The Two-Sentence CISO — Visibility, Blame, and Mature Conviction
Visibility ≠ effectiveness, and blame ≠ accountability. The rarest technology leader can say "Yes — and here is the risk, priced" and "I was wrong about that risk. Change the control." in the same quarter.
Learning objectives
- Explain why the public knows breached CISOs and celebrity CIOs rather than quiet operators, and what the celebrity research does and does not establish.
- Distinguish blame from accountability using four tests, and explain why executive turnover after a breach tracks perceived scope of duties rather than causal contribution.
- Articulate what each of the four sentences — the Two-Sentence Test plus the Risk Corollary — actually requires of the person saying it.
- Produce a Personal Calibration Plan: tendency profile, three dials, fit and discretion analysis, bad-news mechanisms, 90-day commitments, and the Risk Corollary rehearsed with your CEO.
Core lesson
This is the capstone, and it asks one question: what would it take for you to be a technology executive whose judgment is worth having when it is inconvenient?
Two confusions stand in the way. The first is between visibility and effectiveness. You can name breached CISOs and a handful of celebrated CIOs; you cannot name the operators who ran clean programs for a decade, because prevention has no press release and the counterfactual is unobservable. The second is between blame and accountability. Blame is what an organization does after a bad outcome, and it lands where perceived scope of duties says it should. Accountability is a design decision made in advance — who owns which risk, at what threshold, recorded where. A company can have plenty of the first and none of the second.
The course's closing device is four sentences. Two from the CEO edition: "We're going to do this." and "I was wrong. Change the plan." Two added by the security chair — the Risk Corollary: "Yes — and here is the risk we are accepting, priced." and "No — and here is what would change my answer." Each requires something specific, and the requirement is usually structural rather than temperamental.
In the Effectiveness Equation — Traits × Behaviors × Organizational Context × Current Moment — this module works on Behaviors, and produces the artifact the course exists for: a Personal Calibration Plan you write about yourself, with dates.
The big idea
Visibility ≠ effectiveness, and blame ≠ accountability. The rarest technology leader can say "Yes — and here is the risk, priced" and "I was wrong about that risk. Change the control." in the same quarter.
Almost everyone can manage one of those. The leader who only prices is eventually the one who accepted the wrong thing and never revisited it; the leader who only revises never made a decision anyone could act on. Holding both is not a personality; it is a set of mechanisms plus the standing to use them.
What the research says
FRAMEWORK Hayward, Rindova & Pollock (2004), from the CEO library, developed the construct of CEO celebrity: journalists attribute a firm's distinctive and consistent strategic actions to the CEO's disposition, and the CEO who internalizes that attribution becomes overconfident about their own efficacy and persists with the actions that generated the celebrity even after they stop paying off. It is a theory-building paper with propositions, not an empirical test, so cite it for the mechanism rather than for effect sizes.
RESEARCH FINDING Malmendier & Tate (2009), from the CEO library, supplies the empirical half. Using prestigious business-press awards as a shock to status and comparing winners with matched predicted winners who did not win (US large firms, 1975–2002), award-winning CEOs subsequently underperformed relative to their own prior record and to the matched group; they received higher pay, spent more time on outside activities such as board seats and book-writing, and their firms showed more earnings management, with the effects strongest where governance was weak. Mean reversion is partly but not entirely addressed by the matching design. INTERPRETATION No equivalent study exists for CIOs or CISOs. The mechanism is plausible in a security chair and unproven there.
RESEARCH FINDING Chatterjee & Hambrick (2011), also from the CEO library, found that narcissistic CEOs appear to discount objective performance feedback while amplifying their risk taking in response to media praise and awards. Archival proxies for narcissism; associations. Read together with the two studies above, the pattern is that public recognition changes what an executive attends to — and the specific thing it displaces is the unglamorous, corrective signal.
RESEARCH FINDING Banker & Feng (2019) is the accountability evidence. Breaches attributed to system deficiency increased CIO turnover likelihood by 72 percent; breaches caused by criminal fraud or human error showed no significant association with CIO turnover. CEO turnover rose after both system-deficiency and human-error breaches; CFO turnover showed no relationship. Archival matching of disclosed breaches to executive changes, with breach cause classified from public descriptions, and turnover is not always dismissal. INTERPRETATION Consequences track the perceived scope of the executive's duties, not their causal contribution. That is a description of blame, and it is why "were you at fault?" and "were you removed?" are different questions.
