Why CIOs and CISOs Aren't Normal Either
Technology leaders are selected for a different temperament than CEOs — and the CISO is selected for a temperament the CEO's own optimism will fight.
Learning objectives
- Contrast the CEO temperament (optimism, risk tolerance, agency) with the dispositions the CIO and CISO roles select and reward.
- Explain why the CISO's structural role creates a built-in tension with the CEO's optimism, and how mature technology executives manage it with the Risk Corollary.
- Distinguish 'CISOs tend to be X' from 'X makes a good CISO', and say plainly where the evidence on technology executives' temperament is thin.
- Describe the selection filters — self-selection, promotion out of engineering, executive appointment, breach survival — that make the CIO/CISO population unrepresentative.
Core lesson
The CEO edition opened with an uncomfortable fact: the people who become CEOs are a filtered population, and the filters select for temperament — optimism, risk tolerance, a strong sense that one's own actions decide outcomes — long before they select for results. This module makes the same argument about CIOs and CISOs, with one twist: the technology executive is filtered by different sieves, toward a different temperament, and then placed in a room with the CEO the first set of sieves produced.
Three claims follow. First, the CIO and CISO populations are as unrepresentative of capable adults as the CEO population, but in a different direction — the CISO in particular is selected for a disposition we call, descriptively, enablement with institutional paranoia. Second, the tension between a CEO paid to believe and a CISO paid to imagine failure is structural, not personal; it exists whoever holds either chair, and the mature technology executive manages it with the Risk Corollary. Third, the evidence on technology executives' temperament is thin — no psychometric study of CIOs or CISOs exists in our library — so most of what this module says about disposition is labeled hypothesis, and anyone who tells you otherwise is selling something.
In the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on the Traits term: what the typical technology executive's profile looks like, how it got that way, and why the base rate is a description of who survived, not a prescription for who to become.
The big idea
The CEO is selected to believe; the CISO is selected to doubt; the CIO is selected to build — and the same company needs all three to be right at once.
A CEO's optimism is not a flaw to be corrected by the security function, and a CISO's skepticism is not a personality problem to be managed by the CEO. They are the outputs of different filters, installed in the same building because the company needs both a reason to move and a reason to check. The combined CIO/CISO — the normal case below a billion dollars of revenue — has to hold the builder's belief and the risk officer's doubt in one head, which is why this edition exists.
What the research says
The CEO base rate, from the CEO library
RESEARCH FINDING Graham, Harvey and Puri (2013, from the CEO library) administered validated psychometric instruments to a large survey of CEOs and CFOs of public and private firms. CEOs scored markedly more risk-tolerant and more optimistic than population norms; roughly 80% of US CEOs were classified "very optimistic," against roughly 65% of CFOs, and those traits were associated with more acquisitions and more short-term debt. What it supports: the person a CISO reports to, directly or at one remove, is very probably drawn from a population unusually inclined to believe things will work out. What it cannot: anything about CIOs or CISOs, who were not surveyed, or any causal claim — the design is cross-sectional and self-reported.
What the CISO literature actually contains
RESEARCH FINDING Ashenden and Sasse (2013) conducted five in-depth interviews with CISOs, who described their obstacles as "a perceived lack of power, confusion about their role identity, and their inability to engage effectively with employees"; the authors argued CISOs must build credibility through communication and engagement so that security becomes "business as usual" rather than a specialist function. Five interviews, UK, 2013: illustration, not measurement — but the role's influence problem described from inside it.
RESEARCH FINDING Maynard, Onibere and Ahmad (2018), in a systematic literature review, concluded that "there has been little emphasis on understanding the role of the CISO as a strategist" and proposed a competency set for the CISO as strategist. A framework-level contribution; nobody has tested whether those competencies improve outcomes. Peer-reviewed research has also examined CISO appointments and reporting positions in relation to breach events (Karanja, 2017); our bibliography could not retrieve the abstract, so no finding from it is cited here.
RESEARCH FINDING (Tier 3, practitioner survey). IANS Research and Artico Search (2026) surveyed more than 600 security leaders: 47% of CISOs held EVP/SVP-level titles; 64% reported to IT leaders (CIO or CTO) and 36% to non-IT leaders such as the CEO, COO, general counsel or chief risk officer; 52% said their responsibilities were "not manageable given current resources"; 69% were "open to changing jobs within the next year." A self-selected survey from vendors with a commercial interest in the CISO market, without response-rate information. Base rates only.
