The Trait Dial for Technology Leaders — Eight Dials and Two Overlays
Mediocre technology leaders run on one setting — usually the one that got them promoted. Exceptional CIOs and CISOs move the dial, and know which two dials the role adds.
Learning objectives
- Apply the eight dials to technology decisions: aggression↔caution on a cloud migration, decisiveness↔inquiry in an incident, hands-on↔delegation for the former engineer, centralization↔decentralization on platform versus product teams.
- Use the two overlay dials — Control↔Enablement and Prevention↔Resilience — as FRAMEWORK, and map each to the eight schema dials.
- Apply the Overuse Ladder with technology-specific rungs, including rigor→bureaucracy as 'the security review that ships nothing' and caution→'never breached because nothing is ever deployed.'
- Read the four contextual signals — threat level, regulatory posture, balance sheet, deal cycle — that should move a dial.
Core lesson
The CEO course's Trait Dial — eight paired settings, neither pole a virtue, a default on each set by temperament and reinforced by whatever worked last time — transfers to the technology executive unchanged. What changes is the decisions the dials are applied to, and two settings the role adds.
FRAMEWORK The eight dials are aggression↔caution, decisiveness↔inquiry, optimism↔skepticism, hands-on↔delegation, urgency↔patience, unilateral↔consensus, innovation↔operational discipline, and centralization↔decentralization. This module applies them to a cloud migration, an incident, a former engineer's team, and a platform-versus-product-team argument. It then adds two overlay dials — Control↔Enablement and Prevention↔Resilience — which are not new data but new lenses: each is a combination of two schema dials that technology leaders move together so often that they deserve a name.
The Overuse Ladder acquires technology-specific rungs. Rigor becomes bureaucracy as the security review that ships nothing; caution becomes the CISO who is never breached because nothing is ever deployed.
In the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on Behaviors: the connection between your defaults and the situation. Four contextual signals — threat level, regulatory posture, balance sheet, deal cycle — tell you when to move.
The big idea
Mediocre technology leaders run on one setting — usually the one that got them promoted. Exceptional CIOs and CISOs move the dial, and know which two dials the role adds.
The engineer promoted for caution runs caution; the architect promoted for boldness runs boldness; the CISO hired after a breach runs control. Each was right once. The evidence on executive traits keeps finding inverted-U shapes and dualities, not "more is better," and the technology role adds a structural twist: the same person is often paid to build and to preserve, which means running one setting is not just suboptimal but self-contradictory.
What the research says
RESEARCH FINDING The shape of the evidence is Zhang and Rajagopalan (2010, from the CEO library). Among 193 US CEOs who departed between 1993 and 1998, the level of strategic change had an inverted-U relationship with firm performance: moderate change was associated with better results, excessive change with worse, and both effects were larger for outside CEOs. Modest sample, archival proxies, accounting performance, observational. What it supports: neither "change more" nor "change less" is a strategy. INTERPRETATION For the technology executive this is the transformation finding — the Transformation CIO's mandate has a peak, and past it the ERP-plus-cloud-plus-reorg program becomes the thing that fails.
RESEARCH FINDING Herrmann and Nadkarni (2014, from the CEO library) found the duality inside a trait. In 120 Ecuadorian SMEs, CEO conscientiousness hindered the initiation of strategic change but improved the performance of changes that were implemented; extraversion and openness related to initiation only. Small-firm, single-country, cross-sectional survey. INTERPRETATION This is the innovation↔operational discipline dial in one finding, and it is the reason the overlay dial Prevention↔Resilience exists: the discipline that makes patching reliable is the discipline that makes the platform change slow.
RESEARCH FINDING Owens and Hekman (2012, from the CEO library), from 55 leader interviews, found that humility — high inquiry, high consensus — works only from a leader perceived as competent, and appears less effective under extreme threat or time pressure. Qualitative, not CEO- or CISO-specific. What it supports: the decisiveness↔inquiry dial has a context that moves it, and an incident is that context.
