"Dual-fit imperative in security leadership: a grounded theory investigation of CISO role enactment in modern organisations."
The thesis has a complete survey with some interesting answers from a small set of CISCO. Now the conclusion/recommendation seems a bit broad and very generic imho.