Your First 90 Days as a CISO
The instinct when you take a CISO seat is to start fixing things immediately. Resist it. The fastest way to fail in a new security-leadership role is to show up with a checklist from your last job and start swinging — because the checklist that made you successful somewhere else was shaped by that company’s specific politics, tech, and history, none of which followed you through the door. The first ninety days aren’t for fixing. They’re for learning what’s actually load-bearing, so that when you do start changing things, you change the right ones.
First 30: listen more than you talk
Meet everyone — and not just the security team. The engineers who’ll roll their eyes at your controls. The sales leaders who see security as a deal-blocker. The finance person who signs off on your budget. The support reps who know exactly which ugly workaround the whole business quietly depends on. Each of them holds a piece of the real map, and none of them will hand it over if you walk in acting like you already know it. My first month is mostly asking “why is it done this way?” and then shutting up long enough to actually hear the answer.
And the answer matters, because half the things that look broken to a new CISO are broken for a reason. That baffling exception, that control everyone routes around, that risk nobody’s fixed — often there’s a story: a past incident, a business constraint, a fight someone already lost. If you kill it on day three without knowing the story, you either recreate the original problem or you burn a relationship you needed. Listening first isn’t politeness. It’s how you avoid confidently fixing things that weren’t actually broken.
Take the real inventory while you listen
Alongside the conversations, I’m building an honest picture of what actually exists — not the architecture diagram, the reality. What data do we hold and where does it really live? What’s internet-facing that shouldn’t be? Who has access to what, and how much of it is stale? Almost every environment I’ve walked into had a gap between the official story and the ground truth, and the size of that gap is itself one of the most useful things you learn in month one. You can’t prioritize risk you haven’t actually seen, and the org chart won’t show it to you — the systems will.
Days 30–60: find the fires that are actually burning
Every environment has a hundred problems and the budget to fix maybe five this year. The skill — the entire skill — is telling the difference between what’s genuinely on fire and what’s just ugly. Ugly offends your professional taste. On fire ends careers. I hunt for the risks that are both likely and expensive: the exposures an attacker could actually reach, that sit on top of something the business genuinely can’t afford to lose. Those go to the top. The rest — the messy-but-contained, the theoretically-bad-but-unreachable — I let sit, no matter how much the mess offends me, because spending your first quarter’s capital on tidiness is how you arrive at the real fire with an empty tank.
Don’t confuse activity with priority
There’s a trap in this phase: the loudest problem is rarely the biggest one. The thing generating the most complaints, the most tickets, the most hallway grumbling, is usually loud precisely because it’s visible — and the risks that actually keep me up are often the quiet ones nobody’s complaining about because nobody can see them. Part of prioritizing is having the spine to tell a room full of people that the thing annoying them most this week is not the thing I’m fixing first, and to explain why in language they’ll accept. That’s uncomfortable, and it’s the job.
Days 60–90: ship one visible win
Credibility is currency, and you earn it by delivering something real before your first quarter closes. Not a strategy deck — an actual outcome people can feel. Something that closes a risk that mattered, or removes a piece of friction the business hated, ideally both. That first win is what buys the trust to do the slow, unglamorous work that fills year one, the work that has no visible payoff for months. Pick it carefully: big enough to matter, small enough to actually finish on time, and legible enough that people outside security understand what changed.
And then make sure everyone knows it happened — not to take a victory lap, but because a security team that ships visible wins gets treated very differently than one that only ever shows up with warnings and asks. The story you establish in the first ninety days — are you the person who says no, or the person who makes hard things possible — is the story you’ll be living with for years. Spend that first quarter earning the right version of it.
None of this is as satisfying as walking in and fixing everything you can see. But I’ve watched too many talented security leaders flame out in six months because they mistook motion for progress — swinging hard, breaking things, spending their credibility before they understood what it was for. Listen, prioritize, ship one real win. Do the first ninety days with that discipline and you’ll have earned something no title grants you on day one: the room’s permission to actually lead.