Glossary
57 terms. Each carries an epistemic label and links to the module that defines it.
A
Agentic AI risk
INTERPRETATIONThe exposure created when an AI system is granted the ability to act
B
Blameless post-incident review
FRAMEWORKA structured review of an incident that establishes the sequence, the contributing conditions and the fixes without assigning individual fault, on the premise that fault-finding buys one accountability story and costs all future reporting. One of the five mechanisms in the Information-Environment Stack.
Board technology committee
RESEARCH FINDINGA standing board committee with delegated oversight of technology and cyber risk. Over 2005–2014, firms with such committees were more likely to report breaches in a given year
Breach-cost research
RESEARCH FINDINGThe body of archival work estimating what breaches cost firms. Early event studies found the market penalized breaches of confidential data but not other incidents (Campbell, Gordon, Loeb & Zhou, 2003) and an average two-day market-value loss of about 2.1% (Cavusoglu, Mishra & Raghunathan, 2004). More recent work finds attacks exposing personal financial information associated with shareholder losses far exceeding out-of-pocket costs, consistent with reputational damage (Kamiya, Kang, Kim, Milidonis & Stulz, 2021). Practitioner averages (IBM & Ponemon, 2025: $4.44 million) are self-selected vendor estimates and are order-of-magnitude only.
C
CIO turnover after breaches
RESEARCH FINDINGThe labor-market consequence of a disclosed breach for the technology executive. CIO departures were about 72% more likely after breaches attributed to system deficiencies and showed no significant association after breaches attributed to criminal fraud or human error; CEO turnover rose after both system-deficiency and human-error breaches, CFO turnover after neither (Banker & Feng, 2019; archival, cause coded from public descriptions; the paper concerns CIOs, not CISOs).
Consent order
FACTA formal, enforceable agreement between a regulator and a regulated firm that resolves supervisory findings by imposing remediation obligations, timetables, independent validation and reporting. Its practical effect on a technology executive is to move the roadmap's ownership outside the company.
Control ↔ Enablement
FRAMEWORKThe first of the two overlay dials this edition adds. Control is the posture that treats security as the authority to constrain; enablement treats it as the capability to let the business move safely. Taught narratively and mapped onto the eight schema dials as approximately centralization ↔ decentralization plus caution ↔ aggression.
Cyber insurance
FACTA policy transferring some financial consequences of a cyber incident. Its underwriting questionnaire
Cyber risk quantification
FRAMEWORKThe practice of expressing security exposure as expected or distributional loss rather than as a maturity score or a control count. The reasoning is sound and the inputs are weak: expected loss and vulnerability are rarely measurable, so a quantified answer is a constructed number whose assumptions must travel with it.
D
Decision rights
FRAMEWORKThe explicit allocation of who may decide what, at what threshold, without escalation
E
Enablement with institutional paranoia
INTERPRETATIONThe curriculum's description (not diagnosis) of the mature technology executive's working disposition: a genuine drive to let the business move, held in permanent tension with the assumption that something is already wrong and has not yet been found. The counterpart to the bank CEO's "ambition combined with institutional paranoia" in the CEO edition.
Epistemic labels (FACT / RESEARCH FINDING / INTERPRETATION / FRAMEWORK / HYPOTHESIS)
FRAMEWORKThe five tags every consequential claim in the curriculum carries: FACT (uncontested, verifiable, or a legal requirement); RESEARCH FINDING (reported in cited research, usually correlational); INTERPRETATION (the program's reading of what findings mean); FRAMEWORK (a teaching structure, useful rather than "true"); HYPOTHESIS (plausible, not well tested).
F
FINRA examination
FACTA routine or for-cause examination by the Financial Industry Regulatory Authority, the self-regulatory organization overseeing US broker-dealers. Examinations request evidence
Fit Equation (extended)
FRAMEWORKvocabulary anchorIndustry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line = CIO/CISO Fit. The CEO edition's equation with one term added, because a technology executive's discretion is granted by structure rather than assumed. Multiplicative by design: fit fails at the weakest term.
G
Gordon–Loeb model
RESEARCH FINDINGAn analytical model in which optimal security investment for an information set depends on its value, its vulnerability and the productivity of security spending; under the two classes of breach-probability function the authors assume, optimal investment does not exceed about 37% of expected loss, and it can be rational to invest less in the most vulnerable assets (Gordon & Loeb, 2002). Later work shows other functional forms can justify more; the 37% bound must always be quoted with its assumptions.
