Risk
1/4/2010
09:37 PM
Chris Murphy
Chris Murphy
Commentary
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Global CIO: 13 CIOs Describe Their Biggest Mistakes

We all make decisions we wish we could do over. These leaders aren't afraid to admit theirs.

When InformationWeek editors drew up questions for our ongoing CIO Profile series, we included one asking about the "Decision I wish I could do over." I was ready for a lot of job interview type responses, of the "my biggest fault is trying too hard" variety.

Instead, I've been blown away by the candor, humility, and perspective these leaders have shared. CIOs have discussed genuine mistakes--hold the sugar coating, with a side of lesson learned. They've relived problems with vendor contracts, outsourcing, and project management. They've lamented letting a troubled project drag on. Many are intensely personal looks back on career missteps, including chasing dot-com riches.

It's leadership by example. Of course we all know it's OK to make mistakes--in concept. The hard part is staring down the real thing. Here are some "Decisions I wish I could do over" that your CIO peers shared during the past year, with links to their full CIO Profiles:

Michael Manchisi , CTO, MasterCard Global Technology and Operations: As a financial officer earlier in my career, I saw all the signs that a project was heading south, but I kept it going longer than I should have. I learned the importance of failing fast and redirecting resources and dollars to more mission-critical projects.

Peter Whatnell, CIO of Sunoco: At one company, we were looking at a major legacy replacement project and a number of the executives didn't want to "go to the trouble" of defining a business case, arguing that it was an obvious business infrastructure investment. Against my better judgment, I was convinced to go along with that view. Of course, 10 months later, the project was killed.

Ed Trainor, CIO of Amtrak: When I was CIO of Paramount Pictures, a subsidiary of Viacom, the CIOs of the major Viacom business units launched a company-wide infrastructure outsourcing initiative that ultimately failed, primarily because the result/reward structure was overly unbalanced in Viacom's favor, as we didn't construct a true win-win situation for both parties. One lesson I learned was that there has to be sufficient benefit for both parties to make it truly successful. I also learned that outsourcing is simply another way of many to accomplish your business objectives and that it isn't a general solution to be applied to all problems.

Mark Greenlaw, VP and CIO of Cognizant: 2003 was a tough year for me when the startup I worked for was acquired, and I was laid off. I took a job that wasn't right for me. I stayed only a short time and felt I let down the person who hired me.

Global CIO
Global CIOs: A Site Just For You
Visit InformationWeek's Global CIO -- our new online community and information resource for CIOs operating in the global economy.

Amin Kassem, Executive VP and CIO of SHPS: A major software vendor tried to change a software licensing model on already licensed software in order to charge higher fees. After we obtained bids from competitors, it quickly stopped its efforts to change the licensing model, and I kept the software. I wish I'd replaced the vendor, as it wasn't serving as our business partner. Thankfully, its technology plays a less critical role in our current technology strategy.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5208
Published: 2014-12-22
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbit...

CVE-2014-7286
Published: 2014-12-22
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via unspecified vectors.

CVE-2014-8015
Published: 2014-12-22
The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400.

CVE-2014-8017
Published: 2014-12-22
The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur41673.

CVE-2014-8018
Published: 2014-12-22
Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCur19651, CSCur18555, CSCur1...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.