Why context bounds the technology executive
RESEARCH FINDING Peppard (2010), from interviews with CIOs, executives and commentators, argued that CIO performance is largely a function of organizational context — above all "the IT savviness of the CEO and the leadership team" — and that blaming CIOs for disappointing IT returns misplaces accountability. Interview-based, no outcome data; cite it for the framing.
RESEARCH FINDING Preston, Leidner and Chen (2008), the practitioner-facing companion to Preston, Chen and Leidner (2008), crossed a CIO's strategic decision-making authority with strategic leadership capability to define four profiles — IT Orchestrator (high/high), IT Advisor (low authority, high capability), IT Mechanic (high authority, low capability) and IT Laggard — and reported that IT's contribution to firm performance varied with the profile. Survey-based, cross-sectional, perceptual. What it supports: effectiveness depends on the match between granted authority and brought capability; capability without authority is a recognized under-performing profile.
RESEARCH FINDING Haislip, Lim and Pinsker (2021), using reported breaches from 2005 to 2017, found that CEOs with IT expertise were associated with fewer reported data security breaches, that a CIO on the top management team was "significantly associated with reduced DSBs of all types examined," and that CFOs with IT expertise were less likely to report breaches. Reported breaches only; associations. No single appointment is shown to cause fewer breaches, and the CFO finding warns that "fewer reported breaches" can mean fewer reports.
Personality × Power, from the CEO library
RESEARCH FINDING Hambrick and Finkelstein (1987, from the CEO library) introduced managerial discretion — the latitude of action available to an executive — as the variable that decides how much an executive's characteristics matter; Hambrick (2007) added that heavy job demands increase reliance on heuristics and dispositions. Li and Tang (2010), surveying 2,790 Chinese manufacturing CEOs, found hubris associated with more firm risk taking, markedly more so where discretion was greater. What it supports: traits become visible in outcomes in proportion to the power the holder has — for the CISO usually low, and in an incident suddenly high.
Where the evidence is weak
Almost everywhere. There is no psychometric study of CIOs or CISOs in this library; the closest CEO-library evidence, Kaplan and Sorensen's (2021) 2,603 assessments of candidates for CEO, CFO, COO and other top roles, shows the C-suite is not one population but does not break out technology roles. The CISO literature is a five-person interview study, a literature review, a paper whose abstract we could not retrieve, and a vendor survey; the CIO literature is stronger on structure than on disposition. Every statement here about the temperament the roles select is therefore a HYPOTHESIS built from the filters and from the CEO evidence by analogy. What the evidence does establish is negative and important: the CEO population is unusually optimistic and risk-tolerant, and the technology executive works for it.
Explanation
Start with the CEO base rate, because it is the CISO's problem
INTERPRETATION You are not the CEO. You work for one, and the CEO you work for is, on the best evidence available, more likely than four out of five ordinary people to believe the plan will work (Graham, Harvey & Puri, 2013). That disposition was selected for; it is why there is a company for you to secure; and it is the single most important feature of your operating environment, because your job — half of it, if you hold both — is to say what could go wrong to a person constitutionally inclined not to hear it.
Nothing about that is personal. A CISO who experiences the CEO's optimism as a character flaw has misread a base rate as a biography; a CEO who experiences the CISO's doubt as obstruction has done the same in reverse.
The filters that produce a technology executive
FRAMEWORK The CEO edition described three stacked filters — who wants the job, who gets promoted toward it, who the board picks. The technology executive passes through four, and each prefers a temperament.
The first is self-selection into technology. HYPOTHESIS People who spend their twenties with systems tend to like problems that have answers and prefer being right to being liked; security adds people who enjoy thinking about how things break, a specific and slightly unusual pleasure. The second is promotion out of engineering: the best engineer gets the team-lead job, and at each step the organization selects on technical performance while the job it is filling requires something else — the Player → Coach transition, where many technology careers mature or stall.
The third is executive appointment, where the paths diverge. INTERPRETATION A CIO is usually appointed to build something and chosen for the builder's disposition: agency, optimism, comfort with capital. A CISO is often appointed in response to something — a near-miss, a regulator's letter, a peer's breach. Peer-reviewed research has examined CISO appointments in relation to breach events (Karanja, 2017); we cannot quote its findings, but a role created under threat and staffed for vigilance selects a different temperament than a role created to ship.
