Module 4Unit I. The Technology Executive's Mind80 minEquation term: Behaviors

Confidence, Overconfidence, and the Breach

Breaches do not fire technology executives; the response to breaches does — and the same overconfidence that builds a program can conceal its failure.

Learning objectives

  1. State precisely what Banker and Feng (2019) found about CIO turnover after breaches, why breach type matters, and what the study does not cover.
  2. Describe the SEC's 2023 cybersecurity disclosure regime as FACT, and the materiality determination inside it as judgment.
  3. Distinguish productive conviction from epistemic arrogance in a live incident, using observable behaviors rather than tone.
  4. Apply the Two-Sentence Test and the Risk Corollary under time pressure, as scheduled mechanisms rather than dispositions.

Core lesson

Anyone who has been in the room during a serious incident knows the two failure modes, and both are made of confidence. The first is the leader who will not commit: every hypothesis provisional, every decision waiting for more telemetry, the organization drifting because nobody said "we are treating this as X until 6pm." The second is the leader who commits and then stops listening: the first theory becomes the only theory, contradicting evidence becomes noise, and the room gets smaller.

This module is about the ridge between them, and about what happens afterwards. The evidence on executive turnover after breaches is more specific than the folklore — it concerns CIOs, not CISOs, and only one category of breach is charged to them. The disclosure regime is a legal fact with a four-business-day clock, and the judgment inside it is yours. And the psychology of overconfidence, borrowed from the CEO literature, names a dangerous pattern: discounting the unpleasant objective feedback your program generates while amplifying on the pleasant social feedback your role attracts. Productive conviction and epistemic arrogance look identical from outside for about an hour; after that they diverge in observable ways, and the divergence can be designed rather than hoped for.

In the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module changes the Current Moment term. An incident is the moment; how you hold confidence inside it is the variable.

The big idea

Not every breach is charged to the same executive — accountability follows the perceived scope of your duties, and the response you run is part of what decides which kind of breach yours becomes.

The first half is a research finding, stated carefully below. The second is an interpretation, and the reason this module exists: attribution happens in descriptions written after the fact, and what you can show you knew, priced and escalated beforehand is most of what those descriptions have to work with.

What the research says

Who loses their job, and for which breach

RESEARCH FINDING Banker and Feng (2019) matched disclosed breaches to executive changes and found that breaches attributed to system deficiency "increase CIO turnover likelihood by 72 percent," while breaches caused by criminal fraud or human error showed no significant association with CIO turnover. The pattern differs by seat: CEO turnover increased after both system-deficiency and human-error breaches, and CFO turnover showed no relationship at all. The authors frame it as "negative labor market consequences for executives who fail to meet performance expectations within the scope of their duties."

Three qualifications, none optional. This is a study of CIO turnover; there is no CISO turnover study in this library, and anyone quoting "72%" about CISOs is quoting something that was not measured. Breach-cause classification relies on public descriptions, so the study measures how breaches were characterized, not their underlying physics. And turnover is not always dismissal; these are associations.

RESEARCH FINDING Haislip, Lim and Pinsker (2021), using reported breaches from 2005 to 2017, found "CEOs with IT expertise are associated with fewer DSBs," that CFOs with IT expertise were less likely to report breaches, and that "the presence of a CIO as part of the TMT is significantly associated with reduced DSBs of all types examined." Expertise was coded from biographies; only reported breaches are observable; the CFO result may reflect reporting behavior. Associations, not a causal case for any appointment.

RESEARCH FINDING Higgs, Pinsker, Smith and Young (2016) found that over 2005–2014 "firms with technology committees are more likely to have reported breaches in a given year than are firms without the committee," and that "the presence of a technology committee mitigates the negative abnormal stock returns arising from external breaches." Reported breaches conflate occurrence, detection and disclosure; committee formation is endogenous. Visible board oversight changes both what gets reported and how it is priced.

