Module 11Unit IV. The Leaders and the Capstone95 minEquation term: Current Moment

What Five Leaders Teach — Venables, Farshchi, Clinton, Carter, Halamka

Five documented careers, read for decisions rather than personalities, show the same thing the research shows: fit, calibration and information environment beat charisma.

Learning objectives

  1. For each of the five leaders, state the situation, the documented decision, the result as reported, and what it teaches against the course frameworks.
  2. Contrast the five on the dials and the overlays, including Farshchi's post-breach control posture against Venables' and Clinton's enablement posture.
  3. Identify what is contested or thinly documented in each record — including that Clinton's record is inputs only, because a private company's security outcomes are unobservable, and that his 2025 'AI employee' forecast was publicly scored as having missed.
  4. Extract cross-case patterns without hero worship: reporting line and board mechanisms, crisis ownership, tenure and calibration, enablement versus control.

Core lesson

This module does what the course has so far refused to do: it names real people. Five of them — Phil Venables, Jamil Farshchi, Jason Clinton, Rob Carter and John Halamka — read strictly for what they decided, what mechanism they installed, and what was reported afterwards, by whom.

The discipline is the point. A leader profile is the most seductive artifact in executive education, because a career reads like a causal story and almost never is one. So the module teaches a method before it teaches a person: locate the situation, isolate the documented decision, name who reported the result, then ask what it teaches. Adjectives about the person are excluded because they are unfalsifiable and they crowd out the mechanism you could copy.

In the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on Organizational Context, because the five careers show context doing far more of the work than any personal quality could. By the end you should be able to read any leader profile and say which sentences are evidence, which are company statements, and which are admiration in a suit.

The big idea

Five documented careers, read for decisions rather than personalities, show the same thing the research shows: fit, calibration and information environment beat charisma.

They also show something about the record itself. The security leaders you can read about are the ones who were breached, who published, or who worked in the open — so the reading list is a sample drawn by publicity, not by effectiveness. Learn the mechanisms; distrust the shape of the collection.

What the research says

This section is about method: what a documented career can and cannot support. Every study below is evidence about the record, not about any of the five.

RESEARCH FINDING— selection into visibility. Banker & Feng (2019) matched disclosed breaches to executive changes and found that breaches attributed to system deficiency increased CIO turnover likelihood by 72 percent, while breaches attributed to criminal fraud or human error showed no significant association. Archival; breach-cause classification depends on public descriptions; associations only. INTERPRETATION This is the mechanism that populates reading lists like this one. A technology executive becomes publicly legible at the moment blame is assigned, and blame tracks the perceived scope of the job. The careers we can document are therefore disproportionately those where something failed in a way that was classified as the executive's own.

RESEARCH FINDING— the unobserved denominator. Amir, Levi & Livne (2018) compared attacks firms disclosed with attacks they withheld that were later revealed by outside sources: withheld attacks were associated with about a 3.6% decline in equity value in the month of discovery, disclosed attacks with about 0.7%. Identification of "withheld" attacks depends on later external discovery; the study pre-dates mandatory disclosure. INTERPRETATION The design contains the lesson. Attacks never discovered cannot appear in any dataset, and neither can the careers built on top of them. When a profile says "no publicly reported breach during his tenure," the honest reading is that the record mixes clean programs with undiscovered ones in unknown proportion.

RESEARCH FINDING— the count is ambiguous in both directions. Higgs, Pinsker, Smith & Young (2016) found firms with board-level technology committees more likely to have reported breaches over 2005–2014, plausibly because they detect and disclose more. Edmondson (1996) found that across eight nursing units, stronger team climate and more active manager coaching were associated with higher detected error rates (r = .74). Both correlational; both conflate occurrence with reporting. INTERPRETATION A high incident count can mean good detection; a low one can mean silence. Neither alone distinguishes a strong program from a quiet one — which is why a leader's public incident history is poor evidence about them.

