Working with the CEO and the Board — Structural Power, Budgets, Disclosure
A CIO's or CISO's discretion is granted, not assumed; the mature executive spends the first year building the relationships that grant it and the rest keeping the board's attention proportionate to the risk.
Learning objectives
- Explain structural power and social capital as the two sources of CIO/CISO authority, and say which one each current problem is limited by.
- Design a board reporting cadence that is honest, proportionate and priced, and defend it against the demand for a single reassuring number.
- Run the budget conversation as risk pricing rather than fear, using Yes-And / No-Unless and a defensible expected-loss argument.
- Score the eleven-item discretion audit for your own role and identify the two items that actually bind.
- Adapt reporting and escalation design to the CEO you actually have, using the documented case of a technical, broadcasting CEO as the extreme.
Core lesson
Module 9 taught the room. This module teaches the two people in it who decide how much of your judgment ever becomes a decision.
A CEO's latitude is broad by default. A technology executive's is issued — by a reporting line someone else drew, a budget process someone else runs, a committee calendar someone else sets. Two sources produce it. Structural power is what is written down: where you report, what you can spend, what you can stop, whose name is on the risk acceptance. Social capital is what is not: whether the CFO believes your numbers, whether the audit chair calls you before the meeting. Structural power without social capital produces a leader nobody listens to who can nevertheless block things. Social capital without structural power produces a well-liked advisor whose advice is optional.
In the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on Organizational Context, and specifically on the fraction of your Behaviors that survives the trip upward. You leave with three instruments: a board cadence that is honest, proportionate and priced; a budget conversation run as risk pricing instead of fear; and an eleven-item discretion audit you can score in twenty minutes and act on for a year.
The big idea
A CIO's or CISO's discretion is granted, not assumed; the mature executive spends the first year building the relationships that grant it and the rest keeping the board's attention proportionate to the risk.
Authority you were not given can be earned, but only in the currency the institution actually trades in: evidence, priced positions, and a record of having been right and having said when you were not. And attention has an optimum. A board that hears nothing about cyber is not being protected; a board that hears about it monthly at the same volume stops hearing it at all.
What the research says
RESEARCH FINDING Preston, Chen & Leidner (2008) names the variable: CIO strategic decision-making authority — what the organization actually lets the technology executive decide. The citation is confirmed but the abstract could not be retrieved for this library, so no effect size or sample may be quoted from it. Its peer-reviewed practitioner companion (Preston, Leidner & Chen, 2008) is the usable artifact: crossing authority with strategic leadership capability yields four profiles — IT Orchestrator (high/high), IT Advisor (low authority, high capability), IT Mechanic (high authority, low capability), IT Laggard (low/low) — with IT's contribution to performance varying by profile. Perceptual, cross-sectional, associations. It supports the claim that authority and capability must be matched; it says nothing about how to obtain authority.
RESEARCH FINDING Karahanna & Preston (2013) measured the relationship itself: with matched responses from CIOs and top-management-team members at 81 US hospitals, the structural, cognitive and relational dimensions of CIO–TMT social capital facilitated knowledge exchange, and alignment mediated the path to financial performance. One sector, cross-sectional, correlational — evidence that relationship quality is a mechanism, not proof that a warmer relationship causes better returns.
RESEARCH FINDING The most useful finding here is a null one. Preston & Karahanna (2009), using 243 matched CIO–top-team pairs, found shared understanding of the role of IS was built by shared language, shared domain knowledge and formal "systems of knowing." Contrary to the authors' expectation, informal social interaction and experiential similarity did not significantly affect it. Cross-sectional survey, self-reported constructs. INTERPRETATION The mechanism beats the friendship. Design the cadence; the golf is optional.
RESEARCH FINDING Feeny, Edwards & Simpson (1992) originated the framing — the relationship, not the CIO's skills alone, as the unit of analysis; its abstract could not be retrieved for this library, so cite it for the framing only. Gerow, Grover, Thatcher & Roth (2014) later pooled the alignment literature and found all mean corrected correlations with performance positive — a meta-analysis of cross-sectional surveys with modest, heterogeneous effects.
