Risk
1/4/2010
09:37 PM
Chris Murphy
Chris Murphy
Commentary
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Global CIO: 13 CIOs Describe Their Biggest Mistakes

We all make decisions we wish we could do over. These leaders aren't afraid to admit theirs.

When InformationWeek editors drew up questions for our ongoing CIO Profile series, we included one asking about the "Decision I wish I could do over." I was ready for a lot of job interview type responses, of the "my biggest fault is trying too hard" variety.

Instead, I've been blown away by the candor, humility, and perspective these leaders have shared. CIOs have discussed genuine mistakes--hold the sugar coating, with a side of lesson learned. They've relived problems with vendor contracts, outsourcing, and project management. They've lamented letting a troubled project drag on. Many are intensely personal looks back on career missteps, including chasing dot-com riches.

It's leadership by example. Of course we all know it's OK to make mistakes--in concept. The hard part is staring down the real thing. Here are some "Decisions I wish I could do over" that your CIO peers shared during the past year, with links to their full CIO Profiles:

Michael Manchisi , CTO, MasterCard Global Technology and Operations: As a financial officer earlier in my career, I saw all the signs that a project was heading south, but I kept it going longer than I should have. I learned the importance of failing fast and redirecting resources and dollars to more mission-critical projects.

Peter Whatnell, CIO of Sunoco: At one company, we were looking at a major legacy replacement project and a number of the executives didn't want to "go to the trouble" of defining a business case, arguing that it was an obvious business infrastructure investment. Against my better judgment, I was convinced to go along with that view. Of course, 10 months later, the project was killed.

Ed Trainor, CIO of Amtrak: When I was CIO of Paramount Pictures, a subsidiary of Viacom, the CIOs of the major Viacom business units launched a company-wide infrastructure outsourcing initiative that ultimately failed, primarily because the result/reward structure was overly unbalanced in Viacom's favor, as we didn't construct a true win-win situation for both parties. One lesson I learned was that there has to be sufficient benefit for both parties to make it truly successful. I also learned that outsourcing is simply another way of many to accomplish your business objectives and that it isn't a general solution to be applied to all problems.

Mark Greenlaw, VP and CIO of Cognizant: 2003 was a tough year for me when the startup I worked for was acquired, and I was laid off. I took a job that wasn't right for me. I stayed only a short time and felt I let down the person who hired me.

Global CIO
Global CIOs: A Site Just For You
Visit InformationWeek's Global CIO -- our new online community and information resource for CIOs operating in the global economy.

Amin Kassem, Executive VP and CIO of SHPS: A major software vendor tried to change a software licensing model on already licensed software in order to charge higher fees. After we obtained bids from competitors, it quickly stopped its efforts to change the licensing model, and I kept the software. I wish I'd replaced the vendor, as it wasn't serving as our business partner. Thankfully, its technology plays a less critical role in our current technology strategy.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0103
Published: 2014-07-29
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

CVE-2014-0475
Published: 2014-07-29
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

CVE-2014-0889
Published: 2014-07-29
Multiple cross-site scripting (XSS) vulnerabilities in IBM Atlas Suite (aka Atlas Policy Suite), as used in Atlas eDiscovery Process Management through 6.0.3, Disposal and Governance Management for IT through 6.0.3, and Global Retention Policy and Schedule Management through 6.0.3, allow remote atta...

CVE-2014-2226
Published: 2014-07-29
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtains sensitive information via unspecified vectors.

CVE-2014-3020
Published: 2014-07-29
install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.

Best of the Web
Dark Reading Radio