Methods & Experience

The ultimate reading list for CxOs


Fundamental insights into leading a CIO function – and a curated selection of my articles for everyone responsible for IT, data and digitalization.

First published May 2018 · revised September 2026 · reading time approx. 20 minutes

Almost every company's business is now shaped by information technology, data and digital platforms – and increasingly by artificial intelligence. Anyone with responsibility at board or executive level must therefore understand the potential and the limits of these technologies systematically, because using them wisely has turned from a tool into a critical success factor.

On this page I summarize what I have learned about effective IT leadership in more than 35 years as CIO, CTO, Head of Corporate IT Audit, CISO and interim manager at Siemens, Hewlett Packard, ThyssenKrupp and the German health insurer Kaufmännische Krankenkasse. Part 1 contains the fundamental insights, Part 2 a reading list organized by topic.

35+Years of practice
6Key topics
27Articles
Part 1 · Fundamental insights at a glance

01The changing role of the CIO

Since around 2000 the use of outsourcing, and since around 2010 the triumph of cloud-based as-a-service models, have reduced the share of value creation for which a Chief Information Officer is directly responsible. Four developments are fundamentally changing the role:

In practice there are more than 50 different C-level titles. In large companies the CIO, CDO, Chief Data Officer and CISO compete every day for responsibilities, headcount and budget. That is rarely productive. Too many cooks spoil the broth – one reason to clean out and simplify your organizational model from time to time. CIOs who fail to adapt their scope to the demands of digitalization and the cloud risk turning the mocking translation "Career is over" into a self-fulfilling prophecy.

50 shades of CxO: C-level functions in practice
50 shades of CxO: C-level functions in practice
2026 update

Artificial intelligence has added yet another role: many companies have now appointed people responsible for AI. At the same time, AI agents are increasingly taking over steps in business processes. The question of who is responsible for the architecture, data, security and governance of these agents is therefore becoming a core question for the CIO function. Anyone who does not consciously simplify the organizational model here is setting up the next conflict over responsibilities.

Every board gets the CIO it deserves. If IT costs are the only metric the board cares about, it should not be surprised when its CIO focuses mainly on managing costs and neglects contributions to business value.

Since the 1980s – starting with the shareholder-value dogma and the deregulation of financial markets – seven mutually reinforcing developments have been shaping information technology in companies: financial capitalism, unlimited growth, globalization, automation, digitalization and softwarization, dematerialization and virtualization, and the attention economy and surveillance capitalism. The qualifications of a modern CIO must reflect these developments.

The CIO's responsibility – traditional and future
The CIO's responsibility – traditional and future

Three terms worth keeping apart

Digitization, digitalization and digital transformation
Digitization, digitalization and digital transformation

Anyone who wants to enable innovation and disruption also has to break away from linear thinking and deliberately make use of fundamental paradigm shifts.

Innovation and disruption through paradigm shifts
Innovation and disruption through paradigm shifts

02Designing the organization

After the reorganization is before the reorganization. Sepp Changeberger, German organizational consultant (tongue in cheek)

Organizational development is a wonderful field in which you can spend years of your life. Before designing an organization, you should define what it is supposed to achieve and express this as design criteria – e.g. clear accountabilities, proximity to customers and the business, controllability, scalability and cost efficiency. Only then is it worth discussing boxes and lines.

Design criteria for new organizations
Design criteria for new organizations

There are a number of common organizational logics for CIO functions, such as structuring by life cycle ("Plan – Build – Run"), by business unit, by process or by region – in practice usually as a hybrid. Service management is typically based on ITIL, project management on PMI, PRINCE2 or agile methods. One rule applies: process organization beats organizational structure. How work actually flows matters more than the organization chart.

Common organizational logics for CIO functions
Common organizational logics for CIO functions
Process organization beats organizational structure
Process organization beats organizational structure

The company as a system

A company is a system whose elements influence one another – like the heart, lungs and brain in the human body. The essential properties of a system are properties of the whole. They arise from the interaction of the elements, not from their sum. Excellent eyesight, a steady hand and concentration only make a good marksman when they work together.

It follows that anyone who wants to improve a company must not optimize individual elements in isolation, but has to improve the interaction of functions, organizational units, processes, data, applications and infrastructure. If, like Dr. Frankenstein, you assemble the most powerful body parts from different organisms, you do not get a perfect human being but a monster.

Three tools that have proven themselves

Input-value add-output charts reduce the process idea to its core: does every function deliver what the next one needs – and vice versa?

Input-value add-output charts
Input-value add-output charts

The task structure survey is a somewhat old-fashioned but very effective instrument. For one month, employees record in a standard grid how much time they spend on which tasks. The grid can be derived from organization charts and roles or from frameworks such as COBIT. Done properly, the survey reveals, among other things:

Task structure survey
Task structure survey

Roles are clusters of logically related tasks. Ideally, three to five roles are assigned to an employee through his or her job profile. Roles serve as the anchor for job descriptions, target agreements, performance reviews, training, change measures and the granting of access rights. Linking access rights to roles rather than to individuals allows changes in processes and responsibilities to be implemented quickly and consistently.

Roles as a vehicle for different use cases
Roles as a vehicle for different use cases
2026 update

The task structure survey is experiencing a renaissance: it is the most solid basis for deciding which tasks are suitable for AI agents and which require human judgment. And the role model becomes a prerequisite for granting agents proper permissions – an agent needs clearly defined rights just as much as an employee does.

03Steering and prioritizing

Only measure what you want to manage. And only manage what you can measure. after Peter Drucker

The performance and conformance of a CIO function develop best when both are managed systematically. Innovation is the exception; here Gunter Dueck's insight applies: process is the death of innovation.

"A fool with a tool remains a fool" – and if all you have is a hammer, every problem looks like a nail. Nevertheless, managing large CIO functions in particular requires a set of proven methods and frameworks. The most important one for IT governance is COBIT. It provides process descriptions with objectives and metrics as well as a practical maturity model, and it is an excellent basis for reorganizing CIO functions. COBIT can easily be combined with ITIL and other frameworks for service management and service delivery.

Methods, tools and frameworks for managing IT organizations
Methods, tools and frameworks for managing IT organizations
Overview of the COBIT 5 governance processes
Overview of the COBIT 5 governance processes
The COBIT process maturity model
The COBIT process maturity model

Because staff, budget, time and management capacity are limited, IT projects and IT services should be prioritized using a portfolio approach. Two-dimensional matrices with four or nine fields have proven useful, with dimensions such as alignment with strategy and architecture, legal and regulatory obligation, cost advantages, and risk and complexity. The approach has to be tailored to the company.

Portfolio matrices for prioritizing projects and services
Portfolio matrices for prioritizing projects and services
Effectiveness matters more than efficiency. If you are driving in the wrong direction, you will not reach your destination even with 600 horsepower and the best driver in the world.
CIO performance and conformance management based on COBIT
CIO performance and conformance management based on COBIT

04Architecture as a blueprint

Hardly anyone would build a house or develop a building area without an architecture and a development plan. If it later turns out that the load-bearing walls are too weak or the conduits for cables are missing, it gets expensive. Yet when it comes to the process and IT landscape, which largely determines a company's performance and the experience of customers, employees and suppliers, there are apparently managing directors and board members who believe they can do without.

Enterprise IT architecture as the basis for systematic development of the IT landscape
Enterprise IT architecture as the basis for systematic development of the IT landscape

The IT landscape plan reveals gaps (missing IT support), redundancies (duplicate spending) and dependencies (complexity) between IT systems in relation to business processes and organizational units. The enterprise target architecture ties together processes, roles, data and IT. Central master data management and standardized platforms for integration, communication and collaboration, and content management ensure that the right hand knows what the left hand is doing. Protecting personal data and intellectual property – especially the "crown jewels" – is of course part of it.

IT landscape plan: gaps, redundancies and dependencies
IT landscape plan: gaps, redundancies and dependencies
The enterprise target architecture as the link between processes, roles, data and IT
The enterprise target architecture as the link between processes, roles, data and IT

A modern architecture relies on standards and best practices such as the ISO/IEC 27000 family for information security, ISA-95 for integrating production and enterprise IT, COBIT for governance and ITIL for service management. Enterprise architecture is not rocket science, and there are many roads to Rome. That makes it all the more important to have it managed by professionals who know their craft – not only on the IT side but also on the business side.

