Why the most expensive technical strategy decisions are the ones made by default in the gap between two reorgs

Last quarter I spent two days trying to find who approved a piece of our integration layer. Not to blame anyone. The choice looks strange on paper, and strange choices usually mean somebody knew something I don't.

Nobody approved it. It was built in the gap between one VP leaving and their replacement finishing their listening tour. Three teams each needed the same data, each solved it locally and defensibly, and by the time anyone had the standing to say "let's do this differently," it had four dependencies and a dashboard. The decision was never made. It accumulated.

Mary and Tom Poppendieck: if commitments are delayed beyond the last responsible moment, decisions get made by default, which is generally not a good way to make decisions. Organizations manufacture those moments reliably.

Korn Ferry puts average CIO tenure at 4.6 years. McKinsey puts a typical reorg at ten months from plan to practice, productivity falling for most of it, and over 80% miss the value expected of them. Watkins puts a new leader's ramp at 90 days before they contribute more than they consume. Stack ramp-up against settling and you get six to nine months where nobody has both the context and the standing to make a hard-to-reverse bet. That range is my arithmetic, not a finding, but every input is documented, and two reorgs in you know the shape.

Architectural debt is the expensive kind. CMU's Software Engineering Institute made the case in 2012: architectural rework compounds through dependencies in a way that messy code inside one service never does. And Reinertsen found 85% of product managers cannot state the cost of delaying a project, which is why a nine month vacuum never shows up on a budget. A real bill with no line item.

Conway's Law finishes the job. Reshuffle the org every couple of years and the architecture inherits each structure in turn, leaving seams where old reporting lines used to be.

The fix is not more central control. DORA's research shows teams that can make significant changes without outside permission outperform those that cannot. Decisions moving downward during a gap is often fine. The failure is that they move silently, so the next leader inherits consequences without reasoning, and either rubber stamps them or rips them out.

The mechanisms worth having are boring. Architecture decision records, which Michael Nygard proposed in 2011 for this reason. Harmel-Law's advice process, where anyone can decide provided they consult the affected and the informed, and write down what they heard. Fitness functions that keep checking your intent after the person who held it has gone.

Avelino and colleagues computed the bus factor of 133 open source systems: 46% depend on a single person. If your CTO and two most senior engineers left next month, how much of your architecture would still be a decision, and how much would be a rumour nobody feels safe touching?

Research dossier: leadership transition gaps, decision vacuums, and "accidental architecture"

Prepared as an objective, fact-and-data-rich briefing. Research only. This does not draft a post; it assembles the evidence, separates strong from weak sourcing, and tests the thesis including where it fails.

TL;DR

  • The thesis holds up in its parts but no single study proves the specific "6-9 month window in which no one has clear authority." Technology leaders do turn over faster than CEOs, reorgs are frequent and mostly fail to deliver value, senior decision-making is slow and expensive, and architecture provably erodes when nobody actively governs it. The precise duration of the "authority vacuum" is the weakest link and should be presented as a reasoned estimate, not a measured fact.
  • The most defensible spine: CIO average tenure is 4.6 years while CEO tenure is 6.9 years (Korn Ferry, 2020), and S&P 500 CEO median tenure fell to 4.8 years by 2022 (Equilar), so a change somewhere in a large firm's top team is close to an annual event; more than 80 percent of reorgs fail to deliver expected value and about 60 percent reduce productivity (McKinsey via HBR); a typical reorg takes about 10 months plan-to-practice; technical debt runs at up to 40 percent of IT balance sheets (McKinsey) and about $1.52 trillion accumulated in the US (CISQ, 2022); and architecture decays by "drift" and "erosion" when left untended (Perry and Wolf, 1992).
  • Two zombie statistics need flagging: the "CISO tenure is 18-26 months" figure is weakly sourced and contradicted by better data (~4 years), and the "6-9 months of no authority" duration is plausible but not empirically established (the only "6-9 months" figure in the literature refers to how long a reorg takes to deliver value, not to a decision vacuum).

