A Field Guide to the CISO’s First 90 Days

The new CISO has 90 days to figure out what the security program actually does, what it does not, and what the board needs to know. Here is the playbook.

Dark cinematic editorial image for A Field Guide to the CISO’s First 90 Days - abstract cyan and electric blue digital composition in deep black, hacker aesthetic, no text no logos

4 MIN READ

A new CISO has 90 days before the board, the CEO, and the regulators form a view of the program. What gets done in that window tends to define the next 90 quarters. Someone who uses those 90 days to listen, to learn, to assess, and to plan has a real shot at a long tenure. Someone who uses them to announce the new strategy, the new tooling, and the new team has a real shot at not making it to month seven.

The first 30 days is for listening, not speaking. The new CISO should sit down with every C level executive, the general counsel, the head of internal audit, the head of compliance, the business unit leads, and the IT and engineering leads, and the goal of every conversation should be the same: understand what the stakeholders need from security, what they think of the current program, what they will fund, and what they will block. The same window should include a read of every incident report from the last 18 months, because the incident history is the part of the program that tells the real story, and a review of the budget and the headcount, because the budget and the headcount are the constraints that will define the first year.

Days 1 to 30: listen before you speak

Run a proper listening tour, and resist the urge to pitch. Walking into a meeting with a slide deck and a 12 month plan has already lost the meeting, because anyone who arrives with a slide deck has decided what the answer is before the conversation has happened. The new CISO who walks in with a notebook and a list of questions has a real chance of hearing the answer, and the answer is usually more useful than the slide. The conversations to prioritise: the CEO (what the board is asking), the CFO (what the budget will bear), the general counsel (what the regulators are watching), the head of internal audit (what the audit findings are), the business unit leads (what the operations team needs to keep running), and the IT and engineering leads (what the current program can actually do).

Days 31 to 60: assess, then prioritise

Two written assessments, both shared with the key stakeholders. The risk register ranks the top 10 threats in the language the board understands, with the impact, the likelihood, and the existing control for each. The register feeds the strategy, and the register sits as the document the board will see. The maturity assessment benchmarks the current program against a known framework (NIST CSF, ISO 27001, or the CIS Controls), and the assessment shows where the program is strong, where it is weak, and where the gap is the most expensive to close. Both documents need stakeholder sign off before the strategy work starts, because strategy without stakeholder buy in is strategy that gets blocked at the first budget cycle.

Days 61 to 90: plan, then communicate

Build the 12 month strategy, with the 90 day plan, the 6 month plan, and the 12 month plan, and put the budget, the headcount, the risks, and the assumptions in writing. The strategy document is the new CISO’s contract with the organisation, and the strategy document is the document the board will hold the CISO to at the next quarterly review.

Run a team assessment, and be honest about what it finds. The assessment produces a talent roadmap: the high performers to retain, the medium performers to invest in, the low performers to move out, the open roles to fill, the promotions to make, and the exits to plan. The roadmap forms the part of the strategy that takes the longest to land, and the roadmap forms the part the CISO cannot afford to leave for month seven.

Build the board presentation, in the board’s language, with the risk framing, the budget, the timeline, and the asks. The board presentation forms the foundation for the rest of the tenure. A CISO who nails the board presentation in the first 90 days has a real shot at the next 90 quarters.

A CISO first 90 days timeline chart with days 1 to 30 listening, days 31 to 60 assessing, days 61 to 90 planning as the three phases, dark navy background, cyan and warm amber.
CISO first 90 days: listen in the first 30, assess in the second 30, plan and communicate in the third 30.

The bottom line

Listen, assess, plan. The first 90 days is for learning what the organisation actually needs from security, not for telling the organisation what it needs. The CISO who uses the 90 days correctly has a real shot at the next 90 quarters.


Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading