Fit — Industry, Regulation, Stage, and the Reporting Line
Industry matters less than the problem — but for technology leaders the regulator and the reporting line are part of the problem.
Learning objectives
- Profile the technology executive's job in financial services (FINRA/SEC/OCC; broker-dealers and RIAs), healthcare (HIPAA, clinical safety), industrial/OT, retail/consumer, and government/defense, distinguishing framework from evidence.
- Map six stage profiles — startup, scale-up, post-breach turnaround, transformation, post-merger integration, regulatory consent order — to the dial settings each rewards.
- Apply the extended Fit Equation (Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line = CIO/CISO Fit) to a real role.
- Argue when a post-breach company and a pre-IPO company need psychologically similar technology leaders, and where the resemblance breaks.
Core lesson
Module 8 taught the role — Player, Coach, Architect. This module teaches the room the role is played in. A technology executive who is superb in one company can be replaced in eighteen months in another without changing a single habit, because industry, regulator, stage and reporting line reward different settings on the same dials.
The CEO edition argued that industry matters less than the problem: a troubled bank and a troubled tire company may need more similar leaders than two healthy banks. That argument survives the move to the CIO and CISO chair, with one adaptation. For the technology executive, the regulator is not background. It writes part of the job description, decides what "evidence" means, and sometimes sits in the room. And the reporting line — CEO, CFO, CIO, general counsel, risk — decides how much of the executive's judgment ever reaches the people who allocate capital. Both are terms in the equation, not footnotes.
In the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module changes the Organizational Context term. It gives you five industry profiles, six stage profiles, an extended Fit Equation with the Reporting Line added, and one sophisticated move: seeing when two companies that look nothing alike need the same leader. You leave able to write the problem before the profile, and to name the term you personally are weakest on.
The big idea
Industry matters less than the problem — but for technology leaders the regulator and the reporting line are part of the problem.
A post-breach healthcare system and a pre-IPO payments company share a problem — produce credible, documented evidence of control, fast, under outside scrutiny — that may demand more similar technology leaders than two healthy hospitals with different CEOs. Fit fails at the weakest term, and for the CIO or CISO the weakest term is often the one nobody put in the job posting.
What the research says
RESEARCH FINDING The foundational evidence that structure should follow the problem is Banker, Hu, Pavlou & Luftman (2011). In a large-firm archival panel using data from 1990–1993 and 2006, the "right" CIO reporting line depended on strategy: differentiation firms performed better when the CIO reported to the CEO, cost-leadership firms when the CIO reported to the CFO — a relationship the authors say holds "independent of whether IT plays a key strategic role in the firm." Associations under controls, with the endogeneity of the reporting choice addressed statistically; the data predate cloud-era roles. It supports "there is no universally correct reporting line." It says nothing about CISOs or about companies smaller than the panel covers.
RESEARCH FINDING Healthcare offers the two cleanest studies of how regulation shapes the return on security effort. Kwon & Johnson (2014), using a Cox proportional-hazard model on US healthcare organizations — chosen because breach disclosure is mandated and investment data exist — found proactive security investment associated with lower subsequent failure rates and better cost-effectiveness than reactive investment, and that "external pressure decreases the effect of proactive investments on security performance." Angst, Block, D'Arcy & Kelley (2017), in a matched panel of over 5,000 US hospitals and 938 breaches (2005–2013), found that "symbolic" adoption of security practices diminished the effectiveness of investment and raised breach likelihood, while deeper integration into IT routines was associated with fewer breaches. One-sector, reported-breach-only designs; adoption depth inferred from institutional profile. INTERPRETATION Together they describe the regulated-industry trap: the regulator pushes spending, and spending under pressure tends toward the symbolic. A control adopted to satisfy an examiner buys less than the same control adopted because someone inside wanted it.