The fourth is survival. In a practitioner sample, 69% of CISOs were open to changing jobs within the year and 52% called the job unmanageable with current resources (IANS, 2026 — Tier 3). Churn is a filter: what remains is the temperament that can tolerate being responsible for outcomes it does not fully control.
The temperament the roles select — a hypothesis, labeled
HYPOTHESIS For the CIO: high agency, high uncertainty tolerance, a systems view, optimism about what technology can do, and a builder's impatience — closer to the CEO temperament than any other C-suite role except perhaps the COO. For the CISO: vigilance, a default toward skepticism, comfort with being the least popular person in the room, tolerance for ambiguous evidence (was that alert nothing, or the first thing?), and a conscientiousness that borders on the compulsive. The combined CIO/CISO — the normal case below a billion dollars of revenue and the universal case in the MSP and vCISO world — is asked to have both.
FRAMEWORK On the Trait Dial these are defaults, not settings: the CIO default sits toward optimism, aggression and urgency; the CISO default toward skepticism, caution, inquiry and operational discipline, and on this edition's overlay dials toward control and prevention. Module 6 is about turning the dials; this module is about knowing where they start.
The CISO disposition has a name in this course: enablement with institutional paranoia — the counterpart to the bank CEO's "ambition with institutional paranoia" in the CEO edition, and like it a description, not a diagnosis. Enablement is the half that says yes; institutional paranoia assumes the adversary is already inside and the control that worked last quarter is the one being probed now. A CISO with only the second half is a control. A CISO with only the first is a liability.
The built-in tension, and the tool for it
INTERPRETATION Put the selected CEO and the selected CISO in a budget meeting. The CEO asks, with the sincerity of a person for whom things have generally worked out, why the new client cannot go live next week; the CISO explains, with the sincerity of a person who has read the incident reports, why it cannot. Neither is wrong about their own job. The meeting fails because each treats the other's disposition as a position to be argued out of.
FRAMEWORK The Risk Corollary is the way out and the closing device of every module in this edition. A mature technology executive can say both: "Yes — and here is the risk we are accepting, priced." And: "No — and here is what would change my answer." The first converts the CEO's optimism into an informed bet with a named owner. The second converts the CISO's skepticism from a wall into a door with a price on it. Both require a priced view of risk (Module 3) and the standing to state it (Module 10). Neither requires the CISO to become an optimist or the CEO a pessimist. The tension stays; it becomes productive.
Personality × Power for the technology executive
INTERPRETATION Traits need power to be visible: a disposition shapes outcomes in proportion to the discretion the situation grants (Hambrick & Finkelstein, 1987). A CEO's discretion is broad by default. A CIO's or CISO's is set by someone else — the reporting line, the budget process, the board's committee structure, the regulator. Ashenden and Sasse's (2013) CISOs named "a perceived lack of power" as their first obstacle; Preston, Leidner and Chen (2008) named the mismatch: the IT Advisor, capable without authority. Hence the extra term in this edition's Fit Equation. FRAMEWORK Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line = CIO/CISO Fit. Two executives with identical temperament and capability produce different outcomes depending on whether the reporting line lets their judgment reach the decision.
Discretion spikes at two moments: the incident, when for the hours a breach is live the CISO has more real authority than anyone in the building — and Li and Tang's (2010) finding that hubris expresses itself most where discretion is greatest belongs in the war room (Module 4); and the budget cycle after a peer's breach, when the CEO briefly becomes a pessimist. Hambrick (2007) adds that heavy job demands push executives toward heuristics and dispositions: if half of CISOs call the job unmanageable, half are operating in exactly the conditions under which default settings run the show.
"CISOs tend to be X" versus "X makes a good CISO"
INTERPRETATION Everything above describes who survives the filters. None of it is evidence that the surviving temperament produces better security. "CISOs tend to be skeptical" is a base rate; "skepticism makes a good CISO" is a causal claim with no study behind it. The closest the library gets — a CIO on the top team is associated with fewer reported breaches (Haislip, Lim & Pinsker, 2021) — is a finding about structure, not disposition, and about reported breaches, which the same paper's CFO result shows can fall because reporting falls.
