Home About Experience Insights Projects First 90 Days Contact
← Back to Insights Writing

The New CISO's First 90 Days: Diagnose Before You Prescribe

Every new CISO gets the same well-meaning advice on day one: do a listening tour, build a risk register, write a strategy, land some quick wins. It's sound as far as it goes. But it misses the step that determines whether everything else works, and that gap is the reason so many promising security leaders stumble in their first year.

The missing step is diagnosis. Before you can decide what to do in your first 90 days, you have to work out what kind of situation you've actually walked into, because the playbook that suits one type of role will actively undermine you in another.

That idea isn't mine. It comes from Michael Watkins' The First 90 Days, which remains the best general-purpose transition book ever written, and which maps onto a CISO's first quarter almost uncannily well. Here's how I think about applying it.

The clock is already running

Watkins' central finding is that every new leader starts out as a net cost to the organisation and only later becomes a net contributor. He calls the point where that flips the breakeven point, and across his research it lands, on average, around the six-month mark. Everything in a good 90-day plan is really in service of one goal: pulling that point forward.

For a CISO, the clock is especially unforgiving. You inherit live risk on day one. Nobody pauses the threat landscape while you get your bearings, and an incident in week three doesn't care that your strategy isn't finished. So the plan has to do two things at once: build a considered, evidence-based programme, and put a minimum viable safety net under the organisation immediately. More on that below.

Diagnose first: the STARS model

This is the part most new leaders skip, and it's the part that matters most. Watkins argues that every transition falls into one (or more likely, a blend) of five situations, and he uses the acronym STARS:

  • Start-up: building something from nothing. No team, no strategy, no precedent.
  • Turnaround: a function that's visibly broken. A breach, a failed audit, an enforcement notice.
  • Accelerated growth: scaling controls at the pace the business is scaling headcount and markets.
  • Realignment: a function that used to be fine but has quietly drifted into irrelevance. No burning platform. Yet.
  • Sustaining success: inheriting something genuinely good, where the job is to protect it and find the next increment of value.

Here's why this matters so much for security specifically: the wrong diagnosis produces the wrong instinct at exactly the moment your instincts get the most scrutiny.

Walk into a Realignment situation (stale policies, shelfware tooling, a risk register nobody reads) and act as though it's a Turnaround, and you'll alienate people who genuinely believe things are fine. You'll come across as an alarmist who hasn't done their homework. But the realignment challenge is precisely the opposite problem: nobody thinks anything is wrong. Your job for the first 90 days is less about fixing controls and much more about building an evidence-based case that change is needed at all, via assessment findings, sector benchmarks, near-misses and threat trends. Denial, not deficiency, is the enemy.

Conversely, walk into a genuine Turnaround and treat it with Realignment-style caution (endless consultation, gentle evidence-building, consensus before action) and you'll be seen as timid at exactly the moment the organisation has given you a rare, real mandate for decisive change. Everyone already knows something's broken. That mandate has a shelf life. Use it.

The other trap is treating STARS as a single label for the whole role, when in practice most CISO jobs are a blend across dimensions. You might be doing a Start-up build on the team (there isn't one yet) inside an organisation that's really in Realignment on culture (nobody's convinced security needs the investment). Diagnose the team, the tooling, the governance and the culture separately. Each might sit in a different quadrant, and each needs its own matched approach.

Negotiate the terms before you're judged by them

Watkins' other big contribution is a simple discipline: don't wait to be told what success looks like. Go and negotiate it. He frames this as five ongoing conversations with your new boss (for most CISOs, that's a CIO, COO, CFO or CEO):

  1. Where are we, really? Align on the STARS diagnosis together, because disagreement here poisons everything downstream.
  2. What does good look like? At 30, 60, 90 days, and a year out. What would count as an early failure?
  3. What will you give me to do this? Budget, headcount and political air cover, tied explicitly to outcomes.
  4. How do you like to work? Communication style, cadence, how much you can decide alone versus what needs sign-off, and critically, what counts as a "no surprises" incident escalation.
  5. Where do I need to grow? Usually a later conversation, but naming your own gaps honestly (cloud depth, a new sector's regulatory landscape, financial modelling) tends to build credibility rather than spend it.

Most new CISOs get conversation two by accident and never have the other four on purpose. That's a mistake. Skipping the expectations conversation in particular is how you end up at day 90 discovering your boss was quietly measuring something you never agreed to.

What this looks like in practice

With the diagnosis and the expectations conversation as the backbone, the actual 90 days breaks into three overlapping phases.

Days 1 to 30: understand and baseline. This is Watkins' "accelerate your learning" imperative: treat learning as a deliberate, structured investment rather than something that happens by osmosis. One-to-ones with your line manager, peers, Legal, Data Protection, HR, Finance, internal audit, and whoever owns your organisation's most sensitive data or most critical process. Ask everyone the same three questions: what should security stop, start, and continue? Build your technical baseline in parallel: assets, architecture, controls, third parties, incident history. And put a minimum viable incident escalation arrangement in place immediately, even if it's a one-pager, because the plan has to survive being interrupted by a real event.

Days 31 to 60: design and align. Draft the strategy, but let its tone follow your STARS diagnosis: bold and corrective for a Turnaround, evidence-heavy and persuasive for a Realignment, protective and incremental for Sustaining Success. Propose an operating model. Quantify your top risks in a methodology that gives leadership decision-useful numbers rather than red-amber-green theatre. And do the unglamorous political work Watkins calls "creating alliances": map who needs to support your strategy at approval, and don't let the approval meeting be the first time they see it.

Days 61 to 90: deliver and demonstrate. Secure formal sign-off, on the back of alliances you built rather than a paper you sprang on people. Land one or two genuinely visible early wins, chosen deliberately, matched to what stakeholders told you mattered in month one, and delivered in a way that models the culture you want the function known for. Set up the standing governance rhythm: a first risk report to the board, an incident plan drafted or refreshed, third-party risk under way for key suppliers. And don't skip Watkins' last, quietest imperative: keep your own balance. A CISO who's burnt out by day 80 delivers none of the above.

The test that actually matters

Forget the frameworks for a second. At day 90, there's one question worth asking yourself: can you tell a credible, evidenced story (what I found, what I fixed, what's next) that your boss, your board, and your own team would all recognise as true?

If the answer's yes, you've pulled the breakeven point forward. If it's no, the problem usually traces back to the very start: not to a lack of effort in the delivery phase, but to skipping the diagnosis, or assuming everyone already agreed on what success meant. Worth getting right before you start building anything else.

Also published on Medium.

Read on Medium →