
Cyber risk has emerged as a particularly urgent concern due to its potential for existential disruption and mounting regulatory pressures. Despite corporate boards' increased attention to cyber risk, old challenges persist as new threats emerge. Our27 hours of interviews with 42 board directors, board advisors and board-facing executives identified two core types ofgovernance challenges: (1) internal structural issues and (2) external cyber threats.(1) For each challenge, we offer expert-backed guidance on how to anticipate, prepare and respond. We conclude with challenges we believe must still be addressed(2).
Low-code platforms empower business professionals to build applications without ment requires new roles, structures and mindsets. Drawing on 36 interviews in two firms at different levels of low-code maturity, we define a practical five-level maturity model and highlight the evolving role of low-code champions who bridge the IT and business domains. We show how organizational context, IT support and community learning shape success and provide actionable guidance for traversing the first three maturity levels (1,2)
Leading large-scale AI-driven transformation is never easy, especially in a highly regulated industry like healthcare. But the Digital Transformation & Innovation group at HCA Healthcare is delivering a steady drumbeat of innovative value for employees and patients. In this interview, Dr. Michael Schlosser, who leads enterprise-wide digital transformation and innovation for HCA Healthcare, describes the mechanisms he and his team use to engage top leaders, rank-and-file employees and even regulators to produce transformative AI-powered innovations quickly and safely.
Cybersecurity governance is increasingly regulated, yet best practice remains fragmented across executive leadership. This article, which draws on our 31 interviews with financial sector leaders, identifies pressing challenges around cybersecurity governance-specifically those connected to tensions around (1) accountability vs. authority, (2) strategic alignment vs. operational execution and (3) clarity vs. ambiguity. To strengthen organizational resilience, we propose a framework for cybersecurity responsibility, ownership and accountability (CROA) and then offer seven recommendations, as well as a self-assessment tool for executives.
Business-to business (B2B) marketplaces are experiencing a resurgence, promising to simplify global sourcing amid increasing geopolitical tensions, trade tariffs and supply chain disruptions. However, managers mistakenly apply business-to-consumer (B2C) marketplace scaling techniques within B2B contexts. Based on case studies of two pioneering B2B marketplaces, we highlight how B2C-platform thinking leads managers into scaling traps. The cases underscore the importance of setting a viable focus, deliberate product building, as well as physical selling and right-touch service, to establish and scale B2B marketplaces in traditional industries.(1,2)
The Society for Information Management's 45th Annual IT Issues and Trends study received responses from 704 IT executives, including 211 CIOs and 344 unique organizations. AI continued its rise to reach the top of the most important IT management issues, followed by Cybersecurity, and Alignment of IT and Business. 54.2% of organizations reported increasing IT headcount, the lowest percentage since 2020. 90.5% reported increases in average IT salaries, down from 97.0% in 2024. The most common criteria for assessing CIO performance were Customer Satisfaction, Value of IT to the Business, Strategic Contribution of IT, IT Availability and Cybersecurity Issues. Interestingly, Cost Control dropped out of the top five to 22nd. The average tenure of CIOs was 7.4 years (median 5years), with 46.2% reporting to the CEO. CIOs continue to come primarily from outside the organization at high levels (80.3%), with 22.3% coming from prior non-IT positions.
AI's proliferation in data analytics will fundamentally disrupt the role of the data analyst as we know it today. In this article, we establish the current state of hiring and working in data analytics, based on our survey of hiring managers. Then, we speculate on anticipated changes to this current state as the world becomes increasingly AI-driven, and we validate these speculations with semi-structured interviews of individuals in the data analytics field. Based on these speculations, we provide recommendations for data analytics professionals to prepare for and thrive in an age ofAI-led disruption.