RESEARCH FINDING— the record is not a neutral window. Hayward, Rindova & Pollock (2004, from the CEO library) theorize that media-created executive celebrity fosters hubris and strategic persistence. Malmendier & Tate (2009, from the CEO library) find that CEOs who attain "superstar" status through media awards tend to underperform afterwards, earn more, and divert effort outside the firm, particularly where governance is weak. About CEOs, not CIOs or CISOs. INTERPRETATION Together they undo the intuitive use of recognition: an award is not a measurement of past performance but a treatment applied to a career, and the measured associations of that treatment are unflattering. Every award in the five profiles is therefore listed only to be discounted.

FACT— company-reported outcomes. The most quotable numbers here are statements by companies about themselves: Equifax's posture score and its sub-one-minute mean time to detect; FedEx's estimated $300 million first-quarter impact from NotPetya. These are facts about what the company said, produced by vendor benchmarking tools or internal accounting rather than independent audit. Cite them as disclosure, never as measured effects of an executive.

FACT— the private-company blind spot. For one of the five there is no outcome evidence of any kind. Anthropic is private: incident history, budgets, headcount, detection and response metrics, red-team results and audit findings are all unobservable from outside. Clinton's record is therefore inputs only — stated threat models, named control mechanisms, published decision frameworks. INTERPRETATION That is not a deficiency of the case; it is the case. It shows in clean form what is true in weaker form for all five: reputation in this profession is built on the legibility of a leader's reasoning, and legibility is not evidence that the reasoning worked.

Where the evidence is weak

No study in either library measures the effect of an individual CIO or CISO on security outcomes, and none could easily be designed: the outcome is rare, partly unobservable, confounded by industry and scale, and reported by the interested party. Everything in Section 4 connecting a decision to a result is therefore INTERPRETATION.

Explanation

Phil Venables — the long-horizon Architect with no crisis

Situation. CISO of Goldman Sachs from 2000 to 2017 with the standing of a partner, then chief operational risk officer; first CISO of Google Cloud, December 2020 to March 2025. Neither chair was created by a breach.

Documented decisions. He stayed — seventeen years in one chair and, on leaving, "being a CISO for 30 years spanning 4 CISO roles." He built institutions outside his own firm: co-founder of the Center for Internet Security (2000), co-founder and chairman of Sheltered Harbor (2015–2020), chair of SIFMA's cyber committee (2017–2020). In November 2025 he set out "CISO 2.0" — the CISO as "peer business executive," "peer technology leader," and "long-term player" — moving the organization "from a fire station, reacting to disasters, to a flywheel." In 2026 he proposed Control Reliability Engineering, treating "a Control Incident (a failed control)" with "the same gravity as a Security Incident."

Reported result. None measurable. No major breach was publicly reported at Goldman during his tenure, which per Section 3 is not evidence.

What it teaches. The Architect's leverage runs past the firm: Sheltered Harbor mutualizes recovery risk across competitors, rational only if your risk includes the state of the institutions around you. And the long-horizon argument is the only defense a no-crisis program has — Farshchi's discretion was supplied by an event; this had to be re-argued every budget cycle.

Jamil Farshchi — the post-crisis mandate, taken twice

Situation. CISO of The Home Depot from March 2015, about six months after the 2014 breach of 56 million payment cards; CISO of Equifax from February 2018; EVP and CTO from March 2024, with Equifax appointing a separate CISO in 2025.

Documented decisions. The reporting line was structural from the start — CISO direct to the CEO, with a line to the board. CEO Mark Begor's Senate testimony of 7 March 2019 records the machinery: an incremental $1.25 billion of security and technology spending for 2018–2020, "nearly 1,000" IT and security professionals added in 2018, security goals attached to the bonuses of 3,900 employees, and a "Board Cyber Audit Framework" of metrics developed by the CISO. From 2020 the company published a Security Annual Report annually. His own description in May 2018: "basically an open checkbook," and "before a breach, your success is dependent on convincing people about the value of security. I don't have to do that."

Reported result — company-reported. Posture scores exceeding technology and financial-services industry averages for six consecutive years (the sixth reported after a separate CISO was in post); mean time to detect under one minute; a roughly $3 billion transformation called "principally complete" in March 2026.

