New: ESProfiler Services. Expert consultancy, augmented by AI.
ESPROFILER IconESPROFILER
Capability ExchangeCapability Exchange
Platform
How it worksHow you onboardHow you operate
Services
All ServicesSecurity Reality BaselineSecurity Consolidation Baseline
Use Cases
All
Resources
AllArticlesWebinarsEvents & ConferencesProduct Releases
AboutCareersStatus
Log InBook Demo
Back to all posts
2026-07-21
Articles

The New CISO's First 90 Days: A Security Stack Checklist

A 12-week checklist for new CISOs reviewing an inherited security stack: inventory, framework coverage, overlap and board reporting, without breaking anything.

The New CISO's First 90 Days: A Security Stack Checklist

A practical checklist for reviewing an inherited security stack without breaking anything or waiting on a manual audit.

This covers one workstream of a new CISO's first 90 days: the stack itself. It runs alongside the stakeholder mapping and discovery work of the same period, and is no substitute for it. That work depends on relationships and context no checklist can provide.

Weeks 1 to 2: Get oriented without touching anything

  • List every security tool currently in production, including the ones that look inactive or forgotten

  • Identify who owns each tool today. Note where ownership is unclear or undocumented

  • Pull contracts and renewal dates for every tool, so nothing lapses or auto-renews by accident

  • Ask each owner what the tool does day to day, rather than what it was bought for

  • Flag any tool nobody can confidently explain

Weeks 3 to 4: Map coverage against frameworks

  • Map each tool's actual capabilities against the frameworks your organisation is accountable to, whether that is MITRE ATT&CK, NIST, or CIS Controls

  • Note where two or more tools cover the same capability

  • Note where a required capability has no tool covering it at all

  • Make no changes yet. This stage builds the picture everything later acts on

Weeks 5 to 6: Check overlap and recoverable spend

  • Compare licensing costs across tools with overlapping capabilities

  • Decide which overlapping tool is the stronger one to keep, based on coverage and integration rather than cost alone

  • Hold off cancelling anything until you have confirmed no hidden dependency exists elsewhere in the stack

  • Document the potential savings, even if you act on none of them yet. Boards respond to a number

Weeks 7 to 8: Check AI and shadow tool exposure

  • Ask department heads what AI tools their teams are using, formally or informally

  • Check whether existing security tools already control AI-related data flows before assuming a new tool is needed

  • Flag any tool or workflow where sensitive data may be leaving the organisation without oversight

  • If you find a gap, draft a lightweight interim policy rather than waiting for a full governance framework

Weeks 9 to 10: Identify quick, safe wins

  • Pick one or two changes that are low risk, clearly justified by the data you have gathered, and visible to the business

  • Avoid large-scale changes this early. Credibility is easier to spend once it has been earned

  • Brief your team before any change lands, and explain the reasoning as well as the decision

Weeks 11 to 12: Prepare for the board

  • Translate your findings into three things: coverage gaps, overlapping spend, and planned next steps

  • Lead with business impact. Keep the technical detail in reserve for questions

  • Bring the data. A board trusts a documented gap more than a described one

  • Set expectations for what happens next, so the first meeting is not mistaken for the finished plan

A note on timing

Most of the delay lives in weeks 3 to 4. Mapping capability against frameworks is the slowest part of any manual audit. Platforms like ESProfiler compress that step from weeks into minutes, which is often the difference between finishing this checklist inside 90 days or still working through it in month four.

If you would rather have it done for you, the Security Reality Baseline covers most of this checklist as a fixed-cost, fixed-time engagement, typically four to six weeks.

Ready to Optimize
Your Security Stack?

Talk to our team to see how ESPROFILER can help you gain full visibility and control over your security investments.

Book a Demo

Platform

  • Market Layer
  • Capability Layer
  • Commercial Layer
  • Tribal Layer
  • Architect Layer

Services

  • All Services
  • Security Reality Baseline
  • Security Consolidation Baseline

Company

  • About Us
  • Jobs
  • Resources
  • Changelog
  • Contact
ESPROFILER IconESPROFILERNCSC For Startups AlumniSupported By GoogletechUK Winner
© 2026 ESPROFILER. All rights reserved.
Policies & Terms