RESEARCH FINDING Amir, Levi & Livne (2018) compared attacks firms disclosed with attacks they withheld that outsiders later revealed: withheld attacks were associated with a decline of approximately 3.6% in equity value in the month of discovery, against about 0.7% for disclosed attacks. Archival, pre-dating mandatory disclosure, and withheld attacks are observable only when someone else finds them. Concealment is priced when discovered — the market's version of the boundary the Sullivan case draws in law.
RESEARCH FINDING Edmondson (1996) is the reason a quiet year is not self-evidently a good one. In eight nursing units across two hospitals (146 respondents), units with stronger team climates and more active nurse-manager coaching showed higher detected drug-error rates — the correlation between manager coaching and detected errors was r = .74, and with intercepted errors r = .71. Correlational, in healthcare, with error rates drawn from reporting systems that climate itself affects, which is the paper's point. Her 1999 study of 51 teams then linked psychological safety to learning behavior and performance, cross-sectionally and in a single company. Low incident counts can signal silence rather than safety.
RESEARCH FINDING Two more studies bound what a leader's authority actually rests on. Ashenden & Sasse (2013), interviewing five CISOs, found they described their central obstacles as low perceived power, confusion about role identity and weak engagement with employees — illustrative, not generalizable. Cram, D'Arcy & Proudfoot (2019), pooling 95 papers across 17 antecedent categories, found employees' attitudes, personal norms and ethics were the strongest predictors of security-policy compliance while punishment and rewards were among the weakest — largely survey-based studies measuring intention more often than behaviour. INTERPRETATION The lever the blame-oriented organization reaches for first is the one the evidence rates lowest.
TIER 3. For base rates only, from a self-selected practitioner sample: the IANS/Artico State of the CISO 2026 survey of more than 600 security leaders reports that 52% say their responsibilities are not manageable given current resources and 69% are open to changing jobs within the next year.
Where the evidence is weak
There is no study in either library of CISO or CIO celebrity, of what public profile does to a security executive's judgment, or of whether any of the four sentences improves any outcome. The celebrity research is about CEOs in a different labour market, with awards as the status shock and share price as the outcome; a security executive has neither. Banker & Feng (2019) concerns CIOs, not CISOs, and measures turnover rather than fault. The Sullivan case is a documented legal record about one person, not evidence about a population. Everything in section 4 that is not explicitly cited is FRAMEWORK and INTERPRETATION.
Explanation
Why the public knows the breached and the celebrated
INTERPRETATION There are two doors through which a technology or security executive's name reaches the public. One is a breach. The other is a stage — a keynote, a profile, an award, a vendor's advisory board. Both are visibility events, and neither is a measurement. The operators who ran good programs for a decade without an incident are invisible by construction, because the evidence of their work is an absence, and absences are not news.
Hayward et al. (2004) explain the machinery. Journalists need a cause, and a person is a better cause than a control framework, so distinctive and consistent action gets attributed to disposition. In security this attribution runs backwards: the distinctive, consistent, visible action is almost always an incident response, so the person the public associates with security competence is disproportionately someone who was present at a failure. The most-known names in the field are a sample selected on the outcome the field exists to prevent.
Then the second-order effect. Malmendier & Tate (2009) found award-winning CEOs underperforming their own prior record afterwards, earning more, and diverting effort outward; Chatterjee & Hambrick (2011) found narcissistic CEOs discounting objective feedback while amplifying risk-taking in response to praise. HYPOTHESIS The security analogue is not that a famous CISO becomes reckless. It is that a CISO who has become a public representative of their program acquires a reason not to hear that the program is worse than described — and the corrective signal a CISO depends on (the near-miss, the click, the misconfiguration) is exactly the signal that is easiest not to hear. Untested in this population.
The course's phrasing: visibility ≠ prevalence; visibility ≠ effectiveness. A profile is evidence that someone found you interesting.