Visibility compounds the confusion. The CISOs the public knows are almost without exception the ones whose companies were breached in the press; the CIOs the public knows ran famous transformations. Visibility ≠ prevalence; visibility ≠ effectiveness. The quiet operator who priced risk correctly for fifteen years is invisible by construction. Do not build your model of a good technology executive from the ones you have heard of.
What to do with the base rate
FRAMEWORK Locate yourself on the Maturity Model — Temperament → Capability → Maturity → Fit — honestly at level one. Temperament is what the filters left you with, it is mostly not trainable, and it is the source of every rung on the Overuse Ladder you will climb: institutional paranoia climbs skepticism → cynicism and caution → paralysis; the builder's optimism climbs optimism → delusion and urgency → recklessness. Judge yourself against the filtered population: a CISO who is "cautious" relative to the people who become CISOs is very cautious indeed. And notice which job you are in. In the MSP and SMB world the technology executive is a Player by necessity, and the dominant danger is not overuse of a trait but insufficient action and no second opinion — in an environment where, in the 2025 DBIR sample, ransomware was present in 88% of SMB breaches (Verizon, 2025 — Tier 3, non-random contributor sample).
Example
Fictional composite. Harbor Line Business Services is a business-process and managed-services firm in Stamford, Connecticut: founded in 2019, $16 million in revenue, 120 employees, about 85 clients across registered investment advisers and small broker-dealers, medical and dental groups, law and accounting firms, and regional retailers in Connecticut, Massachusetts and the Hudson Valley. Roughly 40 clients buy a fractional CISO service on top of managed IT. The founder and CEO, Rob Castellano, came up in enterprise software sales and is, by his own cheerful description, "a yes person." The CIO and CISO is one person, Elena Marsh, a former network engineer and service-delivery lead who joined in 2021 as the firm's first technology executive.
In March, Castellano signs the firm's largest healthcare client to date: a nine-location orthopedic group with 340 staff, a vendor-hosted electronic health record, and a departing IT contractor who has given three weeks' notice. Castellano has told the group's CEO that Harbor Line will "take over on the first of the month" — in nineteen days.
Marsh's onboarding baseline takes six weeks: identity audit, MFA enforcement, endpoint agents, backup verification, and a review of every vendor with access to patient data. A nineteen-day takeover means Harbor Line inherits administrative credentials it has not reviewed, on devices it has not seen, under a business associate agreement that puts Harbor Line's name second on any breach.
The conversation that follows is the module in miniature. Castellano's position is sincere: the client is bleeding, the contractor is leaving, and a firm that cannot start when a client needs it is not a firm he wants to run. He is not being reckless. He is being a CEO. Marsh's first instinct — she notices it, which matters — is to say it cannot be done, in a tone that ends the meeting. That is the CISO default: skepticism, caution, and the comfort of being the person who said no.
She does something else. She takes two hours, prices it, and comes back with both sentences.
"Yes — we can take over on the first, and here is the risk we're accepting. For four weeks we'll be operating on credentials and devices we haven't verified, at a HIPAA-covered entity, on a stack whose last owner is leaving. What goes wrong in that window is an inherited admin account being used, or a backup that doesn't restore. I'd put the chance of a material incident in those four weeks at something like one in twelve, against roughly one in fifty once the baseline is done. The cost if it lands is the group's notification obligations and ours, and probably the contract. I need the client's CEO to sign that acceptance in writing, in those words."
"And here is what would change my answer to a clean yes: three things before the first. Reset every administrative credential the day the contractor leaves, enforce MFA on the EHR and email that week, and test-restore one server before we touch anything else. Five working days, and I need the contractor's cooperation for the first one."
Castellano takes the second version to the client. The client's CEO, who had never been told what a takeover involves, signs the acceptance, funds the five days, and — because Marsh's numbers were ranges rather than a wall — asks what it would cost to have the whole baseline done in three weeks. The answer becomes a paid accelerated-onboarding tier that Harbor Line now sells.
INTERPRETATION Nothing about Marsh's temperament changed. Her skepticism reached the decision as a price rather than a refusal, and the CEO's optimism reached the client as a bet with a named owner rather than a promise. The filters produced two people who would always disagree about the first of the month; the Risk Corollary let them disagree usefully.
Leader Contrast
Put three archetypes in Marsh's chair, facing the same nineteen days.
