Module 7Unit II. The Signature Frameworks, Adapted85 minEquation term: Traits

The Maturity Model for CIOs and CISOs — Temperament, Capability, Maturity, Fit

Temperament gets you into technology, capability gets you the title, maturity keeps your strengths from becoming the reason you were replaced, and fit decides whether any of it works here.

Learning objectives

  1. Populate the four levels for the technology executive: Temperament (uncertainty tolerance, agency, emotional regulation under incident); Capability (architecture, vendor and capital judgment, incident command, communication upward, risk quantification, talent); Maturity (calibration, receiving bad news, distinguishing ego from evidence, letting the business own its risk); Fit (this company, reporting line, regulator, stage, mandate).
  2. Explain why the levels are ordered and why a surplus at a higher level does not substitute for a deficit below it.
  3. Self-locate on each level with evidence — artifacts, attributed outcomes and other people's ratings — rather than adjectives.
  4. Use the model as a CEO or board would, to tell a capability gap from a maturity gap from a fit gap in a sitting CIO or CISO.

Core lesson

The CEO course's Maturity Model — four ordered levels, each presupposing the one below — is the organizing structure of this edition too. What changes for the technology executive is the content of every level and the weight of the top one.

FRAMEWORK Level 1, Temperament: uncertainty tolerance, agency, emotional regulation under incident. Level 2, Capability: architecture, vendor and capital judgment, incident command, communication upward, risk quantification, talent. Level 3, Maturity: calibration, receiving bad news, distinguishing ego from evidence, and letting the business own its risk. Level 4, Fit: this company, this reporting line, this regulator, this stage, this mandate.

The levels are ordered and non-substitutable. A mature, well-placed CISO who cannot price a risk is a well-liked bystander. A capable, well-placed CISO without maturity runs the Overuse Ladder until the strengths become the reason for the exit.

INTERPRETATION One thing is heavier here than in the CEO edition. A CEO's discretion is broad by default; a technology executive's is granted by someone else — which makes Level 4 the largest source of failure and, unusually, partly negotiable. You cannot renegotiate your temperament. You can renegotiate a reporting line.

In the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — Temperament is Traits, Capability and Maturity are Behaviors, and Fit is those multiplied by Context and Moment.

The big idea

Temperament gets you into technology, capability gets you the title, maturity keeps your strengths from becoming the reason you were replaced, and fit decides whether any of it works here.

Nearly all technology-executive development spend goes to Level 2 — frameworks, certifications, board-communication coaching. Nearly all technology-executive failure happens at Levels 3 and 4. The model exists to stop a capability gap, a maturity gap and a fit gap from being treated as one problem with one remedy, because two of the three remedies will then be wrong.

What the research says

The model is a synthesis. Each level rests on evidence introduced earlier; the ordering and the non-substitutability claim are INTERPRETATION built from the pattern of findings, not a tested result.

RESEARCH FINDING— Level 1. The temperament case begins as a contrast. Graham, Harvey and Puri (2013, from the CEO library) found CEOs substantially more risk-tolerant and optimistic than population norms — roughly 80% of US CEOs classified as very optimistic against about 65% of CFOs. Cross-sectional and self-reported: it supports an unusual executive temperament, not that the CIO's or CISO's is the same one, and no comparable psychometric study of technology executives exists in this library. From inside the role, Ashenden and Sasse (2013) interviewed five CISOs and found them naming a perceived lack of power, confusion about role identity and an inability to engage employees as their main obstacles — illustrative, not generalizable. The IANS and Artico State of the CISO 2026 survey of more than 600 security leaders (Tier 3, practitioner, self-selected) reports 52% saying their responsibilities are not manageable with current resources and 69% open to changing jobs within the year. INTERPRETATION That is the load the temperament level has to bear.

RESEARCH FINDING— Level 2. Maynard, Onibere and Ahmad (2018), in a systematic review across information security and strategic management, concluded that the CISO's role as a strategist is under-theorized and proposed a competency set for it — a framework contribution that does not test whether having the competencies improves outcomes. Gordon and Loeb (2002) supply the discipline behind one cluster: an analytical model in which optimal security investment depends on an information set's value, vulnerability and the productivity of spending, and in which — for the breach-probability functions the authors assume — optimal investment does not exceed about 37% of expected loss. Not empirical, and the assumptions must be stated whenever the figure is used.

