ciso.diy
CISO 90-Day Onboarding Workbook preview
Governance CISO onboardingnew CISO90-day planvCISO

CISO 90-Day Onboarding Workbook

The 12-tab assessment workbook for a CISO joining a company — stakeholder mapping, a deep program gap assessment against the frameworks that organization cares about, quick-win tracker, board briefing builder, and the 30/60/90-day milestone framework. For the employed CISO who needs the analysis in depth; if you are arriving fractionally, on an interim basis, or into a seat nobody has held before, start with The First 100 Days Kit.

What this actually gives you

  • Most new CISOs spend their first 90 days in reactive mode — firefighting, attending every meeting, and producing a board deck that reflects no real analysis.
  • The 5 questions every new CISO should answer in the first 30 days before making any commitments.
  • A structured program gap analysis against the frameworks the organisation actually cares about, plus risk register initialisation and quick-win identification.
  • If you are arriving fractionally, on an interim basis, or into a seat nobody has held before, The First 100 Days Kit is the better starting point — this is the depth tool for a CISO joining a company.

Most new CISOs spend their first 90 days in reactive mode — firefighting, attending every meeting, and producing a board deck that doesn't reflect any real analysis. This workbook structures the first 90 days into a defensible program assessment and stakeholder alignment process.

Built for the CISO joining a new organization who needs the programme analysis done properly — the depth is the point, and the 12 tabs are where it lives.

If you are arriving another way, The First 100 Days Kit is the better starting point: it carries four entry modes, the day-1 continuity checklist for a seat that was left empty, and the role charter and fractional engagement letter. Practitioners running client engagements often want both — this workbook for the assessment, that kit for the sprint and the paperwork.

Workbook structure:

30-Day Foundation — stakeholder mapping (technical, business, board), existing program inventory, critical asset identification, and the 5 questions every new CISO should answer in the first 30 days before making any commitments.

60-Day Assessment — structured program gap analysis against the frameworks the organization cares about, risk register initialization, quick-win identification (high-visibility / low-effort), and first board or executive briefing preparation.

90-Day Strategy — 12-month roadmap draft, budget ask framework, team assessment, vendor landscape review, and the board presentation that establishes credibility for the program.

Stakeholder Map — tracks all security-relevant relationships: CTO/CIO, Legal/GC, CFO, HR, Business Units, Board Audit Committee, external auditors, key vendors. Includes communication cadence tracker and influence/interest matrix.

Quick-Win Tracker — 20 pre-seeded high-visibility security improvements that can be completed in the first 90 days with existing resources. Each with effort estimate, visibility rating, and risk reduction impact.

Board Briefing Builder — structured output template that auto-populates from the assessment tabs. Produces a first-90-days brief suitable for Audit Committee or full Board presentation.

User Guide covers the 5 most common new-CISO mistakes, how to navigate the inherited-debt conversation with leadership, the vCISO-specific onboarding variations, and how to use the 90-day output to establish budget credibility.

What's included

  • Excel (.xlsx) — fully editable
  • Word (.docx) — User Guide — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-04-23
Workbook tabs 12