Disclosure: the rule, and the concealment premium

FACT The SEC adopted its cybersecurity disclosure rules on 26 July 2023. Form 8-K Item 1.05 requires disclosure of a material cybersecurity incident — nature, scope, timing and material impact — within four business days after the registrant determines the incident is material. Regulation S-K Item 106, which appears as Item 1C in Form 10-K, requires annual disclosure of the processes for assessing, identifying and managing material cyber risks, the material effects of risks and prior incidents, the board's oversight of cyber risk, and "management's role and expertise in assessing and managing material risks." Comparable requirements apply to foreign private issuers on Forms 6-K and 20-F. Annual disclosure began with fiscal years ending on or after 15 December 2023 and incident disclosure from 18 December 2023, with smaller reporting companies given 180 additional days. The rule is a legal requirement, not a finding.

RESEARCH FINDING Amir, Levi and Livne (2018) compared attacks firms disclosed with attacks they withheld that outsiders later revealed: "withheld cyber-attacks are associated with a decline of approximately 3.6% in equity values in the month the attack is discovered, and disclosed attacks with a substantially lower decline of 0.7%." The authors estimate managers disclose when investors already suspect about a 40% likelihood of an attack. Attacks never discovered are unobservable by construction, and the period predates the SEC rules. RESEARCH FINDING Campbell et al. (2003) add the type condition — the significant market reaction appeared for breaches involving unauthorized access to confidential data and not otherwise — and Kamiya et al. (2021) found firms whose boards had attended to risk management before an attack suffered smaller excess losses. The response is priced, and so is the preparation.

Overconfidence, and how leaders respond to feedback

RESEARCH FINDING Malmendier and Tate (2008, from the CEO library) found that CEOs classified as overconfident — by an option-holding proxy (failing to diversify personal exposure to their own firm) and a press-portrayal proxy — were about 65% more likely to make an acquisition, and that the market reacted more negatively to their deals (about −90 basis points against −12 for other CEOs). Both measures are proxies, the panel predates 1995, and alternative explanations were addressed but not eliminated. Overconfidence is a measurable tendency to over-weight one's own judgment, with visible costs.

RESEARCH FINDING Chatterjee and Hambrick (2011, from the CEO library) introduced "capability cues" — contextual signals about one's current ability — and found CEO risk-taking generally rose after positive cues and fell after negative ones, but that highly narcissistic CEOs were much less responsive to objective performance feedback and considerably more responsive to social praise such as media coverage and awards. Archival panels (capital outlays 1992–2006; acquisition premiums 2001–2008), an unobtrusive index, associations.

RESEARCH FINDING Edmondson (1996) studied eight nursing units across two hospitals (146 respondents) and found units with stronger team climates and more active manager coaching showed higher detected error rates (r = .74 for coaching) — because error rates come from reporting systems that climate itself affects. Owens and Hekman (2012, from the CEO library) identified three observable humble-leader behaviors and found humility appears less effective under extreme threat or time pressure.

Where the evidence is weak

There is no study here of CISO turnover, of executives under the SEC rules, or of whether any response behavior changes how a breach is later attributed. Banker and Feng (2019) is the closest finding on executive accountability, and it concerns CIOs and public characterizations. The overconfidence literature is about CEOs, uses proxies, and transfers to the technology executive only by argument. Everything this module says about conviction inside an incident is FRAMEWORK and INTERPRETATION.

Explanation

The asymmetry, and what it implies

RESEARCH FINDING Start from the finding, exactly: system-deficiency breaches were associated with a 72% higher likelihood of CIO turnover; fraud and human-error breaches were not. The CEO's exposure was broader — turnover rose after system-deficiency and human-error breaches — and the CFO's was nil.

INTERPRETATION Read that as a map of perceived duty: the CIO owns the systems, the CEO the systems and the people, the CFO neither. The corollary is uncomfortable — whether a breach is yours depends less on what happened than on which story fits it. A stolen credential used by a criminal group is a fraud story; a clerk approving a fraudulent invoice is human error; an unpatched edge device with a known exploit is system deficiency. One intrusion can be described all three ways depending on where the account starts.