Key findings and the most quotable, defensible statistics

  • CIO tenure 4.6 years vs CEO 6.9 years. Korn Ferry's January 2020 analysis of the 1,000 largest US companies by revenue found: "The average tenure for the CIO is 4.6 years," while "At an average of 6.9 years, CEO tenure is the longest in the C-suite," itself down from 8.0 years in Korn Ferry's 2016 analysis. CIOs are among the youngest and shortest-tenured C-suite roles, second only to CMOs.
  • CEO median tenure fell 20 percent in a decade. Equilar (featured in Barron's, 2023): "the median tenure among the S&P 500 companies has decreased 20% from six years in 2013 to 4.8 years in 2022," while the average fell only slightly, from 7.6 to 7.2 years, because a few "forever CEOs" pull the mean up. Spencer Stuart separately reported average S&P 500 CEO tenure of 8.9 years in 2023, down from an 11.2-year pandemic peak in 2021.
  • Over 80 percent of reorgs fail to deliver value. McKinsey survey, via Harvard Business Review "Getting Reorgs Right" (November 2016): "more than 80% fail to deliver the value they are supposed to in the time planned, while 10% cause real damage to the company," with reduced productivity in about 60 percent of cases. A separate McKinsey figure: only about 23 percent of reorganizations are judged successful in hindsight.
  • A typical reorg takes about 10 months. McKinsey Organization Practice white paper (2011): "A typical reorganization takes ten months from plan to practice," and more than half of executives said productivity fell during that period. Reorgs are routine: 82 percent of executives had experienced a restructuring at their current firm, 70 percent within the previous two years.
  • Executives waste roughly 40 percent of their decision time. McKinsey "Decision making in the age of urgency" (2019 survey, 1,259 respondents): managers "spend an average of 37 percent of their time making decisions, and 58 percent of this time is used ineffectively," costing a typical Fortune 500 company "more than 530,000 days of lost working time and roughly $250 million of wasted labor costs per year." Fast decisions correlated with good ones (fast deciders were about twice as likely to report high quality), undercutting the "good or fast, pick one" assumption.
  • Technical debt is up to 40 percent of IT balance sheets. McKinsey "Tech debt: Reclaiming tech equity" (October 6, 2020, survey of about 50 CIOs at firms over $1 billion): tech-debt principal "accounts for up to 40 percent of IT balance sheets," companies pay an extra 10 to 20 percent on top of project costs, and 30 percent of CIOs said more than 20 percent of their new-product budget is diverted to debt. McKinsey's 220-company analysis linked top-quintile tech-debt scores to about 20 percent higher revenue growth than the bottom quintile. [1]
  • US technical debt is about $1.52 trillion. CISQ (Consortium for Information and Software Quality), "The Cost of Poor Software Quality in the US: A 2022 Report," author Herb Krasner: "the cost of poor software quality in the US has grown to $2.41 trillion... accumulated software technical debt... has grown to approximately $1.52 trillion."
  • Architectural erosion is a named, studied phenomenon since 1992. Perry and Wolf, "Foundations for the Study of Software Architecture," distinguished erosion (decay from violating the architecture) from drift (decay from insensitivity to it).
  • Loosely coupled architecture is a top predictor of performance. DORA / Accelerate State of DevOps 2021 (p.26): "elite teams who meet their reliability targets are three times more likely to have adopted such an architecture than low-performing teams."

Details by research area

1. Tenure, turnover, vacancy, and ramp-up

CIO and CTO. Korn Ferry's 2020 read (4.6 years) is the cleanest large-sample figure; a 2017 Korn Ferry read had CIO tenure around 4.3 years and average age 51, and a later Fortune 100 study put it at "just over five years." Across sources CIOs are consistently among the shortest-tenured executives. An academic study of 384 CIO resumes (Springer, Information Systems and e-Business Management, 2021) used tenure as a proxy for success and noted most CIOs had been in post three years or less.

