

What's inside?
Two checklists in one, across 15 device and infrastructure types:
Days 1–30: Understanding the landscape - initial security assessment, asset inventory, stakeholder meetings across IT, legal, PR, risk, and the board, plus a first-pass risk register.
Days 31–60: Crafting your roadmap - defining priorities tied to business outcomes, establishing governance and policies, building (or restructuring) your team.
Days 61–90: Executing and communicating - quick wins, incident response readiness, and the 90-day briefing to leadership.
What you’ll learn
By the end, you'll be able to:
Run a structured 30-day assessment that uncovers the "house-on-fire" issues (quicksand accounts, missing MFA, patch backlogs, hard-coded passwords) before they become your problem.
Map the six high-risk areas every new CISO should audit first: data, ransomware readiness, insider threats, third-party risk, compliance, and human factors.
Build a security roadmap in business language "high likelihood of a data breach causing downtime for our e-commerce platform," not "unpatched servers."
Identify quick wins that reduce real risk and earn the political capital you'll need for bigger asks (MFA enforcement, encryption toggles, phishing reporting).
Deliver the 90-day board briefing that moves you from observer to leader: current state, risks, priorities, vision, and the support you need.
The typical CISO tenure is 18 months. Roughly 60% of breaches involve insiders or employee mistakes. Your first 90 days decide whether you're ahead of either number.
Who’s this for?
Read this if you're a…
First-time CISO stepping into the role in the next quarter and want a day-by-day structure to run against.
Experienced CISO joining a new org who wants to skip the usual traps and compress the learning curve.
VP of Security or Head of Security likely to be promoted into the CISO seat and preparing for the jump.
CEO, COO, or board member working out what your new CISO should actually be doing in their first 90 days, and what to ask for.