HYPOTHESIS The most consequential thing a technology executive does before an incident may therefore be documentary. If the exception log shows the edge device was flagged, priced and deferred by a named business signatory — Module 2's second decision right and Module 3's Risk Corollary — the account contains a fact no defensive narrative could supply afterwards. Nothing here tests that; it is the implication of a study showing attribution matters, plus the observation that attribution is built from records. Note what it does not license: building a record so blame lands elsewhere is a different activity from building one so decisions are visible, an organization tells them apart within a quarter, and the first destroys the reporting culture Module 5 depends on.

Overconfidence, translated

INTERPRETATION The CEO overconfidence literature transfers with one substitution. Malmendier and Tate's (2008) proxy is a CEO who declines to diversify away exposure to their own firm — behavior that says "my judgment about this company beats the market's." The security analogue is the executive who declines to expose their own program to independent judgment: no external red team, no third-party assessment, no standing second opinion, no adversarial review of the architecture they designed. HYPOTHESIS Under-diversified assurance is the equivalent, and unlike a personality it is visible in a calendar and a budget.

Chatterjee and Hambrick's (2011) capability cues are the sharper tool: risk-taking tracked feedback, but the most narcissistic executives discounted objective performance feedback and responded strongly to social praise. INTERPRETATION Security leadership offers a bad ratio of the two. Objective cues arrive as criticism — pen-test findings, control failures, missed detections, an audit reopening a closed item. Social cues are pleasant and abundant — a board compliment, a conference invitation, an award, a profile after a clean year. An executive who does not deliberately weight the first over the second is calibrated by the wrong signal; Module 12 returns to this as the celebrity problem.

Productive conviction versus epistemic arrogance, inside an incident

FRAMEWORK Both begin identically: the executive commits early and publicly to a working account, because an incident with no committed hypothesis is one where forty people investigate forty things. The divergence is structural and shows up in five places.

The claim. Conviction says "we are treating this as credential compromise on the build pipeline." Arrogance says "this is credential compromise on the build pipeline." One is a decision; the other is a fact that has not been earned.

The kill criteria. Conviction names in advance what would overturn the hypothesis: "if egress logs show nothing outbound from that subnet by 4pm, we are wrong." Arrogance never specifies what would change its mind, which is what makes contradicting evidence look like noise.

The clock. Conviction schedules the review at fixed intervals, with a named person whose job is to argue the alternative. Arrogance revisits when it feels like it, which under stress is never.

The room. Conviction gets larger as confidence rises, because a confident hypothesis is cheap to test. Arrogance narrows to the same three names.

The report upward. Conviction carries the confidence level and the alternative alongside the hypothesis. Arrogance reports only the hypothesis, because uncertainty feels like weakness — and a CEO who hears only certainty at hour six hears only betrayal at hour thirty.

INTERPRETATION These are mechanisms, not virtues, deliberately. Owens and Hekman (2012, from the CEO library) suggest humility appears less effective under extreme threat or time pressure — exactly the condition an incident creates. Do not rely on being humble at 3am: write the kill criteria into the procedure, put the review on the clock, and name the dissenter in the runbook before you need one.

The disclosure decision, as judgment inside a fact

FACT The rule's four-business-day clock starts at the materiality determination, not at discovery (SEC, 2023). INTERPRETATION That puts the judgment where the rule cannot reach. The determination is legal, financial and factual at once, which is why the technology executive's job in it is narrow and non-negotiable: give counsel and the CEO an accurate, current, uncertainty-labeled picture, including what is not yet known, and update it when it changes. Deciding materiality is not the CISO's call; corrupting the inputs to it is the CISO's failure. Amir et al. (2018) supply the economics — concealment is priced at discovery, not at the decision.

A documented case: the decision to conceal

FACT Joseph Sullivan, then Uber's chief security officer and previously Facebook's, was convicted in October 2022 of obstruction and misprision of felony for concealing Uber's 2016 breach, sentenced in 2023, and had the conviction affirmed by the Ninth Circuit on 13 March 2025 (United States v. Sullivan, No. 23-927).

