Sun Tzu and The Art of CIO Success
By Steven Fox, Founder of SecureLexicon

The General is the bulwark of the State
if the bulwark is complete at all points
the State will be strong
if the bulwark is defective
the State will be weak
- Sun Tzu
Sun Tzu said that a strong General is required for strategic success. This leader acts as a powerful business champion. If you wish to be a CIO, you must be prepared for that role. If you are a CIO, I hope this article illuminates the importance of your contribution.
What factors influence the success of a Chief Information Officer (CIO)? While many have commented on this topic, I place credibility on the insight of those who have experienced that level of leadership.
A June 3rd, 2009 Midwest Technology Leaders panel discussion explored the attributes critical to landing a CIO job. Interestingly, Sun Tzu attributed many of these qualities to the leader of an army – The General.
The CIO is a “General”. Generals are not concerned with how the weapons function or how the rank-and-file are performing. This is the job of the lieutenants. The General focuses on the strategic application of resources on the battlefield.
It is his/her duty to bring the plans of the sovereign (e.g. the CEO, the Board of Directors) to fruition.
Below are three principles that the CIO must employ to achieve success.
Business Acumen
The general who thoroughly understands the advantages that accompany variation of tactics knows how to handle his troops. The general who does not understand these, may be well acquainted with the configuration of the country, yet he will not be able to turn his knowledge to practical account - Sun Tzu
According to John Crary, Vice President of Information Technology for Lear Corporation, “While technical knowledge is expected, business acumen is more important.”
This perspective is consistent with a 2007 Gartner survey that emphasized the importance of business skills to the CIO role.
While the CIO must understand the tactical possibilities of the infrastructure, its application to the strategy of the business is the real challenge. An intimate understanding of the business is required to meet that challenge.
Executive Character and Integrity
Leadership is a matter of intelligence, trustworthiness, humaneness, courage, and sternness - Sun Tzu
Gary Desai, VP and CIO - Consumer Products Group at Honeywell Information Systems, contributed several insights on the demeanor and character of a CIO: “The attitude and behavior of the CIO must project a grasp of business skills and understanding,” said Desai.
He cautioned the prospective CIO that while technical and business skills can get you the job, it is unproductive and unprofessional behavior that gets you fired. Mr. Desai also stressed that a CIO must “be able to disagree with his/her peers without being disagreeable.”
Sun Tzu’s perspective is instructive because a balance must be struck between the different components of leadership. An intelligent but untrustworthy individual would not make a successful leader, nor would an overly courageous one.
Pragmatically, that balance is dictated by the culture within which the CIO operates.
Builds Strategic Alliances
We cannot enter into alliances until we are acquainted with the designs of our neighbors. We are not fit to lead an army on the march unless we are familiar with the face of the country - Sun Tzu
Collaborative solutions are sometimes required to address competitive problems. This was true during World War II when the USA formed an alliance with European forces. The same holds for the corporate theater.
In Building Alliances Across Divisions, Maya Townsend outlines the questions that must be asked by a CIO who wishes to form an alliance.
Townsend holds that the alliance must have a business justification and that execution must reflect the core competencies of the members.
Thus, the CIO must understand both the business of the alliance members and the implications of the alliance on the competitive environment.
Read Sun Tzu and The Art of Information Security
Steven Fox is an independent information security consultant. He holds a Masters in Business Information Technology from Walsh College, an NSA recognized Center of Excellence. He serves on the board of the Detroit ISSA chapter and is a columnist for the ISSA Journal. He is also the founder of SecureLexicon , a security advisory firm addressing the unique security concerns of nonprofit organizations.
He can be contacted at sfox@securelexicon.com
Follow him on Twitter - @SecureLexicon
Join Steven’s LinkedIn Network
* * *
Stay Informed With ISR News Feeds and Email Alerts Here:
The Publisher gives permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author and to Information-Security-Resources.com
Filed under: Breach, D&O Liability, FEATURE ARTICLE, Financial, Government, Insider Threat, PCI, Sarbanes-Oxley, Steven Fox, Uncategorized, hackers, identity-theft, malware, national security, privacy
Comments
Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!













