
Develop your own CSO startup playbook for the first 100 days, using week-by-week guidance, templates, and real world examples to build foundation, alignment, and program delivery.
Explore the evolving role of the CISO and the seven archetypes, then examine key responsibilities and nine universal areas for security leaders across industries.
Explore the evolving role of the modern CSO and identify seven archetypes: technical, strategic, compliance, builder, customer-facing, crisis manager, and hybrid, and how they fit your company today.
Discover seven archetypes of a modern CISO, from technical and risk-focused to strategic, builder, customer-facing, crisis manager, and hybrid leaders, with their strengths, gaps, and ideal fits.
Identify which of the six or seven CISO archetypes fits your company, prioritize gaps, and plan hires to align with growth, risk, and industry needs.
Explore the nine core responsibilities every security leader must master, from governance and risk management to secure product collaboration and incident response, with emphasis on organizational context.
Explore the evolving CSO role and the key CISO responsibilities in module one, and complete the exercise to align archetypes with career and company needs and identify gaps.
Explore a five-step framework for a CISO's first 100 days—prepare, assess, plan, act, and measure—built around Gartner's and New Harbor Security playbooks to guide phased implementation.
Research the organization using public information on the company site and LinkedIn, noting the mission, culture, stakeholders, privacy policy, and security pages. Connect with executives and plan initial meetings.
Plan initial meetings by coordinating with your hiring manager to gather leadership and security staff names, schedule introductions, and show readiness before day one, including securing executive assistant support.
research your organization's mission and core values, review privacy policy and security documentation, and plan stakeholder meetings to prepare for the first 100 days as a ciso.
Establish your foundation in days one to ten by reviewing security programs, meeting colleagues, learning team structure, and launching a foundational checklist while staying visible in key risk discussions.
Review existing information security programs to understand audits, reports, responsibilities, and the security roadmap. Check with program managers to grasp ongoing projects and the overall GRC security program.
Schedule introductions with key team members and stakeholders, starting with direct reports and primary peers, then indirect reports, and include the InfoSec org, product security, technology, and facilities teams.
Hold a department meeting to share your vision and emphasize collaboration. Talk about your background, strengths, and beliefs in team culture and security to establish credibility as a leader.
Document the ciso’s first 100 days by mapping each team’s roles, tools, and providers, including GRC, auditors, security operations, and product security, and capture likes and improvement needs.
Be visible and meet people with an introduction email and abbreviated bio. Introduce yourself in person or remotely and start conversations on Slack or Teams.
Identify the business ending event by surveying direct teams and peers about the largest risks, compile findings into an initial assessment, and visualize them as a pie chart.
Compile a foundational checklist to map disciplines, team roles, responsibilities, and roadmaps; capture projects, operations, tools, service providers, budgets, and risks, guided by the NIST Cybersecurity Framework Quickstart Guide.
Review information security programs, meet colleagues, and map team structure with key stakeholders. Draft your introduction email to stakeholders and outline your approach to learning each discipline and risk area.
Plan weeks three to six to cover eight topics: information security assessment, one-on-ones, team dynamics, team communications, project snapshot, budget metrics, key business risks, and the foundational checklist.
Queue an information security assessment with your team, using CIS or NIST as a guide. Decide on internal self-assessment or external assessment to inform a future roadmap.
Hold one-on-one meetings with your entire team, including indirect reports and key leaders, and learn team dynamics through listening, questions, and clear notes.
Review email distribution lists and chat channels to map help desk and all-hands access. Identify Slack and Teams channels used by the team and establish access steps.
Take a project snapshot by listing completed projects from the last six months and those underway or planned for the next six months, then roll up a visual for review.
Review your security budget, ownership, tools, and external services or managed service provider partnerships with the finance partner; project next year’s spend based on this year and prior usage.
Ask each team member about areas of concern and the organization's largest existential risks, uncovering the scariest risks and revealing insights into knowledge, depth, and operational focus.
Complete the foundational checklist and close any gaps from weeks one and two, keeping the checklist handy and consulting CISO Compass by Todd Fitzgerald for reference.
