Try GOLD - Free
The Case for Lean Cybersecurity Leadership
MIT Sloan Management Review
|Spring 2025
More complex hierarchies can lead to overconfidence that exacerbates risk.
Few would expect that adding resources to a critical operational area could compromise its effectiveness. But as organizations beef up their cybersecurity teams in response to the growing threat and cost of cybercrime, they may be inadvertently blunting their ability to accurately assess their own exposure to risk.
Businesses' natural response to growing cyber risk has been to invest in and grow their cybersecurity capabilities, including creating new leadership roles for safeguarding the confidentiality, integrity, and availability of organizational data. However, our research uncovered a surprising paradox that can render such expansion counterproductive. We found that experienced security teams can exhibit a collective overconfidence that makes responses to cyberthreats less effective. While leaders might expect that adding senior-level positions to a cybersecurity team will improve its capabilities, doing so can increase this organizational overconfidence, with potentially catastrophic effects on IT security.
This phenomenon of decision-making bias stemming from overconfidence, referred to as illusory superiority, has been found in other settings as well. Under certain conditions, people — regardless of their competence level — overestimate their abilities, skills, or qualities relative to those of their peers. There are clear downsides to illusory superiority: Individuals tend to engage in more risky behaviors, underestimate the effort needed to complete a task, and disregard valuable feedback. Overestimating one's own ability can also harm teamwork and result in suboptimal personal and group outcomes.
This story is from the Spring 2025 edition of MIT Sloan Management Review.
Subscribe to Magzter GOLD to access thousands of curated premium stories, and 10,000+ magazines and newspapers.
Already a subscriber? Sign In
MORE STORIES FROM MIT Sloan Management Review
MIT Sloan Management Review
Assess What Is Certain in a Sea of Unknowns
Understanding what won't change clarifies what might — and strengthens decision-making in volatile times.
13 mins
winter 2026
MIT Sloan Management Review
Ask Sanyin: Why Is It So Hard to Pull the Plug on a Project?
We're finding it difficult to wind down projects that no longer serve our priorities.
2 mins
winter 2026
MIT Sloan Management Review
Integrate Sustainability and Innovation to Find New Opportunities
Five common innovation practices can help leaders pursue sustainability as a growth strategy.
12 mins
winter 2026
MIT Sloan Management Review
The Case for Quiet Corporate Activism
Leaders concerned that they will be penalized for championing sustainability and diversity can still sustain their commitments.
11 mins
winter 2026
MIT Sloan Management Review
The Perils of Algorithmic Pricing
Some revenue management systems based on algorithms may lead to unintended collusion and antitrust violations.
9 mins
winter 2026
MIT Sloan Management Review
Broadening Future Perspectives at the Bank of England
Leaders at the U.K’s central bank sought to broaden their thinking about future risks and opportunities. Here’s how they built longer-term horizon-scanning capabilities and what they learned along the way.
9 mins
winter 2026
MIT Sloan Management Review
How Nesting Changes Platform Strategy
Should your platform host another platform — or be hosted by one? Here's how to think through the choices.
14 mins
winter 2026
MIT Sloan Management Review
Are You an Authentic Leader or an Authentic Jerk?
Leaders who are true to their values can inspire trust and respect, but not if \"being yourself\" becomes the problem.
13 mins
winter 2026
MIT Sloan Management Review
How to Make Scenario Planning Stick
Developing future scenarios can deepen leaders’ strategic insights. Establishing scenario planning as an ongoing capability and reaping its full benefits require linking it to other processes.
16 mins
winter 2026
MIT Sloan Management Review
A Faster Way to Build Future Scenarios
This streamlined approach to scenario planning incorporates AI and helps managers navigate future uncertainties more efficiently.
13 mins
winter 2026
Listen
Translate
Change font size