Blame is not accountability
FRAMEWORK Banker & Feng (2019) found CIO departures about 72% more likely after breaches attributed to system deficiency and no significant association after breaches attributed to fraud or human error. Note what that is not: a finding that CIOs cause system-deficiency breaches. It is a finding that organizations remove executives when the failure falls inside the perceived boundary of their job. Blame follows the shape of the role description.
Accountability is different, and four tests separate them.
Was it named in advance? Accountability is written down before the outcome — this person accepts this class of risk to this threshold. Blame is assigned afterwards, from the outcome backwards.
Does it attach to a role or a person? Accountability survives a personnel change because the obligation belongs to the chair. Blame is about the individual and ends when they leave, which is why blame is cheaper and changes nothing.
Does it produce a system change or a roster change? After a genuinely accountable failure, the control, the threshold or the decision right changes. After a blame event, the org chart changes and the control does not.
Could the person have said no beforehand? Accountability without the authority to refuse is a trap. This is where Module 10's discretion audit returns: an executive scoring zero on veto rights and incident command authority is being held accountable for outcomes they had no structural means to prevent.
The organizational cost of confusing the two is measurable in the reporting culture. Cram et al. (2019) found sanctions among the weakest predictors of security-policy compliance and employees' own norms among the strongest; Edmondson (1996) found better-led units reporting more errors. A blame-oriented program produces the number an executive wants to see and none of the information they need.
The four sentences and what each requires
FRAMEWORK Each sentence has a precondition that is usually structural, not emotional.
"We're going to do this." Requires a priced position you can defend, the standing to state it (Module 10), and willingness to own the consequence when the price turns out to be wrong. Its failure mode is the executive who converts every decision into an options paper so that no sentence is ever attributable.
"I was wrong. Change the plan." Requires three things and only one of them is character. It requires a mechanism that tells you — the Information-Environment Stack from Module 5: near-miss reporting, blameless review, standing red-team, direct lines from engineers, the quarterly "what we got wrong." It requires a record of what you believed and when, or you cannot tell revision from revisionism. And it requires an environment where saying it is survivable, which is a fact about your CEO as much as about you.
"Yes — and here is the risk we are accepting, priced." Requires quantification you can defend and will volunteer the weakness of (Gordon & Loeb, 2002, and its assumptions), a named accepter who is not you, a written record, and a review date. A "yes" without those four is not a priced acceptance; it is agreement with extra vocabulary.
"No — and here is what would change my answer." Requires that the changing condition be real and reachable — a compensating control, a contract term, a test result, a date. Falsifiability is the whole point. A "no" whose condition cannot be met is a refusal in costume, and the business learns to route around you rather than negotiate with you.
INTERPRETATION The pair that is genuinely rare is the third and second in the same quarter: pricing a risk, accepting it in public, then returning three months later to say the price was wrong. That is what "enablement with institutional paranoia" looks like when it is real rather than a slogan.
The Sullivan case
FACT Joseph Sullivan, then chief security officer of Uber and previously chief security officer of Facebook, was convicted in October 2022 of obstruction and misprision of a felony for concealing Uber's 2016 breach, was sentenced in 2023, and had his conviction affirmed by the Ninth Circuit on 13 March 2025 (United States v. Sullivan, No. 23-927).
INTERPRETATION The case is taught here for one reason and misused for several others, so be precise about all of them. It is not evidence about Sullivan's competence as a security executive; nothing in the record speaks to that. It is not a case about being breached — Uber's breach is not what was prosecuted. It is a case about concealment from the people entitled to know, decided by a court, and it marks the outer boundary of the first sentence. "We're going to do this" is a decision you own; it stops being a decision and becomes something else at the point where the choice is to keep a material fact from a regulator.
Two connections make it a course case rather than a news story. Amir et al. (2018) is the market's version of the same boundary: withheld attacks later discovered were associated with roughly a 3.6% equity decline against 0.7% for disclosed ones — concealment is priced when it is found. And the SEC's 2023 rules have since converted part of the judgment into a dated obligation: a material incident is disclosed on Form 8-K within four business days of the materiality determination (FACT). What remains judgment is the determination itself, and that judgment is made by someone under pressure who believes the situation is contained. Every executive in this course will at some point believe a situation is contained.