What it teaches. The mechanisms are copyable and the conditions are not. Direct reporting, a named board metric format and an annual published report convert temporary attention into permanent format — the real problem of a post-breach mandate, because attention decays faster than programs mature. Bonus linkage is the most copied and least examined element, and the research argues against it: Cram, D'Arcy & Proudfoot (2019), pooling 95 studies, found attitudes and personal norms far stronger predictors of compliance than punishment and rewards. INTERPRETATION It buys visible compliance in a chastened company; Angst et al. (2017) adds that symbolic adoption buys no protection.

Jason Clinton — the inputs-only record

Situation. About eleven and a half years at Google, latterly leading Chrome infrastructure security; inaugural CISO of Anthropic from April 2023 to approximately September 2025, and Deputy CISO since, when Anthropic hired Vitaly Gudanets as CISO. Anthropic is private, so nothing about outcomes is observable.

Documented decisions. He organized his own time around one asset: "I probably spend almost half of my time as a CISO thinking about protecting that one file" — the model-weights file — with the threat model stated as denial to criminals, terrorists and states rather than protection of intellectual property. The controls his organization implemented were published in May 2025: two-party control requiring a physical security key, a justification and second-party authorization at the time of request; egress bandwidth controls restricting data flow out of the environments where weights reside; binary allowlisting; mandatory cryptographic commit signatures. That document names the adversary classes it covers and places sophisticated state-sponsored attackers using novel attack chains explicitly out of scope. In July 2026 he authored a public decision procedure for agentic AI: "our jobs are to make agentic risk legible and bounded," a four-question model ("What untrusted content does it ingest? What actions can it take, and on whose behalf? What is the blast radius if it is misaligned? What observability do I have?"), least agency, and admin-paced rollout gated on telemetry.

Reported result. None. No incident history, no metrics, no budget, no audit findings.

What it teaches. Three things, none requiring belief that the program works. The dial is set per asset, not per person: maximum control on the crown jewel, deliberate enablement elsewhere. Publishing your ceiling is a maturity behaviour — naming the attacker class your controls do not stop is the institutional form of "I cannot do this yet." And the calibration case: in April 2025 he told Axios that AI "virtual employees" with their own credentials would begin operating on corporate networks within roughly a year; a year later John Gruber wrote that the prediction "has fallen flat on its face" and called the original piece "an advertisement" rather than a security warning. INTERPRETATION A missed public forecast is an ordinary cost of speaking publicly, and its teaching value lies in what follows — plus a warning for anyone speaking through a vendor's channel: the audience decides whether you were warning or selling.

Rob Carter — the inherited estate

Situation. CIO of FedEx for roughly 25 years to 30 June 2024, running the technology behind about 15 million daily shipments and a decade-long programme to simplify what he called the company's "accidental architecture."

Documented decisions and the event. He ran a decade-long simplification of the estate while integrating a newly acquired European subsidiary onto it. In June 2017 NotPetya hit that subsidiary, TNT Express, mid-integration. FedEx disclosed on 20 September 2017 an estimated $300 million first-quarter impact, later put at about $400 million; stated it had no cyber insurance covering the loss and was "re-examining the cyber-insurance market"; and described a recovery requiring restoration of "every facility, hub and depot."

Reported result. The loss figures above are the company's own. A securities class action over the disclosure was dismissed with prejudice on 4 February 2021.

What it teaches. M&A integration is a security decision, usually made by people who are not in the room. The exposure was not FedEx's own controls but an inherited estate nobody had priced into the deal model. Kamiya et al. (2021) is the closest evidence: attacks are associated with shareholder losses exceeding out-of-pocket costs. INTERPRETATION The uninsured loss is the more useful half — risk transfer is a pricing decision in the Gordon–Loeb (2002) sense, taken here only after the loss landed.

John Halamka — crisis ownership in public

Situation. CIO of CareGroup and Beth Israel Deaconess Medical Center from 1998. Between 13 and 18 November 2002 a spanning-tree loop, triggered by a large research data upload, took the hospital network down for about three and a half days and forced clinicians back to paper.

Documented decisions. He shut the network down entirely rather than continuing partial isolation, brought in Cisco's assurance team, rebuilt the core over a weekend — and documented the failure publicly: "I made a mistake. And the way I can fix that is to tell everybody what happened so they can avoid this."

