ciso.diy
The First 100 Days Kit preview
Governance new CISOfirst 100 daysvCISOfractional CISO

The First 100 Days Kit

New seat, empty seat, or fractional seat — the hundred days that decide your tenure. Four entry modes auto-filter a 34-task plan, a 14-domain baseline including AI governance and personal liability, a budget builder in percent of revenue and IT, and the role charter and fractional engagement letter with a no-certification-without-verification clause.

What this actually gives you

  • Average CISO tenure is under four years and roughly a third of seats change hands in any year, which makes “the last one left” the modal way a security leader arrives, not an edge case.
  • Four entry modes, one plan. The 34-task plan auto-filters by the mode you set — an interim sees continuity tasks first, a fractional sees the engagement-letter and retainer tasks, a first-ever leader gets governance basics front-loaded.
  • Both the charter and the engagement letter carry a no-certification-without-verification clause: where a regulator makes a named person certify, that signature is personal, and a fractional CISO can be asked to sign for controls they were never given access to verify.
  • AI governance and personal liability are baseline domains in their own right — 14 domains scored 0–4, with an AI-inventory task in week two.

Average CISO tenure is under four years, and roughly a third of the seats change hands in any given year — which makes "the last one left" the modal way a security leader arrives, not an edge case. Three quarters now report worrying about personal liability, and nearly all of them own AI governance without a budget line for it.

Four entry modes, one plan. That is the design choice that makes this work. A new FTE CISO, a fractional or vCISO starting an engagement, an interim who inherited an empty seat, and the first security leader a company has ever had are doing overlapping but genuinely different first hundred days — so the 34-task plan auto-filters by the mode you set, while the interviews, the baseline and the board report stay shared.

Set the mode and the interim sees continuity tasks first; the fractional sees the engagement-letter and retainer-conversion tasks; the first-ever leader gets governance basics front-loaded. One kit, not four, and no task list padded with work that does not apply to you.

01 First 100 Days Plan & Tracker (XLSX, 7 sheets) — setup and mode; the 34-task plan across three phases with progress and behind counters; a 14-domain program baseline scored 0–4, including AI governance and insurance/liability as domains in their own right; quick wins with before, after and evidence; a budget builder giving floor, standard and target as a percentage of revenue and of IT spend; a 19-item obligations calendar; and stakeholders.

02 Day-1 Continuity Checklist (DOCX) — 26 checks across access, open items, obligations, evidence and people, for the seat that was empty when you got there, plus the day-3 note template. If the predecessor left badly, this is the first file to open.

03 Stakeholder Interview Guides (DOCX) — CEO, CFO, GC, CIO/IT, board chair, business-unit heads, HR, the MSP and the predecessor. Questions paired with what to listen for.

05 Role Charter & Fractional Engagement Letter (DOCX) — the two instruments that decide what happens when something goes wrong. (A) the charter: scope, decision rights, reporting line, protections. (B) the vCISO engagement letter: services, authority, certifications, liability, incidents and term, with Schedule 1 deliverables and a Schedule 2 authority matrix.

Both carry a no-certification-without-verification clause, and it is there for a specific 2026 reason: where a regulator makes a named person certify — NYDFS Part 500, an SEC filing — that signature is personal and a false certification is its own violation. A fractional CISO can be asked to sign for controls they were never given the access to verify. The clause is how you decline in advance rather than in the moment.

06 Day-100 Board Report (PPTX) — four slides: what I found, what I fixed, the risks and the plan, and what I need, with three budget options and three decisions requested.

07 Guide — The First 100 Days (PDF) — the seat as it exists in 2026, the four modes, what to do before day 1, the three phases, the four mandates including AI governance, inherited obligations, personal liability, the fractional specifics, what to do when the predecessor left badly, the day-100 report, the failure patterns and an FAQ.

File 05 wants a lawyer. The liability clauses (§A.6) and the certification clauses (§B.4) are the most valuable language in the kit and the most consequential. They are starting points for counsel to adapt in your jurisdiction, not executable agreements.

Where this sits. The CISO 90-Day Onboarding Workbook is the 12-tab assessment machinery for working the programme gap in depth. This kit is the mode-aware sprint plan and the engagement instruments around it — the charter, the letter and the day-100 board report. Practitioners running client engagements usually want both.

Pairs with Pillar 06, the operating model this sprint converts into; with the Cyber Insurance Application Readiness Kit as the fastest honest technical baseline in week two; and with I've Been Breached, because the tabletop in your first hundred days should use the thing you would actually reach for.

Adapt it to your mandate. Counsel finalises the charter and the letter.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-03
Pages 6