Analyze the decision class, not the man. The course takes no position on his character, motives or the fairness of the outcome, and nothing in this curriculum's sources would support one. What the case establishes is narrower and more useful: concealing a breach from parties entitled to know it is a decision a security executive can personally be prosecuted for, and an appellate court has affirmed a conviction on those facts. The exposure is personal and criminal rather than merely corporate, which changes the calculus of any "we'll handle this internally" conversation. It predates the SEC rules, so the decision class exists independently of any disclosure regulation. And it is the pattern this module describes in its most consequential form: an executive with standing, inside an incident, deciding alone what other people needed to know.

The two sentences under time pressure

FRAMEWORK The Two-Sentence Test changes shape under time pressure. "We're going to do this" acquires a time box: "we act on this hypothesis until 4pm." "I was wrong. Change the plan" becomes an appointment rather than a virtue — the scheduled review is where it gets said on time, by design, instead of at hour thirty when it has become an admission.

The Risk Corollary runs the same way. "Yes — and here is the risk, priced": "Yes, we can restore the ERP tonight; the risk is reinfection from an image we have not finished validating — one chance in four, five more days down if it happens." "No — and here is what would change my answer": "Not tonight; what would change it is a clean differential on the two remaining images, six hours of work I can start now." Both require a price under time pressure, which is why Module 3 comes first.

Example

Fictional composite. Merrimack Instrument Corporation is a NASDAQ-listed precision-instruments manufacturer in Lowell, Massachusetts: $640 million in revenue, 2,300 employees. Ellen Barros is CIO; Dev Kapoor is CISO and reports to her. On a Tuesday at 06:40 the managed detection provider flags anomalous authentication against a build server in the firmware pipeline, inside a vendor-managed continuous-integration environment.

By 08:15 Kapoor has a hypothesis and states it as one: "We are treating this as a compromised service account in the CI tenant, with no movement into the plant networks. If we are wrong, the tell is outbound traffic from the plant VLANs to anything we cannot name, and we check at 12:00." He names the plant network engineer as designated dissenter, whose only job today is to argue the other case.

At 12:00 the dissenter has something. Not outbound traffic — a firmware build artifact signed nineteen hours before the authentication anomaly. The hypothesis is not merely incomplete; its timeline is backwards.

This is the moment the module is about. Kapoor's credibility is attached to the 08:15 account, the CEO has been briefed on it, and treating the artifact as a logging anomaly would cost nothing today. Instead the review does what it was built for: "I was wrong about the timeline. We are now treating this as a supply-chain compromise of the build environment, duration unknown. Confidence medium. The alternative I cannot exclude is a mislabeled rebuild, and I will know by 18:00."

Then the disclosure question. Counsel opens the materiality file; the CFO models exposure. Kapoor's job is inputs — what is known, what is not, what would change each. He declines to offer an opinion on materiality and says so when the CEO asks, then adds what the CEO actually needs: the four-business-day clock under Form 8-K Item 1.05 begins when the company determines materiality (SEC, 2023), so the pace of that determination is a decision to make deliberately rather than by drift.

Three days later the attribution question arrives as a draft statement. System deficiency, or criminal intrusion? Both descriptions are available. The CI environment had been flagged eight months earlier in an architecture review — no separate signing enclave, shared service credentials, no independent verification of build artifacts. Kapoor priced remediation at $310,000, recommended it, was deferred a quarter on cost, and because Merrimack runs its exception log properly the deferral is signed by the COO in Kapoor's own words.

INTERPRETATION That signature does not protect Kapoor's job and is not meant to. It makes the eventual account accurate in a way no post-incident narrative could: a known weakness, priced, escalated and consciously accepted, followed by an intrusion that exploited it. Merrimack discloses; the COO's deferral practice does not survive the quarter; and the review that gets written is about the decision rather than about who to blame.

