Glossary

57 terms. Each carries an epistemic label and links to the module that defines it.

A

Agentic AI risk

INTERPRETATION

The exposure created when an AI system is granted the ability to act

B

Blameless post-incident review

FRAMEWORK

A structured review of an incident that establishes the sequence, the contributing conditions and the fixes without assigning individual fault, on the premise that fault-finding buys one accountability story and costs all future reporting. One of the five mechanisms in the Information-Environment Stack.

Board technology committee

RESEARCH FINDING

A standing board committee with delegated oversight of technology and cyber risk. Over 2005–2014, firms with such committees were more likely to report breaches in a given year

Breach-cost research

RESEARCH FINDING

The body of archival work estimating what breaches cost firms. Early event studies found the market penalized breaches of confidential data but not other incidents (Campbell, Gordon, Loeb & Zhou, 2003) and an average two-day market-value loss of about 2.1% (Cavusoglu, Mishra & Raghunathan, 2004). More recent work finds attacks exposing personal financial information associated with shareholder losses far exceeding out-of-pocket costs, consistent with reputational damage (Kamiya, Kang, Kim, Milidonis & Stulz, 2021). Practitioner averages (IBM & Ponemon, 2025: $4.44 million) are self-selected vendor estimates and are order-of-magnitude only.

C

CIO turnover after breaches

RESEARCH FINDING

The labor-market consequence of a disclosed breach for the technology executive. CIO departures were about 72% more likely after breaches attributed to system deficiencies and showed no significant association after breaches attributed to criminal fraud or human error; CEO turnover rose after both system-deficiency and human-error breaches, CFO turnover after neither (Banker & Feng, 2019; archival, cause coded from public descriptions; the paper concerns CIOs, not CISOs).

Consent order

FACT

A formal, enforceable agreement between a regulator and a regulated firm that resolves supervisory findings by imposing remediation obligations, timetables, independent validation and reporting. Its practical effect on a technology executive is to move the roadmap's ownership outside the company.

Control ↔ Enablement

FRAMEWORK

The first of the two overlay dials this edition adds. Control is the posture that treats security as the authority to constrain; enablement treats it as the capability to let the business move safely. Taught narratively and mapped onto the eight schema dials as approximately centralization ↔ decentralization plus caution ↔ aggression.

Cyber insurance

FACT

A policy transferring some financial consequences of a cyber incident. Its underwriting questionnaire

Cyber risk quantification

FRAMEWORK

The practice of expressing security exposure as expected or distributional loss rather than as a maturity score or a control count. The reasoning is sound and the inputs are weak: expected loss and vulnerability are rarely measurable, so a quantified answer is a constructed number whose assumptions must travel with it.

D

Decision rights

FRAMEWORK

The explicit allocation of who may decide what, at what threshold, without escalation

E

Enablement with institutional paranoia

INTERPRETATION

The curriculum's description (not diagnosis) of the mature technology executive's working disposition: a genuine drive to let the business move, held in permanent tension with the assumption that something is already wrong and has not yet been found. The counterpart to the bank CEO's "ambition combined with institutional paranoia" in the CEO edition.

Epistemic labels (FACT / RESEARCH FINDING / INTERPRETATION / FRAMEWORK / HYPOTHESIS)

FRAMEWORK

The five tags every consequential claim in the curriculum carries: FACT (uncontested, verifiable, or a legal requirement); RESEARCH FINDING (reported in cited research, usually correlational); INTERPRETATION (the program's reading of what findings mean); FRAMEWORK (a teaching structure, useful rather than "true"); HYPOTHESIS (plausible, not well tested).

Related: Proxy measure

F

FINRA examination

FACT

A routine or for-cause examination by the Financial Industry Regulatory Authority, the self-regulatory organization overseeing US broker-dealers. Examinations request evidence

Fit Equation (extended)

FRAMEWORKvocabulary anchor

Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line = CIO/CISO Fit. The CEO edition's equation with one term added, because a technology executive's discretion is granted by structure rather than assumed. Multiplicative by design: fit fails at the weakest term.

G

Gordon–Loeb model

RESEARCH FINDING

An analytical model in which optimal security investment for an information set depends on its value, its vulnerability and the productivity of security spending; under the two classes of breach-probability function the authors assume, optimal investment does not exceed about 37% of expected loss, and it can be rational to invest less in the most vulnerable assets (Gordon & Loeb, 2002). Later work shows other functional forms can justify more; the 37% bound must always be quoted with its assumptions.