Reported result. The episode became the Harvard Business School case CareGroup (McFarlan & Austin, 29 January 2003, no. 303-097) — the only one of the five records that does not depend primarily on the subject's own account.

What it teaches. Partial isolation, then full shutdown, then rebuild is a resilience decision taken against a prevention instinct — in a hospital, a patient-safety decision before an IT one. The deeper lesson is what preceded it: infrastructure lifecycle neglected because it was invisible. The public post-mortem is the Two-Sentence Test's second sentence, performed institutionally.

Cross-case patterns

FRAMEWORK— four patterns, stated as patterns and not as findings.

1. Reporting line and board mechanisms decide whether judgment travels. Farshchi's line to the CEO and his Board Cyber Audit Framework are the clearest instance: a format the board adopted, which outlives the person who wrote it. Venables' partner standing is the same variable supplied by governance; Clinton's reporting line is not public at all. Banker et al. (2011) is the evidence that the line matters and none is universally correct. INTERPRETATION The transferable act is not "report to the CEO" but to install one repeatable reporting format the board owns.

2. Crisis ownership is a decision about the information environment, not about courage. Halamka shut the network down and then published; FedEx disclosed a nine-figure impact and its own lack of insurance; Farshchi made the metrics public annually. Ashenden & Sasse (2013) found CISOs describing low perceived power, unclear role identity and weak engagement as their central obstacles — and public ownership of failure moves all three at once.

3. Tenure and calibration travel together. Venables and Carter are the long tenures, and both records are about multi-year architecture rather than a single decision. Zhang & Rajagopalan (2010, from the CEO library) found an inverted-U between strategic change and performance, with a wider swing for outsiders. INTERPRETATION Long tenure is the precondition for one kind of program and a risk factor for one kind of blindness; the question is whether the leader re-derives the plan or merely continues it. Clinton's publicly scored forecast shows what re-deriving requires: a dated claim someone can check.

4. Enablement versus control is a per-situation setting. Farshchi's post-breach posture is control-weighted, correctly, for a season; Venables' CISO 2.0 and Clinton's "legible and bounded" are enablement-weighted, in organizations not on fire; Halamka's shutdown is maximal control for four days inside a career of clinical enablement. INTERPRETATION Enablement is not the more sophisticated setting. All five were chosen against a situation, and every failure in Section 7 is a setting that outlived the situation justifying it.

Example

Fictional composite.

Devika Raman is CIO and CISO of Sable Ridge Managed Services, a 90-person BPM/MSP firm in Worcester, Massachusetts, running the network, help desk, email and security program for about 140 SMB and mid-market clients — a dozen broker-dealers and RIAs, thirty medical and dental practices, the rest professional services. Revenue is $21 million; her security budget, including her own time, is under $600,000.

In March the founder-CEO forwarded her a magazine profile of a well-known post-breach CISO with three words: "Can we do this?" The profile described a direct line to the CEO, $1.25 billion of incremental spend, a thousand hires in a year, bonuses wired to security goals for 3,900 people, and a board metrics framework. Her first instinct was to reply that the comparison was absurd. Her second, better instinct was to separate the mandate from the mechanism.

The mandate, she wrote back, was supplied by an event: a public breach had reset the reporting line, the budget and the board's attention before that CISO arrived. Sable Ridge had no such event, so every mechanism would have to be argued on its merits, annually, against payroll and a sales hire. Bonus linkage for 3,900 people is meaningless in a firm of ninety — and worse, it installs a compliance lever where the actual constraint was that engineers did not tell her things.

Two mechanisms transferred, and cost almost nothing. The first was a named format the owners adopt: one page for the quarterly owners' meeting — what we said we had, what we can prove we have, the gap, the date, and the two risks we are accepting on purpose. The second was evidence per control: she rewrote the program so every control pointed at a log, a ticket or a review rather than a policy sentence. Eleven weeks of work, and it surfaced that quarterly access reviews at four clients existed only as attestations.

Then the part she did not plan. In September a broker-dealer client's compliance officer asked Raman to walk her board through "how you know your controls work." Raman used the same one-pager with the client's controls in it. By December, seven clients were paying a monthly fee for the format, and Sable Ridge had a vCISO product built from a mechanism extracted from a company two thousand times its size. What she did not copy was what the profile spent most of its words on: the person.

