CISO_PREP

The 90-Day CISO Plan: Worked Example

Every section of the template filled in end-to-end, so you can see what "good" looks like before you adapt it.

Part of the CISO Interview Template Pack · cisoprep.com


About this example

Northwind Commerce is a fictional company, invented for this document. Every fact below was constructed for illustration. Do not cite any of it as real.

The profile: a mid-market e-commerce platform, roughly $800M revenue, full PCI-DSS scope, a SOC 2 Type II completed six months ago with findings, a team of 14 inherited after the previous security leader left for a larger company, cyber insurance renewing in 5 months, a quarterly audit committee.

Every entry below traces back to one of those facts. That internal consistency is the whole game: a panel can smell generic best practices, but cannot argue with a plan where every line answers something specific about their business.

Why this works: Northwind has visible, datable pressure (renewal in 5 months, findings aging, quarterly committee). Deadlines you inherit are more persuasive than priorities you invent. For a real company, hunt for the inherited clocks first.


Company snapshot

Field Entry
Company, stage, revenue model Northwind Commerce. Mid-market e-commerce platform, ~$800M revenue. Merchants sell through the platform; Northwind takes a cut of every processed payment plus subscription fees. Revenue stops when checkout stops.
The 2–3 things security must protect (1) The payment flow: revenue engine and PCI scope. (2) Checkout uptime: an hour down is measurable lost revenue, worst in Q4. (3) The customer and merchant data platform: 40M records; a breach here is a churn event, not just a fine.
Regulatory and contractual drivers PCI-DSS Level 1 (annual ROC). SOC 2 Type II with 3 open findings. Insurance renewal in 5 months; the carrier will ask about the same controls the SOC 2 flagged. State privacy laws. Security addenda with the top 20 enterprise merchants.
Known history No public breach. SOC 2 findings: incomplete production access reviews, no tested disaster recovery for the order database, logging gaps in the payment stack. Previous security leader left after 3 years; team of 14 inherited intact but unled for 4 months.
My operating assumptions from the outside (1) The SOC 2 findings are unremediated or partial, and the clock is running. (2) The renewal will be harder than last year and the CFO doesn't know that yet. (3) The team is competent but demoralized; at least one strong person is a flight risk. (4) Engineering ships fast and sees security as a gate. (5) The crown jewel is the payment flow, but the biggest unmanaged risk is the data platform: everyone watches what makes money, nobody watches what stores it.

Why this works: Every assumption is falsifiable. "Security is probably underfunded" is filler. "The renewal will be harder and the CFO doesn't know yet" is a claim you can be wrong about, which is exactly what makes it credible.


Phase 1 (Days 1–30): Listen and assess

Goal: understand the business, the risk, and the politics before changing anything. Anti-goal: announcing a strategy, reorganizing the team, buying anything.

