By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Women Technology Leaders Are Already Flying. The Enterprise Is Still Building the Runway.

Women CIOs and CISOs are already leading at enterprise scale. The gap isn’t capability — it’s authority, governance, and operating models that haven’t caught up.

Irene Thong

Olgethorpe Power Corporation | Chief Information Officer

Women leaders are exposing an operating-model problem that affects the entire technology C-suite: accountability is expanding faster than authority and organizational support.        

Women technology leaders are often described as “breaking barriers” or “finally earning a seat at the table.” While well intentioned, that language treats arrival as the central challenge.

But women are already leading global technology platforms, cybersecurity resilience, AI adoption, regulatory compliance, and enterprise transformation.

They are not waiting to take off.

They are flying complex aircraft while the runway is still being built beneath them.

The unfinished runway is not a question of capability. It is the gap between what organizations expect technology leaders to deliver and the authority, resources, governance, and institutional support provided to them.

While my doctoral research focused specifically on women CIOs in Fortune 500 organizations, the questions it raises around authority, accountability, and organizational support extend beyond the CIO role. As AI, cybersecurity, and digital transformation responsibilities expand, these same questions increasingly apply to CISOs, CTOs, CDOs, and other technology executives.

Women did not create this gap. Their experience often makes it easier to see.

Women Are Already in the Cockpit

In 2026, women lead a record 11% of Fortune 500 companies. That is worth recognizing and still represents only 55 of the 500 most influential corporate leadership positions in the United States. 

The imbalance is equally relevant in technology. Women hold approximately one-quarter of CIO and CIO-equivalent roles in Fortune 500 companies, according to my doctoral research.

Cybersecurity presents a similar picture. Women represent approximately 22% of the cyber workforce. They remain underrepresented, even as women in the profession assume substantial leadership and hiring responsibilities.

The pipeline is therefore only part of the story. 

Women are already reaching positions of enterprise accountability. The more immediate question is what happens when they get there.

Appointment Does Not Automatically Create Authority

My doctoral research found that women often progress by repeatedly proving themselves on enterprise-critical work, building trust across functions, and becoming the leaders organizations turn to when disruption demands change.

But elevation alone does not stabilize executive authority.

Sustained success depends on whether the organization reinforces the leader’s mandate and embeds transformation into governance, operating models, decision processes, and performance measures.

Individual capability matters. Institutional design determines whether that capability can produce durable change.

This distinction is particularly important when leaders are appointed during periods of disruption. A difficult mandate may offer visibility and opportunity, but it can also carry a high probability of failure if authority, resources, and expectations are not aligned.

The relevant governance question is straightforward:

When an organization appoints a leader to navigate disruption, does it also provide the conditions required for that leader to succeed?

The Mandate Has Changed. The Enterprise Often Has Not.

Technology executives are no longer expected simply to run systems. They are expected to shape strategy, manage enterprise risk, modernize legacy environments, scale AI, lead transformation, and produce measurable business value.

Deloitte’s 2026 study of more than 660 senior technology executives found that 79% identify driving business outcomes as their top priority. Yet 75% say their operating model must fundamentally change to deliver greater value. 

The widening mandate is especially visible for Chief Information Security Officers (CISOs). Splunk’s 2026 researchfound that 96% now oversee AI governance and risk in addition to expanding responsibilities across privacy, compliance, third-party exposure, DevSecOps, and operational technology. 

This is more than workload growth. It is a widening gap between accountability and authority.

As I argued in ““The 360° CIO is here.” , most operating models have not caught up technology executives increasingly operate with 360-degree accountability but only 180-degree authority.

They are expected to integrate AI, data, cybersecurity, platforms, resilience, and transformation. But many of the decisions shaping those outcomes remain distributed across business units, functions, vendors, and executive committees.

A business unit may select an AI platform. A product team may adopt a new model. Finance may launch an analytics capability. Each decision may make sense in isolation.

When fragmentation, data exposure, duplicated investment, or regulatory risk emerges, however, the CIO or CISO is expected to make the enterprise whole.

