K01", "tendency": "K", "tendency_name": "intellectual_humility", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "When I am sure about something, I make a point of asking what would prove me wrong."}, {"id": "K02", "tendency": "K", "tendency_name": "intellectual_humility", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "By the time an issue reaches me, I usually understand it better than the people who bring it."}, {"id": "K03", "tendency": "K", "tendency_name": "intellectual_humility", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "b", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "My judgment is the reason I am in this job; I trust it over the room's."}, {"key": "b", "text": "The room usually knows something I do not; I trust it over my first read."}]}, {"id": "K04", "tendency": "K", "tendency_name": "intellectual_humility", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You built your MSP's security stack yourself over eight years and know it better than anyone. Your new security lead, hired from a much larger company, tells you that your standard client network segmentation is the reason incidents at client sites keep spreading beyond the first machine, and shows you an analysis that contradicts what you have told clients for years.", "options": [{"key": "1", "text": "Adopt her design across every client; she has looked at it with fresh eyes, and your own view is eight years old.", "tag": "overuse"}, {"key": "2", "text": "Take the analysis seriously: ask her to walk you through it, tell her which of your assumptions it would overturn, and pilot her design at one client.", "tag": "high"}, {"key": "3", "text": "Explain why SMB clients do not work that way — you have seen this before from enterprise people who do not understand a 40-person client's budget — and move on.", "tag": "low"}, {"key": "4", "text": "Ask your senior engineer and the IT manager at your longest-standing client to review her analysis and come back with a joint view.", "tag": "neutral"}]}, {"id": "L01", "tendency": "L", "tendency_name": "talent_orientation", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "I personally spend several hours a week on recruiting, developing or reviewing the people in the key roles in my organization."}, {"id": "L02", "tendency": "L", "tendency_name": "talent_orientation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "Filling senior roles is mostly a matter of running a good process and letting HR and the hiring manager do their jobs."}, {"id": "L03", "tendency": "L", "tendency_name": "talent_orientation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "a", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "The biggest lever I have is who is in the key technical and security roles, so I treat those as my decisions."}, {"key": "b", "text": "The biggest lever I have is how the organization runs, so I make the key roles someone else's decisions."}]}, {"id": "L04", "tendency": "L", "tendency_name": "talent_orientation", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are CIO of a 700-person PE-backed healthcare services company. Your infrastructure manager is loyal, well liked and nine years in. He is adequate; you are fairly sure a better operator exists, and the next two years — a cloud migration and the sponsor's exit — are the ones that matter.", "options": [{"key": "1", "text": "Give him a clear brief for the migration and an executive coach, and revisit in two quarters.", "tag": "neutral"}, {"key": "2", "text": "Start a confidential search now, and if you find someone clearly better, make the change and handle his exit generously.", "tag": "high"}, {"key": "3", "text": "Keep him. Adequate and trusted is worth a lot going into a migration, and a new manager would spend six months learning what he already knows.", "tag": "low"}, {"key": "4", "text": "Replace him and, while you are at it, benchmark every direct report against the market this quarter; an exit is not the time for tolerance.", "tag": "overuse"}]}, {"id": "M01", "tendency": "M", "tendency_name": "operational_discipline", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "Every important commitment in my organization has a number, an owner and a date, and I review them on a fixed rhythm."}, {"id": "M02", "tendency": "M", "tendency_name": "operational_discipline", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "I run my organization more on judgment and relationships than on dashboards and cadences."}, {"id": "M03", "tendency": "M", "tendency_name": "operational_discipline", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "b", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "I would rather have people who know what to do than a process that tells them."}, {"key": "b", "text": "I would rather have a process that works than depend on people always knowing what to do."}]}, {"id": "M04", "tendency": "M", "tendency_name": "operational_discipline", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You have just been hired as the first CIO of a 400-person company where technology was run for fifteen years by a manager who kept it in his head. There is no change calendar, no patch or backup metrics, no reliable asset inventory, and department heads are used to walking over to ask for things.", "options": [{"key": "1", "text": "Install a weekly operations review, a change calendar and a one-page sheet of patch, backup and ticket metrics in your first thirty days, and hold to it even when the old guard calls it bureaucratic.", "tag": "high"}, {"key": "2", "text": "Keep the incumbent's style for the first six months; it kept the company running, the department heads trust it, and you will learn the environment faster through the door than through a dashboard.", "tag": "low"}, {"key": "3", "text": "Bring in the full operating model from your last company — service catalogue, ticket taxonomy, KPIs at every level, monthly reviews for every function — in the first quarter.", "tag": "overuse"}, {"key": "4", "text": "Start with the three numbers that matter most and a single weekly meeting, and add structure as the department heads see its value.", "tag": "neutral"}]}, {"id": "N01", "tendency": "N", "tendency_name": "stakeholder_orientation", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "I invest in relationships with the CEO, the board, auditors or regulators well before I need anything from them."