The Technical CISO says no, and says it well. Six weeks is what the work takes; a takeover on unverified credentials at a covered entity is not a risk to be priced but a mistake to be prevented. The gain is real: if the inherited environment is as bad as most are, the Technical CISO has kept Harbor Line's name off a breach notification. The cost is that the decision never reaches the client as a choice, Castellano hears a wall rather than a price, and next time he asks the account manager instead. Ashenden and Sasse's (2013) "perceived lack of power" is often self-inflicted this way: power only ever used to refuse is power the organization learns to route around.
The Business-Risk CISO says yes and prices it — but the temptation is to price it to the CEO's liking, with ranges becoming point estimates that land where the deal closes. The gain is the deal and a CEO who thinks of security as an enabler. The cost is that "yes as identity" slowly under-prices every risk, and the day the inherited admin account is used, the acceptance turns out to have been priced by someone who wanted to be liked. Enablement without institutional paranoia is a liability with good manners.
The Enterprise CIO, dropped into a 120-person MSP, reaches for governance: a steering committee, an onboarding policy with an exception process, a risk register the client's board can review. Each instrument is right at 5,000 people and wrong at 120, where the exception process is a conversation and the risk register is Marsh's notebook. The gain is the mechanism Harbor Line will need at 500 people; the cost is that the nineteen days pass while it is designed. This is Module 8's "enterprise CIO in a 40-person company" mismatch, seen from the client's side.
Marsh's path — priced yes, conditional no, both in writing — is available to all three. None of their defaults lands there without effort.
Failure mode
The technology executive's temperament fails in two opposite directions, and the Overuse Ladder describes both.
INTERPRETATION The CISO side climbs skepticism → cynicism and caution → paralysis. Skepticism, the trait that finds the misconfiguration everyone else missed, becomes a reflexive assumption that every request is a threat. Caution, the trait that insists on the test restore, becomes the CISO who is never breached because nothing is ever deployed. Rigor climbs to bureaucracy — the security review that ships nothing — and "no" stops being an answer and becomes an identity. The organization adapts: it stops asking. Projects route around the security function, the CEO finds an account manager who will say yes, and the CISO, now consulted on nothing, experiences the isolation Ashenden and Sasse (2013) describe and blames the organization's immaturity rather than the wall.
The CIO side climbs optimism → delusion and urgency → recklessness. The builder's belief that the platform will work becomes an inability to hear that it is not; the migration date announced to the board becomes a fact the engineers must not contradict; and the combined CIO/CISO finds the builder's half quietly overruling the risk officer's half in every meeting, because the builder's half is the one the CEO rewards.
HYPOTHESIS The combined role has a failure mode of its own: alternation. Under pressure the CIO/CISO does not integrate the two arguments but switches between them — a builder on Monday, a risk officer on Thursday — and the organization learns that the technology executive's answer depends on their mood.
Early warning signs, for the executive or the CEO watching them:
- The security function's answer can be predicted before the question is asked, and the prediction is "no."
- Requests for exceptions have stopped arriving — not because the controls are accepted but because people have learned where to go instead.
- The technology executive has not accepted a priced risk in writing in two quarters; every yes was unconditional or every no was.
- The CEO describes the CIO/CISO as "great, but you have to manage them," and the CIO/CISO describes the CEO as someone who "doesn't get it."
- Reported security incidents are falling, and nobody has asked whether reporting is falling with them.
The correction is not a different temperament. It is the recognition that the temperament is a default, that the default is where the filters left you, and that the job from here on is learning to move it.
Personal reflection
- Which of the four filters shaped you most: choosing technology, being promoted out of engineering, being appointed to build or to prevent, or surviving an incident? What did each reward in you, and what did it let you avoid learning?
- Describe the CEO you work for (or the client CEOs you serve) in base-rate terms. Are they more or less optimistic than the roughly four-in-five figure for US CEOs? How has your own default adjusted to theirs — and in which direction?
- Write down the last three times you said no to a business request. For each: did you say what would change your answer? If not, what did the requester do next?
- Write down the last three times you said yes. For each: did you price the risk being accepted, and did someone other than you sign for it?
- Which rung — skepticism → cynicism, caution → paralysis, optimism → delusion, urgency → recklessness — is closest to your reflex under pressure? What is the evidence from the last year?
- If you hold both jobs: in the last month, which half of you won more arguments inside your own head, the builder or the risk officer? Was that the right half for the month you were having?
