Platform Launch and Research Status
Tradecraft Labs launches as a public research platform. This entry documents the current state of the BISO Governance research, what has been completed to date, and what comes next in the practitioner interview phase.
Today marks the launch of Tradecraft Labs as a public research platform. The goal of this platform is to document research in progress, not just final outputs. That means publishing working theories, raw observations, literature frameworks, and the reasoning behind decisions as they happen, not only when a paper is complete.
This first entry documents where the BISO Governance research stands.
What Has Been Completed
The foundational work for this research is done. The literature review is complete, covering 15+ sources across organizational governance theory, strategic alignment, boundary-spanning leadership, enterprise risk management, and the emerging body of BISO-specific literature. The annotated bibliography and literature matrix are finalized.
The research proposal has been submitted. The working thesis has gone through one significant revision. The framing shifted from describing the BISO primarily as a communication or translation function to positioning it as a governance intermediary. That shift is documented in the Research Insights artifact, which now reflects version 2 of the working thesis.
The interview framework is in place. The interview guide has been finalized, and an initial pool of eight practitioners has been identified across six functional perspectives: executive technology leadership, cybersecurity leadership, governance and risk, security partnership, business leadership, and communications.
Current Stage: Practitioner Interviews
The interview phase is underway. The interviews are semi-structured and designed to surface practitioner experience with security-business governance, risk acceptance, trust, and the value of BISO or equivalent functions. Each interview will be documented using a consistent analysis template to support systematic theme identification.
The central questions driving the interview phase:
- Does the governance intermediary framing hold up against practitioner experience?
- Is trust genuinely a prerequisite for effective governance, or is that framing too strong?
- How do practitioners measure or recognize BISO value in practice?
- Does the conceptual model (Trust → Communication → Governance → Risk-Informed Decisions) reflect how these processes actually work?
The Working Thesis
The current working thesis is version 2:
The Business Information Security Officer (BISO) functions as a governance intermediary and boundary-spanning leadership role that enables organizations to navigate competing cybersecurity and business priorities through structured risk-based decision making. Its effectiveness is determined less by technical authority and more by its ability to facilitate governance processes, improve decision quality, establish stakeholder trust, and influence organizational risk decisions.
This thesis will continue to evolve as interview data is collected and analyzed. The journal will track that evolution.
What Comes Next
Interview completion and analysis. As each interview is finished, an analysis will be completed using the interview template and themes will be mapped against the working thesis. The journal will document significant findings, challenges to the thesis, and new directions as they emerge.
The goal is not to defend the thesis. The goal is to find out whether it holds.