RESEARCH FINDING Angst, Block, D'Arcy and Kelley (2017) is the most important security-specific finding for the dial. In a matched panel of over 5,000 US hospitals and 938 breaches from 2005 to 2013, hospitals were classified as "symbolic" or "substantive" adopters of IT security practices based on institutional factors; symbolic adopters tended to belong to smaller systems and to be older, smaller, for-profit, non-academic, faith-based and less IT-entrepreneurial. Symbolic adoption diminished the effectiveness of security investment and was associated with an increased likelihood of breach; deeper integration of security into IT routines was associated with fewer breaches. One sector, adoption depth inferred from institutional profile rather than observed, reported breaches only. What it supports: a Control setting that produces policy without integration buys nothing. What it cannot support: which hospitals' leaders chose which setting, or why.
RESEARCH FINDING Kwon and Johnson (2014), using a Cox proportional-hazard model on US healthcare organizations, found proactive security investments associated with lower subsequent failure rates and better cost-effectiveness than reactive investments, and — the finding that matters for the contextual signals — that "external pressure decreases the effect of proactive investments on security performance." Archival, one sector, disclosed breaches only. What it supports: the Prevention↔Resilience dial rewards moving before the event; and regulatory pressure, which pushes leaders toward compliance-shaped spending, can weaken the benefit of the spending it forces.
RESEARCH FINDING Kamiya, Kang, Kim, Milidonis and Stulz (2021), in an archival event study of successful cyberattacks on US firms, found that attacks exposing personal financial information were associated with shareholder losses much larger than out-of-pocket costs, that firms whose boards had attended to risk management before the attack suffered smaller excess losses, and that after an attack firms increased risk-management and IT investment and reduced managers' risk-taking incentives. Board attention is proxied; associations. What it supports: the organization's own dial moves after an attack, toward caution and control, whether or not the executive moves it — which is why the post-breach setting is so often over-applied later.
RESEARCH FINDING Three CEO-library findings establish that defaults are sticky and drift. Bertrand and Schoar (2003, from the CEO library) showed managers carry persistent decision "styles" across firms. Hambrick and Fukutomi (1991) proposed that tenures pass through seasons ending in convergence and dysfunction — a conceptual model. Chatterjee and Hambrick (2011) found highly narcissistic CEOs, by proxy measures, discounted objective performance feedback and amplified risk after media praise. What these support together: the setting hardens with success, and the technology leader who has just had a clean year is the one whose dial most needs checking.
RESEARCH FINDING (Tier 3, descriptive). The Verizon 2025 Data Breach Investigations Report, a practitioner report drawn from a non-random contributor sample of 12,195 confirmed breaches, reports ransomware present in 44% of breaches and in 88% of SMB breaches, third-party involvement in 30%, and the human element in roughly 60%. Base rates only. Gordon and Loeb (2002), an analytical model rather than an empirical study, shows that under the breach-probability functions the authors assume the optimal security investment does not exceed 37% of the expected loss from a breach — a reasoning tool whose assumptions must be stated whenever the figure is used. INTERPRETATION Together they supply the threat-level and balance-sheet signals: the base rate tells you what is likely; the Gordon–Loeb logic tells you that "spend until safe" is not a setting.
Where the evidence is weak
No study tests the Trait Dial or the overlays; they are frameworks built to organize findings made separately. The inverted-U evidence is about strategic change at CEO level. Angst et al. and Kwon and Johnson are single-sector healthcare studies of investment, not of leaders' settings. The claim that a technology executive who deliberately moves a setting does better than one who does not is the course's working HYPOTHESIS, not a demonstrated result.