Recap the module with an infosec assessment, one-on-one meetings, team dynamics, and a project snapshot, reviewing budget, metrics, and business risks to prevent a potential business-ending event.
Explore steering committee preparation, meetings with business leaders, and participation in InfoSec projects within the plan to act transition, aligning security efforts with business goals.
Conduct one-on-one meetings with business leaders to learn their top security concerns and how security supports their goals, while building relationships and identifying strategic gaps in enterprise-wide risks.
Show up and be visible in current infosec initiatives, listening and learning as a fly on the wall; take notes to build a prioritized, risk-based view for the big picture.
Outline steering committee preparation, engage with business leaders, and participate in information security projects, then complete a simple three-slide update for a hypothetical steering committee.
Define your vision and budget for the security program by reviewing the operational security budget, establishing your program, assessing the security team's skills, and beginning your information security assessment.
Review your second quarter budget and metrics by meeting your finance partner regularly, monitor spend, and tell the story of over or under budget to stay on course.
Craft a security vision aligned with your company's business objectives and define a concise mission statement of the team's purpose; share both with stakeholders for feedback.
Conduct a skills inventory by evaluating your team's strengths and development areas, documenting them in a private, guarded spreadsheet, and using findings to guide leadership development and possible role realignments.
Begin information security assessment by coordinating 10 to 12 one-hour interviews with key stakeholders, applying NIST, CSF, or CIS critical security controls, and managing a 60-hour, two-month process.
Review the operational security budget, define program vision and mission, assess the security team skills, and begin information security assessment with a hands-on exercise to draft vision and mission statements.
Explore the act phase’s charter and leadership module, covering writing or reviewing the information security charter, appointing team leaders, and enhancing visibility of active projects.
Draft an information security charter that defines objectives, roles and responsibilities, authority, and decision-making processes, establishing boundaries and accountability as the program's north star for guiding governance and scope.
Appoint leaders by assessing current leadership roles, moving aspiring leaders into spots that fit their desire, aptitude, and experience, and reclaiming roles for those who prefer individual contributor work.
Be present in the first 100 days of a CISO by attending project meetings, joining discussions, providing guidance, and voicing risks and recommendations as you move from assess to act.
Recap the information security charter, appoint team leaders, and increase visibility in active projects, then draft or edit a program charter with Graph AI and Sans Institute references.
Formalize your information security strategy and secure approval for your security charter. Engage the security steering committee or board and formalize a security awareness team during weeks 11–14.
Finalize the strategy by defining objectives and milestones from the information security assessment, then use the results to build a plan and set milestones across your program deliverables.
Steer co and board engagement requires scheduling regular steer co meetings with an executive assistant, owning the committee, and aligning updates for security risk reviews and training goals.
Coordinate with key stakeholders to approve the security charter, initiate via email with a 30-day deadline, and secure verbal sign-off while tracking changes if needed.
Form and lead the security awareness team to drive campaigns, phishing remediation, and communications, using psychology and content delivery to create awareness activities, guided by the Sands Security Awareness Framework.
Draft an outline of your security awareness plan, focusing on phishing avoidance and scams such as fake free pizza offers or overdue toll notices.
Welcome to the First 100 Days of a CISO! This course will walk you through the essential steps, real-world examples, and practical exercises to set you up for success.
Created and delivered by a 3-time CISO (Chief Information Security Officer and Chief Security Officer), with nearly twenty years working in Information Security and cybersecurity.
By the end of this course, you will have built your own CISO start-up playbook, through the exercises after each module. You’ll also have access to all the templates created and shared in the course files.
The course will be structured, with an initial introduction to the CISO role, and how it’s evolved, and the different CISO personas.
Then will walk through an approach to tackling your first 100 days on the job, actually going week-by-week, through the playbook. This will include the following:
Building your foundation
Conducting an initial assessment and holding 1:1s
Building alignment and gaining participation
Defining your vision and reviewing your budget
Creating a charter and leadership (engaging and delegating)
Strategy, steering committee, and Board of Directors engagement
Program delivery and communications
In this 100 day journey, you have the opportunity to establish your credibility and elevate the security reputation within the company.