That mismatch is the unfinished runway.

The Runway is an Operating Model

The runway is not a mentoring program or a leadership course. It is the organizational infrastructure that makes executive leadership sustainable:

  • Authority proportionate to accountability
  • Direct board access and protected escalation channels
  • Adequate budget, talent, and organizational capacity
  • Clear ownership and acceptance of risk
  • Consistent performance and succession criteria
  • Sponsorship that continues when conditions become difficult

When these elements are incomplete, the consequences become visible during AI deployments, cyber incidents, mergers, restructurings, and large-scale transformations.

A CISO may be accountable for AI risk but unable to stop the business from adopting a high-risk model. A Chief Information Officer (CIO) may be responsible for enterprise integration but have limited influence over technology spending outside IT. A transformation leader may own the outcome but not the people, processes, or operating decisions required to deliver it.

A title is not an operating model.

No board would accept a critical system without defined ownership, controls, escalation paths, or recovery capacity. Executive roles carrying material enterprise risk deserve the same design discipline.

AI is the Immediate Stress Test

AI makes the accountability-authority gap difficult to ignore.

Organizations cannot respond by simply adding “AI governance” to a CIO’s or CISO’s job description.

They must decide who can approve or stop an AI deployment, who owns the business outcome, who evaluates the risks, who accepts residual risk, and how unresolved disagreements reach the board.

Without clear answers, accountability will accumulate around technology leaders while authority remains fragmented elsewhere.

That is not empowerment. It is unmanaged enterprise risk.

Five Actions Leaders Can Take Now

Boards, CEOs, and executive teams do not need to wait for a leadership transition or crisis to begin strengthening the runway.

1. Match authority to accountability

Document the outcomes assigned to each technology executive and the decisions that executive can make. If a leader is accountable for an outcome but lacks authority over the decisions shaping it, identify who shares that accountability.

2. Define who can stop unacceptable risk

Establish in advance who can pause an AI deployment, reject a technology exception, or escalate a material cyber concern. Protected escalation should be part of governance—not dependent on a leader’s political capital.

3. Audit how executive credibility is built

Examine who receives enterprise-critical assignments, cross-functional exposure, board visibility, and responsibility for high-value transformation. Sponsorship should create access to consequential work, not merely advice and encouragement.

4. Review the conditions surrounding difficult appointments

When a leader is appointed during disruption, evaluate whether the role includes sufficient authority, resources, time, and organizational support. Do not assess the individual’s performance without also assessing the design of the mandate.

5. Measure leadership-system health

Review appointment, compensation, tenure, succession, and departure patterns across gender and race. Apply the same rigor to leadership infrastructure that the organization applies to financial, operational, and cyber risk.

These are not peripheral diversity actions.

They are governance practices that improve decision quality, strengthen succession, and reduce execution risk for the entire enterprise.

Finishing the Runway

Women technology leaders are not waiting to take off.

They are already at altitude, navigating AI acceleration, cyber threats, regulatory scrutiny, legacy complexity, and continuous transformation.

The defining question is not whether women are ready to lead. It is whether organizations are prepared to provide the authority and infrastructure that leadership at this level requires.

Finishing the runway is about equity. It is also about something every CISO, CEO, and director should recognize immediately: Reducing avoidable enterprise risk.

When the leadership system is properly built, successful landings stop being treated as extraordinary.

They become what a resilient enterprise expects.

About the Author

Dr. Irene Thong is a technology executive and Chief Information Officer with over 25 years of experience who helps leaders fuse human talent, technology, and strategy into measurable business outcomes. She champions cybersecurity as a core business imperative and advocates her “Converge to Amplify” philosophy—aligning judgment, tech, strategy, and resilience for lasting transformation. Her latest book, The Chapter in Between, explores leadership, identity, and the courage to navigate uncertainty.

Previous Post

Innovator Series S2 Episode 4: Dan Shiebler of Artemis Security

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.