RESEARCH FINDING— where Level 2 meets Level 4. Preston, Chen and Leidner (2008) studied CIO strategic decision-making authority; its abstract could not be verified here, so it is cited only for the general proposition. Its peer-reviewed practitioner companion (Preston, Leidner & Chen, 2008, MIS Quarterly Executive) crosses authority with capability into four profiles — IT Orchestrator, IT Advisor (capability without authority), IT Mechanic (authority without capability) and IT Laggard — and reports that IT's contribution varies by profile. INTERPRETATION This module's central claim as a two-by-two.

RESEARCH FINDING— Level 3. Owens and Hekman (2012, from the CEO library), from 55 leader interviews, identified admitting limits, spotlighting others' strengths and modeling teachability as observable humble-leader behaviors — working only from a leader perceived as competent, and less well under extreme threat or time pressure. Edmondson (1996) gives the security version of receiving bad news: across eight nursing units in two hospitals (146 respondents), units with better team climate and more active manager coaching showed higher detected error rates (manager coaching correlated with detected errors at r = .74). Correlational and in healthcare, but the lesson transfers: a low incident count can mean silence rather than safety. Cram, D'Arcy and Proudfoot (2019), meta-analyzing 95 papers across 17 antecedent categories, found employees' attitudes and norms far more strongly associated with security-policy compliance than punishment or rewards — largely survey-based, often measuring intention rather than behavior.

RESEARCH FINDING— the accountability edge. Banker and Feng (2019) found breaches attributed to system deficiency associated with about a 72% higher likelihood of CIO turnover, while breaches attributed to criminal fraud or human error showed no significant association. Archival; cause classification comes from public descriptions. INTERPRETATION Accountability appears to track the perceived scope of the executive's duties — the distinction a Level 3 leader has to draw in public without sounding evasive.

RESEARCH FINDING— Level 4. Fit has the strongest evidence base of the four, all correlational and none of it a matching rule. Banker, Hu, Pavlou and Luftman (2011) found the right CIO reporting line depended on strategy: CIO-to-CEO in differentiation firms, CIO-to-CFO in cost-leadership firms. Karahanna and Preston (2013), across 81 US hospitals with matched CIO and top-team responses, found the social capital of that relationship associated with alignment and, through alignment, with financial performance. Haislip, Lim and Pinsker (2021), across reported breaches from 2005 to 2017, found firms with a CIO on the top management team associated with fewer reported breaches of all types examined. Peppard (2010) argues from interviews that CIO performance is largely a function of context — in particular the IT savviness of the CEO and leadership team. Karanja (2017) has examined CISO appointments and reporting positions in relation to breach events; its abstract could not be verified here, so nothing more specific may be claimed.

RESEARCH FINDINGFRAMEWORK— why this order. Hambrick (2007, from the CEO library) argues executives' characteristics shape choices most where discretion is high and job demands are heavy, because heavy demands push leaders back onto heuristics and dispositions. INTERPRETATION Maturity sits above capability because under load you fall back on temperament, and maturity decides whether that fallback is regulated. Fit sits on top because discretion decides how much any lower level matters — and this edition weights it hardest, since a CIO or CISO does not set their own discretion.

Where the evidence is weak

No study tests this four-level model; it is a framework. Level 1 is the weakest link — there is no peer-reviewed psychometric profile of CIOs or CISOs in this library, so it is populated by analogy and by five interviews, and Level 3 borrows from adjacent literatures. Use the model to structure a conversation; do not use it to score a person.

Explanation

Why four levels, and why in this order

FRAMEWORK The model answers a question CEOs, boards and technology executives get wrong constantly: when a CIO or CISO is not working, what kind of thing is missing? Four levels, four remedies, four timescales.

