
Every new CISO walks in with a plan. By week three, that plan is usually worthless. Not because the plan was bad, but because you fundamentally misread the organization before you had a chance to understand it. I learned this the hard way in my first CISO role, and I have watched dozens of peers make the same mistakes since.
The transition guides and onboarding playbooks were written by people with time to write playbooks. The reality is messier, more political, and far more dependent on relationships than any certification prepared you for. What follows is what I wish someone had told me before I walked into that first executive meeting.
What Every New CISO Gets Wrong
Every transition guide tells you to spend your first month listening. That advice is correct but incomplete. The real challenge is listening for the right things. You need to understand not just the technical landscape but the political one. Who actually has power? Who controls budget? Who has the CEO’s ear? These answers matter more than any vulnerability scan.
Most new CISOs fail not because they lack technical competence but because they misread the organizational dynamics. The previous CISO probably left for a reason, and that reason is your inheritance. Maybe they burned bridges with IT. Maybe they oversold risk and lost credibility. Maybe they had no executive support and gave up. Understanding that history shapes everything you can accomplish.
Your first 90 days are not about fixing problems. They are about building the relationships and credibility that will let you fix problems later.
Days 1-30: Listen More Than You Talk
In your first month, schedule one-on-ones with every executive and every direct report. Do not bring an agenda beyond wanting to understand their perspective. Ask them what they think security does well, what it does poorly, and what they wish would change. Then close your mouth and take notes.
Pay close attention to the patterns. If three executives mention the same frustration, that is your first priority whether you like it or not. If your team keeps referencing the same organizational blocker, that is your second priority. Their perception is your reality until you earn the credibility to reshape it.
Meet with your team individually before holding any team meetings. You need to understand each person’s motivations, frustrations, and capabilities. Some will be waiting for permission to excel. Others will be counting down to retirement. A few might be actively undermining the program. You cannot know which is which from an org chart.
Resist the urge to make promises. When someone asks if you will fix something, say you are still learning. When someone asks your opinion on a past decision, say you were not there and cannot judge. Every early commitment reduces your flexibility later.
Days 31-60: Build Your Map
By your second month, you should have a working mental model of the organization. Now you can start documenting what you have. Request a complete inventory of security tools, contracts, and their renewal dates. You will discover redundant tools, shelfware, and contracts nobody remembers signing.
Review your budget in detail. Understand where money is committed versus discretionary. Identify any upcoming renewals that give you leverage to renegotiate or consolidate. Your predecessor’s tool choices are now your problem, but upcoming renewals are your opportunity.
Assess your team’s capabilities honestly. Where are the skill gaps? Where is the depth? If one person holds all the knowledge for a critical system, that is a risk. If nobody has incident response experience, or your team has never run a blameless postmortem, those are bigger risks. Do not fill gaps yet. Document them. If you need to backfill or add headcount, know what you’re actually looking for before you start interviewing.
Start building relationships with peer leaders in IT, legal, HR, and finance. These relationships will determine whether your initiatives get support or quietly sabotaged. Find common ground. Understand their priorities. Security does not exist in isolation, and CISOs who forget this spend their tenure fighting organizational antibodies.
Days 61-90: Start Moving the Needle
Your third month is when you can start making visible changes, but they should be calculated. Pick one or two quick wins that address the pain points you heard in month one. These should be achievable within 30 days and noticeable to people outside security. Maybe it is fixing a painful access request process. Maybe it is retiring a tool everyone hates. Small wins build momentum.
Begin drafting your 12-month roadmap, but do not publish it yet. Socialize pieces of it with key stakeholders to test reactions. If the CFO recoils at a budget implication, you need to know that before you present to the board. If the CTO has concerns about operational impact, address those in private first. Define how you will measure success before committing to initiatives.
Your first board presentation is coming, and it will set expectations for your entire tenure. Keep it simple. Present your assessment of the current state, the two or three biggest risks, and your general approach. Do not ask for major budget increases yet. Boards want to see judgment before they fund ambition.
If you inherited a team with performance problems, have direct conversations now. By 90 days, everyone has had time to show you who they are. Document issues. Begin coaching. If someone cannot or will not improve, start the process to move them out. Waiting longer only makes this harder.
The Traps That Catch New CISOs
The biggest trap is trying to prove yourself too fast. You were hired because leadership believed you could do this job. They are giving you time to learn. Using that time to push aggressive changes signals insecurity, not competence. The best CISOs I know moved deliberately in their first year and aggressively in their second.
Another trap is falling in love with the previous CISO’s enemies. Maybe IT really is difficult to work with. Maybe the development team really does ignore security. But you are not your predecessor. Those relationships can be rebuilt if you approach them fresh. Inheriting grudges makes you weaker.
Watch for the trap of audit-driven priorities. A finding from last year’s audit will be presented to you as urgent. It might be. It might also be something the auditors flagged that has no real business impact. Learn to distinguish between compliance theater and actual risk reduction.
The loneliest trap is isolation. The CISO role can feel like you are the only person who sees the risk. That is partly true and partly perspective distortion. Find peers outside your organization. Join a CISO community. Talk to people who understand what you are experiencing. This job is too hard to do alone.
What Success Looks Like at 90 Days
After 90 days, success is not a transformed security program. Success is understanding what you have, building the relationships you need, and having a credible plan. If executives trust your judgment, your team knows your expectations, and you have identified the two or three things that actually matter, you are ahead of most people in this role.
The real transformation happens in year two, when your early investments in relationships start paying dividends. The project that seemed impossible because IT would never agree? It becomes possible when you have spent a year proving you understand their constraints. The budget you could not get? It becomes available when the board sees you deliver on smaller commitments.
Your first 90 days are about earning permission to lead. The security improvements come later, built on the foundation you are laying now. Anyone can walk in and demand changes. The CISOs who last are the ones who build coalitions first.
Take notes on everything. Six months from now, you will need to remember what the CFO said in your first meeting. Document the state you inherited so you can show progress later. Write down the names of people who were helpful and those who were obstacles. This institutional memory becomes invaluable.
Most importantly, give yourself grace. The learning curve is steep and the stakes are high. Every CISO I respect has stories about missteps in their first role. What matters is learning quickly, adjusting course, and staying focused on building something sustainable rather than impressive.