Ridiculous For Someone At My Level
Bellhaven Business Services · Business-process outsourcing and managed IT/security services for SMB and mid-market clients · $18M · Scale-up · Private
The account manager's call is tomorrow. Kestrel is 22% of revenue and the reference account for the firm's entire financial-services pipeline. Your engagement letter makes you an adviser and implementer under the client's direction — you do not own the decision, only the consequences of it.
Take the decision →Knowledge check
Pick an answer to reveal the explanation. Nothing is scored or stored.
1Graham, Harvey and Puri (2013), from the CEO library, found which of the following?
The study surveyed CEOs and CFOs, not technology executives; it found associations, not causes; and it is the base-rate reason the CISO's disposition will meet resistance.
2"CISOs tend to be skeptical" is best described in this course as:
There is no psychometric study of CISOs in the library; the profile is inferred from the filters, and selection is not prescription.
3In one or two sentences, explain why the tension between a CEO and a CISO is structural rather than personal, and name the tool this course gives the CISO for managing it.
Model answer. The CEO is drawn from a population selected for optimism and risk tolerance and the CISO from one selected for vigilance and doubt, so the disagreement exists whoever holds either chair; the Risk Corollary — "Yes, and here is the risk we're accepting, priced" / "No, and here is what would change my answer" — turns it into a priced decision rather than an argument about temperament.
Reading a base rate as a biography is the error the module is built to prevent, in both directions.
4The IANS and Artico Search (2026) figures — 64% of CISOs reporting to IT leaders, 52% describing the role as not manageable — may be used in this course as:
A self-selected survey by firms with a commercial interest describes prevalence and nothing else.
Key takeaways
- The CEO population is unusually optimistic and risk-tolerant on the best available evidence, and the technology executive works for it; the CISO's disagreement with the CEO is structural, not personal.
- CIOs and CISOs pass through four filters — choosing technology, promotion out of engineering, appointment to build or to prevent, surviving incidents — that select for a builder's temperament in the CIO and "enablement with institutional paranoia" in the CISO. This is a hypothesis; no psychometric study of technology executives exists in our library.
- "CISOs tend to be X" is a base rate; "X makes a good CISO" is an unsupported causal claim. Visibility ≠ prevalence; visibility ≠ effectiveness.
- The technology executive's discretion is granted, not assumed — hence the Fit Equation's Reporting Line term — and it spikes in incidents and post-breach budget cycles, exactly when dispositions run unsupervised.
- The Risk Corollary — "Yes, and here is the risk we're accepting, priced" / "No, and here is what would change my answer" — is how a selected skeptic and a selected optimist disagree usefully. Know your default; the rest of the course is about moving it.
Research cited in this module
- Graham et al. (2013)Managerial attitudes and corporate actions. Journal of Financial Economics · tier 2 · verified
- Kaplan & Sorensen (2021)Are CEOs different?. Journal of Finance · tier 2 · verified
- Ashenden & Sasse (2013)CISOs and organisational culture: Their own worst enemy?. Computers & Security · tier 1 · verified
- Maynard et al. (2018)Defining the strategic role of the Chief Information Security Officer. Pacific Asia Journal of the Association for Information Systems · tier 1 · verified
- Karanja (2017)The role of the chief information security officer in the management of IT security. Information & Computer Security · tier 1 · partially verified
- ians2026 (2026). State of the CISO 2026 Benchmark Report · tier 1 · verified
- Peppard (2010)Unlocking the performance of the chief information officer (CIO). California Management Review · tier 1 · verified
- Preston et al. (2008)Examining the antecedents and consequences of CIO strategic decision-making authority: An empirical study. Decision Sciences · tier 1 · partially verified
- Haislip et al. (2021)The impact of executives' IT expertise on reported data security breaches. Information Systems Research · tier 1 · verified
- Hambrick & Finkelstein (1987)Managerial discretion: A bridge between polar views of organizational outcomes. Research in Organizational Behavior · tier 1 · verified
- Hambrick (2007)Upper echelons theory: An update. Academy of Management Review · tier 1 · verified
- Li & Tang (2010)CEO hubris and firm risk taking in China: The moderating role of managerial discretion. Academy of Management Journal · tier 1 · verified
- verizon2025 (2025). 2025 Data Breach Investigations Report · tier 1 · verified
Each entry opens the research card with method, limitations and the usable claim.