H

HIPAA

FACT

The US Health Insurance Portability and Accountability Act. Its Security Rule requires administrative, physical and technical safeguards for electronic protected health information, and business associate agreements extend those obligations contractually to service providers

I

Incident command

FACT

The practice of running an incident under one named commander with defined roles (technical lead, communications, legal, scribe), a single timeline of record and explicit decision authority, so that decisions are made once and recorded. Distinct from technical response: the commander's job is the decision process, not the forensics.

Information-Environment Stack

FRAMEWORK

This edition's five mechanisms for hearing bad news sooner: near-miss reporting → blameless post-incident review → standing red team → direct lines from engineers → the quarterly "what we got wrong." Built because a security program's quality is bounded by the worst thing someone was willing to tell you.

Intra-industry spillover

RESEARCH FINDING

The pricing of a peer's breach against you. Around Target's December 2013 breach, 168 publicly listed US retailers experienced negative abnormal returns, larger for firms more similar to Target and smaller for firms with stronger IT capability, marketing ability and CSR records (Kashmiri, Nicol & Hsu, 2017; single event, one industry).

IT–business alignment

RESEARCH FINDING

The degree to which technology strategy, investment and operations correspond to the business's strategy. Pooled across the literature, every dimension of alignment was positively associated with performance and the much-discussed "alignment paradox" largely disappeared in meta-analysis (Gerow, Grover, Thatcher & Roth, 2014; underlying studies correlational). Shared understanding between CIO and top team is built by formal mechanisms and shared knowledge, not by informal socializing (Preston & Karahanna, 2009; 243 matched pairs).

L

Least agency

FRAMEWORK

The design principle that an autonomous or semi-autonomous system should be granted the narrowest scope of action that lets it do its job

M

Managerial discretion

RESEARCH FINDING

The latitude of action available to an executive, arising from the task environment, the organization and the executive's own characteristics (Hambrick & Finkelstein, 1987, CEO library; conceptual), with empirical support strongest for environmental sources (Wangrow, Schepker & Barker, 2015, CEO library). For CIOs and CISOs it is granted rather than assumed, which is why it is a term of the extended Fit Equation.

Materiality

FACT

In US securities law, whether a reasonable investor would consider information important. It is the trigger for incident disclosure: the four-business-day clock under Form 8-K Item 1.05 runs from the registrant's determination of materiality, not from detection (SEC, 2023). The determination is a judgment made jointly by counsel, finance and the security leader.

Maturity Model

FRAMEWORKvocabulary anchor

Four ordered levels, inherited from the CEO edition and populated for this role: Temperament (uncertainty tolerance, agency, regulation under incident) → Capability (architecture, vendor and capital judgment, incident command, risk quantification, upward communication) → Maturity (calibration, receiving bad news, letting the business own its risk) → Fit (this company, this reporting line, this regulator, this mandate). Higher levels do not substitute for lower ones.

MFA (multi-factor authentication)

FACT

Requiring more than one category of evidence to authenticate. Its practical significance is as a base-rate control: credential abuse remained the most common initial access vector at 22% of breaches in the 2025 DBIR sample of 12,195 breaches (Verizon, 2025; Tier 3, convenience sample). The executive question is never whether MFA is deployed but who holds the exceptions.

Model weights

FACT

The learned numerical parameters of a trained machine-learning model. They matter to a security leader because possession of the weights approximates possession of the capability, which makes them a concentrated asset with an unusually small blast radius for exfiltration and an unusually large one for consequences.

MSP / MSSP

FACT

A managed service provider operates a client's IT; a managed security service provider operates security functions such as monitoring and detection. Both hold privileged access across many clients, which makes them a concentration of risk in both directions: third-party involvement appeared in 30% of breaches in the 2025 DBIR sample (Verizon, 2025; Tier 3).

N

NIST CSF 2.0 functions

FACT

Since February 2024 the NIST Cybersecurity Framework has organized cybersecurity outcomes into six functions: Govern, Identify, Protect, Detect, Respond, Recover. Govern is the addition, placing executive and board accountability alongside the technical functions; the framework is voluntary and outcome-focused and does not prescribe how outcomes are achieved (NIST, 2024).