Temperament is what you arrived with. Uncertainty tolerance is the capacity to act on an incomplete asset inventory and a vendor advisory that says "under investigation" — every security decision has an unknown denominator, and the leader who needs the denominator is not slow, they are absent. Agency shows up as one behavior: asking for what is not yours to ask for — the budget line the CFO did not offer, the seat in diligence, the escalation path to the audit committee. Emotional regulation under incident is what this role adds: at hour six the executive's affect sets the room's, and visible fear produces a team that hides findings while visible contempt produces a team that stops bringing them. Temperament is mostly not trainable in adulthood, and it is the raw material of every rung on the Overuse Ladder.

Capability is what you learned — six clusters. Architecture: knowing what a design does under failure and under attack, and saying so before it is built. Vendor and capital judgment: knowing what you are buying, what you are giving up and what it costs to leave. Incident command: running a room, holding a timeline, keeping a decision log. Communication upward: making a technical risk legible to people who will never read the finding, without inflating it. Risk quantification: exposure in money and probability rather than in colors, with Gordon and Loeb (2002) as the discipline. Talent: hiring and replacing security people, which is hard because the market is thin and the executive is often the best technician in the room.

Maturity regulates the first two. Calibration is Module 6's dial plus the literal version: a log of predictions with confidence levels, checked. Receiving bad news has a security-specific test — Edmondson (1996) found better climate produced more reported errors, so a mature leader reads a falling incident count as ambiguous and asks whether reporting fell instead. Distinguishing ego from evidence is what happens when a new hire says the architecture you designed is why the detection gap exists; Module 8 is built on that case. Letting the business own its risk is the hardest: you do not own the company's risk, you own the quality of the risk decision. Present a priced choice, let an accountable leader accept it in writing, then support the thing you argued against. Cram, D'Arcy and Proudfoot (2019) is the evidence underneath — a program run as enforcement runs on the weak levers — and Banker and Feng (2019) is the warning: the scope you accept in calm weather is the scope you are judged on in bad.

Fit is whether the first three match this job. The reporting line is the most consequential term, and the one Banker et al. (2011) show should follow strategy rather than fashion. Fit is a relation, not a property, and it changes when the situation does.

Why the levels do not substitute

INTERPRETATION The tempting error is that a surplus above compensates for a deficit below. Maturity and fit without capability is the calibrated leader who cannot read an architecture or price a risk: the program is pleasant, the bad news arrives early, and both describe a program someone else is running. In the Preston, Leidner and Chen (2008) profiles this is the IT Mechanic; Owens and Hekman (2012) make the same point from the humility side, since the behaviors work only from a leader perceived as competent.

Capability and fit without maturity is the common case, because capability is visible at hiring and maturity is not: the excellent CISO whose team stopped bringing near-misses in year two and whose incident numbers look superb for reasons Edmondson (1996) would recognize. Capability and maturity without fit is the distinctive failure of this role — a well-regulated CIO reporting three levels down in a company whose CEO treats technology as a cost line (Peppard, 2010) — and it is frequently not the executive's doing, which is why it gets misdiagnosed as one. The model is forgiving in one direction only: strong lower levels widen the range of situations you fit, because maturity is what lets the dial move.

Self-locating with evidence, not adjectives

FRAMEWORK "I'm pragmatic" is not a location. Each level takes a different evidence type, and using the wrong type is the commonest self-assessment error.

  • Temperament — behavior under load. The decision log from your worst incident, read for how many consequential calls you made before you had 60% of the facts, and how many you deferred that did not need deferring.
  • Capability — artifacts, one per cluster. The last architecture decision record and what it got wrong; the last three vendor renewals and what you conceded; the last memo you sent upward and whether any decision changed because of it; one loss estimate written before an event; how long the hire you should have replaced stayed.
  • Maturity — other people's evidence. The 360 gap between your self-rating and your team's; the worst thing you heard last quarter, who told you and how long they sat on it; whether you can state the risk each exception carries rather than who asked for it.
  • Fit — the Fit Equation and a discretion audit. Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line. Then: what can you spend without asking, who can overrule you, can you reach the audit committee without your boss's permission, and what happened the last three times you said no.

How a CEO or board should use it

FRAMEWORK The model turns "the CISO isn't working" into four conversations. The temperament screen is a floor, not a differentiator. The capability assessment runs by cluster, with two warnings: selectors over-weight the interpersonal impression in the room and, in technology roles, the credential — evidence of vocabulary rather than of incident command. The maturity probe is the part that gets skipped: ask for the last risk decision the candidate handed back to a business owner, and ask former engineers whether bad news went up early and what happened to whoever brought it. The fit analysis asks what discretion this person will actually have.

