CISO Tribune

Analysis

The first 90 days: how a new CISO takes over a security organization

The standard playbook for a newly appointed CISO: what to assess, what to promise, what to ship, and the political mistakes that shorten tenures before they start.

By CISO Tribune Editorial · Published July 22, 2026 · 2 min read

TL;DR: New CISOs fail in the first year for political reasons more often than technical ones. The working playbook for the first 90 days: establish the true risk baseline, reset expectations with the board using that baseline, ship one visible fix, and defer the reorganization.

What does a new CISO need to learn in the first 30 days?

The gap between the stated program and the real one. Every security organization has an official narrative — the deck the previous CISO showed the board — and an operational reality visible in incident tickets, audit findings, and the backlog. The first month is spent measuring that gap: which controls exist on paper only, which risks were formally accepted and by whom, and which parts of the estate nobody currently owns. The output is a private baseline the new CISO trusts.

What should a new CISO promise the board?

Less than the board wants to hear. The credible move in the first quarter is to present the baseline honestly — including the gap between what was previously reported and what the new CISO found — and commit to a small number of measurable improvements with dates. Every experienced board has watched a security leader promise a transformed program in a year; the ones who over-promise inherit their predecessor's narrative and own it when it breaks.

What should actually ship in the first 90 days?

One visible, finishable thing. Common choices: closing a known audit finding that has embarrassed the company repeatedly, fixing the incident-response escalation path and proving it with an exercise, or getting an accurate asset inventory for the crown-jewel systems. The point is organizational: the security program demonstrates it can finish something, which buys the authority to start bigger work.

What are the mistakes that shorten a CISO's tenure early?

Three recur. Reorganizing before understanding who holds the institutional knowledge. Fighting the reporting-line battle publicly before building allies — the structure fight is winnable, but only from a position of delivered credibility. And accepting the inherited risk register without re-validating it, which means owning surprises that were someone else's judgment calls. The pattern across all three: the first 90 days are governance work wearing an engineering costume.

Frequently asked questions

What should a new CISO do first?
Establish the real risk picture before making promises: inventory crown-jewel systems, review recent incidents and audit findings, meet the executives who own the risk, and validate what the board was last told about the program — which often differs from reality on the ground.
When should a new CISO reorganize the security team?
Rarely in the first quarter. Early reorganizations spend political capital before the CISO knows which people carry the institutional knowledge. Most experienced operators assess through one full incident or audit cycle before restructuring.

CISO Tribune Editorial

Editorial Desk

The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.