Explanation
How to read a dial
FRAMEWORK Each dial has two poles, neither a virtue; a default, where you sit when not thinking about it; and a range you can reach with effort. Calibration has three parts: know your default from behavior rather than self-description, read the signals that call for a different setting, and recognize the overuse failure at each end so you know when you have gone too far. Dials move in clusters: a CISO who moves toward caution usually moves toward centralization and control at the same time. That cluster is the post-breach profile, and it is right after a breach. The failure is running it three years later.
The eight dials, applied
Aggression ↔ Caution — the cloud migration. Aggression is the seven-month lift-and-shift with hardening afterward; caution is hardening first and accepting the slip. Signals for aggression: a lease that ends, a balance sheet that can absorb a miss. Signals for caution: an active campaign against your sector, thin cash, an identity platform you do not yet trust. Overuse of aggression: risk tolerance → recklessness. Overuse of caution: the CISO who is never breached because nothing is ever deployed.
Decisiveness ↔ Inquiry — the incident. At 2 a.m. with a credential-stuffing alert, decisiveness is isolating the segment now; inquiry is thirty more minutes of log review first. Owens and Hekman (2012) supply the rule: under threat and time pressure, inquiry costs more than it buys. Signals for inquiry: an irreversible action (wiping the only evidence), a decision outside your competence (clinical systems), a team that has gone quiet. Overuse of decisiveness: the isolate-everything call that takes the business down harder than the attacker did. Overuse of inquiry: the incident call where nobody has been told to do anything.
Optimism ↔ Skepticism — the vendor's dashboard. Optimism is believing the migration partner's timeline and the MDR vendor's coverage claim; skepticism is asking for the evidence. Signals for skepticism: a green dashboard nobody has tested, a control on the slide and not on the server (Module 5), praise arriving faster than results. Overuse of optimism: the symbolic adoption Angst et al. (2017) found buys no protection. Overuse of skepticism: the CISO who cannot sign off on anything.
Hands-on ↔ Delegation — the former engineer. Hands-on is reading the alerts and reviewing the firewall rules yourself; delegation is setting the outcome and letting the security lead own the method. Signals for hands-on: a failing function, a new domain, a crisis. Signals for delegation: a lead who has earned it, a scale where your attention is the scarcest resource, a team that waits to be told. Module 8 is built on this dial.
Urgency ↔ Patience — remediation and program-building. Urgency is the ninety-day remediation sprint; patience is the two-year identity program. Kwon and Johnson (2014) reward moving before the event, which sounds like urgency and is actually patience: proactive investment is made when nothing is on fire. Overuse of urgency: a remediation pace the organization stops distinguishing from the executive's habit. Overuse of patience: the audit finding "in progress" for three cycles.
Unilateral ↔ Consensus — the policy and the exception. Unilateral is deciding the MFA policy and informing; consensus is deciding it with the business units. Signals for unilateral: a decision only you can own, a deadlock, an incident. Signals for consensus: a control the business must operate and could quietly route around. Overuse of unilateral: the CISO who says no and is routed around. Overuse of consensus: the exception register that grows every quarter.
Innovation ↔ Operational Discipline — the platform change and the patch. Innovation is the new platform and the re-architecture; discipline is patch cadence, baselines, backup tests. Herrmann and Nadkarni (2014) show the tension: the trait that finishes hurts starting. Overuse of innovation: tool churn — adaptability → strategy-of-the-month. Overuse of discipline: the security review that ships nothing.
Centralization ↔ Decentralization — platform versus product teams. Centralization is a single security function that gates every deployment; decentralization is security engineers embedded in product teams with the center setting standards. Signals for centralization: an integration, a compliance failure, a post-breach period, a company where the center is the only competence. Signals for decentralization: a scale the center cannot know, an engineering culture that ships daily, a CISO who has become the bottleneck.
The two overlay dials
FRAMEWORK Data stays on the eight schema dials. The overlays are taught narratively, because technology executives move certain pairs together so often that naming the pair is more useful than naming its parts.
