CISO Strategy

Commanding the Crisis: 90-Day Roadmap to Boardroom Confidence

✎ Kieran Upadrasta 📅 2026-01-15 🎓 CISSP, CISM, CRISC, CCSP

When a new CISO arrives — or when an existing CISO needs to reset the security function's credibility — the first 90 days determine everything. This paper provides a structured roadmap for commanding the crisis: establishing board-level confidence in the organisation's cyber resilience within a compressed 90-day timeline. The roadmap is structured in three 30-day phases: Assess (understanding the current state, identifying critical gaps, and establishing baseline metrics), Architect (designing and initiating the most impactful improvements), and Assure (demonstrating measurable progress to the board and establishing ongoing governance cadence).

Each phase includes specific deliverables, stakeholder engagement strategies, and communication frameworks designed to build confidence progressively. The roadmap draws on the author's experience of multiple CISO transitions across Tier 1 financial institutions.

  1. 01The First 90 Days: Why They Matter
  2. 02Phase 1: Assess (Days 1-30)
  3. 03Phase 2: Architect (Days 31-60)
  4. 04Phase 3: Assure (Days 61-90)
  5. 05Board Engagement Strategy
  6. 06Quick Wins and Visible Progress
  7. 07Stakeholder Communication Framework
  8. 08Sustaining Momentum Beyond 90 Days
K

Kieran Upadrasta

CISO & Strategic Cyber Consultant · CISSP, CISM, CRISC, CCSP

27 years securing financial services · Big 4 pedigree (Deloitte, PwC, EY, KPMG) · Zero breaches managing £500B+ in assets

https://www.kie.ie · LinkedIn