RESEARCH FINDING The market prices the type of breach, and the type depends on the industry. Campbell, Gordon, Loeb & Zhou (2003) found limited evidence of an overall negative stock reaction to reported breaches, a highly significant negative reaction where the breach involved unauthorized access to confidential data, and none where it did not. Kamiya, Kang, Kim, Milidonis & Stulz (2021) found attacks involving loss of personal financial information associated with shareholder losses much larger than out-of-pocket costs; spillover to industry peers; smaller excess losses where boards had attended to risk management beforehand; and, afterward, increased risk-management and IT investment and reduced risk-taking incentives for managers. Event studies of disclosed attacks; short windows; proxied governance. INTERPRETATION An industry that holds personal financial data lives in a different loss function from one that holds industrial telemetry. That is the first reason the job differs by industry: not the technology, but what the market and the regulator do when the data leaves.
RESEARCH FINDING Kashmiri, Nicol & Hsu (2017) studied 168 publicly listed US retailers around Target's December 2013 breach and found contagion: other retailers lost value on average, more if they resembled Target in size and product market or shared governance ties, less if they had stronger IT capability, marketing ability and CSR records. Single event, single industry, cross-sectional proxies. A competitor's breach is priced against you, moderated by your own visible capabilities.
RESEARCH FINDING Higgs, Pinsker, Smith & Young (2016) found, over 2005–2014, that firms with board-level technology committees were more likely to have reported breaches, and that a technology committee mitigated the negative abnormal returns from external breaches. Reported breaches conflate occurrence with detection and disclosure; committee formation is endogenous. INTERPRETATION Governance changes both what gets reported and how the market reads it — a preview of Module 10.
FACT Two rule-and-standard sources define part of the terrain. The NIST Cybersecurity Framework 2.0 (26 February 2024) provides a taxonomy of high-level cybersecurity outcomes for organizations of any size, sector or maturity and adds a Govern function alongside Identify, Protect, Detect, Respond and Recover; it is voluntary, outcome-focused and not evidence of effectiveness. The SEC's cybersecurity disclosure rules (adopted 26 July 2023) require public companies to disclose a material cybersecurity incident on Form 8-K within four business days of determining it is material, and to describe annually their processes for managing material cyber risk, the board's oversight of that risk, and management's role and expertise; incident disclosure applied from 18 December 2023, with 180 extra days for smaller reporting companies. Legal requirements, not findings.
RESEARCH FINDING From the CEO library, Karaevli (2007) studied CEO succession in the US airline and chemical industries from 1972 to 2002 and found no direct main effect of "outsiderness": outsiders helped when pre-succession performance was poor and the environment turbulent, and the effect depended on what changed alongside the succession. Zhang & Rajagopalan (2010), also from the CEO library, found among 193 US CEOs an inverted-U relationship between strategic change and performance, with outsiders experiencing larger gains from moderate change and larger losses from excessive change. Archival, observational, about CEOs. INTERPRETATION These are the closest evidence for the stage profiles below; read them as analogy.
RESEARCH FINDING— TIER 3. Base rates only, from self-selected practitioner samples: the IANS Research & Artico Search State of the CISO 2026 survey of more than 600 security leaders reported that 64% of CISOs report to IT leaders and 36% to non-IT leaders; the 2025 Verizon DBIR's contributor sample of 12,195 confirmed breaches reported ransomware present in 44% of breaches and 88% of SMB breaches.
Where the evidence is weak
Almost everything above concerns large public companies or US hospitals. There is no peer-reviewed study in this library of the technology executive's job in industrial/OT environments, in government and defense, or in the SMB and MSP world most of this course's first learners inhabit. The industry profiles below are therefore FRAMEWORK and INTERPRETATION, informed by the loss-function evidence and the regulatory facts, not by studies of CISOs in each sector. The stage profiles borrow from CEO succession research. Treat both as lenses to test against your own situation.
Explanation
What a regulator does to the job
FRAMEWORK The CEO edition described five forces that make industries produce different CEOs: capital intensity, regulation, cycle length, customer concentration and the nature of the product. For the technology executive, regulation changes character. A regulator does three things to a CIO or CISO that it does not do to most CEOs.