}, {"id": "N02", "tendency": "N", "tendency_name": "stakeholder_orientation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "If I run the technology well, the CEO, the board, the auditors and the other constituencies will look after themselves."}, {"id": "N03", "tendency": "N", "tendency_name": "stakeholder_orientation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "a", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "Part of this job is knowing what each constituency needs to hear, and when."}, {"key": "b", "text": "Part of this job is making sure the results speak so that I do not have to."}]}, {"id": "N04", "tendency": "N", "tendency_name": "stakeholder_orientation", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 2, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are CISO of a 2,000-person broker-dealer. A FINRA cybersecurity examination request letter arrived this week with a three-week deadline; the audit committee chair has asked you to spend more time with the committee; and your largest institutional client has sent a security questionnaire tied to its renewal. You have one open day this week.", "options": [{"key": "1", "text": "Spend it with your GRC and infrastructure leads assembling the FINRA evidence; the rest is noise until that is right.", "tag": "low"}, {"key": "2", "text": "Spend it with the audit committee chair, the general counsel and the CFO, one-on-one, so that the board is with you before either of the other two conversations becomes a fight.", "tag": "high"}, {"key": "3", "text": "Split it: a morning with the chair, an afternoon on the FINRA response, and a call with the client's security team next week.", "tag": "neutral"}, {"key": "4", "text": "Spend it on calls with the client's CISO, two other large clients' security teams and the FINRA examination coordinator, to shape how the firm is seen before any of it hardens.", "tag": "overuse"}]}, {"id": "O01", "tendency": "O", "tendency_name": "learning_orientation", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "After a decision that went well, I still do a post-mortem to find out what we got right by luck."}, {"id": "O02", "tendency": "O", "tendency_name": "learning_orientation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "At this stage of my career, my accumulated judgment is a better guide than most new information."}, {"id": "O03", "tendency": "O", "tendency_name": "learning_orientation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "b", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "I am at my best when I am applying what I already know to a problem I recognize."}, {"key": "b", "text": "I am at my best when a problem forces me to learn something I did not know."}]}, {"id": "O04", "tendency": "O", "tendency_name": "learning_orientation", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 3, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You have run your MSP's security practice for twelve years with strong client retention. A younger competitor with a different model — platform-first, largely automated, sold as a subscription at half your price — is winning SMB clients in your market. Your team is dismissive.", "options": [{"key": "1", "text": "Spend two days with people who use the competitor's service and with people who have worked there; assume they know something and find out what.", "tag": "high"}, {"key": "2", "text": "Commission a six-month study of the competitor, bring in a consultant, and hold next year's tooling and hiring plan until it is complete.", "tag": "overuse"}, {"key": "3", "text": "Trust your team's read; you have watched \"next-generation\" competitors come and go for twelve years, and SMB clients still need a person who answers the phone.", "tag": "low"}, {"key": "4", "text": "Ask your service-delivery lead to prepare a competitive assessment for the next leadership meeting.", "tag": "neutral"}]}, {"id": "P01", "tendency": "P", "tendency_name": "emotional_regulation", "overuse_flag": "secondary", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "+", "stem": "People can bring me bad news without having to guess what mood I am in first."}, {"id": "P02", "tendency": "P", "tendency_name": "emotional_regulation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "likert", "keying": "-", "stem": "When I am under real pressure, the people around me can tell, and it changes how they deal with me."}, {"id": "P03", "tendency": "P", "tendency_name": "emotional_regulation", "overuse_flag": "none", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "forced_choice", "keying": "a", "stem": "Which statement is closer to how you actually operate?", "options": [{"key": "a", "text": "My reaction to bad news is deliberately the same as my reaction to good news."}, {"key": "b", "text": "My reaction to bad news is honest, and people know where they stand."}]}, {"id": "P04", "tendency": "P", "tendency_name": "emotional_regulation", "overuse_flag": "primary", "bank_version": "v1", "status": "active", "maturity_level": 1, "meta": {"source_path": "assessment/item-bank-v1.md", "content_version": "0.1.0-cio", "built_at": "2026-09-04T01:11:45Z", "status": "draft"}, "type": "sjt", "keying": "tagged", "stem": "You are CIO and CISO of a 600-person physician group. Your infrastructure lead has just told you that a file share containing patient records has been reachable from the internet for three weeks, and that it was found by an outside researcher who emailed the front desk rather than by your team. He looks like he expects to be fired.", "options": [{"key": "1", "text": "Ask him to put the full timeline together while you call the privacy officer and outside counsel.", "tag": "neutral"}, {"key": "2", "text": "Tell him exactly what you think of a three-week gap, then get to work on containment and the notification clock.", "tag": "low"}, {"key": "3", "text": "Thank him for telling you, ask what you both need to do in the next two hours — close the share, preserve the logs, start the clock with counsel — and deal with what went wrong in the process tomorrow.", "tag": "high"}, {"key": "4", "text": "Say nothing about the failure at all, now or later; it is done, the notification is what matters, and the team will read your calm as confidence.", "tag": "overuse"}]}]}