O

OT (operational technology)

FACT

The systems that monitor and control physical processes: industrial control systems, building management, clinical devices, plant floor equipment. Distinguished from IT by safety consequences, long asset lifetimes, vendor-controlled patching and an availability requirement that makes many standard IT controls inapplicable.

Overuse Ladder

FRAMEWORKvocabulary anchor

Strength → overused strength → liability, inherited from the CEO edition with technology-specific rungs: rigor → bureaucracy ("the security review that ships nothing"); caution → paralysis ("never breached because nothing is ever deployed"); delegation → abdication ("the MSP handles it"); detail → micromanagement (reading every alert); adaptability → strategy-of-the-month.

P

Player → Coach → Architect

FRAMEWORKvocabulary anchor

Three role shapes keyed to scale. The Player does the work (SMB, MSP, fractional CISO); the Coach gets work done through a team they can still see (mid-market); the Architect designs the system through which work is done by people they cannot see (enterprise). Dominant dangers in order: insufficient action; inability to let go; isolation and dashboard fiction.

Policy compliance

RESEARCH FINDING

Whether employees follow security policy. Pooled across 95 studies and 17 antecedent categories, the strongest predictors were value-oriented

Prevention ↔ Resilience

FRAMEWORK

The second overlay dial. Prevention invests in stopping the event; resilience invests in surviving it

Proactive vs. reactive investment

RESEARCH FINDING

Security spending made before a failure versus after one. In US healthcare, proactive investment was associated with lower subsequent failure rates and greater cost-effectiveness than reactive investment, and external regulatory pressure decreased the effect of proactive investment on security performance (Kwon & Johnson, 2014; one sector, disclosed breaches, hazard-model associations).

Proxy measure

FACT

An indirect indicator standing in for something unobserved: option-holding for overconfidence, board risk committees for governance attention, reported breaches for breaches. Every finding built on a proxy carries measurement error and must be described as proxy-based

Psychological safety

RESEARCH FINDING

A shared belief that a team is safe for interpersonal risk-taking

R

Red team

FACT

An adversarial exercise in which a team attempts to achieve a defined objective against the live environment, testing detection and response as well as controls. "Standing" red team means the capability is continuous rather than an annual engagement, which is what makes it an information-environment mechanism rather than an audit artifact.

Reporting line

RESEARCH FINDING

Who the CIO or CISO reports to, and therefore what they can escalate without permission. In a large-firm archival study the "right" CIO reporting line depended on strategy: CIO-to-CEO associated with better performance in differentiation firms, CIO-to-CFO in cost-leadership firms (Banker, Hu, Pavlou & Luftman, 2011; pre-cloud data). In a 2026 practitioner survey, 64% of CISOs reported to the CIO or CTO and 36% to a non-IT executive (IANS Research & Artico Search, 2026; Tier 3, self-selected).

Risk acceptance (exception)

FRAMEWORK

A documented decision to run a known exposure, with a named owner who is not the security leader, a stated price, a compensating control and an expiry date. An undocumented exception is an unowned risk; an exception register that only grows is a program losing ground.

Risk Corollary

FRAMEWORK

This edition's companion to the Two-Sentence Test, and the pair of sentences every security leader must be able to say to a CEO: **"Yes

RPO / RTO

FACT

Recovery point objective (how much data the business can afford to lose, measured in time) and recovery time objective (how long it can afford to be down). They are business decisions expressed in technical terms, and the useful executive question is not what the documented objectives are but when they were last demonstrated.

S

SEC cybersecurity disclosure (8-K Item 1.05; 10-K Item 1C)

FACT

Since December 2023, US public companies must disclose a material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining materiality, and must annually describe their processes for assessing and managing material cyber risk, the board's oversight, and management's role and expertise

Security culture

INTERPRETATION

The working beliefs that determine what people actually do when a control is inconvenient and what they do after they make a mistake. Treated in this edition as a control rather than a nicety, on the reasoning that a program depends on people reporting the click, the misconfiguration and the near-miss

Shadow IT / shadow AI

FACT

Technology adopted by the business without the technology function's involvement. Shadow AI is its current form; IBM/Ponemon's 2025 sample associated shadow-AI incidents with about $670,000 in additional average breach cost and reported that 63% of organizations had no AI governance policy (IBM & Ponemon, 2025; Tier 3, vendor-sponsored). Its usual cause is not defiance but latency: the exception queue was slower than the business's decision.