The 11 conversations, with what each one produced

# Who Question asked What was learned
1 CEO "What would make you consider security a failure two years from now?" Two answers, unprompted: a breach that makes enterprise merchants leave, and "security becoming the reason we ship slower than competitors." He cited a rival's breach and the defections that followed. Uptime never came up; he assumes it.
2 CFO "How has security spend been planned historically, and what was the last ask you declined?" Security is a line inside the IT budget, flat for 3 years. She declined a $400K "platform consolidation" ask because it had no definition of done. She raised the renewal herself: premiums up 30 to 40 percent, carrier wants evidence on MFA, backups, and logging.
3 General Counsel "Where are we exposed today that keeps you up at night, and how do we handle privilege in incidents?" The top-20 merchant addenda promise 48-hour breach notification and annual pen tests; he can't prove either is operationally true. No privilege protocol for incidents; the last tabletop was 2 years ago, without legal.
4 Audit committee chair "What do you want from my reporting that you weren't getting?" Trend, not snapshot: "Every quarter I got a new dashboard with new metrics and no way to tell if we were getting better." She personally committed to the full board that the SOC 2 findings would close within the year.
5 Head of Engineering "Where does security help or hurt your velocity today?" A manual review adds 5 to 8 days to any release touching the payment stack, through a ticket queue with one reviewer. Engineers route around it by batching changes, which makes each review bigger and riskier.
6 Head of Product "What's on the roadmap that should scare me?" A Q4 launch of stored payment credentials for one-click checkout (a significant PCI scope expansion), and an AI merchant-analytics feature training on transaction data with no governance review. Both committed externally.
7 Head of People "What does the exit-interview data say about my team?" Two departures during the leaderless gap, both citing "no growth path." Comp is below the 50th percentile. The interim manager (the GRC lead) is respected but exhausted and didn't want the role.
8 Chief Revenue Officer "What do customers and prospects actually ask about security?" Enterprise deals stall on security questionnaires, which sales answers ad hoc, sometimes optimistically. Two pipeline deals are blocked pending SOC 2 evidence. Prospects already ask about the AI feature's data handling.
9 Inherited team leads (1:1s) "What did the last leader protect you from, and what could they never get funded?" He absorbed exec escalations personally, which is why nothing is written down. The unfunded ask: payment-stack log aggregation (the same SOC 2 gap) and a second reviewer. The detection engineer is interviewing elsewhere.
10 IT leader "What do you own that I'm accountable for?" More than expected: backups, identity, and endpoints all sit in IT. Backups run nightly but a restore of the order database has never been tested. MFA covers corporate SSO but not three legacy admin paths into production.
11 Previous CISO (reachable) "What would you have done differently, and what could you never get funded?" "I'd have fixed access reviews in year one; it poisoned every audit." Never funded: payment-stack logging, asked twice, framed as compliance both times, declined both times. Parting advice: "The CFO funds things with definitions of done."

Why this works: The answers disagree with each other, which is what real organizations do. A plan that discovers tension is believable; one where every stakeholder endorses the CISO's agenda is fiction. Conversation 11's "declined twice, framed as compliance" is the most useful sentence in the phase: it tells you how NOT to ask.

Phase 1 outputs (the gate to Phase 2)

Stakeholder worry map (verbatim worries)

Stakeholder Stated worry, their words
CEO "A breach that makes enterprise merchants leave" / "security becoming why we ship slower"
CFO "The insurance renewal, and asks with no definition of done"
GC "We've promised 48-hour notification and annual pen tests, and I can't prove either"
Audit chair "No trend. And I told the board the findings would close this year"
Eng "The 5-to-8-day payment review queue"
Product "Nothing scares me" (which is itself the finding)
CRO "Deals stalling on security questionnaires"
Team "No growth path, and nobody ever funded the logging"

Crown-jewel inventory (what actually matters)

  1. Payment processing flow (revenue engine, PCI scope, expanding in Q4)
  2. Order database and customer data platform (40M records; restore never tested)
  3. Checkout availability (direct revenue linkage, Q4 concentration)
  4. Merchant financial data (contractual addenda, churn risk on breach)
  5. Production identity paths (three legacy admin routes without MFA: connective tissue for everything above)

Inherited-commitments list

Team assessment

14 people: 5 security engineering, 3 detection and response, 3 GRC, 2 application security, 1 vendor risk. Capability is real; the GRC lead held the function together unled. Gaps: single-threaded appsec review, no leadership layer, comp below market, detection engineer interviewing. No reorg needed; the problem is leadership and funding, not design.

Draft risk list (unranked; ranking is Phase 2 work)

  1. Untested restore of the order database
  2. Three legacy admin paths into production without MFA
  3. Payment-stack logging gaps (SOC 2 finding, insurance question, detection blind spot)
  4. Incomplete production access reviews (SOC 2 finding)
  5. 48-hour notification promise with no rehearsed incident process
  6. Q4 stored-credential launch expanding PCI scope without security design input
  7. AI analytics feature training on transaction data, no governance review
  8. Single-threaded payment review queue driving batching in engineering
  9. Detection engineer flight risk in a 3-person detection team
  10. Ad hoc, occasionally optimistic questionnaire answers going to enterprise prospects

Why this works: The draft list includes a people risk (#9) and a truth-telling risk (#10), which most inherited registers omit because they are politically awkward. Listing them before anything goes upward keeps Phase 2 honest.


Phase 2 (Days 31–60): Prioritize and align

Goal: turn findings into a risk-ranked view the executive team agrees with. Anti-goal: a 40-page assessment nobody reads.