RESEARCH FINDING Two studies describe what boards do to outcomes. Higgs, Pinsker, Smith & Young (2016) found that over 2005–2014 firms with board-level technology committees were more likely to report breaches — plausibly because they detect and disclose more — and that a committee mitigated the negative abnormal returns from external breaches. Kamiya, Kang, Kim, Milidonis & Stulz (2021) found firms whose boards had attended to risk management before an attack suffered smaller excess losses. Archival, associations, governance proxied. INTERPRETATION Visible oversight changes both what surfaces and how the market reads it — the strongest argument here for building the cadence before you need it.
RESEARCH FINDING Amir, Levi & Livne (2018) compared attacks firms disclosed with attacks they withheld that were later revealed from outside: withheld attacks were associated with an equity decline of approximately 3.6% in the month of discovery, disclosed attacks about 0.7%. The period predates mandatory disclosure, and withheld attacks are observable only when someone else finds them. Concealment is priced when discovered.
FRAMEWORK From the CEO library: managerial discretion (Hambrick & Finkelstein, 1987) holds that how much an executive matters depends on the latitude the environment, the organization and the executive's own makeup allow; Hambrick's (2007) update adds that characteristics matter most where discretion exists and job demands are heavy. Both conceptual; Wangrow, Schepker & Barker's (2015) review finds support strongest for environmental sources and weakest for individual ones. Note the irony: the organizational source — the least studied — is the dominant one for a CIO or CISO.
RESEARCH FINDING Peppard (2010), interview-based in a refereed practitioner journal, argues CIO performance is largely contextual and names "the pivotal role of the IT savviness of the CEO and the leadership team." It points where Ashenden & Sasse's (2013) five CISO interviews point: the leaders themselves named low perceived power and unclear role identity as their main obstacles.
FRAMEWORK Gordon & Loeb (2002) supplies the budget instrument: optimal security investment depends on the value of the information set, its vulnerability and the productivity of spending, and — for the two classes of breach-probability function the authors assume — does not exceed about 37% of expected loss. Analytical, not empirical; other functions justify higher fractions. Quote the bound only with its assumptions attached.
FACT and TIER 3. The SEC's cybersecurity rules (adopted 26 July 2023) require disclosure of a material cybersecurity incident on Form 8-K within four business days of the materiality determination, and annual disclosure of processes for managing material cyber risk, the board's oversight of that risk, and management's role and expertise — the board's oversight is now a disclosed object. The NACD/ISA Director's Handbook on Cyber-Risk Oversight (2023) is the de facto US reference for what directors are advised to do; practitioner guidance, not evidence it works. The IANS/Artico State of the CISO 2026 survey of 600+ security leaders reports 64% of CISOs reporting to IT leaders and 36% to non-IT leaders, and 52% saying their responsibilities are not manageable with current resources — self-selected sample, base rates only.
Where the evidence is weak
Nearly all of the CIO evidence is survey-based, cross-sectional and perceptual, much of it from one sector or from before cloud, before the SEC rule, and before the CISO was a board-facing role. There is no study in this library of CISO authority, of board cyber cadence, of budget negotiation, or of any of the three instruments below; Banker, Hu, Pavlou & Luftman (2011) tells you the right reporting line depends on strategy and nothing more specific. Everything in section 4 that is not explicitly cited is FRAMEWORK and INTERPRETATION.
Explanation
Two sources of authority
FRAMEWORK List every decision in your organization that carries technology or security risk, and mark how you would actually affect each one. Some you affect because a document says so — you approve the change, you sign the exception, you can stop the release. That is structural power, and it survives your absence and a bad quarter. Others you affect because someone chooses to ask you and believe your number. That is social capital, and it evaporates the week you are wrong in public and cannot say so. Personality × Power applies with a twist: Power here is granted rather than seized, so the same person holds different amounts of it in two companies. The IT Mechanic blocks anything and explains nothing, and is removed by a CEO tired of losing arguments he cannot follow. The IT Advisor is this course's more common tragedy: the excellent fractional CISO whose recommendations are read, admired and not funded. Opposite remedies — the Mechanic must price rather than prohibit; the Advisor must convert goodwill into written structure.
