Chief Information Security Officers on Top Management Teams: Impact on Firms’ Innovation

  • Gao Y
  • Wattal S
  • Thatcher J
0Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The growing frequency of information security breaches and the rising importance of cybersecurity have prompted many firms to include chief information security officers (CISOs) in their top management teams (TMTs). Although CISOs are often viewed narrowly through a security-focused lens, our research shows that their inclusion in TMTs can offer a strategic advantage by significantly enhancing firm innovation. We identify three mechanisms that explain this effect: (1) reducing preventable security risks that might otherwise hinder innovation efforts; (2) enabling the adoption of innovation technologies (e.g., cloud computing, big data) that carry strategic security risks; and (3) strengthening security controls that protect intellectual property and mitigate innovation-related threats. Importantly, the CISO’s background matters. Those with specialized experience—either in the same industry or with prior executive roles—have a stronger impact on driving innovation. This research illuminates how CISOs’ presence on TMTs affects firms’ value creation from a security risk management perspective, and provides guidance for firms seeking to hire CISOs for innovation.The rapid rise in information security incidents and the growing significance of cybersecurity have prompted many firms to elevate chief information security officers (CISOs) to top management teams (TMTs). Although prior work has examined the security-related impact of the CISO on firms, the implications of elevating the CISO to the TMT regarding the value of businesses have not been explored. Understanding how to integrate CISOs into TMTs is critical, as they bring a unique perspective on security risk management to executive decision making. To understand the implications of this change in TMTs’ composition, we conducted a longitudinal analysis of S&P 1,500 firms. Our results show that the presence of the CISO on the TMT positively impacts firms’ innovation. We identify three mechanisms that explain the impact of CISO presence on the TMT on innovation: reduced security risk, enhanced security controls, and the facilitated adoption of innovation enablers with a strategic security risk, thereby increasing firms’ innovation. Additionally, we find that the work experience of the CISO mattered because CISOs on TMTs with specialized experience increase firms’ innovation. This research illuminates how CISOs’ presence on TMTs affects firms’ value creation from a security risk management perspective. We also provide nuanced insights into how the professional experience of the CISO on the TMT impacts firms’ innovation. Our findings provide guidance for firms seeking to hire CISOs for TMTs who can effectively manage firms’ information security and contribute to value creation by supporting innovation.History: Indranil Bardhan, Senior Editor; Pallab Sanyal, Associate Editor.Supplemental Material: The online appendix is available at https://doi.org/10.1287/isre.2023.0197 .

Cite

CITATION STYLE

APA

Gao, Y., Wattal, S., & Thatcher, J. (2026). Chief Information Security Officers on Top Management Teams: Impact on Firms’ Innovation. Information Systems Research, 37(2), 1276–1288. https://doi.org/10.1287/isre.2023.0197

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free