H
HIPAA
FACTThe US Health Insurance Portability and Accountability Act. Its Security Rule requires administrative, physical and technical safeguards for electronic protected health information, and business associate agreements extend those obligations contractually to service providers
I
Incident command
FACTThe practice of running an incident under one named commander with defined roles (technical lead, communications, legal, scribe), a single timeline of record and explicit decision authority, so that decisions are made once and recorded. Distinct from technical response: the commander's job is the decision process, not the forensics.
Information-Environment Stack
FRAMEWORKThis edition's five mechanisms for hearing bad news sooner: near-miss reporting → blameless post-incident review → standing red team → direct lines from engineers → the quarterly "what we got wrong." Built because a security program's quality is bounded by the worst thing someone was willing to tell you.
Intra-industry spillover
RESEARCH FINDINGThe pricing of a peer's breach against you. Around Target's December 2013 breach, 168 publicly listed US retailers experienced negative abnormal returns, larger for firms more similar to Target and smaller for firms with stronger IT capability, marketing ability and CSR records (Kashmiri, Nicol & Hsu, 2017; single event, one industry).
IT–business alignment
RESEARCH FINDINGThe degree to which technology strategy, investment and operations correspond to the business's strategy. Pooled across the literature, every dimension of alignment was positively associated with performance and the much-discussed "alignment paradox" largely disappeared in meta-analysis (Gerow, Grover, Thatcher & Roth, 2014; underlying studies correlational). Shared understanding between CIO and top team is built by formal mechanisms and shared knowledge, not by informal socializing (Preston & Karahanna, 2009; 243 matched pairs).
L
Least agency
FRAMEWORKThe design principle that an autonomous or semi-autonomous system should be granted the narrowest scope of action that lets it do its job
M
Managerial discretion
RESEARCH FINDINGThe latitude of action available to an executive, arising from the task environment, the organization and the executive's own characteristics (Hambrick & Finkelstein, 1987, CEO library; conceptual), with empirical support strongest for environmental sources (Wangrow, Schepker & Barker, 2015, CEO library). For CIOs and CISOs it is granted rather than assumed, which is why it is a term of the extended Fit Equation.
Materiality
FACTIn US securities law, whether a reasonable investor would consider information important. It is the trigger for incident disclosure: the four-business-day clock under Form 8-K Item 1.05 runs from the registrant's determination of materiality, not from detection (SEC, 2023). The determination is a judgment made jointly by counsel, finance and the security leader.
Maturity Model
FRAMEWORKvocabulary anchorFour ordered levels, inherited from the CEO edition and populated for this role: Temperament (uncertainty tolerance, agency, regulation under incident) → Capability (architecture, vendor and capital judgment, incident command, risk quantification, upward communication) → Maturity (calibration, receiving bad news, letting the business own its risk) → Fit (this company, this reporting line, this regulator, this mandate). Higher levels do not substitute for lower ones.
MFA (multi-factor authentication)
FACTRequiring more than one category of evidence to authenticate. Its practical significance is as a base-rate control: credential abuse remained the most common initial access vector at 22% of breaches in the 2025 DBIR sample of 12,195 breaches (Verizon, 2025; Tier 3, convenience sample). The executive question is never whether MFA is deployed but who holds the exceptions.
Model weights
FACTThe learned numerical parameters of a trained machine-learning model. They matter to a security leader because possession of the weights approximates possession of the capability, which makes them a concentrated asset with an unusually small blast radius for exfiltration and an unusually large one for consequences.
MSP / MSSP
FACTA managed service provider operates a client's IT; a managed security service provider operates security functions such as monitoring and detection. Both hold privileged access across many clients, which makes them a concentration of risk in both directions: third-party involvement appeared in 30% of breaches in the 2025 DBIR sample (Verizon, 2025; Tier 3).
N
Near-miss reporting
FRAMEWORKA channel for reporting events that did not become incidents
NIST CSF 2.0 functions
FACTSince February 2024 the NIST Cybersecurity Framework has organized cybersecurity outcomes into six functions: Govern, Identify, Protect, Detect, Respond, Recover. Govern is the addition, placing executive and board accountability alongside the technical functions; the framework is voluntary and outcome-focused and does not prescribe how outcomes are achieved (NIST, 2024).