It defines evidence: in an unregulated company, "we have access controls" is a claim about the system; in a regulated one it is a claim about a document an examiner can request, and a claim true in the system but false in the document is a finding. It sets the clock: exam cycles, notification deadlines and consent-order milestones do not care about your roadmap. And it changes the loss function: the market's penalty depends on what kind of data left (Kamiya et al., 2021; Campbell et al., 2003); the regulator's penalty depends on whether you could show you were trying. Two companies with identical technical exposure can have very different jobs at the top of technology, because one of them will be asked to prove it.
INTERPRETATION The healthcare evidence is the warning that comes with the territory: regulatory pressure moves spending toward the symbolic. The regulated-industry executive's central discipline is refusing to let the examiner's list become the program. "Institutional paranoia" describes the leader who treats the regulator's minimum as a floor; the failure mode treats it as a ceiling.
Five industry profiles
FRAMEWORK Teaching profiles, not findings. Each names the dominant loss, the regulator's presence, and the dial settings the profile rewards.
Financial services. Broker-dealers are examined by FINRA and the SEC; registered investment advisers by the SEC and the states; banks by the OCC, the Federal Reserve, the FDIC or state regulators depending on charter. The dominant loss is the one Kamiya et al. (2021) measured — personal financial data — compounded by a regulator who arrives on a schedule with a request list and reads your written supervisory procedures against your logs. The job rewards operational discipline over innovation, caution on anything customer-facing, and a skill the CEO course does not teach: writing controls that are true. In a small broker-dealer served by an MSP or a fractional CISO, the vCISO's real product is the gap between the procedures manual and what happens on the network. The rung is rigor → bureaucracy, "the security review that ships nothing."
Healthcare. HIPAA and mandated breach notification make this the one sector with clean panel data. The dominant loss is not primarily financial: availability is clinical safety, and a ransomware event that takes down the electronic health record is a patient-safety incident before it is a privacy incident. The job rewards resilience on the Prevention ↔ Resilience overlay — recovery time is the metric — and consensus with clinicians, who will route around any control that slows care. The trap is the compliance-only CISO who is HIPAA-perfect and operationally fragile.
Industrial and operational technology. No study in this library covers it; INTERPRETATION only. The dominant loss is physical: production stops, or something moves that should not. Legacy equipment cannot be patched on an IT schedule, vendors own the control systems, and the plant floor regards IT as a visitor. The job rewards patience over urgency, decentralization — plant managers own their floors — and the resilience end of the overlay, because prevention on a twenty-year-old controller is a fiction.
Retail and consumer. Card data, consumer identity, seasonality, thin margins. Kashmiri et al. (2017) show the distinctive feature: a competitor's breach is priced against you, and your own visible IT, marketing and CSR capabilities are the shield. The job rewards aggression on customer-facing technology — the business is a technology business whether it admits it or not — and operational discipline on the payment perimeter. The card networks and the plaintiffs' bar stand in for the regulator. Control ↔ Enablement sits further toward enablement than anywhere else, and the failure mode is banking's in reverse: enablement → exposure.
Government and defense. Clearance, procurement rules, mandated frameworks and a reporting line that runs through appointees or agency heads. Discretion is structurally low; the leader's power is almost entirely borrowed. The job rewards consensus, patience, and running a program through mandated process without letting the process become the program. It punishes the unilateral operator, whose speed reads to the oversight apparatus as the culture that caused the last problem. Profile only.
Six stage profiles
FRAMEWORK Stage is the most time-sensitive term of the Fit Equation. Six recognizable situations:
1. Startup. The problem is existence; security is a Player's job — the vCISO, the MSP, the founder's laptop. Dial: hands-on, urgency, innovation, enablement. Danger: insufficient action, and no second opinion. Ransomware in 88% of SMB breaches (Verizon, 2025, Tier 3) is the base rate being priced.
2. Scale-up. The problem is organization: the first security hire who is not you, decision rights, an actual platform. Dial: delegation, decisiveness on structure, operational discipline arriving for the first time. Danger: the founder-engineer who cannot let go (Module 8).
3. Post-breach turnaround. The problem is credibility under blame. Dial: centralization, decisiveness, urgency, skepticism, unilateral — for a season. Kamiya et al. (2021) describe what companies actually do: raise risk-management and IT investment, cut managers' risk-taking incentives. The CEO course's turnaround paradox applies in full: "Cut. Replace. Centralize. Decide. Move." is correct for a season that ends more quietly than it began.
4. Transformation. The problem is changing the operating model — cloud, ERP, platforms — while the business keeps running. Dial: aggression, innovation, decisiveness, with Zhang & Rajagopalan's (2010) inverted U in view: moderate change helps, excessive change hurts, and the outsider's swing is wider both ways. Discretion high, tenure short; "strategy-of-the-month" is the rung.
5. Post-merger integration. The problem is two of everything and a deal thesis that depends on becoming one. Dial: decisiveness early on architecture and identity, consensus on culture, skepticism about the synergy case, operational discipline. The hidden term is security debt: the acquired company's controls are now your attack surface, and nobody priced that in the deal model.
6. Regulatory consent order. The problem is legitimacy: a regulator has concluded the company cannot be trusted to run its own controls and has written down what must change and by when. Dial: caution, consensus with the regulator, patience, inquiry, operational discipline. Nearly the inverse of the post-breach turnaround — and companies move from one to the other, which is why the executive right for the first is so often wrong for the second.
The extended Fit Equation
FRAMEWORK Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line = CIO/CISO Fit. Multiplicative, so fit fails at the weakest term.
Reporting Line is the term the CEO course did not need, and Banker et al. (2011) is the evidence that it is not decorative. INTERPRETATION Reporting to the CFO puts the technology executive inside the cost conversation; to the CEO, inside the strategy conversation; to the CIO — as roughly two-thirds of CISOs do, per the IANS 2026 practitioner survey — inside the delivery conversation, where the person judging the risk is the person whose projects carry it. None is wrong. Each is wrong for a particular problem. A CISO built for the strategy conversation, sitting two levels below it, experiences the job as a slow argument with a wall — and the wall experiences the CISO as someone who does not understand the business.
The practical test: for each of the seven terms, write one line describing the company and one describing yourself. Circle the term where the lines disagree most. That is your fit problem, and it is usually not the one the recruiter discussed.
When a post-breach company and a pre-IPO company need the same leader
INTERPRETATION A healthcare system nine months after a ransomware event, under regulator inquiry and plaintiff discovery. A payments company eighteen months from a listing. Different industries, different moods — one grieving, one celebrating — and, on the surface, opposite stage profiles.
Now write the problem. The post-breach company must produce, quickly, documented and auditable evidence that its controls exist and work, for an outside party that assumes they do not. The pre-IPO company must produce the same evidence for outside parties — underwriters, auditors, and after listing the SEC's annual disclosure of risk processes, board oversight and management expertise (FACT: SEC, 2023) — that will assume nothing. Both are evidence-factory problems. Both reward centralization of control ownership for a season, operational discipline, decisiveness on structure, skepticism about every inherited claim, and a leader who communicates upward in the outside party's language. Both punish the enablement-first leader who regards documentation as overhead.
The resemblance breaks at the information environment. The post-breach company is a blame environment, where reporting has usually collapsed — nobody wants to be the next finding. The pre-IPO company is an optimism environment, where nobody wants to slow the listing. Same leader, same dials, opposite silences to break. HYPOTHESIS The technology executive who has done one is unusually well-suited to the other — and unusually likely to misread the silence, because the last silence had a different cause.
Example
Fictional composite.
Marcus Oyelaran had been CISO of Quarrystone Health Partners — a physician-owned group of 46 practices in Connecticut and Massachusetts, $380M revenue, 2,400 employees — for eleven months when the ransomware event happened. The EHR was down six days. Two clinics reverted to paper. The Office for Civil Rights opened an inquiry; a class action followed within a month. His reporting line, which had run to a CIO who left that quarter, was moved to the CEO.
