---
title: First 90 Days as a CISO | Free eBook | TSC
description: Practical guidance for new CISOs on making an impact in their first 90 days, from risk assessment to security culture.
image: https://thesecuritycompany.com/hubfs/guide-to-first-90-days-as-CISO.webp
---

[Skip to content](https://thesecuritycompany.com/blog/90-days-as-a-new-ciso-ebook#main-content)

[![TSC Logo large](https://thesecuritycompany.com/hs-fs/hubfs/TSC%20Logo%20large.png?width=95&height=78&name=TSC%20Logo%20large.png)](https://thesecuritycompany.com/)

- [Human Risk Platform](https://thesecuritycompany.com/tscs-human-risk-management-platform)
- [Products & Services](https://thesecuritycompany.com/productsandservices)
- [Success Stories](https://thesecuritycompany.com/success-stories)
- [Resources](https://thesecuritycompany.com/our-resources)
- [Blog](https://thesecuritycompany.com/blog)

[Book a demo](https://thesecuritycompany.com/contact-us)

![Search icon](https://5018647.fs1.hubspotusercontent-na1.net/hubfs/5018647/Design/Icons/Font%20Awesome/search.svg)

[Book a demo](https://thesecuritycompany.com/contact-us)

[All posts](https://thesecuritycompany.com/blog/all)

 July 22, 2026

# How to make an impact in your first 90 days as a new CISO

    The Security Company  ·   2 minute read

![Presenter standing beside a security awareness display with breach statistics, representing CISO priorities, employee cyber security training, phishing awareness and incident response.](https://thesecuritycompany.com/hs-fs/hubfs/guide-to-first-90-days-as-CISO.webp?width=1920&height=1080&name=guide-to-first-90-days-as-CISO.webp)

Discover exactly how to make an impact as a new CISO and navigate your cyber security leadership transition.

## How to make an impact in your first 90 days as a new CISO

Starting a new role as a Chief Information Security Officer (CISO) is a critical opportunity to assess cyber security risk, strengthen security culture, and align information security strategy with business objectives. This eBook explains how new CISOs can make an impact in their first 90 days by understanding the cyber threat landscape, assessing the organisation's cyber security posture, building stakeholder relationships, and prioritising high-risk areas.

It covers key areas including cyber security strategy, risk assessment, behavioural analysis, incident response planning, board engagement, manager masterclasses, security awareness training, and long-term security culture change. The guide also explores how CISOs can communicate cyber security risks to senior leaders, encourage employee participation, and use structured change models such as Kotter, ADKAR, and Prosci to drive meaningful behaviour change.

**In this free eBook, you'll discover:**

How to assess your organisation's cyber security posture in your first weeks

Building relationships with key stakeholders across IT, HR, legal and the board

Running a risk assessment and gap analysis to prioritise initiatives

Developing a security strategy aligned with your business objectives

Engaging the board and securing leadership buy-in

Communicating the importance of security culture organisation-wide

Using eLearning, games and animations for engaging, measurable training

Running post-implementation assessments to demonstrate effectiveness

---

### Set yourself up for success as a new CISO

TSC helps CISOs strengthen cyber resilience through human risk management, security awareness training, executive engagement, and practical strategies that build lasting security cultures.

[View eBook](https://thesecuritycompany.com/hubfs/TSC-and-the-NIS2-Directive.pdf) [Book a demo](https://thesecuritycompany.com/contact-us)

---

## First 90 days as a new CISO FAQ

### What should a new CISO focus on in the first 90 days?

A new Chief Information Security Officer (CISO) should start by understanding the organisation's cyber security landscape, assessing its current security posture, identifying key risks, and aligning cyber security strategy with business objectives. The first 90 days should also focus on building relationships with the board, senior leaders, IT, legal, compliance, HR, and other stakeholders to create support for long-term security improvement.

### How can a CISO assess cyber security posture effectively?

A CISO can assess cyber security posture by conducting a comprehensive risk assessment, reviewing existing security policies and procedures, performing a gap analysis, and using penetration testing or vulnerability assessments to identify weaknesses. This helps prioritise security initiatives, strengthen defences, and build a clear cyber security roadmap based on organisational risk.

### Why is security culture important for a new CISO?

Security culture is critical because employees play a major role in protecting an organisation from cyber threats such as phishing, social engineering, data breaches, and human error. A new CISO should communicate the importance of security awareness, encourage open reporting, engage managers, and use behavioural analysis to understand employee attitudes and improve cyber security behaviours across the workforce.