Social capital (CIO–TMT)

RESEARCH FINDING

The structural, cognitive and relational quality of the technology executive's relationship with the top management team. In 81 US hospitals, cognitive and relational social capital directly influenced IS strategic alignment, structural social capital worked indirectly, and alignment mediated the relationship with financial performance (Karahanna & Preston, 2013; one sector, perceptual measures).

Structural power

RESEARCH FINDING

The authority a technology executive holds by virtue of position rather than persuasion: reporting line, budget authority, membership of the top team, direct board access, and the right to escalate. Peer-reviewed work examines the antecedents and consequences of CIO strategic decision-making authority (Preston, Chen & Leidner, 2008), and its practitioner companion describes four profiles from crossing authority with capability

Symbolic vs. substantive adoption

RESEARCH FINDING

Whether a security practice is bought and displayed or integrated into how the organization works. Across more than 5,000 US hospitals and 938 breaches (2005–2013), symbolic adoption diminished the effectiveness of IT security investment and was associated with an increased likelihood of breach; deeper integration into IT routines was associated with fewer breaches (Angst, Block, D'Arcy & Kelley, 2017; one sector, adoption inferred from institutional profile).

System-deficiency vs. human-error breach

RESEARCH FINDING

The attribution categories that determine executive consequences. Breaches attributed to system deficiency were associated with about a 72% higher likelihood of CIO turnover; breaches attributed to criminal fraud or human error were not (Banker & Feng, 2019). Attribution is coded from public descriptions and is itself contestable

T

Tabletop exercise

FACT

A facilitated walkthrough of an incident scenario with the people who would actually decide, testing decision rights, escalation, disclosure judgment and communications rather than technical response. Its value is diagnostic: the exercise reveals which decisions have no owner.

Third-party / supply-chain risk

RESEARCH FINDING

Exposure arising from vendors, service providers, software suppliers and their subcontractors. In the 2025 DBIR sample of 12,195 breaches, third-party involvement doubled year on year to 30% (Verizon, 2025; Tier 3, convenience sample), and NIST CSF 2.0 expanded its supply-chain content (NIST, 2024). For BPM and MSP firms the relationship runs both ways: they are somebody's third party.

Trait Dial

FRAMEWORKvocabulary anchor

Eight paired settings a technology executive can move rather than fixed traits: aggression ↔ caution; decisiveness ↔ inquiry; optimism ↔ skepticism; hands-on ↔ delegation; urgency ↔ patience; unilateral ↔ consensus; innovation ↔ operational discipline; centralization ↔ decentralization. This edition adds two overlay dials taught narratively: Control ↔ Enablement and Prevention ↔ Resilience.

Two-party control

FACT

A requirement that two independent principals authorize a sensitive action

Two-Sentence Test

FRAMEWORKvocabulary anchor

A mature executive can say, and mean, both "We're going to do this." and "I was wrong. Change the plan." Inherited unchanged from the CEO edition; in this edition it is paired with the Risk Corollary, and the capstone asks for all four sentences in the same quarter.

U

Underreported attacks

RESEARCH FINDING

Incidents a firm withheld rather than disclosed. Before mandatory disclosure, attacks that were withheld and later revealed by outside sources were associated with a decline of about 3.6% in equity value in the month of discovery, versus about 0.7% for firm-disclosed attacks; the authors interpret this as managers withholding the more severe events (Amir, Levi & Livne, 2018; undiscovered concealment is unobservable by construction).

V

vCISO / fractional CISO

FACT

A security executive engaged part-time or on retainer, typically serving several small and mid-sized companies at once. The dominant form of the role by headcount and the least studied: it supplies standing and judgment without operational capacity, which makes the written boundary between advice and ownership the engagement's most important artifact.

Z

Zero trust

FACT

An architectural approach that removes implicit trust based on network location, requiring every request to be authenticated, authorized and evaluated against device and context signals. Widely adopted as a design principle and widely used as a marketing term; treat maturity claims about it as claims about a program, not a product.