The New CISO's First 90 Days: A Security Stack Checklist
A 12-week checklist for new CISOs reviewing an inherited security stack: inventory, framework coverage, overlap and board reporting, without breaking anything.
The New CISO's First 90 Days: A Security Stack Checklist
A practical checklist for reviewing an inherited security stack without breaking anything or waiting on a manual audit.
This covers one workstream of a new CISO's first 90 days: the stack itself. It runs alongside the stakeholder mapping and discovery work of the same period, and is no substitute for it. That work depends on relationships and context no checklist can provide.
Weeks 1 to 2: Get oriented without touching anything
List every security tool currently in production, including the ones that look inactive or forgotten
Identify who owns each tool today. Note where ownership is unclear or undocumented
Pull contracts and renewal dates for every tool, so nothing lapses or auto-renews by accident
Ask each owner what the tool does day to day, rather than what it was bought for
Flag any tool nobody can confidently explain
Weeks 3 to 4: Map coverage against frameworks
Map each tool's actual capabilities against the frameworks your organisation is accountable to, whether that is MITRE ATT&CK, NIST, or CIS Controls
Note where two or more tools cover the same capability
Note where a required capability has no tool covering it at all
Make no changes yet. This stage builds the picture everything later acts on
Weeks 5 to 6: Check overlap and recoverable spend
Compare licensing costs across tools with overlapping capabilities
Decide which overlapping tool is the stronger one to keep, based on coverage and integration rather than cost alone
Hold off cancelling anything until you have confirmed no hidden dependency exists elsewhere in the stack
Document the potential savings, even if you act on none of them yet. Boards respond to a number
Weeks 7 to 8: Check AI and shadow tool exposure
Ask department heads what AI tools their teams are using, formally or informally
Check whether existing security tools already control AI-related data flows before assuming a new tool is needed
Flag any tool or workflow where sensitive data may be leaving the organisation without oversight
If you find a gap, draft a lightweight interim policy rather than waiting for a full governance framework
Weeks 9 to 10: Identify quick, safe wins
Pick one or two changes that are low risk, clearly justified by the data you have gathered, and visible to the business
Avoid large-scale changes this early. Credibility is easier to spend once it has been earned
Brief your team before any change lands, and explain the reasoning as well as the decision
Weeks 11 to 12: Prepare for the board
Translate your findings into three things: coverage gaps, overlapping spend, and planned next steps
Lead with business impact. Keep the technical detail in reserve for questions
Bring the data. A board trusts a documented gap more than a described one
Set expectations for what happens next, so the first meeting is not mistaken for the finished plan
A note on timing
Most of the delay lives in weeks 3 to 4. Mapping capability against frameworks is the slowest part of any manual audit. Platforms like ESProfiler compress that step from weeks into minutes, which is often the difference between finishing this checklist inside 90 days or still working through it in month four.
If you would rather have it done for you, the Security Reality Baseline covers most of this checklist as a fixed-cost, fixed-time engagement, typically four to six weeks.