The ranked risk list, in business-impact language

Rank Risk Business impact statement
1 Untested restore of the order database If the order database is corrupted or ransomed, we don't know whether we can restore it or how long it takes. In Q4, each day of checkout downtime is roughly $3M. Also the carrier's first question.
2 Legacy admin paths without MFA Three unguarded doors into production. One phished credential ends in risk #1's worst case. A "no" on this carrier item moves the premium.
3 Payment-stack logging gaps If the payment flow is compromised today, we may not detect it and could not reconstruct it for the 48-hour notification. One gap, three exposures: detection, contract, SOC 2 finding.
4 Unrehearsed incident process vs. the 48-hour promise We contractually promised a notification speed we've never rehearsed. A mishandled first incident becomes a churn event on top of a breach.
5 Stored-credential launch without security design input Fine if designed in now; expensive and public if retrofitted after PCI fieldwork. The deadline is external and immovable.
6 Incomplete production access reviews The audit chair personally committed closure to the board. Aging findings compound: next year's report, the carrier, and enterprise questionnaires all read the same finding.
7 AI feature with no data governance review Prospects are already asking. Sold wrong, a questionnaire liability; designed right, a sales answer.
8 Payment review queue driving batching Slower shipping AND riskier changes: the CEO's second failure mode arriving through a process we control.
9 Detection team key-person risk Losing the interviewing engineer takes detection from 3 to 2 during the highest-risk quarter.
10 Ad hoc questionnaire answers Optimistic answers to enterprise prospects are contractual claims we may be failing quietly.

Why this works: Every impact statement names a number, a contract, a date, or a person; never a CVSS score. Ranks 1 through 3 are all carrier questions arriving within 5 months: the ranking quietly converts the renewal deadline into leverage.

Socialization notes

Walked the ranked list past the CFO and GC individually, before any group setting.

Why this works: Socialization produced changes (the #3 vs #4 ordering, the reframing of #8) and intelligence (the reforecast window). If your socialization round changes nothing, you didn't socialize, you rehearsed.

The first budget ask

The ask (day 47, to the CFO): $185K one-time to deploy log aggregation across the payment stack, covering the 12 production services in PCI scope, plus $60K/year run-rate.

Tied to: Risk #3, SOC 2 finding #3, and the carrier questionnaire, by name.

Definition of done: By day 90, all 12 payment services shipping logs with 90-day retention; the SOC 2 finding evidenced as remediated; the carrier questionnaire items answerable "yes" with proof. Verified by the GRC lead, reported in the day-90 readout.

Outcome: Approved in the same meeting, inside the reforecast window. The CFO: "This is the first security ask I've seen with an end state."

Why this works: Compare the two failed asks in the history: the logging request framed as compliance (declined twice) and the $400K consolidation with no definition of done. This ask is deliberately smaller than the program will need, because its real product is not logs, it is credibility for the year-one budget conversation. It also quietly funds the team's oldest unfunded wish, which the team notices.

Quick wins (two, both passing the four-part filter)

Quick win 1: Tested restore of the order database.

Quick win 2: Kill the ticket-queue payment review; replace it with an embedded review lane.

Why this works: The second win is the higher-value one precisely because it REMOVES friction. A new CISO who kills a hated process in the first 60 days buys more goodwill than any deployed tool. And the pattern list makes explicitly a risk decision that was previously being made by queue-evasion.

Phase 2 outputs


Phase 3 (Days 61–90): Deliver and report

Goal: the first board-ready readout and a repeatable operating rhythm. Anti-goal: a reassuring readout. Everything wrong right now is inherited; in a year it's yours. Spend the bluntness while it's free.

The day-90 readout (delivered to the audit committee, day 88)

1. What I found. Northwind's posture is better than the audit paper trail suggests and worse than the contracts require. The team is capable; the gaps are funding and process, not competence. Three specifics: we had never tested a restore of the order database (we now have, in under 7 hours); we cannot yet reconstruct activity in the payment stack (logging completes this week); and we have promised merchants a 48-hour breach notification we have never rehearsed. One SOC 2 finding is closed, one closes this week, one is scoped for next quarter. Stated plainly: some of our questionnaire answers today are more optimistic than our controls.