Leader Contrast

Hour six at Merrimack, four archetypes in Kapoor's chair.

The Technical CISO is deepest in the artifacts and slowest to commit. Every hypothesis stays provisional because the evidence genuinely is incomplete — true, and at hour six unhelpful. The gain is that this archetype rarely commits to a wrong account. The cost is that forty people investigate forty things, the CEO gets no usable statement, and the vacuum is filled by whoever is most confident in the room, usually a vendor. The Overuse Ladder rung is humility → hesitation, and it costs more in an incident than anywhere else.

The Business-Risk CISO commits early, communicates well, and briefs upward with a clean narrative. The gain is an organization that moves. The risk is what Chatterjee and Hambrick (2011, from the CEO library) describe from the other end: responsiveness to the social cue — the CEO's visible relief at a clear story — and slowness to weight the objective cue that contradicts it. The scheduled hypothesis review is the control for this archetype, and it works only if someone other than the CISO owns the calendar entry.

The Post-Breach CISO (Turnaround), brought in after a prior failure, centralizes hard: single bridge, single voice, decisions in hours. Often correct — a program that has just failed usually needs less consultation, not more. But a narrowed room is the shape epistemic arrogance takes, so the archetype most likely to be right about strategy is the most likely to miss the artifact at 12:00. The mitigation is not more consultation; it is a named dissenter and a review on the clock.

The Regulated-Industry CIO/CISO has the disclosure machinery built — counsel in the first hour, the materiality file open, the audit committee on a schedule — so nobody improvises the legal question at 3am. The cost is subtler: when the disclosure clock dominates, the incident gets managed toward a defensible filing rather than toward the truth about the environment. INTERPRETATION The tell is the first time someone edits a timeline for how it will read rather than for whether it is right.

Failure mode

Confidence becomes destructive on two rungs of the Overuse Ladder, and the incident context accelerates both.

INTERPRETATION Confidence → arrogance is the classic path: the hypothesis becomes an identity, the dissenter is reframed as unhelpful, the bridge narrows, and the executive stops distinguishing "I decided this" from "this is true." The mechanism is not stupidity — under time pressure a committed hypothesis is enormously efficient, and abandoning it is expensive, visible and personally costly at the moment the executive has least slack.

Optimism → delusion is slower and operates between incidents: the executive who reads a quiet quarter as a working program, when Edmondson (1996) shows low reported-error counts can equally mean people stopped reporting. Paired with the capability-cue asymmetry, it produces a leader fed by conference invitations and starved of pen-test findings.

Decisiveness → impulsiveness is the third, specific to hour one: declaring the incident contained before the evidence supports it, because closure is what everyone in the building wants from you.

Early warning signs, for the executive, the CEO or the board:

  • Nobody in the last three incidents can name the evidence that would have overturned the leading hypothesis.
  • The incident bridge has fewer people on it at hour twelve than at hour two, and no one decided that.
  • The program has had no external red team, third-party assessment or adversarial architecture review in a year.
  • Reported near-misses and phishing reports are falling, and this is being presented as improvement.
  • Post-incident reviews name people more often than they name decisions.

Personal reflection

  1. Take your last serious incident. What was your hour-one hypothesis, and what evidence had you named in advance that would overturn it? If none, what were you actually doing when you said you were investigating?
  2. Who is the designated dissenter in your incident procedure — by name, in the document? If nobody, who plays that role informally, and what has it cost them?
  3. Over the last twelve months, what exposed your program to independent judgment — red team, third-party assessment, adversarial review? If the answer is thin, is that a budget decision or a preference?
  4. Of the last five significant pieces of feedback about your program, how many were objective (findings, failures, misses) and how many social (praise, invitations, recognition)? Which set changed a decision?
  5. If a breach at your company were described three ways — criminal fraud, human error, system deficiency — which would the public record best support, and what did you do this year that determines the answer?
  6. Write the sentence you would say to your CEO at hour twelve if your hour-one account turned out to be wrong. Say it out loud. Is the discomfort about the company or about you?
Simulation · this module · ~10 min

Eleven Of A Hundred And Forty

Narragansett Business Services · Business-process outsourcing and managed IT/security services, New England · $28M · Scale-up · Founder-owned

You decide by noon. Full scoping takes about 96 hours; a partial answer for the top 40 by sensitivity takes about 24. Logging retains 30 days and the token may have been valid longer, so the picture you have at 09:00 may be structurally incomplete. The MSAs set a duty to notify with no deadline attached to it.