INTERPRETATION Order matters. Social capital is the only currency available in year one, because nobody rewrites a reporting line for a stranger; year two is spent converting it into written decision rights while goodwill is high. Skip the first and you get told no; skip the second and you spend a tenure re-earning permission you should have banked.
Instrument 1 — the board cadence: honest, proportionate, priced
FRAMEWORK Board reporting fails in two directions: a wall of green indicators teaches the board that this topic never contains news, and an unstructured recitation of threats teaches them it is permanently alarming. Three properties fix both. Honest means bad news has a permanent home in the format and that home is never empty; if "what we got wrong" is blank two quarters running, either your program has no learning function or your reporting has a filter. Edmondson (1996) is the diagnostic: units with better climate reported more errors, so a falling incident count can mean rising silence. Proportionate means volume tracks exposure, not the news cycle. Priced means every risk carries a number with a method: "High" is not a number, and "roughly $4–7M of expected annual loss, driven mostly by third-party access, method in the appendix, and here is what I am unsure about" is.
The quarterly pack, four parts, in order:
- Position. Two or three sentences — what we protect, the largest exposures, what changed — written so the audit chair can repeat it accurately in a hallway.
- Priced exposure. Three to five risks, each with an owner, a loss range and method, the decision that would reduce it, and its cost. Accepted risks carry the accepter's name and a review date.
- Evidence. Not maturity scores: for each control you claim, what would an examiner or a plaintiff's expert be shown?
- What we got wrong. Near-misses, failed tests, self-discovered findings, and last quarter's forecasts that did not hold. Including yours.
Two standing rules: pre-agree the escalation trigger — write into the minutes now what would cause you to contact the chair between meetings — and no single index, which is section 9 in full.
Instrument 2 — the budget conversation as risk pricing
FRAMEWORK Fear-based budgeting works exactly once per CEO. It buys a spike after an industry breach, decays, and makes your funding a function of other people's disasters. Arrive instead with a priced portfolio and let the business choose. Gordon & Loeb (2002) is the discipline, and its bound of roughly 37% of expected loss carries two cautions you should volunteer yourself: the bound depends on assumed classes of breach-probability function, and your expected loss is an estimate you constructed rather than a fact you retrieved. A CFO who watches you attack your own model will believe the rest of it.
Three columns, not one. Buying down: spend that reduces expected loss, with the reduction and the method — "this costs $310K a year and moves third-party access from about $5M of expected annual loss to about $2M; confidence in the $5M is moderate." Accepting: risk you recommend the company keep, priced, with a named accepter and a review date — a portfolio rather than a wish list, and the Risk Corollary in budget form: "Yes — and here is the risk we are accepting, priced." Cannot price: exposures where you have no defensible number, said plainly, with a costed proposal for getting one. Executives lose credibility faster by pricing what they cannot than by admitting they cannot.
INTERPRETATION Then run Yes-And / No-Unless on requests coming the other way, with the changing condition real and reachable: a compensating control, a contract term, a test result, a date. A "No" whose condition is unreachable is a "No" wearing a costume.
Instrument 3 — the eleven-item discretion audit
FRAMEWORK Discretion is usually discussed as a property of a person. For a technology executive it is mostly a property of the chair — so measure the chair. Score each item 0–3; total out of 33.
