CISO Tribune

Guide

CISO First 90 Days: A Week-by-Week Plan for a New Security Leader

What to do in the first 90 days as a new CISO, structured around NIST's Cybersecurity Framework functions and CISA's baseline security practices: assess before you buy, build a risk register boards can read, then report.

By Hadass Liza Bitton · Published October 8, 2026 · Last reviewed October 8, 2026 · 6 min read

TL;DR: The first 90 days as a CISO run in three phases that map onto NIST's Cybersecurity Framework: assess before acting (Govern, Identify), prioritize and fix what the assessment surfaced (Protect, Detect), then exercise the plan and report it to the board (Respond, Recover, back to Govern). None of the frameworks cited here prescribe a 90-day clock; it is a planning convention this guide uses to organize work that NIST and CISA describe in terms of what to do, not how fast to do it. The one instruction every source agrees on, explicitly or in practice: understand what you are protecting and how the organization already handles risk before changing anything.

Why structure the first 90 days around a framework instead of a checklist

Generic "90-day plan" advice risks becoming a list of good habits with no anchor. This guide ties each phase to a specific function of the NIST Cybersecurity Framework, because CSF 2.0, published February 26, 2024, is the reference most security programs already measure themselves against, which means a new CISO's first assessment can double as the program's first framework-mapped baseline rather than a one-off exercise thrown away once the CISO settles in.

NIST describes five of the six functions this way: Identify "assists in developing an organizational understanding" of cybersecurity risk to systems, people, assets, data and capabilities; Protect "outlines appropriate safeguards to ensure delivery of critical infrastructure services"; Detect "defines the appropriate activities to identify the occurrence of a cybersecurity event"; Respond "includes appropriate activities to take action regarding a detected cybersecurity incident"; and Recover covers restoring capabilities and keeping resilience plans current. The sixth function, Govern, was added in the 2.0 update specifically to cover how an organization's cybersecurity risk strategy, policy and oversight are established and monitored, which is squarely the new CISO's own layer of the work, not the security team's.

Days 1-30: assess, do not act yet

The first phase is entirely Identify and Govern work, and the hardest discipline is resisting the urge to fix things before you understand them.

  • Build the asset and risk inventory. NIST's Identify function exists because an organization cannot protect what it has not catalogued: systems, data, third parties and the risks attached to each. This is slower than it sounds at a company with any history of shadow IT or unmanaged acquisitions, and it is the foundation everything else in the plan stands on.
  • Meet the people who own budget and risk decisions. The CISO's actual authority comes from relationships with the CFO, General Counsel, the CIO or CTO, business-unit leaders and the board committee that owns cybersecurity oversight, not from the org chart alone. CISA's NICE Workforce Framework frames the executive cybersecurity leadership role around exactly this: authority to make and carry out enterprise-wide decisions, which only works if the people with budget and veto power already know and trust the new CISO.
  • Compare documented policy against actual practice. Every organization has a security policy document; fewer have a policy document that matches what teams actually do. The gap between the two is where the real risk sits, and it is only visible to someone asking questions in month one, before the honeymoon period ends.
  • Resist buying anything. A new tool bought before the assessment is complete is, at best, a guess about which gap matters most, and at worst a sunk cost defending a decision made with incomplete information.

Days 31-60: prioritize against a recognized baseline

Once the assessment produces a list of gaps, the second phase turns that list into a prioritized, fundable plan, using Protect and Detect as the organizing functions.

CISA's Cross-Sector Cybersecurity Performance Goals exist for exactly this moment: a voluntary baseline of high-impact practices, explicitly designed, in CISA's words, to help organizations "kickstart their cybersecurity efforts" rather than demand a mature program on day one. Version 2.0 of the CPGs aligns with CSF 2.0 and adds a Govern-aligned category covering leadership accountability and oversight, alongside existing categories spanning account and device security, data protection, vulnerability management, supply chain risk, and incident response. Mapping the month-one gap list against this baseline, rather than against every control a vendor pitches, keeps the second phase focused on what reduces the most risk per dollar rather than what is newest.

Concretely, this phase means:

  • Turning the risk list into a register with owners, costs and dates. A gap with no owner and no date is a slide, not a plan.
  • Closing the highest-impact, lowest-effort items first. Misconfigurations, missing multi-factor authentication, unpatched internet-facing systems and stale access rights are the recurring entries across baseline frameworks like the CPGs, precisely because they are common, fixable and disproportionately exploited.
  • Starting (not finishing) the harder structural work. Supply-chain risk reviews, a real incident response plan rather than a document nobody has read, and continuous monitoring take longer than 30 days; this phase starts them and sets a realistic finish date rather than pretending they will be done by day 90.