INTERPRETATION A board that will not change the reporting line, the budget authority or the escalation path is not selecting a CISO; it is selecting who will be blamed. FACT Regulation S-K Item 106 has since December 2023 required US public companies to disclose annually the board's oversight of cybersecurity risk and management's role and expertise in assessing and managing material cyber risks (SEC, 2023). HYPOTHESIS Most technology-executive exits described as capability failures are maturity or fit failures — consistent with the discretion literature and with Peppard (2010), and not tested directly.

Example

Fictional composite. Northway Retail Group is a $1.4B-revenue specialty retailer — 240 stores across the Northeast, 6,800 employees, a growing e-commerce channel, cost-leadership strategy. Its first CISO, Dev Anand, was hired twenty months ago from a larger retailer where he had run threat detection. He reports to the CIO, who reports to the CFO.

At the May board meeting the CEO said the sentence that starts this kind of review: "I don't think the CISO is working." Her evidence was real. A store-systems vulnerability had been open eleven months. The e-commerce team had launched a loyalty integration without security review and mentioned it afterward. Dev's board deck was three slides of maturity scores and a heat map, and when the audit committee chair asked what a breach would cost, he said it depended. Two merchandising VPs described security as an obstacle. The CFO wanted to know why headcount had grown 40% with nothing to show.

The audit committee chair — a former operations executive — took a month and ran the four levels separately.

Temperament. She read the incident log from a February payment-terminal event: Dev took command in eleven minutes, made three containment calls before the forensics vendor reached the bridge, and was right on two. No deficit.

Capability. Uneven, and specifically so. Architecture and incident command were strong. Vendor judgment was weak: three overlapping tools in eighteen months, one never deployed past pilot. Risk quantification was absent — "it depends" was not modesty; no loss estimate had ever been written.

Maturity. Mixed, with one clear gap. The 360 showed his team rating him high on receiving bad news; an analyst had escalated a misconfiguration over Dev's own architecture and been thanked in front of the group. But every business leader described the same pattern: Dev took risk decisions onto himself. When merchandising wanted the loyalty integration he did not price it and hand it back — he said no, was overruled two levels up, and then declined to support the launch. He was carrying other people's risk and losing.

Fit. Northway is a cost-leadership retailer, and Banker, Hu, Pavlou and Luftman (2011) found CIO-to-CFO reporting associated with better performance in exactly that strategy, so the structure was defensible on its face. But Dev's line put two people between him and the board, his spending authority stopped at $25,000, and he had never sat in diligence for either acquisition closed since he arrived. The eleven-month vulnerability lived in store systems owned by a VP of retail operations who had declined the maintenance window four times. Dev had escalated twice, to his CIO, and stopped.

The chair's one-page conclusion: this is not one problem. A capability gap in risk quantification and vendor judgment — trainable, with a deadline. A maturity gap in letting the business own its risk. And a fit gap the company created: no escalation path, no diligence seat, and a systems owner who could decline a window without consequence.

Northway did three things. It gave Dev a standing audit-committee slot with a direct line to its chair. It replaced the maturity deck with three numbers and one priced decision a quarter, and assigned the FP&A lead to build the first loss models with him — a quarter's work that produced a $9M–$14M range for a card-data event and changed the tooling conversation immediately. And it introduced a risk-acceptance form any business leader may sign for a named risk, in writing, with an expiry date. The VP of retail operations signed one for the store-systems window, and four weeks later took the window.

Eleven months on, the vulnerability was closed and the exception register held nineteen signed items with owners and dates. Dev's summary was blunter than the chair's: "I thought my job was to stop bad decisions. It was to make sure the right person made them, and knew what they cost."

Leader Contrast

Take the same May meeting and put three archetypes in Dev Anand's chair when the chair delivers the one-page diagnosis.