What he did over the next fourteen months was not clever. He centralized ownership of every control under his own office, replaced the MSP that held the backup contract, and wrote a control inventory that mapped each control to evidence — a log, a ticket, a review — rather than to a policy sentence. He reported monthly to the board in one format: what we said we had, what we can prove we have, the gap, the date. He was blunt with clinicians and unpopular for a season. The inquiry closed with a corrective action plan rather than a penalty; the litigation settled.
Eighteen months later a search firm called about Larkspur Payments — a Boston payments company, $210M revenue, 900 employees, venture-backed, planning a listing within two years. The CFO was frank: "We have a security team that ships fast and documents nothing. The underwriters will ask for what you built at Quarrystone." Oyelaran's dials — centralization, operational discipline, skepticism, decisiveness on structure — had been set in a blame environment. He was about to use them in an optimism environment.
It worked, mostly. The control inventory transferred almost verbatim; the monthly format became the audit committee's format. Engineering leaders who expected a "no" machine got a CISO who said yes to nearly everything and priced it: "Yes — and here is the risk we are accepting, in customer-record terms, until the access-review automation lands in Q3." The listing's disclosure of risk processes and board oversight was drafted from his inventory.
The place it did not work was the one the hypothesis predicts. At Quarrystone, silence had meant fear, and he had broken it by making reporting safe. At Larkspur, silence meant enthusiasm; nobody was afraid, they were busy. He spent four months reading the absence of bad news as the health of the program before an engineer mentioned, in passing, that a customer-facing API had shipped without the review his inventory said was mandatory — not concealed, just not considered worth mentioning. The control existed in the document and not in the system: the symbolic-adoption pattern (Angst et al., 2017), produced not by a regulator but by a roadmap.
He fixed it as he had fixed things before: a direct line from engineering leads to his office, a standing "what shipped without us" item in the weekly, and a written note to the CEO that he had misread the environment. Same leader, same dials, second silence — recognized late, because it sounded like the first one.
The coda: a year after the listing, an industrial firm with a plant-floor OT estate approached him. He declined. "The problem there is patience," he told the recruiter, "and I have been hired twice for the opposite."
Leader Contrast
Put four archetypes in the Larkspur seat — pre-IPO, an optimism environment, an engineering culture that ships and does not document, eighteen months to a listing.
The Technical CISO sees the undocumented estate as an engineering problem and starts fixing it personally: reviewing code, hardening the API gateway, writing detections. Gain: real control improves fast, and engineers respect the competence. Cost: the underwriters do not ask whether the API is hardened; they ask for evidence that a process hardens every API. This leader builds protection and not proof, and the Fit Equation fails at the Problem term.
The Business-Risk CISO reads the room correctly: the company's currency is speed and the board wants the listing. This leader prices everything, says yes often, and builds the disclosure narrative early. Gain: the best relationship with the CFO and the cleanest board materials of the four. Cost: pricing risk in an optimism environment tends toward under-pricing, because every number is negotiated with people who want it lower. "Yes" as identity. The API that shipped without review goes unnoticed longer here, because this leader has fewer direct lines to engineers and more to executives.
The Post-Breach CISO — Oyelaran's own archetype — brings the evidence factory ready-made. Gain: the fastest path to an auditable program. Cost: the turnaround dials — centralization, unilateral, urgency — were set for a blame environment, and in an optimism environment they read as distrust. Engineering leaders who were never at fault are treated as if they were. The leader who does not notice the season has ended becomes the reason the best engineers leave in year two.
The Regulated-Industry CIO/CISO treats the listing as a regulator arriving: reads the disclosure rule, builds to it, staffs a compliance function early. Gain: nothing surprises this leader at the listing; the SEC's annual disclosure requirements (FACT) are met on the first filing. Cost: the examiner's list becomes the program — the Kwon & Johnson (2014) pattern in which external pressure weakens the return on proactive investment. A payments company that is compliance-perfect and product-slow has fit the Governance term and failed the Strategy term.
