CISO_PREP

The Security Strategy One-Pager Template

The single page a CISO hands the CEO: posture, three pillars, sequencing, and the ask, with nothing left to interpret.

Part of the CISO Interview Template Pack · cisoprep.com


What this page is

The deck is for the meeting. This page is for everything around the meeting: the CEO who wants the strategy without the slides, the panel that keeps your leave-behind after the interview, the CFO who reads it before budget season. It is one page, six elements, no diagrams, and it should survive being read by someone with ninety seconds and no context.

The test for every line: could a skeptical executive repeat it to someone else accurately after one read? If a line needs you standing next to it to make sense, rewrite it.


The structure

Build it in this exact order. One page, hard limit. If it spills to two, your pillars are too broad or your initiatives are a backlog.

1. Posture sentence (one sentence, top of page)

[Company]'s security program is [honest one-line position relative to the risks that matter], and this plan moves [the biggest gap] from [current state] to [target state] by [date].

2. Three pillars (one block each; never four)

Each pillar gets exactly three lines:

Pillar: [Plain-English name tied to a business outcome] Objective: [The end state, in one sentence a director could repeat.] Initiatives: [Two or three, concrete enough that "done" is observable.] Measure: [One number, its current value, its target, and its date.]

3. Sequencing line (one sentence)

We do [pillar/initiative] first because [dependency or risk logic], then [second], then [third]; [what we are deliberately not doing this year] waits.

4. Ask line (one sentence, bottom of page)

This plan needs [$ amount / headcount / decision] in [timeframe]; without it, [named risk] stays [state] through [date].


Filled example

The following is for Meridian Health, an illustrative mid-cap healthcare SaaS company invented for this template. It does not exist and every number is made up. It is here to show the altitude and specificity the page needs, not to be copied.


Meridian Health: Security Strategy, FY27

Meridian's security program is resilient against commodity attacks but materially exposed to a ransomware event in the production platform, and this plan moves that risk from red to amber by Q4 while protecting the HITRUST timeline our bookings depend on.

Pillar 1: Make platform recovery a tested fact Objective: A production-wide ransomware event becomes a bad week, not an existential quarter. Initiatives: Execute the first full-stack recovery exercise (Q3); close the immutable-backup gap for the two remaining data stores; put executives at the table in the next tabletop. Measure: Verified full recovery time: currently an untested 2-3 day estimate, target a tested 24 hours by December.

Pillar 2: Shrink the blast radius of any one identity Objective: One phished engineer stops being a platform-level event. Initiatives: Just-in-time access for production administrators; retire shared service accounts in the data warehouse; quarterly access recertification that engineering leads actually complete. Measure: Standing production admin accounts: 126 today, under 25 by year end.

Pillar 3: Know our vendors as well as our customers know us Objective: We learn about a vendor problem from our own process, not from the vendor's disclosure. Initiatives: Automate reassessment scheduling for the 60 PHI-handling vendors; add security terms to the top-20 vendor renewal cycle; kill the 14 tools nobody has logged into since January. Measure: PHI vendors past reassessment due date: 34% today, under 10% by Q4, sustained.

Sequencing: Recovery testing comes first because it is the cheapest risk reduction on the page and its findings shape the identity work; identity second because it amplifies every other risk; vendor automation third once the new analyst starts in July. A SOC modernization and the DLP replacement deliberately wait until FY28.

The plan needs $1.8M and one backfilled analyst in Q3-Q4; without the identity funding, our top risk stays red through next fiscal year and I will formally re-raise it in Q1.


What makes each element credible

The posture sentence. Credible versions admit something. "Resilient against X, exposed to Y" is a judgment; "committed to continuous improvement of our security posture" is wallpaper. The tell is falsifiability: if the sentence would still be true after a breach, it was never saying anything. Also resist the reflex to lead with strength; executives trust the leader who names the gap in the first sentence, because everyone else in their day is selling.

Pillar names. Generic pillars are framework categories wearing a trench coat: "Identity & Access," "Governance, Risk & Compliance," "Detect & Respond." Credible pillars are outcomes: "make recovery a tested fact" tells the CEO what the world looks like when it works. If your pillar name could appear unchanged in any company's strategy, it is not your strategy.

Objectives. One sentence, repeatable by a non-technical executive, describing an end state rather than an activity. "Deploy a PAM solution" is an activity and belongs in initiatives. "One phished engineer stops being a platform-level event" is an end state, and it is the sentence the CEO will actually use when the board asks what security is doing.

Initiatives. Two or three per pillar, each with an observable "done." The failure mode is the backlog dump: six initiatives per pillar signals you have not chosen, and choice is the entire product of a strategy. Include one kill or stop item somewhere on the page (Meridian retires 14 unused tools); nothing signals ownership faster than naming what you will stop paying for.

Measures. One per pillar, and it must carry three numbers: current, target, date. "Improve vendor coverage" is not a measure. "34% past due today, under 10% by Q4, sustained" is one, and the word "sustained" matters because it blocks the one-quarter heroics that make metrics lie. If you cannot state the current value, say "baseline by [date]" honestly rather than inventing one.

The sequencing line. This is the most skipped element and the most senior. Anyone can list three pillars; the sequencing line proves you understand dependencies and scarcity. The strongest versions name what deliberately waits, because a strategy with no deferrals is a wish list, and every executive reading the page knows their own function had to defer something this year.

The ask line. Same discipline as the board deck: specific amount, specific gap, and the consequence of no stated flatly, not theatrically. The re-raise commitment ("I will formally re-raise it in Q1") does quiet work: it tells the reader that declining is a decision they are making, not a topic that will disappear.


The three ways this page gets used

1. Interview leave-behind. For the "present your strategy" round, this page is what stays in the room after your deck closes. Print copies; hand them out at the end, not the beginning, or the panel reads ahead of you. Add one line under the title: "Built entirely from public information; assumptions to be validated in my first 30 days." A panel that files your one-pager next to twelve forgettable decks remembers exactly one candidate. Make sure the page and your deck agree perfectly; panels compare, and a mismatch reads as improvisation.

2. Executive onboarding. In your first 90 days as a sitting CISO, this page is the artifact your CEO, CFO, and GC align on before anything goes near the board. Walk each of them through it 1:1 and revise between conversations; the page that reaches the board should already have their fingerprints on it. This is also where the posture sentence earns its keep: getting the CEO to agree to an honest sentence in private is far cheaper than debuting it in a boardroom.

3. Budget pre-read. Attach it to the budget submission or send it to the CFO a week before the planning meeting. The pillars justify the line items, the measures define what funded success looks like, and the ask line is already in the CFO's native format: amount, purpose, consequence. Budgets attached to a one-page strategy survive cost-cutting rounds that spreadsheets alone do not, because the reader can see what breaks when a line is cut.

One maintenance rule: the page is versioned, not disposable. Date it, revise it quarterly, and keep the measures identical across versions so the trend is visible. The second version of this page, showing 126 admin accounts become 41, is more persuasive than anything you can write in the first one.


Meridian Health is a fictional company created for this template. All figures attached to it are invented for illustration.