The five leaders, in one line each
Module 11 does this properly, with sources. Here they are only pointers to where the four sentences have been visible in documented careers: Phil Venables (CISO at Goldman Sachs, then Google Cloud) on long-horizon program building and public first-person reasoning; Jamil Farshchi (CISO at Home Depot and Equifax, later CTO) on the post-breach mandate and the structural mechanisms that came with it; Jason Clinton (Anthropic's inaugural CISO from April 2023 to September 2025, now Deputy CISO) on published decision frameworks — and on a record that is inputs only, since a private company's security outcomes are unobservable, plus a dated public forecast that was later scored as having missed; Rob Carter (FedEx CIO across roughly twenty-five years to June 2024) on tenure long enough to own a full architecture cycle; John Halamka (CareGroup/BIDMC CIO, later Mayo Clinic Platform) on owning a crisis in public. No new facts here. Go to Module 11 before you cite any of them.
The Personal Calibration Plan
FRAMEWORK The deliverable of this course. Six parts, written about yourself, in a document with dates, revisited quarterly.
1. Tendency profile. Your assessment results plus two behavioral anchors per tendency — actual decisions, dated, that show the tendency operating. A tendency you cannot evidence with a decision is a self-description, not a profile. Note explicitly where your self-rating and your last 360 disagreed.
2. Three dials to move. Not eight. For each: the current setting, the setting the next twelve months require, the evidence that you are currently at the first, and the specific recurring situation in which you will practise the second. "Move optimism toward skepticism" is a wish. "In every vendor-security review, write the failure scenario before reading the vendor's questionnaire" is a dial movement.
3. Fit and discretion analysis. The extended Fit Equation — Industry × Scale × Lifecycle × Strategy × Governance × Problem × Reporting Line — with one line for the company and one for you on each term, and the weakest term circled (Module 9). Then the eleven-item discretion audit from Module 10, scored twice: as you see it and as your CEO would. Name your reporting line's actual effect: which conversation it puts you inside, and which it keeps you out of. Banker et al. (2011) is the reminder that no line is universally right; Karahanna & Preston (2013) is the reminder that the relationship is a mechanism you can build even where the line is fixed.
4. Bad-news mechanisms. The Information-Environment Stack, with the current state of each layer and the one you will install next quarter: near-miss reporting, blameless post-incident review, standing red-team, direct lines from engineers and client teams, and the quarterly "what we got wrong." Milliken et al. (2003), from the CEO library, is the working assumption: most employees can recall withholding an important concern from a superior, so assume filtering and audit reach rather than trusting volume.
5. Three 90-day commitments. Each with a date, an observable outcome, and a named person who will tell you if it did not happen. Examples of the right shape: "By 15 March, one written risk acceptance signed by a named business executive, with a review date." "By 30 April, the incident-command authority memo signed." "By 31 May, a blameless review published internally for an incident where my own decision was a contributing factor."
6. The Risk Corollary, rehearsed with your CEO. Not a metaphor — a scheduled conversation with a real decision in it. Bring one thing you are saying yes to with the risk priced and a named accepter, and one thing you are saying no to with the condition that would change your answer. Ask your CEO two questions afterwards: which sentence was easier to hear, and what would have made the other one credible. Owens & Hekman (2012), from the CEO library, identify admitting mistakes and limits as one of three observable humble-leader behaviors that spread to teams — with the caveat that humility appears less effective under extreme threat and time pressure, which is precisely why this conversation is scheduled in calm.
Example
Fictional composite.
Dr. Naomi Etuk had been CISO of Bellhaven Grove Health Partners — a 3,100-employee integrated health system in western Massachusetts — for three years when her CEO forwarded her a note from a national conference organizer inviting her to keynote on "the health system that didn't get hit." She wrote her Personal Calibration Plan that weekend instead of a talk.
Tendency profile. Two anchors per tendency, dated. The uncomfortable one: under time pressure she had twice overridden her own architecture review — once for a scheduling platform in March, once for a remote-radiology integration in September — and both times had told herself it was pragmatism. Her 360 the previous year had a comment she had dismissed: decisive, but the reasons change afterwards.