| # | Item | 0 | 3 |
|---|---|---|---|
| 1 | Reporting line | Two-plus levels down, inside a function whose delivery you police | To the CEO or an executive peer, with a line to a board committee |
| 2 | Budget authority | You request; someone else decides line by line | You own an envelope and reallocate within it |
| 3 | Veto rights | None, written or practical | Written authority to stop a release, deployment or vendor above a threshold, overridable only by a named executive who signs the acceptance |
| 4 | Board access | Someone else summarizes your material | Standing agenda item, plus a session a year without other management present |
| 5 | Hiring authority | Every requisition through a committee that is not yours | You own the plan and select your own leaders |
| 6 | Incident command | Ad hoc; decided during the incident | Written declaration authority, defined powers (isolate, disconnect, engage counsel and forensics), pre-approved retainers |
| 7 | Architecture sign-off | Informed after the decision | Named approver above defined thresholds |
| 8 | Vendor selection | Told which vendors, told when | Veto plus a seat above a spend or data-access threshold |
| 9 | Regulator relationship | No direct contact, ever | Named as accountable; you meet examiners directly, with counsel |
| 10 | Headcount | Fractional or borrowed | Staffed to a plan you wrote and the board saw |
| 11 | Mandate clarity | No written mandate; success undefined | Written mandate, metrics, horizon, and the conditions under which it changes |
The score describes the chair, not the occupant. A fractional CISO at a 60-person client should score low on 5, 9 and 10; that is correct design, not failure. Item 1 is not a quality ranking — Banker et al. (2011) found the performance-associated reporting line depended on strategy, and roughly two-thirds of CISOs report into IT (IANS, 2026, Tier 3) without that being an error.
Score it twice — as you see it, and as your CEO would. The gap is the most valuable output, and it is widest on items 3, 6 and 11: the ones both parties assume are settled and neither has written down.
Move two items, not eleven. Roughly 0–11 is borrowed authority: you are an IT Advisor, and one relationship change ends your program. Roughly 12–22 is mixed, where the binding constraint is usually 3, 6 or 11. Roughly 23–33 is high structural power, where the question inverts to whether your capability matches what you were given. An executive who raises all eleven at once reads as someone building a fiefdom and gets none. Items 6 and 11 are the cheap ones: incident command authority costs nothing in calm and cannot be negotiated mid-crisis, and mandate clarity is free.
Named case — the technical CEO
FACT NVIDIA was founded on 5 April 1993 by Jensen Huang, Chris Malachowsky and Curtis Priem; Huang has been President and CEO since inception, about thirty-three years. He appears here because he is the best-documented example of a technical founder-CEO who has deliberately engineered his company's information environment rather than its org chart. A structural problem to solve, not a model to copy.
A very wide span, reported inconsistently. Huang has described his direct-report group as 50 (Stanford GSB, 25 April 2024) and as 60 (Stripe Sessions 2024); Fortune reported 55 in January 2025. The honest statement is "roughly 50–60, varying by year and by which interview is cited" — any source giving one figure is freezing a moving number. His rationale: "CEOs should have the most reports by definition because the people that report to the CEO require the least amount of management." The arrangement, he said, "probably removes something like 7 layers."
No one-on-ones — with his own staff. At Stripe Sessions 2024: "I don't do one-on-ones and my staff is quite large. Almost everything that I say, I say to everybody," and, pressed, "I really discourage 1-on-1s." This is documented about Huang and his own staff, plus his stated general discouragement. It is not a company-wide prohibition, and no source establishes what NVIDIA managers below him do.
"Top 5 Things," and its ceiling. Employees have sent short bulleted emails listing the top five things in their area, reaching executives directly; Fortune reported in December 2024, drawing on Tae Kim's The Nvidia Way, that Huang sampled around a hundred a day including Sunday evenings, to "detect the weak signals." This must not be taught in the unqualified present tense: Business Insider reporting, covered secondarily in February 2026, describes NVIDIA restricting the system so the emails are distributed more narrowly, at a company well past 30,000 employees.
Two boundaries. The maxim "the mission is the boss" circulates widely as Huang's but traces to summaries of Tae Kim's book rather than to Huang saying it in a citable venue; treat it as Kim's formulation, not as a quotation. And NVIDIA reached a $5 trillion market capitalization (CNBC, 30 October 2025), but no public source establishes any causal link between the span of control, the absence of one-on-ones, the T5T channel and any NVIDIA result. Every management claim above is self-reported in promotional settings, with no audit and no counterfactual.
INTERPRETATION— four lessons for a technology executive under a broadcasting CEO.