O
OT (operational technology)
FACTThe systems that monitor and control physical processes: industrial control systems, building management, clinical devices, plant floor equipment. Distinguished from IT by safety consequences, long asset lifetimes, vendor-controlled patching and an availability requirement that makes many standard IT controls inapplicable.
Overuse Ladder
FRAMEWORKvocabulary anchorStrength → overused strength → liability, inherited from the CEO edition with technology-specific rungs: rigor → bureaucracy ("the security review that ships nothing"); caution → paralysis ("never breached because nothing is ever deployed"); delegation → abdication ("the MSP handles it"); detail → micromanagement (reading every alert); adaptability → strategy-of-the-month.
P
Player → Coach → Architect
FRAMEWORKvocabulary anchorThree role shapes keyed to scale. The Player does the work (SMB, MSP, fractional CISO); the Coach gets work done through a team they can still see (mid-market); the Architect designs the system through which work is done by people they cannot see (enterprise). Dominant dangers in order: insufficient action; inability to let go; isolation and dashboard fiction.
Policy compliance
RESEARCH FINDINGWhether employees follow security policy. Pooled across 95 studies and 17 antecedent categories, the strongest predictors were value-oriented
Prevention ↔ Resilience
FRAMEWORKThe second overlay dial. Prevention invests in stopping the event; resilience invests in surviving it
Proactive vs. reactive investment
RESEARCH FINDINGSecurity spending made before a failure versus after one. In US healthcare, proactive investment was associated with lower subsequent failure rates and greater cost-effectiveness than reactive investment, and external regulatory pressure decreased the effect of proactive investment on security performance (Kwon & Johnson, 2014; one sector, disclosed breaches, hazard-model associations).
Proxy measure
FACTAn indirect indicator standing in for something unobserved: option-holding for overconfidence, board risk committees for governance attention, reported breaches for breaches. Every finding built on a proxy carries measurement error and must be described as proxy-based
Psychological safety
RESEARCH FINDINGA shared belief that a team is safe for interpersonal risk-taking
R
Red team
FACTAn adversarial exercise in which a team attempts to achieve a defined objective against the live environment, testing detection and response as well as controls. "Standing" red team means the capability is continuous rather than an annual engagement, which is what makes it an information-environment mechanism rather than an audit artifact.
Reporting line
RESEARCH FINDINGWho the CIO or CISO reports to, and therefore what they can escalate without permission. In a large-firm archival study the "right" CIO reporting line depended on strategy: CIO-to-CEO associated with better performance in differentiation firms, CIO-to-CFO in cost-leadership firms (Banker, Hu, Pavlou & Luftman, 2011; pre-cloud data). In a 2026 practitioner survey, 64% of CISOs reported to the CIO or CTO and 36% to a non-IT executive (IANS Research & Artico Search, 2026; Tier 3, self-selected).
Risk acceptance (exception)
FRAMEWORKA documented decision to run a known exposure, with a named owner who is not the security leader, a stated price, a compensating control and an expiry date. An undocumented exception is an unowned risk; an exception register that only grows is a program losing ground.
Risk Corollary
FRAMEWORKThis edition's companion to the Two-Sentence Test, and the pair of sentences every security leader must be able to say to a CEO: **"Yes
RPO / RTO
FACTRecovery point objective (how much data the business can afford to lose, measured in time) and recovery time objective (how long it can afford to be down). They are business decisions expressed in technical terms, and the useful executive question is not what the documented objectives are but when they were last demonstrated.
S
SEC cybersecurity disclosure (8-K Item 1.05; 10-K Item 1C)
FACTSince December 2023, US public companies must disclose a material cybersecurity incident on Form 8-K Item 1.05 within four business days of determining materiality, and must annually describe their processes for assessing and managing material cyber risk, the board's oversight, and management's role and expertise
Security culture
INTERPRETATIONThe working beliefs that determine what people actually do when a control is inconvenient and what they do after they make a mistake. Treated in this edition as a control rather than a nicety, on the reasoning that a program depends on people reporting the click, the misconfiguration and the near-miss
Shadow IT / shadow AI
FACTTechnology adopted by the business without the technology function's involvement. Shadow AI is its current form; IBM/Ponemon's 2025 sample associated shadow-AI incidents with about $670,000 in additional average breach cost and reported that 63% of organizations had no AI governance policy (IBM & Ponemon, 2025; Tier 3, vendor-sponsored). Its usual cause is not defiance but latency: the exception queue was slower than the business's decision.