Four-level production IT architecture according to ISA-95
Four-level production IT architecture according to ISA-95
2026 update

AI agents are new building blocks of the architecture. They call tools, access data and carry out actions – and therefore need defined permissions, approval workflows, logging and monitoring. Catalogs or marketplaces for standardized agents are becoming the control layer for this (see my article "Marketplaces for standardized AI agents", in German). Regulatory requirements such as the EU AI Act and the NIS2 Directive are raising the bar for governance and security at the same time.

05People, culture and change

The output of every organization is reduced by factors that appear on no organization chart: management decisions, employee engagement and motivation, politics and turf wars between "little kingdoms", inefficient processes and IT systems, operational and personal failure, and external risks. In the end, often only a fraction of the possible output remains.

How major performance killers reduce the output of any organization
How major performance killers reduce the output of any organization
The culture of any organization is shaped by the worst behavior tolerated (Gruenert/Whitaker)
The culture of any organization is shaped by the worst behavior tolerated (Gruenert/Whitaker)

Some CxOs believe that board decisions implement themselves more or less automatically. In some companies, decisions are not even communicated, with their background and rationale, to the most important multipliers. But change only happens when nine prerequisites are met. Employees must …

The nine prerequisites of change
The nine prerequisites of change

The more of these prerequisites are missing, the less likely it is that the desired change will happen. Without informing, convincing, training, encouraging and supporting people, change is impossible. If I have learned one thing in my professional life, it is this: take nothing for granted and expect the unexpected.

Communication grows faster than the team

Managing communication, relationships and team spirit is at least as important in projects as the classic management of backlog, deadlines, resources and risks. The number of communication relationships grows with n·(n−1)/2: five people have 10 relationships, ten people 45, twenty people already 190. Managing external relationships is like conducting an orchestra – it's the tone that makes the music, and harmonious interplay requires a lot of practice and coordination.

Critical success factors in projects (graphic circulated on social media in 2021; earliest known source: a tweet of 2 September 2021)
Critical success factors in projects (graphic circulated on social media in 2021; earliest known source: a tweet of 2 September 2021)
Communication relationships in projects depending on team size
Communication relationships in projects depending on team size
Stakeholder management is like conducting an orchestra
Stakeholder management is like conducting an orchestra

Digital competence as a leadership task

The EU's digital competence framework (DigComp) describes 21 competences in five areas: information and data literacy, communication and collaboration, digital content creation, safety, and problem solving. The EU aims for 80 % of citizens aged 16 to 74 to have at least basic digital skills by 2030. In 2021 the EU average was 54 %, with Germany below it at 49 %. Competence management is therefore not a task for the HR department alone, but a leadership task.

People with at least basic overall digital skills in 2021 (source: Eurostat)
People with at least basic overall digital skills in 2021 (source: Eurostat)

06Partners and suppliers

The worst IT solution from the best provider may well be better than the best IT solution from the worst provider. Select suppliers with great care – with regard to competence, customer orientation, reliability, capacity for innovation and dependency (keywords: monopolist, vendor lock-in). The same applies to selecting IT solutions. A weighted scoring model helps to make the decision more objective, but it should not be applied mechanically so that the solution with the highest score automatically wins.

Major criteria for selecting IT providers
Major criteria for selecting IT providers
Major criteria for selecting IT solutions
Major criteria for selecting IT solutions
From RfP to delivered product – why requirements must be clearly understood
From RfP to delivered product – why requirements must be clearly understood
Traditional outsourcing vs. cloud services – contrast of business models
Traditional outsourcing vs. cloud services – contrast of business models

Both options turn fixed costs into variable costs. And with both, the client must retain the competence to steer the service provider: in the event of violations of tax, data protection, antitrust or foreign trade law, the client remains responsible to the authorities for the services it has purchased.

Where does your CIO organization stand?

With a quick check I determine the maturity of your CIO organization – from role and organization through governance and architecture to culture and supplier management. Depending on size and complexity, this takes between 3 and 30 person-days. The result: robust findings and concrete recommendations for your management board.

Arrange a conversation
Part 2 · The reading list

27 articles for a deeper dive


I published the following articles on my blog between 2016 and 2026. They deepen the topics of Part 1. Where no English version exists, the article is marked DE. Selected articles will gradually appear in updated form under Methods & Experience.

IT management and organization

Leadership, culture and change

Information security and data privacy

Digitalization, platforms and AI