CISO (handle with care). The frequently repeated claim, "average CISO tenure is 18 to 26 months," is attributed to the Cybersecurity Ventures "CISO Workforce and Headcount 2023 Report" and echoed by CSO Online, SC Media, and Korn Ferry commentary. Cybersecurity Ventures itself hedges it ("estimated at 18 to 26 months by various sources"), and the identical 18-26 range is elsewhere pinned on Nominet and on PwC Luxembourg, which is a classic sign of circular, weakly-grounded sourcing. Better-sourced data contradict it:

  • IANS Research and Artico Search run the leading annual CISO Compensation and Budget study (566 CISOs in 2025; 755 in 2024; 662 for the 2026 State of the CISO report). Their 2026 report has CISOs reporting an average tenure of about nine years across their careers, having often served as CISO at multiple organizations; CISO mobility hit a six-year high with 15 percent changing employers in 2025, up from 11 percent in 2024.
  • Marlin Hawk (470 CISOs at organizations over 10,000 employees) reported average CISO tenure of about four years; 45 percent were in role two years or less in 2022 (down from 53 percent in 2021), with 18 percent annual turnover.
  • Forrester's CISO Career Paths analysis of Fortune 500 CISOs found average tenures of 4.5 years or more (men 5.4 years, women 3.8 years); an independent analysis of Fortune 500 CISOs put the mean at 4.5 years and the median at 3.6 years. Honest position: the "18-26 month" figure is a likely-overstated zombie statistic; real CISO tenure is closer to four years, though CISO turnover is genuinely higher than for CIOs and CFOs.

CDO / Chief Digital or Data Officer. Commonly cited at about 2.5 years average tenure (versus about 4.5 for CFO and about 7 for CEO), reflecting a young, unstable role.

CEO knock-on effect. The Equilar finding matters because CEO turnover cascades: a new CEO typically reshuffles the executive team, resetting the technology leadership layer and often triggering a reorg. So the effective churn facing an architecture is not just its own CIO or CTO changing, but every leadership change above and around it.

Vacancy and ramp-up. Senior technology roles sit empty or interim for months; IANS/Artico commentary notes many open CISO roles stay vacant from three months to a full year. On ramp-up, Michael Watkins's "The First 90 Days" (Harvard Business Review Press, 2003; called "the onboarding bible") frames the first roughly 90 days as the period before a new leader reaches the "breakeven point" where they contribute as much as they consume, and describes change as coming in "successive waves" (learning, then designing, then building support, then implementing), so major structural moves typically come only after that initial learning phase. This supports a genuine lag between a leader arriving and making architectural bets. [2][3]

2. Reorg frequency and outcomes

McKinsey's reorg statistics are the strongest quantitative anchors: over 80 percent fail to deliver expected value in the planned time, about 10 percent cause real damage, and about 60 percent reduce productivity (HBR, 2016); only about 23 percent are judged successful in hindsight; and a typical reorg takes about 10 months plan-to-practice with productivity falling during that period (McKinsey, 2011). Reorgs are routine: 82 percent of executives had lived through one at their current firm, 70 percent within the last two years; about 60 percent of S&P 500 companies launched large-scale cost or reorganization initiatives within a five-year window, and only 26 percent kept costs from creeping back. Note on the "6-9 months" phrase: it appears via NOBL summarizing McKinsey and refers to how long a reorg takes to deliver value, not to a leadership authority vacuum; it is a consultancy synthesis, not a peer-reviewed figure, and should be cited with that caveat.