Control ↔ Enablement ≈ centralization↔decentralization + caution↔aggression. At the Control end, the security function decides, gates and approves; at the Enablement end, the business decides within guardrails the function designs. Neither is a virtue. Control is right after a breach, during a consent order, in a 40-person company where the function is one person, and for any decision whose downside is unbounded. Enablement is right where the business ships faster than the function can review, where the engineering culture is strong, and where the cost of a gate exceeds the risk it screens. The Risk Corollary is the test: "Yes — and here is the risk we are accepting, priced" is an Enablement sentence with a Control-grade risk view behind it. A leader who can only say one of the two sentences is stuck at one end of this dial. Angst et al. (2017) is the warning at the Control end: policies adopted symbolically do not reduce breaches; integration does.
Prevention ↔ Resilience ≈ operational discipline↔innovation + patience↔urgency. At the Prevention end, spend goes to stopping the event: hardening, access control, patching, awareness. At the Resilience end, spend goes to surviving it: immutable backups, segmentation, incident readiness, recovery testing, insurance, the ability to run the clinic on paper for three days. Prevention is the discipline setting with patience — it works before the event and pays off slowly (Kwon & Johnson, 2014). Resilience is the innovation setting with urgency — it assumes the event and asks how fast you get up. The mature setting for most organizations is closer to Resilience than their instincts put them, because the base rates (Verizon, 2025, descriptive) make the event likely and the Gordon–Loeb logic makes "prevent everything" irrational. The failure at the Prevention end is the program that has never tested a restore; at the Resilience end, the program that has stopped patching because "we'll recover."
The contextual signals
FRAMEWORK Four signals should move a technology leader's dial, and the mature executive reads them in combination.
Threat level. An active campaign against your sector — four physician groups hit in six weeks — moves aggression toward caution and Prevention toward Resilience, this quarter. The base rate is not the signal; the base rate is always high. The signal is the change in it.
Regulatory posture. An exam cycle, a consent order, a new disclosure rule moves the dial toward Control and discipline. The Kwon and Johnson (2014) caveat is the trap: external pressure weakened the benefit of proactive investment, plausibly because compliance-shaped spending is symbolic spending. Under a regulator, the mature leader spends to pass the exam and separately spends to be secure, and knows the difference.
Balance sheet. Debt, covenant tests and runway move aggression toward caution and shorten the patience the organization can afford. A debt-free firm can absorb a two-month slip; a levered one may not survive a covenant test that a breach or a failed migration triggers. Gordon and Loeb (2002) is the reminder that the balance sheet also caps what rational security spending looks like.
Deal cycle. A pending acquisition, sale or financing moves the dial toward Control and discipline, because diligence will read your exception register, and toward urgency, because the deal has a date. It also raises the price of a breach: Kamiya et al. (2021) found the market re-prices cyber risk after an attack, and a buyer's diligence team does the same.
Knowing and moving your default
INTERPRETATION Ask a CISO where they sit and they describe where they would like to sit. The evidence that defaults are sticky (Bertrand & Schoar, 2003) says the honest source is behavior: the last ten consequential decisions, where each landed, whether the setting changed when the situation did. Three practices make calibration deliberate. Name the setting before deciding — "this is a decisiveness call." Ask what changed — the seasons model (Hambrick & Fukutomi, 1991) warns that the context moves faster than the leader's perception of it. Watch the overuse signals in Section 7 as leading indicators.
HYPOTHESIS The range a technology executive can reach on each dial predicts sustained effectiveness better than the default does, and the range can be widened by practice. The evidence establishes that context matters and defaults are sticky; it does not yet establish that leaders who train the dial outperform those who do not.
Example
Fictional composite. Coastal Federal Savings is a $2.4B-asset community bank headquartered in New London, Connecticut, with 540 employees, 31 branches, and OCC supervision. Maria Lindqvist has been its CIO and CISO for six years. Her default, by her own account and two 360s, sits toward caution, operational discipline and centralization — the profile the bank's board hired after a predecessor's failed core-banking project. It served the bank through a clean exam cycle and a ransomware wave that hit two regional peers.