First, there is no back channel, so stop planning around one. A CEO who says "almost everything that I say, I say to everybody" has removed the traditional lever, the quiet pre-brief before the board meeting. Influence must be exercised in the room, in front of peers, which raises the standard on the argument and eliminates impression management as a tool. Over-invest in the artifact: the written position must survive being read cold by fifteen people at once.
Second, pre-negotiate the escalation exception, in writing. Security work has an irreducible category that cannot be broadcast: an active incident, an insider investigation, a credible allegation against a named executive. Under a leader who discourages private meetings, a narrow, pre-agreed exception for incident escalation and investigative confidentiality is mandatory — agreed in calm, naming who, how, and what happens in the first hour. That is item 6 of the audit, and failing to secure it beforehand is a foreseeable, avoidable failure. Huang's practice concerns his staff; your own team's one-on-ones are a separate decision, and nothing here argues for imitation.
Third, T5T is a weak-signal design pattern with a headcount ceiling — teach both halves. The mechanism has the shape of good security telemetry: lightweight, high-frequency, unfiltered, valuable for signals too weak to escalate alone. Build the analogue — a low-friction line from engineers, help-desk staff and client teams straight to you — and build the tripwire for its failure, because the reported narrowing past roughly 30,000 employees is the more instructive half: a channel that has silently become filtered leaves an executive on a stale picture with undiminished confidence. Milliken, Morrison & Hewlin (2003), from the CEO library, found most employees can recall withholding an important concern from a superior. Assume filtering; audit the channel's reach.
Fourth, removed layers make an explicit decision-rights map mandatory. The rationale presumes senior people who need no scaffolding, which says nothing about who decides two levels down — exactly where you must find the accountable owner for a risk acceptance. In a hierarchical firm the org chart implies that map; where layers have been removed it must be built by hand: who can accept which class of risk, at what threshold, recorded where, reviewed when. Weill & Ross (2004, Tier 3) is the practitioner argument that decision rights are a design choice; in a flat structure they are a choice nobody has made yet. Peppard (2010) is the counterweight to any romance about technical CEOs: literacy makes the argument faster, but literacy is not scaffolding, and ambiguity about who decides is where security risk accumulates.
Example
Fictional composite.
Ines Delgado became the first CISO of Wren Harbor Systems — a Providence industrial-software company, $290M revenue, 1,100 employees, private-equity owned — in the January after a competitor's ransomware event made the trade press. The CEO, Tomas Wren, had founded the company as a controls engineer and still read pull requests.
She spent her first week scoring the discretion audit. Reporting line, to the CTO: 1. Budget authority: 1. Veto rights: 0. Board access, via the CTO's slide: 0. Hiring: 1. Incident command: 0 — there was a response plan, unsigned, naming a committee. Architecture sign-off: 1. Vendor selection: 1. Regulator relationship: 1. Headcount, four people: 1. Mandate clarity: 0. Nine out of thirty-three, written on the first page of a notebook and shown to nobody for eleven months. She picked two items — incident command authority and a budget envelope — and let the other nine wait.
The first quarter she did nothing structural. She priced. She rebuilt the board material from fourteen slides of green indicators into the four-part pack, and in the first one she reported a red: a third-party integration platform held credentials to 340 customer environments, and she estimated $6–11M of expected annual loss from it, method in the appendix, confidence moderate, driver named. Under what we got wrong she wrote that her own team had inherited and re-signed a client questionnaire attesting to quarterly access reviews that had not run since the previous spring.
The audit chair, Priya Anand, called the following week — the first call, which is the metric that matters. The question was not about the number. It was: "How do you know your $6M isn't $60M?" Delgado said she did not, named the two assumptions that would move it most, and offered to have the range independently checked. Anand asked for the check and put a standing cyber item on the agenda.
The second-quarter budget ran on three columns. Buying down: $480K against roughly $9M of exposure, with expected reductions, the method, and the Gordon–Loeb caution stated plainly. Accepting: two risks the company should keep, priced, with Wren's name on one and the COO's on the other. Cannot price: an AI feature the product team was building against a model API, where she said she had no defensible number and asked for $60K to get one. The CFO approved the third column first, which surprised her, then most of the first.