The Technical CISO hears three findings and accepts one. The vendor-judgment gap is fair; the risk-quantification gap gets answered with an objection that quantification is pseudo-precision — you cannot put a number on a threat actor. There is a real argument there, and Gordon and Loeb (2002) rest on assumptions rarely measurable in practice. But the objection is doing other work: protecting an identity in which security is a technical discipline the business should defer to. The gain is honesty about uncertainty; the cost is that the audit committee still cannot decide anything, and a leader who will not give a range gets a budget set by someone who will.

The Business-Risk CISO accepts the whole diagnosis in the room and has a loss model in three weeks. Fastest recovery available, with a specific failure: the priced-risk posture without the Control-end rigor behind it. The exception register fills quickly, because handing risk back feels like progress. Six quarters later there are ninety-one signed acceptances, nobody has reviewed the expiries, and the company has documented its way into the same exposure. Handing risk back is only maturity if you track what you handed back.

The Enterprise CIO (Architect), imagined in the combined seat, hears "fit gap" and goes to governance: a risk committee, a decision-rights table, a quarterly attestation. Much of this is what Northway lacks. The danger is the one Module 8 names — designing a system and mistaking the design for its operation. A risk-acceptance form no VP ever signs is a document, not a control, and the Architect is least likely to notice the difference from where they sit.

INTERPRETATION The four-level split is what makes the room productive: it separates what Dev must learn, what he must change in himself, and what only the company can give him. Each archetype collapses that split differently, and each collapse is an experienced executive's honest first instinct.

Failure mode

FRAMEWORK The model's characteristic failure is mis-level diagnosis — treating a problem at one level as if it lived at another. Four versions recur.

The capability answer to a maturity problem. A CISO whose team has stopped reporting near-misses is sent to a board-communication workshop. A CIO who runs one dial setting gets a better portfolio dashboard. The remedy is real, the level is wrong, and the failure continues under a more expensive label.

The tooling answer to a maturity problem. The technology-specific version, and the most common. The gap is that the executive does not hear bad news; the response is a GRC platform or an attack-surface subscription. Tools convert a human information problem into a dataset nobody contradicts — the ladder's optimism → delusion rung with a purchase order attached.

The fit answer to a maturity problem. The company decides the leader "isn't right for us," replaces them, and hires a different default into the same reporting line, the same spending authority and the same absent escalation path. The cycle repeats in about two years.

The maturity answer to a fit problem. The kindest failure and the biggest waste: a calibrated, self-aware CIO with no discretion, coached on influence and executive presence. Peppard (2010) argues CIO performance is bounded by the IT literacy of the CEO and top team, and coaching does not move that boundary; Hambrick (2007) says the same thing structurally, since characteristics matter where discretion exists.

INTERPRETATION The Overuse Ladder maps onto the model directly: every rung begins as a Level 1 or Level 2 strength and becomes a liability through a Level 3 deficit — failing to notice the situation changed. A Level 4 change usually reveals it. A new CEO, an acquisition, a first regulator: the setting that was invisible becomes the problem, and it looks like the leader deteriorated when the situation moved.

Early warning signs

  • The development plan has been entirely Level 2 for three years — frameworks, certifications, tooling.
  • The exception register is growing and the executive can name who asked for each exception but not the risk it carries.
  • The leader has never handed a priced risk back to a named business owner in writing.
  • Two CIOs or CISOs have now left the same seat, and the reasons given were different both times.

Personal reflection

  1. For each of the four levels, write one piece of evidence — a decision, an artifact, a piece of feedback — that locates you. Which level was hardest to evidence, and what does that tell you?
  2. Take the six capability clusters. Which one has no artifact behind it? What is the last written, pre-event loss estimate you produced, and how did it turn out?
  3. When did you last hand a priced risk back to a named business owner in writing, and then support the decision you argued against? If you cannot find an instance, whose risk are you currently carrying?
  4. What is the worst thing you heard from your team last quarter? Who told you, how long had they known, and what happened to them afterward?
  5. Run the discretion audit: what can you spend without asking, who can overrule you, can you reach the audit committee without your boss's permission, and what happened the last three times you said no? Which of these could you renegotiate this year, and which have you simply never asked about?
Simulation · this module · ~10 min

The Second Title

Ravenswood Industrial Supply · Distribution of industrial components (cost-leadership strategy) · $4.2B · Mature · Public

The CEO wants an answer this week. A CISO search costs five months and a seven-figure package; the ERP consolidation is at its midpoint and the bolt-on closes in seven months; the annual disclosure describing management's cyber-risk role and expertise is being drafted now.