Fourteen months ago three signals arrived within a quarter. The bank's board approved the acquisition of a $600M-asset savings bank in Rhode Island, closing in ten months. The core-banking vendor announced end-of-support for the on-premises version Coastal ran, with a hosted migration path. And the OCC's annual exam produced a matter requiring attention on third-party risk management — specifically, the bank's oversight of the fintech partners its retail team had signed without technology review.
Maria's default said: slow the migration, centralize the fintech decisions, and take the acquisition's technology integration in-house. That is the Control-and-Prevention cluster, and it had been right for six years. She ran it for about a month, and the signal that she was wrong came from the head of retail, who said in a leadership meeting that the fintech partners were the bank's only deposit growth and that the technology review process had become "where products go to wait."
What she did next is the calibration. She read the signals separately rather than as one threat. The deal cycle moved her toward urgency and discipline on the integration: she hired an integration lead and set a decision-rights table with the target's IT head within six weeks. The regulatory posture moved her toward Control on third-party risk — but she designed it as guardrails, not gates: a two-page intake, a risk tier, and a standing rule that tier-one partners got a decision in ten business days. The migration she moved, deliberately, toward aggression: the vendor's hosted platform had better identity and backup controls than the on-premises estate, so the migration was itself the Prevention-to-Resilience move, and delaying it for caution's sake would have kept the bank on the weaker footing longer.
She left one dial where it was and said so: on the acquisition's day-one connectivity she stayed at caution, because the target's network had never had a penetration test and the integration lead's first finding was a flat network with domain administrators on shared accounts. Day one ran on a segmented bridge for four months.
At the year's end the acquisition had closed, the migration was in its final wave, the OCC matter was closed, and the retail team had signed two new fintech partners through the intake process in under two weeks each. The exam letter noted the third-party program as improved. Maria's read: her default had been right for the bank she inherited and wrong for the bank she now ran, and the three signals had arrived at once precisely because the bank had grown into a different situation while she was still running the old setting.
Leader Contrast
Put four archetypes in Maria Lindqvist's chair the week the head of retail says "where products go to wait."
The Technical CISO hears a business complaint about a security process and reads it as evidence the process is working. Products should wait; that is what review is for. The fintech intake gets more thorough, not faster. The gain is that nothing gets signed without a control review. The cost is that the retail team routes around the process — shadow partnerships, pilots that are not called pilots — and the third-party risk the OCC flagged grows in the one place the CISO cannot see. This is the Control end held past what the situation can absorb, and it produces the symbolic-adoption profile: a strong policy, weakly integrated.
The Business-Risk CISO hears the complaint and moves fast to Enablement: a lightweight intake, a risk-tier model, fintech partners approved within days. The gain is deposit growth and a retail team that stops routing around security. The cost appears at the exam: an OCC examiner reading the tier-one approvals wants to see the evidence behind the tier, and a Business-Risk CISO who has priced the risk without documenting it has made the right decision in a form the regulator cannot accept. The Regulated-Industry signal was read too lightly.
The Transformation CIO sees three change programs and wants to run them as one — migration, integration and the third-party program combined into a fourteen-month transformation with a single steering committee. This is the Zhang and Rajagopalan (2010) inverted-U in a bank: past the peak, the change load exceeds what 540 people can absorb during an acquisition, and the migration wave that slips is the one the regulator asks about. The gain is momentum. The cost is the program that fails because it was three programs.
The Regulated-Industry CIO/CISO reads the exam letter as the whole situation and moves everything to Control and discipline until the matter is closed. This is the most defensible archetype in the room, and it is the one Maria's default resembled. The cost is the Kwon and Johnson (2014) caveat: spending shaped by the examiner's finding closes the finding and may do little for the bank's actual exposure, while the migration — the move that would have improved the identity and backup posture most — waits for a quieter year that a growing bank never gets.