None of the four is wrong for Larkspur. Each fails at a different term, and a board that names the term before hiring gets a better leader than one that names the archetype.
Failure mode
FRAMEWORK— the Overuse Ladder for fit. The rungs fit-failure climbs are familiar, with technology-specific labels: rigor → bureaucracy ("the security review that ships nothing"); caution → paralysis ("the CISO who is never breached because nothing is ever deployed"); operational discipline → the examiner's checklist as the whole program; decisiveness → the turnaround playbook imported into a company that is not in a turnaround; adaptability → strategy-of-the-month in a transformation that never consolidates.
The destructive pattern is not usually a bad leader. It is a good leader for a situation that has ended or a company that was never in it. The post-breach CISO's centralization becomes, in a healthy company, a bottleneck engineers route around, and the workarounds become the attack surface. The regulated-industry leader's evidence discipline becomes, in a startup, a documentation regime a twelve-person engineering team cannot carry, so they stop reading it. The transformation CIO's aggression, past the top of the inverted U (Zhang & Rajagopalan, 2010), produces a company that has changed its operating model three times and mastered none. In each case the leader experiences the mismatch as the organization's failure to understand risk, and the organization experiences it as a leader who does not understand the business. Both are right about the other.
INTERPRETATION The regulator adds a distinctive rung: regulator-as-identity. The leader whose authority came from the examiner — "FINRA requires it," "OCR will ask" — loses the ability to argue for anything the examiner does not require, and the program shrinks to the request list. Kwon & Johnson's (2014) finding that external pressure weakens proactive investment is the empirical shadow of this rung.
Early warning signs
For the technology executive:
- You describe your current company's problem in the vocabulary of your last company's problem.
- Your justification for a control begins with a regulator's name more often than with a loss scenario.
- Engineers, clinicians or plant managers have built workarounds to your controls, and you learned of them from an incident rather than from them.
- Your reporting line changed and your reporting format did not.
For the CEO or board:
- The technology leader was hired for a stage the company has now left, and nobody has re-asked the fit question.
- Board materials describe compliance status and never describe expected loss.
- The CISO reports to a CIO whose delivery targets the CISO is supposed to price, and no one has designed the escalation path for the day they disagree.
Personal reflection
- Write the extended Fit Equation for your current role — one line per term for the company, one for yourself. Which term disagrees most? Was that term discussed when you were hired?
- Name the last control you implemented because a regulator, auditor or client questionnaire required it. Is it substantive or symbolic in your organization today? How do you know?
- Which industry profile describes your temperament best, and which describes your current employer? If they differ, what has closing the gap cost?
- Which of the six stage profiles is your company in now? Which will it be in within two years? Can you move your dials that far, by evidence rather than intention?
- Your reporting line: what conversation does it put you inside, and what conversation does it keep you out of? Whose problem is that?
- Recall a silence you misread — a period of no bad news that turned out to mean something other than health. What did it sound like, and what did you assume?
- If you were offered the post-breach mandate and the pre-IPO mandate on the same day, which would you take — and which would your last three employers say you should take?
What the Procedures Say
Halloran & Pike Securities (served by Tolland Bridge Technology Partners) · FINRA-member broker-dealer with an affiliated registered investment adviser (financial services) · $24M · Mature · Founder-owned
A FINRA cycle examination is live with a request list outstanding. The contract renews in ninety days and Halloran & Pike is Tolland Bridge's fourth-largest account. Two signed attestations are already in the firm's records, and the mailbox event is six months old with unknown exposure.
Take the decision →Knowledge check
Pick an answer to reveal the explanation. Nothing is scored or stored.
1Banker, Hu, Pavlou & Luftman (2011) found that the CIO reporting line associated with better performance depended on what?
The archival study argues structure should follow strategy "independent of whether IT plays a key strategic role"; an association from data covering 1990–1993 and 2006, about CIOs rather than CISOs.
2Kwon & Johnson (2014) found that in US healthcare, external (regulatory) pressure had what effect on proactive security investment?