Take the decision →

Knowledge check

Pick an answer to reveal the explanation. Nothing is scored or stored.

1Which of the following belongs at Level 3 (Maturity) rather than Level 2 (Capability) for a technology executive?

2Banker and Feng (2019) found that CIO turnover was:

3Edmondson (1996) found that nursing units with better team climate and more active manager coaching reported:

4A CEO says her CISO "isn't working." Name the four questions the Maturity Model turns that into, and the different remedy each implies.

Key takeaways

  • The four levels are four different kinds of thing with four different remedies: Temperament (uncertainty tolerance, agency, regulation under incident), Capability (architecture, vendor and capital judgment, incident command, communication upward, risk quantification, talent), Maturity (calibration, receiving bad news, ego versus evidence, letting the business own its risk), Fit (company, reporting line, regulator, stage, mandate).
  • The levels do not substitute. Maturity makes a capability failure gracious rather than avoidable; capability makes a maturity deficit more expensive; and neither survives a fit gap the company will not close.
  • Fit carries more weight in this edition than in the CEO edition, because a technology executive's discretion is granted by someone else — and it is the one term that is partly negotiable, which is why the discretion audit belongs in every self-location.
  • For a CEO or board, the model's most valuable output is the mis-level diagnosis it prevents — the capability, tooling, fit and maturity answers applied to the wrong problem account for most of the money spent on technology-executive difficulty and most of the seats that empty twice.

Research cited in this module

  • Karanja (2017)The role of the chief information security officer in the management of IT security. Information & Computer Security · tier 1 · partially verified
  • Maynard et al. (2018)Defining the strategic role of the Chief Information Security Officer. Pacific Asia Journal of the Association for Information Systems · tier 1 · verified
  • Peppard (2010)Unlocking the performance of the chief information officer (CIO). California Management Review · tier 1 · verified
  • Karahanna & Preston (2013)The effect of social capital of the relationship between the CIO and top management team on firm performance. Journal of Management Information Systems · tier 1 · verified
  • Haislip et al. (2021)The impact of executives' IT expertise on reported data security breaches. Information Systems Research · tier 1 · verified
  • Banker et al. (2011)CIO reporting structure, strategic positioning, and firm performance. MIS Quarterly · tier 2 · verified
  • Banker & Feng (2019)The impact of information security breach incidents on CIO turnover. Journal of Information Systems · tier 2 · verified
  • Preston et al. (2008)Examining the antecedents and consequences of CIO strategic decision-making authority: An empirical study. Decision Sciences · tier 1 · partially verified
  • Ashenden & Sasse (2013)CISOs and organisational culture: Their own worst enemy?. Computers & Security · tier 1 · verified
  • ians2026 (2026). State of the CISO 2026 Benchmark Report · tier 1 · verified
  • Gordon & Loeb (2002)The economics of information security investment. ACM Transactions on Information and System Security · tier 1 · verified
  • Cram et al. (2019)Seeing the forest and the trees: A meta-analysis of the antecedents to information security policy compliance. MIS Quarterly · tier 1 · verified
  • Edmondson (1996)Learning from mistakes is easier said than done: Group and organizational influences on the detection and correction of human error. The Journal of Applied Behavioral Science · tier 1 · verified
  • sec2023 (2023). Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure · tier 1 · verified
  • Hambrick (2007)Upper echelons theory: An update. Academy of Management Review · tier 1 · verified
  • Graham et al. (2013)Managerial attitudes and corporate actions. Journal of Financial Economics · tier 2 · verified
  • Owens & Hekman (2012)Modeling how to grow: An inductive examination of humble leader behaviors, contingencies, and outcomes. Academy of Management Journal · tier 1 · verified

Each entry opens the research card with method, limitations and the usable claim.

Related

Leaders and cases
Dials exercised
Decisiveness ↔ InquiryHands-on ↔ DelegationOptimism ↔ SkepticismUnilateral ↔ Consensus