INTERPRETATION Maria's move — three signals read separately, three dials moved in three directions, one dial held and named — is calibration. None of the four archetypes is wrong in general. Each is wrong for this bank this year in a different way.
Failure mode
FRAMEWORK The Overuse Ladder runs strength → overused strength → liability. The rungs are the CEO course's twelve; the technology versions are what they look like from the CISO's chair.
- Confidence → arrogance. "We would never fall for that." Signal: the CISO stops attending blameless reviews.
- Optimism → delusion. The dashboard is green and nobody has tested a restore. Signal: controls that exist only on the board slide.
- Persistence → stubbornness. The architecture I built is the architecture we keep. Signal: the new security lead's objections are answered with history.
- Decisiveness → impulsiveness. The isolate-everything call that takes down the clinics harder than the attacker would have. Signal: post-mortems where the response cost more than the attack.
- Attention to detail → micromanagement. The CISO who reads every alert. Signal: a SOC that waits for the executive before closing a ticket.
- Empathy → conflict avoidance. The exception granted to the owner, the CFO, the surgeon. Signal: an exception register nobody reviews.
- Dominance → intimidation. The CISO whose "no" ends conversations. Signal: business units bring finished projects to security, not proposed ones.
- Humility → excessive hesitation. Waiting for the complete risk assessment while the port is open. Signal: "still gathering information" at hour six.
- Risk tolerance → recklessness. Enablement without a priced risk view. Signal: "yes" said faster than the risk can be described.
- Vision → fantasy. A three-year architecture and a six-month-old critical vulnerability.
- Operational rigor → bureaucracy. The security review that ships nothing. Signal: time-to-approval measured in quarters.
- Adaptability → strategy-of-the-month. Tool churn — a new SIEM, EDR and framework each year. Signal: nobody can say which control is fully deployed.
INTERPRETATION The rungs pair off — rigor/adaptability, decisiveness/humility, dominance/empathy — because each pair is the two ends of a dial, and a leader who overcorrects from one usually lands on the other. The remedy for the review that ships nothing is not the review that approves everything.
INTERPRETATION The ladder is climbed after success. Chatterjee and Hambrick (2011) found praise, not performance, drove narcissistic CEOs' risk; Kamiya et al. (2021) found organizations move toward caution after an attack. The technology executive's most dangerous year is the one after the clean audit, and the most dangerous setting is the post-breach cluster held three years later.
Early warning signs
- The same setting was used for the last five major decisions regardless of their type.
- Time-to-approval for security review is measured in quarters, and nobody has calculated what it costs.
- The exception register is growing, and the executive can name the exceptions but not the risk each carries.
- The context has visibly changed — a deal, a regulator, a threat wave, a new balance sheet — and the security roadmap has not.
- The executive can name their strengths and cannot name the liability each becomes.
Personal reflection
- Take your last ten consequential technology or security decisions. Mark where each landed on aggression↔caution, decisiveness↔inquiry and centralization↔decentralization. How many settings did you use? Were the situations that different, or were you?
- Which of the two overlay dials describes the setting that got you promoted? Give one decision from the past year where that setting was wrong for the situation and you used it anyway.
- Name the last exception you granted that you would not have granted to someone with less standing. Which rung of the ladder were you on?
- Which of the four contextual signals — threat, regulator, balance sheet, deal — has changed for your company in the last year? Which dial did it move, and did you move with it?
- When did you last say "Yes — and here is the risk we are accepting, priced"? When did you last say "No — and here is what would change my answer"? If one is much easier than the other, which end of Control↔Enablement are you stuck at?
- If your engineers set your dial, where would their settings differ from yours? Have you asked?