Proactive investment was associated with lower failure rates and better cost-effectiveness, but "external pressure decreases the effect of proactive investments on security performance" — the empirical shadow of the symbolic-adoption pattern in Angst et al. (2017).
3State the extended Fit Equation and explain in one sentence why the Reporting Line term is included for the technology executive but not for the CEO.
Model answer. Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line = CIO/CISO Fit; the CEO's discretion is broad by default while the CIO's or CISO's is set by someone else, and Banker et al. (2011) show the same CIO associated with different performance depending on where the line runs.
The equation is multiplicative, so fit fails at the weakest term — often the reporting line nobody discussed at hiring.
4Explain why a post-breach company and a pre-IPO company may need psychologically similar technology leaders, and name where the resemblance breaks.
Model answer. Both are evidence-factory problems — produce documented, auditable proof of control quickly for an outside party — rewarding centralization for a season, operational discipline, decisiveness on structure and skepticism about inherited claims; the resemblance breaks at the information environment, because the post-breach silence is fear and the pre-IPO silence is enthusiasm.
Write the problem before the profile; the same dials can be right for both while the leader misreads the second silence because it sounds like the first.
Key takeaways
- Industry matters less than the problem — but for the technology executive the regulator defines what evidence means, sets the clock and changes the loss function, and the reporting line decides which conversation your judgment reaches. Both are terms in the Fit Equation.
- Reporting-line evidence (Banker et al., 2011) says structure should follow strategy; healthcare evidence (Kwon & Johnson, 2014; Angst et al., 2017) says regulatory pressure pushes spending toward the symbolic, and symbolic adoption does not buy protection.
- The market prices the type of breach, not the fact of one (Campbell et al., 2003; Kamiya et al., 2021), and prices a competitor's breach against you in consumer industries (Kashmiri et al., 2017). The industry profiles are lenses built on that loss function, not findings about CISOs.
- Six stage profiles reward different dial settings, and the executive right for one is often wrong for the next. The consent-order profile is nearly the inverse of the post-breach turnaround.
- Write the problem before the profile. A post-breach company and a pre-IPO company can need the same leader; the silence each produces is different, and reading the second as if it were the first is the characteristic error of the leader who fit the first.
Research cited in this module
- Banker et al. (2011)CIO reporting structure, strategic positioning, and firm performance. MIS Quarterly · tier 2 · verified
- Kwon & Johnson (2014)Proactive versus reactive security investments in the healthcare sector. MIS Quarterly · tier 1 · verified
- Angst et al. (2017)When do IT security investments matter? Accounting for the influence of institutional factors in the context of healthcare data breaches. MIS Quarterly · tier 1 · verified
- Kamiya et al. (2021)Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics · tier 1 · verified
- Campbell et al. (2003)The economic cost of publicly announced information security breaches: Empirical evidence from the stock market. Journal of Computer Security · tier 1 · verified
- Kashmiri et al. (2017)Birds of a feather: Intra-industry spillover of the Target customer data breach and the shielding role of IT, marketing, and CSR. Journal of the Academy of Marketing Science · tier 1 · verified
- Higgs et al. (2016)The relationship between board-level technology committees and reported security breaches. Journal of Information Systems · tier 2 · verified
- nist2024 (2024). The NIST Cybersecurity Framework (CSF) 2.0 · tier 1 · verified
- sec2023 (2023). Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure · tier 1 · verified
- Karaevli (2007)Performance consequences of new CEO 'outsiderness': Moderating effects of pre- and post-succession contexts. Strategic Management Journal · tier 1 · verified
- Zhang & Rajagopalan (2010)Once an outsider, always an outsider? CEO origin, strategic change, and firm performance. Strategic Management Journal · tier 1 · verified
- ians2026 (2026). State of the CISO 2026 Benchmark Report · tier 1 · verified
- verizon2025 (2025). 2025 Data Breach Investigations Report · tier 1 · verified
Each entry opens the research card with method, limitations and the usable claim.