Social capital (CIO–TMT)
RESEARCH FINDINGThe structural, cognitive and relational quality of the technology executive's relationship with the top management team. In 81 US hospitals, cognitive and relational social capital directly influenced IS strategic alignment, structural social capital worked indirectly, and alignment mediated the relationship with financial performance (Karahanna & Preston, 2013; one sector, perceptual measures).
Structural power
RESEARCH FINDINGThe authority a technology executive holds by virtue of position rather than persuasion: reporting line, budget authority, membership of the top team, direct board access, and the right to escalate. Peer-reviewed work examines the antecedents and consequences of CIO strategic decision-making authority (Preston, Chen & Leidner, 2008), and its practitioner companion describes four profiles from crossing authority with capability
Symbolic vs. substantive adoption
RESEARCH FINDINGWhether a security practice is bought and displayed or integrated into how the organization works. Across more than 5,000 US hospitals and 938 breaches (2005–2013), symbolic adoption diminished the effectiveness of IT security investment and was associated with an increased likelihood of breach; deeper integration into IT routines was associated with fewer breaches (Angst, Block, D'Arcy & Kelley, 2017; one sector, adoption inferred from institutional profile).
System-deficiency vs. human-error breach
RESEARCH FINDINGThe attribution categories that determine executive consequences. Breaches attributed to system deficiency were associated with about a 72% higher likelihood of CIO turnover; breaches attributed to criminal fraud or human error were not (Banker & Feng, 2019). Attribution is coded from public descriptions and is itself contestable
T
Tabletop exercise
FACTA facilitated walkthrough of an incident scenario with the people who would actually decide, testing decision rights, escalation, disclosure judgment and communications rather than technical response. Its value is diagnostic: the exercise reveals which decisions have no owner.
Third-party / supply-chain risk
RESEARCH FINDINGExposure arising from vendors, service providers, software suppliers and their subcontractors. In the 2025 DBIR sample of 12,195 breaches, third-party involvement doubled year on year to 30% (Verizon, 2025; Tier 3, convenience sample), and NIST CSF 2.0 expanded its supply-chain content (NIST, 2024). For BPM and MSP firms the relationship runs both ways: they are somebody's third party.
Trait Dial
FRAMEWORKvocabulary anchorEight paired settings a technology executive can move rather than fixed traits: aggression ↔ caution; decisiveness ↔ inquiry; optimism ↔ skepticism; hands-on ↔ delegation; urgency ↔ patience; unilateral ↔ consensus; innovation ↔ operational discipline; centralization ↔ decentralization. This edition adds two overlay dials taught narratively: Control ↔ Enablement and Prevention ↔ Resilience.
Two-party control
FACTA requirement that two independent principals authorize a sensitive action
Two-Sentence Test
FRAMEWORKvocabulary anchorA mature executive can say, and mean, both "We're going to do this." and "I was wrong. Change the plan." Inherited unchanged from the CEO edition; in this edition it is paired with the Risk Corollary, and the capstone asks for all four sentences in the same quarter.
U
Underreported attacks
RESEARCH FINDINGIncidents a firm withheld rather than disclosed. Before mandatory disclosure, attacks that were withheld and later revealed by outside sources were associated with a decline of about 3.6% in equity value in the month of discovery, versus about 0.7% for firm-disclosed attacks; the authors interpret this as managers withholding the more severe events (Amir, Levi & Livne, 2018; undiscovered concealment is unobservable by construction).
V
vCISO / fractional CISO
FACTA security executive engaged part-time or on retainer, typically serving several small and mid-sized companies at once. The dominant form of the role by headcount and the least studied: it supplies standing and judgment without operational capacity, which makes the written boundary between advice and ownership the engagement's most important artifact.
Z
Zero trust
FACTAn architectural approach that removes implicit trust based on network location, requiring every request to be authenticated, authorized and evaluated against device and context signals. Widely adopted as a design principle and widely used as a marketing term; treat maturity claims about it as claims about a program, not a product.