2. What could hurt us. First, compromise of production through the legacy admin paths still lacking MFA: one phished credential reaches the order database, and in Q4 each day of checkout downtime is roughly $3M. Remediation in flight, done next quarter. Second, an incident we detect late and reconstruct slowly, breaching the 48-hour promise and turning a security event into a churn event; the logging work and a Q3 tabletop with legal address this. Third, the stored-credential launch expanding PCI scope: designed with us now (started), routine; retrofitted after assessor fieldwork, expensive and public.

3. What I'm doing, in what order. Four initiatives, each tied to a risk you just heard. Detect and respond first: it collapses the largest gap between what we promise and what we can do. Production access hardening second: carrier-visible and finding-closing. Securing the Q4 launch third: the deadline is external. Team durability fourth but concurrent: we are below market on comp in a 14-person team carrying an $800M platform, and I nearly lost one of three detection engineers.

4. What it costs. The year-one program is $1.4M incremental: $700K run-rate (one appsec engineer, one detection engineer, tooling) and $700K one-time (access automation, launch security work, comp correction). Declining the run-rate keeps the 2-day review SLA on a rotation that fails within two quarters, and leaves detection one resignation from half-staffed through Q4. Declining the comp correction re-runs this year's two departures. The formal ask comes through the budget cycle; today I am asking the committee to agree the risk ranking, so it lands pre-agreed.

Why this works: Section 1 confesses the questionnaire problem before anyone discovers it, converting a future scandal into a present credential. Section 4 doesn't ask for money in the meeting; it asks for agreement on the ranking, which is what a committee can genuinely give, and it prices the "no" in risk terms rather than pleading. The whole readout runs under ten minutes.

The operating rhythm installed

Cadence Forum Content
Weekly Security leadership (5 leads, 45 min) Delivery against the four initiatives, incidents, blockers
Monthly CFO 1:1 (exec sponsor, 30 min) Risk movement against the ranked ten, budget status, decisions needed; same format every month so trend is visible
Quarterly Audit committee The four-section readout, updated; SOC 2 finding tracker until closed; same metrics every quarter, per the chair's request
Annually Full board Posture trend, results against the day-90 commitments, year-two ask

Plus one rhythm this company needs: a monthly launch-security checkpoint with Product until the stored-credential launch ships.

Phase 3 outputs

Why this works: "The gap explicitly accepted by name" is the most-skipped output in the template. In practice it is not a confrontation, just a sentence in shared meeting notes saying who accepted which risk until when. It costs nothing on the day and is worth everything when the accepted risk materializes.


The interview one-pager, written for Northwind

Built ONLY from outside information (public filings-equivalent reading, the security job postings they left up, a prospect's public complaint that surfaced the SOC 2 status). One page. Presented only when asked or when the conversation opens the door.

My first 90 days at Northwind Commerce: working plan, built from the outside

What I believe from the outside (assumptions, stated as such):

Days 1–30: Listen. Eleven structured conversations (CEO through the previous CISO if reachable), a crown-jewel inventory, and an inherited-commitments list: audit remediations, merchant contract promises, insurance conditions. No reorg, no purchases, no strategy announcements.

Days 31–60: Prioritize. A risk list ranked in revenue and contract terms, walked past the CFO and GC individually before any group sees it. One scoped budget ask with a definition of done. One or two quick wins visible outside security, ideally removing friction rather than adding control.

Days 61–90: Deliver. A four-section readout to the audit committee: what I found, what could hurt us, what I'm doing in what order, what it costs. Install a reporting rhythm the committee can compare quarter over quarter.

What I won't do in the first 90 days: reorganize the team, replace the stack, or promise a full risk assessment by day 30.

The caveat, said out loud: "This is my plan given what I can see from the outside. The first 30 days exist to find out where it's wrong, and I'd expect the version I show you at day 45 to be different in at least one important way."

Why this works: The one-pager makes three specific, checkable claims about THEIR business, then explicitly bounds its own confidence. Specificity plus stated uncertainty is what panels read as seniority: certainty from the outside reads junior, vagueness reads unprepared. Notice it never cites the inside facts the full example relies on. Never claim inside knowledge you cannot have.


Northwind Commerce is fictional; all names, figures, findings, and events in this document were invented for illustration.

© CISO Prep · cisoprep.com · Part of the CISO Interview Template Pack.