Executives in regulated industries are facing growing pressure to integrate AI into compliance while preserving oversight. This article describes how a banking group introduced a retrieval-augmented, AI-powered compliance assistant. It outlines what the group's journey reveals about the future of compliance work and the key lessons learned. It highlights the tensions shaping AI-supported compliance: authority illusion, blurred accountability, loss of contextual judgment and widening awareness gaps. The article provides a four-phase framework to help leaders navigate the shift from reactive AI assistants toward agentic, co-reasoning systems.(1,2)
As digital technologies transform businesses and industries, organizations need to decide whether to appoint a CIO or a chief digital officer (CDO) as a single leader or adopt a dual CIO/CDO leadership model. Is a CDO necessary, and if so, what is the reporting relationship?How does the CDO role differ from the CIO role? Should digi-tal leadership remain with the CIO, or should it solely be the responsibility of a CDO? Based on interviews with senior digital leaders, we explore these questions and offer recommendations.1
As IT development is reshaped by artificial intelligence, IT professionals are beginning to create IT products in new ways. Drawing on our study of experienced workers at Netlight Consulting GmbH, a Swedish-founded, internationally operating IT consultancy, this article shows how IT professionals now use AI within theirIT development activities. It also identifies the difficulties and limitations that IT professionals face and explains how the looming rise ofAI "orchestras" will transform how humans and AI build IT together.1
Many firms struggle to scale today's generative and predictive AI systems effectively because their machine learning-based working mechanisms amplify general technology management challenges and create entirely new ones. Based on an in-depth case study of industrial AI pioneer Siemens AG, we describe how to successfully mitigate five critical technology management risks to scale AI globally, and provide recommendations for creating company-wide business impacts with machine learning-based AI systems.1,2
Most companies approach cybersecurity as a necessary expense, like insurance, to cover capital losses. We reveal how cybersecurity can instead be a strategic investment for generating business value and gaining a competitive edge in a networked society. We also provide guidance for information systems (IS) leaders on what capital-creation benefits flow from being a good cyber neighbor.(1)
The accelerating digital transformation of manufacturing is enhancing automation and production efficiency while requiring employees to develop new skills to meet evolving demands. This case study examines how Siemens embedded a human-centric, bottom-up approach to empower employee re- and upskilling through innovative digital learning. Aligned with Siemens's actions, we present a four-phase model on leveraging information systems to address skill gaps, enhance adaptability and tackle re- and upskilling challenges. We also provide five recommendations to help organizations foster lifelong learning in dynamic manufacturing environments.(1,2)
Digital twins (DTs) are increasingly adopted by organizations across various sectors. We report on how one of Europe's largest district heating providers implemented an AI-assisted DT in pursuit of energy efficiency and sustainability. The solution enabled the company to modernize its complex cyber-physical system (CPS) and tap into its rich data capabilities to gain a comprehensive real-time representation of the entire district heating network. Reflecting on the case study, we provide six recommendations for executives in other domains aiming to implement DTs.1,2
Digitally transforming an organization's workspace requires parallel evolution across interdependent layers that influence and reinforce one another. Drawing on our analysis of multinational automotive supplier Continental AG's shop floor digital transformation journey, we propose a practical, three-layer model-IT evolution, work practices evolution and mindset evolution-that, with the associated dynamic capabilities, will ensure successful transformation. We provide recommended actions for aligning and managing interdependencies across the three layers, resulting in reduced implementation risks and improved transformation outcomes.1,2
For decades, organization charts have included an IT box, but that box is now the single greatest drag on realizing value from IT because it creates a permanent fissure between "IT" and "the business," locking in chronic underperformance and failed IT investments. This MISQE Insight surfaces the hidden assumptions of an organizing model that sabotages digital transformation ambitions and describes companies that are organizing for IT differently. It provides practical guidance for a model that shifts the focus from managing IT to generating value from IT.
The explosion in AI development, application and implementation has led to increasingly urgent calls for the responsible use ofAI-as well as increasing confusion about how to practically approach it. This article describes how two organizations started to operationalize responsible AI by taking a systems approach to crafting responsibility pledges and embedding them in organizational practices. We identify a five-phase process, along with corresponding activities and artifacts, and share effectiveness evidence and a roadmap for action.1,2