---

## Related pages

[Human Risk Platform](https://thesecuritycompany.com/tscs-human-risk-management-platform)  
[Products & Services](https://thesecuritycompany.com/productsandservices)

## Related posts

[![Profile of a person with digital data graphics overlaid, representing cyber security culture, behaviour change and organisational security awareness.](https://thesecuritycompany.com/hubfs/cyber-culture-guide-ebook.webp)](https://thesecuritycompany.com/blog/cyber-security-culture-blocks-ebook)

[eBOOK](https://thesecuritycompany.com/blog/tag/ebook)

### [How to beat the cyber security culture blocks](https://thesecuritycompany.com/blog/cyber-security-culture-blocks-ebook)

[![Pharmaceutical professional reviewing stock in a medical storage area with a tablet, representing cyber security risks in the pharmaceutical industry.](https://thesecuritycompany.com/hubfs/cyber-security-in-the-pharma-industry-report.webp)](https://thesecuritycompany.com/blog/cyber-security-pharmaceutical-industry-report)

[REPORT](https://thesecuritycompany.com/blog/tag/report)

### [Cyber security in the pharmaceutical industry](https://thesecuritycompany.com/blog/cyber-security-pharmaceutical-industry-report)

[![](https://thesecuritycompany.com/hubfs/Employee%20Engagement.webp)](https://thesecuritycompany.com/blog/5-reasons-why-your-employee-engagement-campaign-failed)

[ARTICLE](https://thesecuritycompany.com/blog/tag/article)

### [5 Reasons why your employee engagement campaign failed](https://thesecuritycompany.com/blog/5-reasons-why-your-employee-engagement-campaign-failed)

<https://thesecuritycompany.com/cyber-security-insights>

![](https://thesecuritycompany.com/hs-fs/hubfs/bug.webp?width=80&height=80&name=bug.webp) ![](https://thesecuritycompany.com/hs-fs/hubfs/bug_white.webp?width=80&height=80&name=bug_white.webp)

 Go further with emerging threat intelligence, expert analysis and guidance

[![TSC White Logo large](https://thesecuritycompany.com/hs-fs/hubfs/TSC%20White%20Logo%20large.webp?width=100&height=82&name=TSC%20White%20Logo%20large.webp "TSC White Logo large")](https://thesecuritycompany.com/)

**©** The Security Company (International) Limited 2026  
Office One, 1 Coldbath Square, London, EC1R 5HL, UK  
Company registration No: 03703393  
VAT No: 385 8337 51

[linkedin-in icon](https://uk.linkedin.com/company/thesecurityco)

[Home](https://thesecuritycompany.com)

[Human Risk Platform](https://thesecuritycompany.com/tscs-human-risk-management-platform)

**[Products & Services](https://thesecuritycompany.com/productsandservices)**  
[Contact us](https://thesecuritycompany.com/contact-us)

[Privacy &](https://thesecuritycompany.com/tsc-policies)[Cookie Policies](https://thesecuritycompany.com/tsc-policies)

[Terms & Conditions](https://thesecuritycompany.com/tsc-policies)

**Resources**

- [eBooks](https://thesecuritycompany.com/our-resources)
- [Reports & Whitepapers](https://thesecuritycompany.com/our-resources)
- [Cyber Security Calendar](https://thesecuritycompany.com/blog/security-awareness-calendar)
- [Webinars](https://thesecuritycompany.com/our-resources)
- [Blog](https://thesecuritycompany.com/blog)

Copyright © 2026, The Security Company Ltd

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "The Security Company",
    "url" : "https://thesecuritycompany.com/blog/author/the-security-company"
  },
  "dateModified" : "2026-07-30T19:04:36.020Z",
  "datePublished" : "2026-07-22T15:24:45.000Z",
  "headline" : "First 90 Days as a CISO | Free eBook | TSC",
  "image" : [ "https://thesecuritycompany.com/hubfs/guide-to-first-90-days-as-CISO.webp" ],
  "mainEntityOfPage" : {
    "@id" : "https://thesecuritycompany.com/blog/90-days-as-a-new-ciso-ebook",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://thesecuritycompany.com/hubfs/TSC%20Logo%20large.png"
    },
    "name" : "The Security Company"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://thesecuritycompany.com/#organization",
  "@type" : "Organization",
  "description" : "Cyber security awareness training and human risk management for businesses of every size.",
  "logo" : "https://thesecuritycompany.com/hs-fs/hubfs/TSC%20Logo%20large.png?width=190&height=156&name=TSC%20Logo%20large.png",
  "name" : "The Security Company",
  "sameAs" : [ "https://www.linkedin.com/company/thesecurityco/", "https://www.youtube.com/@thesecurityco", "https://vimeo.com/user31176192", "https://thecpdregister.com/providers/cpd-group-providers--790118", "https://ico.org.uk/ESDWebPages/Entry/Z4812822", "https://find-and-update.company-information.service.gov.uk/company/03703393", "https://registry.blockmarktech.com/certificates/19d457f5-bf79-4f85-8f6e-dd2db181ff76/", "https://www.gartner.com/reviews/product/the-security-company-security-awareness-training" ],
  "url" : "https://thesecuritycompany.com/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://thesecuritycompany.com/#website",
  "@type" : "WebSite",
  "name" : "The Security Company",
  "publisher" : {
    "@id" : "https://thesecuritycompany.com/#organization"
  },
  "url" : "https://thesecuritycompany.com/"
}
```