Prøve GULL - Gratis

The Case for Lean Cybersecurity Leadership

MIT Sloan Management Review

|

Spring 2025

More complex hierarchies can lead to overconfidence that exacerbates risk.

- By Andrew Flostrand, Andrew Park, Dionysios Demetis, Jan Kietzmann, Leyland Pitt, and Ian McCarthy

The Case for Lean Cybersecurity Leadership

Few would expect that adding resources to a critical operational area could compromise its effectiveness. But as organizations beef up their cybersecurity teams in response to the growing threat and cost of cybercrime, they may be inadvertently blunting their ability to accurately assess their own exposure to risk.

Businesses' natural response to growing cyber risk has been to invest in and grow their cybersecurity capabilities, including creating new leadership roles for safeguarding the confidentiality, integrity, and availability of organizational data. However, our research uncovered a surprising paradox that can render such expansion counterproductive. We found that experienced security teams can exhibit a collective overconfidence that makes responses to cyberthreats less effective. While leaders might expect that adding senior-level positions to a cybersecurity team will improve its capabilities, doing so can increase this organizational overconfidence, with potentially catastrophic effects on IT security.

This phenomenon of decision-making bias stemming from overconfidence, referred to as illusory superiority, has been found in other settings as well. Under certain conditions, people — regardless of their competence level — overestimate their abilities, skills, or qualities relative to those of their peers. There are clear downsides to illusory superiority: Individuals tend to engage in more risky behaviors, underestimate the effort needed to complete a task, and disregard valuable feedback. Overestimating one's own ability can also harm teamwork and result in suboptimal personal and group outcomes.

FLERE HISTORIER FRA MIT Sloan Management Review

MIT Sloan Management Review

MIT Sloan Management Review

Assess What Is Certain in a Sea of Unknowns

Understanding what won't change clarifies what might — and strengthens decision-making in volatile times.

time to read

13 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

Ask Sanyin: Why Is It So Hard to Pull the Plug on a Project?

We're finding it difficult to wind down projects that no longer serve our priorities.

time to read

2 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

Integrate Sustainability and Innovation to Find New Opportunities

Five common innovation practices can help leaders pursue sustainability as a growth strategy.

time to read

12 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

The Case for Quiet Corporate Activism

Leaders concerned that they will be penalized for championing sustainability and diversity can still sustain their commitments.

time to read

11 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

The Perils of Algorithmic Pricing

Some revenue management systems based on algorithms may lead to unintended collusion and antitrust violations.

time to read

9 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

Broadening Future Perspectives at the Bank of England

Leaders at the U.K’s central bank sought to broaden their thinking about future risks and opportunities. Here’s how they built longer-term horizon-scanning capabilities and what they learned along the way.

time to read

9 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

How Nesting Changes Platform Strategy

Should your platform host another platform — or be hosted by one? Here's how to think through the choices.

time to read

14 mins

winter 2026

MIT Sloan Management Review

Are You an Authentic Leader or an Authentic Jerk?

Leaders who are true to their values can inspire trust and respect, but not if \"being yourself\" becomes the problem.

time to read

13 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

How to Make Scenario Planning Stick

Developing future scenarios can deepen leaders’ strategic insights. Establishing scenario planning as an ongoing capability and reaping its full benefits require linking it to other processes.

time to read

16 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

A Faster Way to Build Future Scenarios

This streamlined approach to scenario planning incorporates AI and helps managers navigate future uncertainties more efficiently.

time to read

13 mins

winter 2026

Listen

Translate

Share

-
+

Change font size