INTERPRETATION The transferable content of a famous career is never the temperament and rarely the budget. It is the two or three mechanisms that survive being stripped of their conditions — found by reading for what was installed, not for what was admired.

Leader Contrast

INTERPRETATION— this section is inference and should be read as hedged. None of the five has been asked this question in public; what follows is how their documented decisions would most plausibly be applied, and a reader who treats it as prediction has already made the module's central error.

The dilemma. Your audit committee chair asks for one number. "I don't want a dashboard. I want a single answer to 'are we secure?' that I can hold you to." Thirty seconds, and a chair who is not being unreasonable.

Venables would most plausibly refuse the number and offer a different one: indicators for whether each named control is currently performing to its stated objective, and which degraded this quarter. Gain: an honest, movable number with an engineering meaning. Cost: it needs a control inventory most companies lack, and the chair may hear evasion first.

Farshchi's documented answer is a benchmarked score with a board format around it — a posture score against industry averages, published annually. Gain: the chair gets what they asked for, and it survives a change of CISO. Cost: the failure mode Angst et al. (2017) describe — the score becomes the program and adoption drifts symbolic.

Clinton's documented posture points at scope rather than score: state what the controls cover and, explicitly, what they do not. Gain: the most honest answer available, and it makes a later incident survivable. Cost: it hands the committee a sentence that reads badly in litigation and worse in a newspaper.

Carter's answer would most plausibly be financial, and would include what is not insured — his documented experience is a nine-figure loss at an acquired subsidiary against no applicable cover. Gain: it speaks the committee's native language and forces the insurance question. Cost: expected-loss numbers in security are estimates wearing a suit.

Halamka's answer would most plausibly be about recovery: how long the organization can run without its systems, and how recently that was proved. Gain: testable, and in clinical or logistics settings the number that matters. Cost: it says nothing about confidentiality, which the market prices most sharply.

INTERPRETATION Four of the five refuse the question as asked and substitute a number they can defend. That refusal — in one sentence, with an alternative attached — is the skill this section teaches.

Failure mode

FRAMEWORK— the Overuse Ladder applied to admiration. The rungs run readingimitationidentificationidentity. The first is what this module asks for; the second is defensible when conditions match; the third is where the leader stops asking whether the situation is the same; the fourth is where a borrowed record answers questions it was never asked.

Idolization. The damage is not that the admired leader was wrong; it is that admiration replaces analysis and mechanisms arrive without their conditions. A CISO who has internalized a famous post-breach program reaches for its instruments as a set, when only two of them fit.

Copying a post-breach playbook into a company that is not post-breach. The most common and most expensive version. Turnaround settings — centralization, urgency, decisiveness, unilateral action, a control-weighted posture — are correct for a season and corrosive afterwards, because they are premised on an organization that has just failed and knows it. Applied to a company that has not, they read as distrust of people who were never at fault. The damage is specific: engineers route around the bottleneck, the workarounds become the attack surface, and you learn about them from an incident rather than from a person.

Mistaking visibility for effectiveness. The reading list is drawn by publicity (Section 3), and the career-level version of the error is optimizing for whatever made your models legible. Malmendier & Tate (2009, from the CEO library) is the sharpest warning: award-winning CEOs subsequently underperformed, earned more, and diverted effort outside the firm, especially where governance was weak. HYPOTHESIS The security-chair analogue — a CISO's conference and publishing load shifting attention away from the program — is untested, but plausible enough that a board should be able to ask about it without it being an insult.

Early warning signs

  • You describe your company's problem in another executive's vocabulary, and the sentence still works if you delete your company's name.
  • A mechanism is in your plan and you cannot state the condition that made it work where you found it.
  • Your program has adopted a benchmark score, and nobody can say what would make it fall.
  • Your incident count is falling and you have not asked whether reporting is falling with it (Edmondson, 1996).

