Cyber Security Awareness Blog | The Security Company

First 90 Days as a CISO | Free eBook | TSC

Written by The Security Company | Jul 22, 2026 3:24:45 PM

Discover exactly how to make an impact as a new CISO and navigate your cyber security leadership transition.

How to make an impact in your first 90 days as a new CISO

Starting a new role as a Chief Information Security Officer (CISO) is a critical opportunity to assess cyber security risk, strengthen security culture, and align information security strategy with business objectives. This eBook explains how new CISOs can make an impact in their first 90 days by understanding the cyber threat landscape, assessing the organisation's cyber security posture, building stakeholder relationships, and prioritising high-risk areas.

It covers key areas including cyber security strategy, risk assessment, behavioural analysis, incident response planning, board engagement, manager masterclasses, security awareness training, and long-term security culture change. The guide also explores how CISOs can communicate cyber security risks to senior leaders, encourage employee participation, and use structured change models such as Kotter, ADKAR, and Prosci to drive meaningful behaviour change.

In this free eBook, you'll discover:

How to assess your organisation's cyber security posture in your first weeks
Building relationships with key stakeholders across IT, HR, legal and the board
Running a risk assessment and gap analysis to prioritise initiatives
Developing a security strategy aligned with your business objectives
Engaging the board and securing leadership buy-in
Communicating the importance of security culture organisation-wide
Using eLearning, games and animations for engaging, measurable training
Running post-implementation assessments to demonstrate effectiveness

Set yourself up for success as a new CISO

The Security Company helps CISOs strengthen cyber resilience through human risk management, security awareness training, executive engagement, and practical strategies that build lasting security cultures.

View the eBook Book an eLearning demo

First 90 days as a new CISO FAQ

What should a new CISO focus on in the first 90 days?

A new Chief Information Security Officer (CISO) should start by understanding the organisation's cyber security landscape, assessing its current security posture, identifying key risks, and aligning cyber security strategy with business objectives. The first 90 days should also focus on building relationships with the board, senior leaders, IT, legal, compliance, HR, and other stakeholders to create support for long-term security improvement.

How can a CISO assess cyber security posture effectively?

A CISO can assess cyber security posture by conducting a comprehensive risk assessment, reviewing existing security policies and procedures, performing a gap analysis, and using penetration testing or vulnerability assessments to identify weaknesses. This helps prioritise security initiatives, strengthen defences, and build a clear cyber security roadmap based on organisational risk.

Why is security culture important for a new CISO?

Security culture is critical because employees play a major role in protecting an organisation from cyber threats such as phishing, social engineering, data breaches, and human error. A new CISO should communicate the importance of security awareness, encourage open reporting, engage managers, and use behavioural analysis to understand employee attitudes and improve cyber security behaviours across the workforce.

Related pages

Human Risk Platform
Products & Services