Three dials. Optimism → skepticism, practised in one recurring place: the vendor review, where she would now write the failure scenario before opening the questionnaire. Hands-on → delegation, because she was still personally approving every firewall change and her deputy had stopped proposing them. Urgency → patience on the clinical-workflow controls, where speed had produced three documented workarounds by nurses in one quarter — the Edmondson (1996) pattern in reverse: not silence, but people telling her in the form of behaviour rather than words.
Fit and discretion. The weakest term of the Fit Equation was Reporting Line: she reported to the CIO, whose delivery targets she priced. Discretion audit, scored as she saw it: 16. Scored as she believed her CEO would: 22. The six-point gap sat almost entirely on veto rights and mandate clarity — items neither of them had ever written down and both assumed were settled.
Bad-news mechanisms. Near-miss reporting existed and produced four reports a quarter, which she had been reading as good news. She reclassified it as a suspicious number for a 3,100-person organization and made auditing its reach the next quarter's project.
Three commitments. A signed risk acceptance for the legacy imaging system from the chief medical officer, with a review date, by 15 March. A blameless review of the September radiology integration — her own override — published internally by 30 April. Written veto thresholds agreed with the CIO and CEO by 31 May.
The Risk Corollary rehearsed. She booked forty minutes with the CEO. The yes: the ambient-documentation AI pilot the clinicians wanted, priced at roughly $2–4M of expected annual loss in its first configuration, accepted by the chief medical officer, reviewed in six months. The no: extending remote access to a third-party billing vendor without a contractual right to audit, with the condition stated — the audit clause, or a broker in front of it.
It did not go as rehearsed. The CEO accepted the yes without argument and pushed hard on the no, and Etuk discovered mid-sentence that her condition was not actually reachable in the vendor's contract cycle — a "no" in costume. She said so out loud, which was the part of the exercise she had not planned, and left with a worse-defined position and a better one to build.
She declined the keynote. Then, six weeks later, she accepted a different invitation: a panel on failed integrations, where the material was the September override and the review she had published about it.
Leader Contrast
Give the same magazine invitation, and the same calibration plan, to four archetypes.
The Technical CISO declines the profile immediately and privately, and the instinct is sound — the visibility research (Hayward et al., 2004; Malmendier & Tate, 2009) describes a real hazard. Gain: no exposure, no distortion, no time lost. Cost: this leader also declines the internal visibility that would let anyone check their reasoning, and their calibration plan lists eight dials they intend to move by force of will and no mechanism that would tell them they had not. Refusal is not calibration; it is the same avoidance in a more respectable coat.
The Business-Risk CISO takes the profile and does it well, redirecting the story toward mechanisms and the team. Gain: hiring improves, the CEO is pleased, the board reads it as validation of their oversight. Cost: this leader now has a public description of the program, and the gap between description and reality becomes a thing to manage rather than a thing to report. Watch the what we got wrong section of the next two board packs; if it shortens, the profile is doing the work the research predicts.
The Post-Breach CISO (Turnaround) treats a clean year with suspicion and refuses to call it a result at all. Gain: exactly the right reading of Edmondson (1996) — the quiet may be silence — and the most rigorous audit of the near-miss channel of the four. Cost: a team that has genuinely performed well is told, for the third year running, that nothing has been proven, and the best detection engineer leaves for somewhere that says thank you. The dials set for a blame environment do not stand down when the blame does.
The Enterprise CIO (Architect) hands the profile to the communications function and turns the calibration plan into a governance artifact: a RACI, a metrics tree, a quarterly review board. Gain: the plan survives this leader's departure, which is more than most calibration plans manage. Cost: a document nobody experiences as personal, and the one thing the exercise was for — the dated, uncomfortable, first-person admission — is delegated into a process. The Two-Sentence Test cannot be performed by a committee.
The invitation is not the decision. The decision is what each leader does with the fact that a good year is ambiguous evidence.
Failure mode
FRAMEWORK— the Overuse Ladder for candor and conviction.