Personal reflection

  1. Take the leader whose record you find most persuasive. Write the three conditions that made their mechanisms work, and mark which of the three you have. What does the gap cost you?
  2. Which element of your current program did you import from someone else's story, and what evidence do you have that it fits here?
  3. If your incident count fell 40% next quarter, what would you check before reporting it as good news?
  4. Write the sentence Clinton's published scoping implies for your own program: "Our controls are designed to stop ____; they are not designed to stop ____." Who above you needs to hear it, and what has stopped you saying it?
  5. Name your inherited estate — systems you did not choose, from an acquisition, a client, an MSP or a predecessor. When was its condition last priced, and by whom?
  6. If forced to give an audit committee one number, which of the five answers in Section 6 would you give?
Simulation · this module · ~10 min

Month Seven at Brightmoor

Brightmoor Benefits Administration · Third-party administration of self-funded health plans (HIPAA business associate) · $610M · Turnaround · PE-backed

Ninety days to show the board something, against a three-year $46M budget, an open OCR investigation, consolidated litigation, a departing largest client, and a reporting line to a CIO who has not been hired.

Take the decision →

Knowledge check

Pick an answer to reveal the explanation. Nothing is scored or stored.

1Banker & Feng (2019) found CIO turnover significantly more likely after which kind of breach?

2What methodological point does this module draw from Amir, Levi & Livne (2018)?

3Which statement about the Jason Clinton record is accurate as this curriculum uses it?

4A CISO tells you reported security incidents fell 40% year on year. Give two readings and say what you would check first.

Key takeaways

  • Read a career for the situation, the documented decision, who reported the result, and the mechanism — never for the person.
  • The reading list is drawn by publicity, not effectiveness. Banker & Feng (2019) explain who becomes documentable; Amir et al. (2018) why a clean record is ambiguous; Malmendier & Tate (2009, from the CEO library) why awards are a treatment rather than a measurement.
  • Company-reported outcomes are facts about what a company said. Clinton's record has no outcomes at all, because a private company's security results are unobservable, and the curriculum says so rather than filling the gap.
  • Four patterns survive the five cases: install a board format rather than chasing a reporting line; own the crisis in public; treat long tenure as a precondition and a risk together; and set the control–enablement dial against the situation, not the personality.
  • Every failure mode here is a setting that outlived its situation, and the earliest warning sign is hearing your own problem described in someone else's words.

Research cited in this module

  • Banker & Feng (2019)The impact of information security breach incidents on CIO turnover. Journal of Information Systems · tier 2 · verified
  • Amir et al. (2018)Do firms underreport information on cyber-attacks? Evidence from capital markets. Review of Accounting Studies · tier 1 · verified
  • Hayward et al. (2004)Believing one's own press: The causes and consequences of CEO celebrity. Strategic Management Journal · tier 1 · verified
  • Malmendier & Tate (2009)Superstar CEOs. Quarterly Journal of Economics · tier 1 · verified
  • Higgs et al. (2016)The relationship between board-level technology committees and reported security breaches. Journal of Information Systems · tier 2 · verified
  • Edmondson (1996)Learning from mistakes is easier said than done: Group and organizational influences on the detection and correction of human error. The Journal of Applied Behavioral Science · tier 1 · verified
  • Kamiya et al. (2021)Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics · tier 1 · verified
  • Banker et al. (2011)CIO reporting structure, strategic positioning, and firm performance. MIS Quarterly · tier 2 · verified
  • Gordon & Loeb (2002)The economics of information security investment. ACM Transactions on Information and System Security · tier 1 · verified
  • Angst et al. (2017)When do IT security investments matter? Accounting for the influence of institutional factors in the context of healthcare data breaches. MIS Quarterly · tier 1 · verified
  • Cram et al. (2019)Seeing the forest and the trees: A meta-analysis of the antecedents to information security policy compliance. MIS Quarterly · tier 1 · verified
  • Zhang & Rajagopalan (2010)Once an outsider, always an outsider? CEO origin, strategic change, and firm performance. Strategic Management Journal · tier 1 · verified
  • Ashenden & Sasse (2013)CISOs and organisational culture: Their own worst enemy?. Computers & Security · tier 1 · verified

Each entry opens the research card with method, limitations and the usable claim.

Related

Dials exercised
Aggression ↔ CautionCentralization ↔ DecentralizationDecisiveness ↔ InquiryHands-on ↔ DelegationUrgency ↔ Patience
Learn categories