Incident command authority arrived in the fourth quarter, by accident. A Saturday alert turned out to be a contained credential-stuffing attempt, but for ninety minutes nobody could say who was allowed to disconnect the integration platform. On the Monday she wrote a one-page authority memo — declaration thresholds, four named powers, pre-approved forensics retainer — and Wren signed it in eight minutes, because he had spent Saturday on the call watching the ambiguity himself. It was the cheapest thing she ever got, and she got it only because she had spent a year being the person whose numbers survived scrutiny.
Re-scored in December: 19 out of 33. Two items moved on purpose and four by consequence. The item she never moved — the reporting line — she had stopped caring about, because board access had done the work she wanted the reporting line to do.
Leader Contrast
Put four archetypes in Delgado's chair in that first quarter: a nine-out-of-thirty-three score, a founder-engineer CEO, an audit chair who has never been briefed directly, and a platform holding credentials to 340 customer environments.
The Technical CISO goes at the platform. Within six weeks the integration is segmented and the risk is genuinely lower. Gain: real reduction, fast, and engineering respects the competence. Cost: nobody outside engineering knows it happened, the discretion score is unchanged, and at budget time this leader asks for money from executives with no priced picture of what was avoided. Capability without authority — and the fix is not more technical work.
The Business-Risk CISO goes at the board. The four-part pack lands in month one and the standing agenda item arrives a quarter earlier than it did for Delgado. Gain: the fastest route to structural power available. Cost: the numbers are early and the confidence is high, and a founder-CEO who reads pull requests will find the one assumption that is wrong. Pricing before you have earned the right to be checked is how a promising CISO becomes "the one who said $6M and it was nothing." Optimism wants dialing toward skepticism about one's own estimates before the first pack, not after.
The Enterprise CIO (Architect) builds apparatus: a risk committee, a decision-rights map, a policy hierarchy, a RACI for exceptions. Gain: at a company three times larger in four years this eventually has to exist. Cost: with four security staff the apparatus outruns the organization's capacity to feed it, and a founder-CEO reads it as bureaucracy arriving ahead of results. Right instrument, wrong year.
The Post-Breach CISO (Turnaround) treats the competitor's event as if it were Wren Harbor's own: centralize, freeze, demand, escalate. Gain: urgency genuinely helps a company that has never had a CISO. Cost: centralization, unilateral and urgency were set for an organization that had already failed; here they read as an outsider assigning blame for a crime nobody committed, and there is no social capital left when the incident-command memo needs signing.
None of the four is wrong about the platform. They differ on what the first quarter is for — and in a nine-out-of-thirty-three chair, it is for becoming the person whose numbers are believed.
Failure mode
FRAMEWORK— the Overuse Ladder for structural power and access.
Access → dependence. Authority running entirely through one relationship — a sponsoring CEO, a friendly audit chair — is a program with a single point of failure, and it fails on the day of a succession, not the day of a breach.
Proportionality → minimization. The discipline of not over-alarming hardens into never alarming. The pack gets smoother, the reds get softer, "what we got wrong" gets shorter, and the executive experiences this as maturity. Edmondson (1996) is the diagnostic: an improving incident count in a worsening reporting climate looks identical to an improving program.
Pricing → false precision. A number with a method becomes a number with a decimal point, then a number nobody remembers constructing, then a number the business plans against. Gordon & Loeb (2002) is a reasoning tool whose inputs are estimates; a model presented as measurement is a liability in the costume of rigor.
Conviction → epistemic arrogance. A technically expert executive under a technically expert CEO can slide from productive conviction into treating every challenge as a comprehension failure in the challenger. It ends the same way for both.
Early warning signs
For the technology executive:
- You cannot name the last thing you told the board that they did not want to hear.
- Your influence on a decision this quarter came entirely from someone choosing to ask you.