Conviction → epistemic arrogance. "We're going to do this" hardens into a habit of treating challenge as a failure of comprehension in the challenger. The tell is that the executive can recall being disagreed with but not being persuaded.
Candor → performance of candor. "I was wrong" becomes a ritual, delivered fluently and always about something cheap — a tool choice, a timeline — and never about a risk acceptance the person argued for. Ritual self-criticism buys the reputation for humility while insulating the decisions that matter. It is harder to detect than concealment because it looks like the thing the course asked for.
Pricing → the number nobody checks. A priced acceptance with a named accepter and a review date is a control. The same acceptance with no review date is a document that ages into a liability, and the executive who produced it will be surprised to find their name on it.
Refusal → "no" as identity. The condition attached to the "no" becomes decorative, then unreachable, then absent. The business stops negotiating and starts routing around, and the workarounds become the attack surface.
Visibility → constituency. The executive acquires an external audience whose expectations differ from the company's, and begins optimizing for the audience that applauds rather than the one that pays. Malmendier & Tate (2009) found award winners diverting effort into outside activities; the security version is a speaking calendar that grows while the near-miss channel quietly dies.
Early warning signs
- Your last three "I was wrong" statements were all about tools and none about a risk you priced.
- Your near-miss reports fell this year and you described that to the board as improvement.
- You cannot name a person who told you something unwelcome in the last quarter.
- You have a public description of your program and a private one, and you know which is accurate.
- The condition attached to your last "no" has not been met and nobody has asked about it since.
Personal reflection
- Name the last time you said "I was wrong" about a risk you had personally priced and argued for. If you cannot, is that because it has not happened or because it was not said out loud?
- Which of the four sentences is hardest for you, and is the obstacle temperament, mechanism or standing? Which of those three could you change this quarter?
- Take your last risk acceptance. Is there a named accepter who is not you, and a review date that has not passed? If not, what does that document actually do?
- Your incident-reporting numbers moved last year. Write both readings — the program improved, and the reporting climate degraded. What evidence would distinguish them, and do you have it?
- If a national publication profiled you next month, what in your program would you not want a careful reader to ask about? Who else already knows about it?
- If you were removed after a breach tomorrow, would it be blame or accountability? Answer using the four tests, not your feelings.
- Write the two Risk Corollary sentences you will say to your CEO this quarter, with the real decision attached to each. Put the date in your calendar before you finish this module.
The Ones Who Got It Right
Sablewood Financial Technologies · Payments and reconciliation platform for mid-market banks (financial technology) · $420M · Mature · PE-backed
Ninety minutes on the record, publication in eight weeks, inside a sale process expected within eighteen months — with two unremediated high findings in the reconciliation service and an on-call rotation of five covering a design of seven.
Take the decision →Knowledge check
Pick an answer to reveal the explanation. Nothing is scored or stored.
1Malmendier & Tate (2009), using business-press awards as a status shock in US large firms from 1975 to 2002, found that award-winning CEOs subsequently:
Effects were strongest where governance was weak, and their firms also showed more earnings management; the matching design partly but not fully addresses mean reversion, and no equivalent study exists for CIOs or CISOs.
2Banker & Feng (2019) found CIO turnover was about 72% more likely after which kind of breach?
Fraud and human-error breaches showed no significant association with CIO turnover, which suggests consequences track the perceived scope of the executive's duties rather than causal contribution — a description of blame, not of accountability.
3State the four tests that distinguish blame from accountability, and explain why the fourth test connects this module to the discretion audit.
Model answer. Was it named in advance, or assigned from the outcome backwards? Does it attach to a role or to a person? Does it produce a system change or a roster change? Could the person have said no beforehand?
The fourth test links directly to Module 10 — an executive with no veto rights and no incident command authority is being held accountable for outcomes they had no structural means to prevent, which is blame wearing accountability's vocabulary.
4Name the four sentences and state one concrete requirement for each — something a person or organization must have, not a disposition.
Model answer. "We're going to do this" requires a priced position and the standing to state it. "I was wrong. Change the plan" requires a mechanism that tells you (the Information-Environment Stack) and a dated record of what you previously believed. "Yes — and here is the risk we are accepting, priced" requires a named accepter who is not you, plus a written record and a review date. "No — and here is what would change my answer" requires a condition that is real and reachable.
