I wrote a preprint paper focused in CIO value proposition. One reviewer suggest that the IT organization only increases business efficiency. What are your thoughts? I think the reviewer may need additional strategic context.
A CIO adds value to an enterprise by working with executive management to understand and document the organization's information security appetite (Landoll, 2021). A security risk appetite refers to the level and type of security risks that an organization is willing to accept or tolerate.
Landoll, D. (2021). The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments (Third edition, Vol. 1). CRC Press. https://doi.org/10.1201/9781003090441