3. Decision authority vacuums and decision latency

McKinsey's decision-effectiveness work gives the hard numbers: managers spend about 37 percent of their time deciding and use 58 percent of that time ineffectively; 54 percent of respondents spend more than 30 percent of their time on decision-making; and even 57 percent of C-level executives call most of their decision time inefficient. Waste at a typical Fortune 500 is about 530,000 manager-days and $250 million a year. Bain's RAPID and the DACI/RACI frameworks exist precisely to assign decision rights, and the McKinsey data show that ambiguity in "who decides" is a measurable drag on both speed and quality. [4]

The strongest conceptual anchor for what happens in a vacuum is Mary and Tom Poppendieck (Lean Software Development, 2003): "If commitments are delayed beyond the last responsible moment, then decisions are made by default, which is generally not a good approach to making decisions." That is exactly the mechanism in the thesis: not a deliberate architectural bet, but a default set by inaction. Direct empirical evidence on architectural decisions specifically during interim leadership is thin. The available commentary comes largely from interim-executive vendors (SecureWorld, Fortium Partners, CXO Partners) describing stalled initiatives, delayed risk decisions, and "vendor-driven" choices during gaps; these are directional and commercially interested, not independent studies, and should be labelled as such. [5]

Don Reinertsen's cost-of-delay work (The Principles of Product Development Flow, 2009) supplies the economics of deferral: "If you only quantify one thing, quantify the cost of delay." He reports that about 85 percent of product managers do not know the cost of delaying a project, and that intuitive estimates of it vary by as much as 50 to 1. The cost of a decision vacuum is therefore real but almost never measured, which is precisely why it accumulates unnoticed. [6][7]

4. Accidental architecture and local optimization

Definitions and lineage. Fred Brooks distinguished essential from accidental complexity in "No Silver Bullet" (1986/1987); accidental complexity is the difficulty we add ourselves. Perry and Wolf (1992) named architectural erosion (decay from violating the architecture) and architectural drift (decay from insensitivity to it). Related terms include design erosion (van Gurp and Bosch), architectural decay (Riaz et al.), code decay (Eick et al.), and software entropy (Jacobson). Foote and Yoder's "Big Ball of Mud" (1997) is the canonical name for a system with no discernible architecture, which is typically the end-state of unmanaged local optimization. A 2022 systematic mapping study, "Understanding software architecture erosion," confirms erosion is a continuously studied, empirically observed phenomenon, not just a metaphor. [8][9]

Cost. McKinsey: up to 40 percent of IT balance sheets, plus 10-20 percent on top of projects, with 30 percent of CIOs saying over 20 percent of new-product budget is diverted to debt, and a 220-company link between low tech debt and about 20 percent higher revenue growth. CISQ (2022, Herb Krasner): about $1.52 trillion accumulated US technical debt within $2.41 trillion total cost of poor software quality, and cites Stepsize's finding that actively managing tech debt lets teams ship at least 50 percent faster. The CMU Software Engineering Institute paper by Nord, Ozkaya, Kruchten and Gonzalez-Rojas, "In Search of a Metric for Managing Architectural Technical Debt" (2012, awarded ICSA Most Influential Paper in 2022), established that the most expensive debt is rooted in architecture rather than code, because rework costs compound through architectural dependencies. This is the direct evidence for "the most expensive decisions are architectural." [10]

Irreversibility. Martin Fowler and others treat architectural decisions as the ones that are hard to reverse. Jeff Bezos's one-way-door / two-way-door framing (Amazon 2015 shareholder letter) captures why leaving architecture to default is dangerous: "Some decisions are consequential and irreversible or nearly irreversible: one-way doors... these decisions must be made methodically, carefully, slowly, with great deliberation and consultation." A vacuum tends to convert would-be deliberate one-way-door decisions into unmanaged defaults made by whoever is closest to the code that week.

Conway's Law and org churn. Melvin Conway (1968, "How Do Committees Invent?", Datamation): "organizations which design systems... are constrained to produce designs which are copies of the communication structures of these organizations." MacCormack, Baldwin and Rusnak tested this "mirroring hypothesis" empirically (Harvard Business School working paper 08-039; Research Policy, 2012), showing products mirror the organizations that build them; Colfer and Baldwin's review of 102 empirical studies found mirroring strongly supported within single firms. The implication for the thesis is direct: if the org chart is reshuffled repeatedly, the architecture inherits each successive communication structure in turn, leaving seams and fragmentation where old teams and reporting lines used to sit. DORA's inverse-Conway guidance and loosely-coupled-architecture findings (2021-2023 State of DevOps) are the constructive counterpart to this. [11][12]

Lock-in and path dependence. Once a local optimization is in place, switching costs and path dependence (the QWERTY literature associated with Paul David) make it sticky. The "last responsible moment" is quietly passed, and what began as a temporary workaround hardens into permanent structure.