Each precondition is structural rather than temperamental, which is why the Personal Calibration Plan pairs the dials with a discretion analysis and dated commitments instead of intentions.
Key takeaways
- Visibility ≠ effectiveness. You know breached CISOs and celebrated CIOs because both are visibility events; prevention has no press release, and the field's best-known names are a sample selected on the outcome the field exists to prevent (Hayward et al., 2004; Malmendier & Tate, 2009; Chatterjee & Hambrick, 2011 — all about CEOs, none about CISOs).
- Blame ≠ accountability. Executive consequences after a breach track the perceived scope of duties, not causal contribution (Banker & Feng, 2019). Test the difference four ways: named in advance, attached to a role, producing a system change, and preceded by the authority to refuse.
- A quiet year is ambiguous evidence. Units with better climate reported more errors (Edmondson, 1996), so falling incident counts must be read against the reporting climate — and sanctions, the lever blame reaches for, are among the weakest predictors of compliance (Cram et al., 2019).
- The four sentences have structural preconditions: a priced position and standing; a mechanism and a dated record; a named accepter and a review date; a reachable condition. The Sullivan case (convicted October 2022, conviction affirmed 13 March 2025) marks the outer boundary of the first sentence — it is about concealment from those entitled to know, not about being breached — and Amir et al. (2018) is the market's version of the same line.
- Write the Personal Calibration Plan: tendency profile with dated anchors, three dials with a recurring situation each, fit and discretion analysis including the reporting line, the bad-news stack with next quarter's layer named, three 90-day commitments with observables, and the Risk Corollary rehearsed with your CEO as a scheduled conversation with a real decision in it.
Research cited in this module
- Hayward et al. (2004)Believing one's own press: The causes and consequences of CEO celebrity. Strategic Management Journal · tier 1 · verified
- Malmendier & Tate (2009)Superstar CEOs. Quarterly Journal of Economics · tier 1 · verified
- Chatterjee & Hambrick (2011)Executive personality, capability cues, and risk taking: How narcissistic CEOs react to their successes and stumbles. Administrative Science Quarterly · tier 1 · verified
- Banker & Feng (2019)The impact of information security breach incidents on CIO turnover. Journal of Information Systems · tier 2 · verified
- Amir et al. (2018)Do firms underreport information on cyber-attacks? Evidence from capital markets. Review of Accounting Studies · tier 1 · verified
- Edmondson (1996)Learning from mistakes is easier said than done: Group and organizational influences on the detection and correction of human error. The Journal of Applied Behavioral Science · tier 1 · verified
- Edmondson (1999)Psychological safety and learning behavior in work teams. Administrative Science Quarterly · tier 1 · verified
- Ashenden & Sasse (2013)CISOs and organisational culture: Their own worst enemy?. Computers & Security · tier 1 · verified
- Cram et al. (2019)Seeing the forest and the trees: A meta-analysis of the antecedents to information security policy compliance. MIS Quarterly · tier 1 · verified
- Owens & Hekman (2012)Modeling how to grow: An inductive examination of humble leader behaviors, contingencies, and outcomes. Academy of Management Journal · tier 1 · verified
- Milliken et al. (2003)An exploratory study of employee silence: Issues that employees don't communicate upward and why. Journal of Management Studies · tier 1 · verified
- Gordon & Loeb (2002)The economics of information security investment. ACM Transactions on Information and System Security · tier 1 · verified
- Hambrick & Finkelstein (1987)Managerial discretion: A bridge between polar views of organizational outcomes. Research in Organizational Behavior · tier 1 · verified
- Banker et al. (2011)CIO reporting structure, strategic positioning, and firm performance. MIS Quarterly · tier 2 · verified
- Karahanna & Preston (2013)The effect of social capital of the relationship between the CIO and top management team on firm performance. Journal of Management Information Systems · tier 1 · verified
- sec2023 (2023). Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure · tier 1 · verified
- ians2026 (2026). State of the CISO 2026 Benchmark Report · tier 1 · verified
Each entry opens the research card with method, limitations and the usable claim.