The new CISO has 90 days to figure out what the security program actually does, what it does not, and what the board needs to know. The 90 days is a hard deadline. The new CISO who uses the 90 days to listen, to learn, to assess, and to plan, will survive. The new CISO who uses the 90 days to announce the new strategy, the new tooling, the new team, will fail. The board, the CEO, and the regulators are watching. Here is the playbook for what to do, and what to not do, in the first 90 days.
Days 1 to 30: listen and learn
Three things, in priority order. The first serves as listening tour. The new CISO meets with every C Level executive, with the general counsel, with the head of internal audit, with the head of compliance, with the heads of the major business units, with the heads of the major IT and engineering teams. The listening tour is not a sales pitch. The listening tour is a data collection exercise. The new CISO needs to know what the stakeholders need from security, what the stakeholders think of the current program, what the stakeholders are willing to fund, and what the stakeholders will block. The second acts as incident history review. The new CISO reads every incident report from the last 18 months. The new CISO reads the root cause analyses, the remediation plans, the lessons learned. The incident history tells the new CISO where the program has been weak. The third functions as budget and headcount review. The new CISO knows what the program spends, what the program is funded for, what the headcount is, what the open roles are, what the attrition has been. The budget review tells the new CISO what is possible in the first year.
Days 31 to 60: assess and prioritise
Three things, in priority order. The first serves as risk assessment. The new CISO produces a written assessment of the top 10 risks the organisation faces, in the language the board understands. The risk assessment acts as input to the strategy. The risk assessment functions as document the board sees. The second is the maturity assessment. The new CISO benchmarks the current program against a known framework (NIST CSF, ISO 27001, the CIS Controls). The maturity assessment tells the new CISO where the program is strong and where the program is weak. The third is the stakeholder alignment. The new CISO walks the risk assessment and the maturity assessment past the key stakeholders. The new CISO gets the stakeholders to agree on the priorities. The stakeholder alignment is what gives the strategy the political cover to be implemented.
Days 61 to 90: plan and communicate
Three things, in priority order. The first serves as strategy document. The new CISO produces the 12 month strategy, with the 90 day plan, the 6 month plan, the 12 month plan, with the budget, with the headcount, with the risks. The strategy document gets reviewed by the CEO, the general counsel, the head of internal audit, the board. The strategy document acts as new CISO’s contract with the organisation. The second functions as team assessment. The new CISO meets with every member of the security team. The new CISO identifies the high performers, the medium performers, the low performers. The team assessment gets translated into a talent plan. The talent plan includes the hires, the promotions, the exits. The third is the board presentation. The new CISO presents the strategy to the board, in the board’s language, with the risk framing, with the budget, with the timeline. The board presentation gets the board bought in. The board presentation serves as the foundation for the rest of the CISO’s tenure.

The bottom line
Listen, assess, plan. The first 90 days is for learning what the organisation actually needs from security, not for telling the organisation what it needs. The CISO who uses the 90 days correctly has a real shot at the next 90 quarters.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