5. Continuity mechanisms that survive personnel change
  • Architecture Decision Records (ADRs). Coined by Michael Nygard in November 2011 ("Documenting Architecture Decisions," written at Relevance/Cognitect). The stated purpose is continuity: those who come later should not have to either accept or overturn a decision without understanding the reasoning behind it. ThoughtWorks placed lightweight ADRs in the "Adopt" ring of its Technology Radar (November 2017), its strongest recommendation; AWS Prescriptive Guidance and the Azure Well-Architected Framework both recommend them. ADRs are the clearest example of a written record that reduces rework when leaders leave. [13][14]
  • Architecture advice process and advisory forums. Andrew Harmel-Law's "architecture advice process" (martinfowler.com, "Scaling the Practice of Architecture, Conversationally," 30 November 2021; book Facilitating Software Architecture, O'Reilly, 2024) decentralizes decisions with one rule and one qualifier: "anyone can make an architectural decision," provided that before deciding they consult everyone who will be meaningfully affected and everyone with relevant expertise (agreement is not required, but seeking and recording the advice is). It pairs with an Architecture Advisory Forum, team-sourced principles, and a team-owned tech radar. This is a governance pattern explicitly designed to survive individuals, because authority sits in a repeatable process rather than one person's judgment.
  • Evolutionary architecture and fitness functions. Ford, Parsons and Kua's fitness functions turn architectural intent into automated, continuously checked guardrails, so the architecture is defended even as the humans change. Team Topologies (Skelton and Pais) provides platform-as-product and enabling-team patterns; DORA shows loosely coupled architecture and teams are among the strongest predictors of delivery performance, and that high-quality documentation amplifies the benefit of technical capabilities (a direct link between written records and outcomes).
  • Knowledge loss and the bus factor. The bus factor (or truck factor) is the minimum number of people who would have to leave before a project is incapacitated. Avelino, Passos, Hora and Valente (ICPC 2016) computed it for 133 popular GitHub systems and found most are dangerously concentrated: 46 percent had a truck factor of 1 and 28 percent a truck factor of 2, so roughly two-thirds sit at 2 or below. This quantifies why undocumented architectural intent can evaporate when a single key person leaves.
  • Governance from other domains. Succession planning, board-level technology governance, and standards bodies embody continuity that outlives any individual. The common thread with ADRs and the advice process is that the decision and its rationale are written down and owned by an institution rather than a person, which is what lets direction survive personnel change.
6. Counterarguments and nuance (evidence against the thesis)
  • Autonomy can beat central control. DORA's central finding is that loosely coupled teams able to make large-scale changes without permission from outside the team outperform. A leadership gap that pushes decisions down to well-aligned, loosely coupled teams is not automatically harmful, and heavy central architecture functions or "architecture by committee" can be actively slower and worse. So an authority vacuum sometimes improves outcomes rather than degrading them.
  • Some deferral is rational. The last-responsible-moment principle (Poppendieck) and YAGNI hold that deciding too early, before you have information, is also costly, and real-options thinking treats keeping options open as valuable. The thesis's own anchor quote cuts both ways: the harm is in passing the last responsible moment, not in waiting up to it.
  • Change fatigue argues for fewer reorgs, not more governance. Gartner found employee willingness to support enterprise change collapsed from 74 percent in 2016 to 43 percent in 2022, while the average employee faced about 10 planned changes in 2022 versus 2 in 2016. This complicates a "just add a continuity mechanism" prescription, because more governance is itself change, and organizations are already saturated. [15][15]
  • The 6-9 month window is not empirically established. No located study measures a 6-9 month authority vacuum after a leadership change. The "6-9 months" figure that does exist refers to how long a reorg takes to deliver value. The thesis's duration claim is best presented as a reasoned synthesis (a roughly 90-day ramp-up lag plus a roughly 10-month reorg settling period, overlapping around leadership changes) rather than a measured constant.

What is strong, what is weak

  • Strong evidence: CIO and CEO tenure (Korn Ferry, Equilar, Spencer Stuart); reorg failure and duration (McKinsey, HBR); decision-time waste (McKinsey); tech-debt cost (McKinsey, CISQ); architectural erosion as a real phenomenon (Perry and Wolf, CMU SEI); Conway's Law and the mirroring hypothesis (Conway; MacCormack, Baldwin and Rusnak; Colfer and Baldwin); ADR provenance and adoption (Nygard, ThoughtWorks); DORA loosely-coupled findings; bus-factor concentration (Avelino et al.).
  • Weak or contested evidence: the "CISO tenure 18-26 months" figure (zombie statistic; better data say about four years); the specific "6-9 month authority vacuum" duration (plausible, not measured); vendor commentary on interim-leadership decision stalls (directional and commercially interested); and third-party restatements of McKinsey reorg figures that sometimes drift from the originals.

Caveats

The numbers come from different populations (US large-cap, Fortune 500, global CISO panels) and different years, so they should not be stacked as if drawn from one sample. Major consultancy findings (McKinsey, Gartner, Bain) are largely proprietary surveys without fully public methodology, and several are self-reported. Most critically, the causal chain in the thesis (leadership gap leads to local optimization leads to accidental architecture) is well-supported at each individual link but has not been demonstrated end-to-end in a single controlled study. It is a strong, well-evidenced synthesis, not a proven law, and is most honestly presented that way.

  1. byteiota — https://byteiota.com/technical-debt-roi-how-mckinseys-20-data-wins/
  2. Rick Lindquist — https://www.ricklindquist.com/notes/the-first-90-days
  3. Trans4mind — https://trans4mind.com/download-pdfs/The%20First%2090%20Days%20-%20Critical%20Success%20Strategies%20for%20New%20Leaders.pdf
  4. McKinsey & Company — https://www.mckinsey.com/capabilities/people-and-organizational-performance/our-insights/three-keys-to-faster-better-decisions
  5. Coding Horror — https://blog.codinghorror.com/the-last-responsible-moment/
  6. Agilesherpas — https://www.agilesherpas.com/blog/cost-of-delay-agile-marketing
  7. Wikipedia — https://en.wikipedia.org/wiki/Cost_of_delay
  8. DEV Community — https://dev.to/kingnonso/reviewing-a-1992-paper-foundations-for-the-study-of-software-architecture-38mk
  9. ScienceDirect — https://www.sciencedirect.com/science/article/abs/pii/S0164121211002044
  10. SEI Insights — https://insights.sei.cmu.edu/news/2012-technical-debt-paper-co-authored-by-seis-nord-and-ozkaya-wins-most-influential-award/
  11. DORA — https://dora.dev/devops-capabilities/technical/loosely-coupled-architecture/
  12. Harvard University — https://dash.harvard.edu/handle/1/34403525
  13. InCuca Tech — https://incuca.net/en/adr-any-decision-record/
  14. Hidekazu-konishi — https://hidekazu-konishi.com/entry/architecture_decision_records_templates_and_operations.html
  15. Harvard Business Review — https://hbr.org/2023/05/employees-are-losing-patience-with-change-initiatives

Commissioned from our research desk. Subject to final editorial discretion.

Why the most expensive technical strategy decisions are the ones made by default in the gap between two reorgs. Explore how leadership transitions create 6-9 month windows where no one has clear authority to make architectural bets, and teams fill the vacuum with local optimizations that calcify into accidental architecture. Research stats on average CISO/CTO tenure and reorg frequency at mid-to-large enterprises. The takeaway is that organizations need decision-making continuity mechanisms that survive personnel changes.