Days 61-90: exercise the plan, then report it

The final phase maps to Respond, Recover and back to Govern: the CISO proves the plan works under simulated pressure, then reports both the plan and the proof to the people who need to trust it.

  • Run a tabletop exercise. Testing the incident response plan on paper, with the actual stakeholders who would be in the room during a real incident, surfaces gaps that reading the document never will: who has authority to make the call, who contacts legal and communications, and how fast the organization can actually move within whatever regulatory clock applies.
  • Ratify the policy set with named owners. Policies with no accountable owner decay the moment the person who wrote them leaves. By day 90, every open policy gap from the first phase should have a name attached, even if the work itself is still in progress.
  • Deliver the first board report. This is where the plan has to land as a business narrative, not a technical inventory. IANS Research's March 2026 study found boards rate their CISO's reporting on regulatory trends affecting risk well (82% rated it good or better) but rate reporting on fast-moving threats and their business impact far worse, with only 6% calling it excellent. A first 90-day report that leads with a ranked risk register, named owners, and a credible timeline, rather than a list of technologies deployed, is the version of this report boards say they are not reliably getting. CISO Tribune's guide to what the CISO job actually involves goes deeper on why this board-communication gap is now central to the role, and the guide to the SEC's disclosure rules covers the regulatory reason a public company's board increasingly expects this report in writing.

What this plan does not cover

This is a framework-anchored starting structure, not a substitute for judgment specific to one company. It says nothing about company size, industry-specific regulation, existing team maturity, or whether the CISO is building a program from zero or inheriting one mid-flight, any of which should compress or reorder these phases. None of the sources cited here claim a 90-day clock is required; it is this guide's organizing device for work that NIST and CISA describe in terms of scope, not schedule.

The honest version

Assess before you touch anything, prioritize against a recognized baseline like CISA's CPGs rather than a vendor's roadmap, then prove the plan works under a tabletop exercise before putting it in front of the board. The frameworks behind each phase, NIST's CSF 2.0 and CISA's Cross-Sector Cybersecurity Performance Goals, were not written as 90-day plans; they describe what good cybersecurity governance and baseline protection look like at any pace, and the discipline of a new CISO's first quarter is choosing to follow that order rather than skipping straight to the fixes that look most visible from the outside.

Frequently asked questions

What should a new CISO do in the first 30 days?
Assess before acting. NIST's Cybersecurity Framework groups this work under its Identify and Govern functions: build an asset and risk inventory, meet the stakeholders who own budget and risk decisions, and compare documented security policy against what teams actually do, before committing to any specific fix.
Should a new CISO buy new security tools in the first 90 days?
Not as a first move. CISA's Cross-Sector Cybersecurity Performance Goals are framed as a baseline of high-impact practices precisely because many gaps are process and configuration gaps, not tooling gaps; assessing what the organization already owns and how it is configured, under NIST's Identify function, comes before any purchase decision.
What does a CISO present to the board after 90 days?
A risk register with named owners, costs and target dates, not a status update. IANS Research's March 2026 study found boards rate their CISO's reporting on regulatory trends well but mark down reporting on fast-moving threats, which argues for a first board narrative that is concrete about what is being fixed, by when, and what is being accepted as residual risk.
Which NIST framework should a first-90-days plan follow?
The NIST Cybersecurity Framework (CSF) 2.0, which organizes cybersecurity work into six functions: Govern, Identify, Protect, Detect, Respond and Recover. NIST added Govern in the February 2024 update specifically to cover leadership accountability, strategy and oversight, the layer a new CISO is hired to own.
How long should the first 90 days actually take?
90 days is a planning convention, not a rule from any framework cited here. NIST and CISA describe what the work covers, not how long each phase should take; a smaller organization may compress this plan, and a CISO inheriting an existing program may skip the assessment phase and move straight to prioritization.

Sources

Hadass Liza Bitton

Writer

Hadass Liza Bitton is a writer at CISO Tribune covering security leadership: the people who take the top security seat, the ones who leave it, and what each move signals. Reach her at hadass@cisotribune.com.

The Briefing

Every verified CISO move of the week, in your inbox Friday.

Every verified CISO move and one piece of analysis, weekly.

Unsubscribe any time. See the privacy policy.