- Your incident-response plan names a committee and no individual, and nobody has signed it.
- You keep a risk register the board sees and a private list of what actually worries you, and they differ.
For the CEO or board:
- Cyber reporting arrives filtered through the person whose delivery targets it constrains.
- The pack shows maturity scores and compliance status but no expected loss and no named risk accepters.
- Nothing has ever been reported between meetings, and nobody has agreed what would cause it to be.
- The technology executive is described as "great in the room" by everyone and holds no written authority to stop anything.
Personal reflection
- Score the eleven-item discretion audit for your role, then score it again as your CEO would. Where is the gap widest, and what does it tell you that neither of you has written down?
- Name the last decision you affected purely through social capital. What happens to it if the person who asked you leaves?
- Open your last board or executive pack. Where in it does bad news structurally belong? If nowhere, who decided that — you, or the format you inherited?
- What is your expected annual loss from your largest exposure, and which two assumptions would move it most? If you cannot answer in ninety seconds, what would it take?
- Write your escalation trigger: the conditions under which you would contact the board chair between meetings. Has anyone agreed to it? If not, what has stopped you asking?
- Which two discretion items actually bind you this year, and what would you stop asking for in order to get them?
- If your CEO broadcasts rather than confides — or simply never meets you alone — what is your written substitute for the private escalation you have been assuming you have?
Nought to a Hundred
Kettlebrook Financial Group · Retirement-plan recordkeeping and wealth management (financial services) · $340M · Mature · Family-owned
Four days until the minutes circulate. The audit chair has asked for a single quarterly number in front of the CEO, who endorsed it on the spot; you are twenty-two months in, report to the CFO, and have met the chair four times.
Take the decision →Knowledge check
Pick an answer to reveal the explanation. Nothing is scored or stored.
1Preston & Karahanna (2009), using 243 matched CIO–top-management-team pairs, found what about shared understanding of the role of IS?
Contrary to the authors' expectation, informal socializing and similarity did not significantly affect shared understanding, while shared language, shared domain knowledge and formal "systems of knowing" did — survey evidence that the designed mechanism beats the friendship.
2Higgs, Pinsker, Smith & Young (2016) found that over 2005–2014, firms with board-level technology committees:
Committees were associated with more reported breaches — plausibly more detection and disclosure — and with smaller negative abnormal returns from external breaches, so this is evidence about visibility as much as safety.
3Distinguish structural power from social capital, and explain why an executive high on one and low on the other fails differently in each case.
Model answer. Structural power is written authority — reporting line, budget envelope, veto rights, board access, incident command — and survives unpopularity; social capital is the quality of the relationship with the top team (Karahanna & Preston, 2013) and determines whether anyone asks or believes you. High structure with low capital produces the "IT Mechanic," who blocks what he cannot explain; high capital with low structure produces the "IT Advisor," whose recommendations are read and not funded (Preston, Leidner & Chen, 2008).
Opposite failures, opposite remedies — the Mechanic must price rather than prohibit, the Advisor must convert goodwill into written decision rights before it decays.
4Name the four claims about Jensen Huang's information practices that this module requires you to qualify, and give the qualification for each.
Model answer. (1) Direct reports: roughly 50–60, varying by year and by which interview is cited (50, 60 and 55 across three 2024–25 sources) — never a single figure. (2) One-on-ones: documented that he does not hold them with his own staff, plus his stated discouragement; not a company-wide prohibition. (3) "Top 5 Things": documented as of 2024 and subsequently reported as narrowed past ~30,000 employees — never the unqualified present tense. (4) "The mission is the boss": not a verified Huang quotation; it traces to Tae Kim's account and should be attributed to him or dropped.
No public source links any of these practices to NVIDIA's results, so the case is taught as a structural problem — no back channel, a pre-negotiated escalation exception, a weak-signal channel with a headcount ceiling, a mandatory decision-rights map — never as an endorsement.
Key takeaways
- Discretion is granted, not assumed. It comes from structural power (what is written down) and social capital (whether anyone asks or believes you), and the two fail in opposite directions — the IT Mechanic who blocks what he cannot explain, the IT Advisor whose advice is admired and unfunded.
- Build the mechanism, not the friendship: in 243 matched CIO–executive pairs formal structures and shared knowledge drove shared understanding while informal socializing did not (Preston & Karahanna, 2009), and in 81 hospitals relationship quality was associated with alignment and, through it, with performance (Karahanna & Preston, 2013).
- A board cadence should be honest, proportionate and priced. Visible oversight changes both what surfaces and how the market prices it (Higgs et al., 2016; Kamiya et al., 2021), and concealment is priced when discovered (Amir et al., 2018).
- Run the budget in three columns — buying down, accepting, cannot price — using Gordon & Loeb (2002) with its assumptions stated; fear-based budgeting works once per CEO. Then score the eleven-item discretion audit twice, once as you see it and once as your CEO would, and move only the two items that actually bind.
- Adapt to the CEO you have. Under a broadcasting technical CEO — documented for Jensen Huang as roughly 50–60 direct reports, no one-on-ones with his own staff, and a weak-signal email channel later reported as narrowed, none of it causally linked to NVIDIA's results — there is no back channel, the escalation exception must be pre-negotiated in writing, the weak-signal channel must be audited for silent filtering, and the decision-rights map must be built by hand.
Research cited in this module
- Preston et al. (2008)Examining the antecedents and consequences of CIO strategic decision-making authority: An empirical study. Decision Sciences · tier 1 · partially verified
- Preston & Karahanna (2009)Antecedents of IS strategic alignment: A nomological network. Information Systems Research · tier 1 · verified
- Karahanna & Preston (2013)The effect of social capital of the relationship between the CIO and top management team on firm performance. Journal of Management Information Systems · tier 1 · verified
- Feeny et al. (1992)Understanding the CEO/CIO relationship. MIS Quarterly · tier 1 · partially verified
- Gerow et al. (2014)Looking toward the future of IT–business strategic alignment through the past: A meta-analysis. MIS Quarterly · tier 1 · verified
- Higgs et al. (2016)The relationship between board-level technology committees and reported security breaches. Journal of Information Systems · tier 2 · verified
- nacd2023 (2023). 2023 Director's Handbook on Cyber-Risk Oversight · tier 1 · verified
- sec2023 (2023). Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure · tier 1 · verified
- Hambrick & Finkelstein (1987)Managerial discretion: A bridge between polar views of organizational outcomes. Research in Organizational Behavior · tier 1 · verified
- Hambrick (2007)Upper echelons theory: An update. Academy of Management Review · tier 1 · verified
- Wangrow et al. (2015)Managerial discretion: An empirical review and focus on future research directions. Journal of Management · tier 1 · verified
- Banker et al. (2011)CIO reporting structure, strategic positioning, and firm performance. MIS Quarterly · tier 2 · verified
- Peppard (2010)Unlocking the performance of the chief information officer (CIO). California Management Review · tier 1 · verified
- Gordon & Loeb (2002)The economics of information security investment. ACM Transactions on Information and System Security · tier 1 · verified
- Kamiya et al. (2021)Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics · tier 1 · verified
- Amir et al. (2018)Do firms underreport information on cyber-attacks? Evidence from capital markets. Review of Accounting Studies · tier 1 · verified
- Ashenden & Sasse (2013)CISOs and organisational culture: Their own worst enemy?. Computers & Security · tier 1 · verified
- Edmondson (1996)Learning from mistakes is easier said than done: Group and organizational influences on the detection and correction of human error. The Journal of Applied Behavioral Science · tier 1 · verified
- Milliken et al. (2003)An exploratory study of employee silence: Issues that employees don't communicate upward and why. Journal of Management Studies · tier 1 · verified
- Weill & Ross (2004). IT Governance: How Top Performers Manage IT Decision Rights for Superior Results · tier 1 · verified
- ians2026 (2026). State of the CISO 2026 Benchmark Report · tier 1 · verified
Each entry opens the research card with method, limitations and the usable claim.