Take the decision →

Knowledge check

Pick an answer to reveal the explanation. Nothing is scored or stored.

1Banker and Feng (2019) found that:

2Under the SEC's 2023 rules, the four-business-day Form 8-K Item 1.05 clock begins:

3Which behavior best distinguishes productive conviction from epistemic arrogance in an incident?

4Your reported phishing clicks and near-misses fell 40% this quarter and the CEO calls it progress. Using Edmondson (1996), what do you say?

Key takeaways

  • Banker and Feng (2019) found breaches attributed to system deficiency associated with a 72% higher likelihood of CIO turnover, with no significant association for breaches caused by criminal fraud or human error. CEO turnover rose after system-deficiency and human-error breaches; CFO turnover did not move. It is a CIO study, and it measures how breaches were publicly characterized.
  • Because attribution is built from records, what you priced, escalated and got signed before the incident is most of what the eventual account has to work with — an implication, not a finding, and not a licence to build a record aimed at blame.
  • Overconfidence in this role looks like under-diversified assurance (no red team, no third-party assessment, no standing second opinion) and like weighting social praise over objective findings — the capability-cue asymmetry Chatterjee and Hambrick (2011) describe.
  • The SEC's four-business-day clock starts at the materiality determination (SEC, 2023). Deciding materiality is not the security executive's call; supplying accurate, uncertainty-labeled inputs to it is. Concealment is priced at discovery (Amir et al., 2018) and, as the Sullivan case establishes, can be prosecuted personally.
  • Productive conviction is a mechanism, not a temperament: a time-boxed hypothesis, named kill criteria, a scheduled review, a designated dissenter, and a briefing that carries the confidence level upward with the conclusion.

Research cited in this module

  • Banker & Feng (2019)The impact of information security breach incidents on CIO turnover. Journal of Information Systems · tier 2 · verified
  • Haislip et al. (2021)The impact of executives' IT expertise on reported data security breaches. Information Systems Research · tier 1 · verified
  • Higgs et al. (2016)The relationship between board-level technology committees and reported security breaches. Journal of Information Systems · tier 2 · verified
  • sec2023 (2023). Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure · tier 1 · verified
  • Amir et al. (2018)Do firms underreport information on cyber-attacks? Evidence from capital markets. Review of Accounting Studies · tier 1 · verified
  • Kamiya et al. (2021)Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics · tier 1 · verified
  • Campbell et al. (2003)The economic cost of publicly announced information security breaches: Empirical evidence from the stock market. Journal of Computer Security · tier 1 · verified
  • Edmondson (1996)Learning from mistakes is easier said than done: Group and organizational influences on the detection and correction of human error. The Journal of Applied Behavioral Science · tier 1 · verified
  • Malmendier & Tate (2008)Who makes acquisitions? CEO overconfidence and the market's reaction. Journal of Financial Economics · tier 2 · verified
  • Chatterjee & Hambrick (2011)Executive personality, capability cues, and risk taking: How narcissistic CEOs react to their successes and stumbles. Administrative Science Quarterly · tier 1 · verified
  • Owens & Hekman (2012)Modeling how to grow: An inductive examination of humble leader behaviors, contingencies, and outcomes. Academy of Management Journal · tier 1 · verified

Each entry opens the research card with method, limitations and the usable claim.

Related

Dials exercised
Decisiveness ↔ InquiryHands-on ↔ DelegationOptimism ↔ SkepticismUnilateral ↔ Consensus