One Migration, Two Companies
Northlake Physician Partners · Physician-practice management — 38 clinics across New York, New Jersey and Connecticut, HIPAA-covered · $410M · Mature · PE-backed
The lease ends in nine months against a seven-month plan. Pulling the three security controls forward adds two months by the partner's estimate; the landlord will extend at a 30% premium. In Context 2 there is also a covenant test in three quarters and an add-on acquisition closing in ten months whose target is meant to land on the new platform.
Take the decision →Knowledge check
Pick an answer to reveal the explanation. Nothing is scored or stored.
1Angst, Block, D'Arcy and Kelley (2017) found that in over 5,000 US hospitals:
The same investment was associated with fewer breaches only where adoption was substantive — deeper integration into IT routines — rather than symbolic.
2Zhang and Rajagopalan (2010) found the relationship between the level of strategic change and firm performance was:
Among 193 US CEOs, moderate change was associated with better performance and excessive change with worse — the shape behind the Transformation CIO's peak.
3State the mapping of each overlay dial to the eight schema dials.
Model answer. Control↔Enablement ≈ centralization↔decentralization + caution↔aggression; Prevention↔Resilience ≈ operational discipline↔innovation + patience↔urgency.
The overlays are teaching lenses, not new data; assessment and simulator data stay on the eight schema dials.
4Kwon and Johnson (2014) found that external pressure on US healthcare organizations:
Proactive investment was associated with lower failure rates, but regulatory pressure weakened the benefit — the trap behind the regulatory-posture signal, where compliance-shaped spending can be symbolic spending.
Key takeaways
- The eight dials transfer to the technology executive unchanged; what changes is the decisions — the migration, the incident, the former engineer's team, the platform-versus-product argument — and neither pole of any dial is a virtue.
- The role adds two overlay dials, Control↔Enablement and Prevention↔Resilience, each a named pair of schema dials; the Risk Corollary is the test of whether you can reach both ends of the first.
- Angst et al. (2017) and Kwon and Johnson (2014) supply the security-specific warnings: Control that produces symbolic adoption buys nothing, and regulatory pressure can weaken the benefit of the spending it forces.
- Four contextual signals — threat level, regulatory posture, balance sheet, deal cycle — should move a dial, and the mature leader reads them separately rather than as one threat.
- The Overuse Ladder's technology rungs — the review that ships nothing, the CISO never breached because nothing is deployed, the tool churn, the unreviewed exception register — are climbed after success, and the post-breach cluster held three years later is the most common one.
Research cited in this module
- Zhang & Rajagopalan (2010)Once an outsider, always an outsider? CEO origin, strategic change, and firm performance. Strategic Management Journal · tier 1 · verified
- Herrmann & Nadkarni (2014)Managing strategic change: The duality of CEO personality. Strategic Management Journal · tier 1 · verified
- Owens & Hekman (2012)Modeling how to grow: An inductive examination of humble leader behaviors, contingencies, and outcomes. Academy of Management Journal · tier 1 · verified
- Angst et al. (2017)When do IT security investments matter? Accounting for the influence of institutional factors in the context of healthcare data breaches. MIS Quarterly · tier 1 · verified
- Kwon & Johnson (2014)Proactive versus reactive security investments in the healthcare sector. MIS Quarterly · tier 1 · verified
- Kamiya et al. (2021)Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics · tier 1 · verified
- Bertrand & Schoar (2003)Managing with style: The effect of managers on firm policies. Quarterly Journal of Economics · tier 1 · verified
- Hambrick & Fukutomi (1991)The seasons of a CEO's tenure. Academy of Management Review · tier 1 · verified
- Chatterjee & Hambrick (2011)Executive personality, capability cues, and risk taking: How narcissistic CEOs react to their successes and stumbles. Administrative Science Quarterly · tier 1 · verified
- Gordon & Loeb (2002)The economics of information security investment. ACM Transactions on Information and System Security · tier 1 · verified
- verizon2025 (2025). 2025 Data Breach Investigations Report · tier 1 · verified
Each entry opens the research card with method, limitations and the usable claim.