Join our Newsletter — 33% off our NHI Course

Discovery Phase

The discovery phase is the initial stage of a security leadership transition, focused on understanding the organisation, its stakeholders, and its current security environment. It relies on interviews, listening, and review of existing processes to build context before any formal prioritisation or redesign begins.

What the discovery phase is trying to establish

The discovery phase is not a prioritisation exercise. Its job is to build a reliable picture of how the organisation actually operates, who influences security decisions, and which controls, processes, and constraints already exist before any redesign or roadmap is set.

That makes the phase more about context than conclusions. Good discovery reduces the risk of designing security changes around assumptions, incomplete stakeholder maps, or a partial understanding of how work gets done in practice.

How discovery works in a security leadership transition

In a leadership transition, discovery usually combines interviews, document review, listening sessions, and informal observation. The point is to understand what is already effective, what is fragile, and where governance responsibilities sit, rather than to judge the organisation too early.

The best discovery work surfaces both formal and informal structures, for example where decisions are documented versus where they are really made. That distinction matters because the formal operating model may not match day-to-day security ownership.

Discovery also creates an early baseline for later decisions. If you do not know the current state, you cannot reliably distinguish inherited strengths from inherited debt, or separate urgent gaps from practices that simply need refinement.

What a strong discovery phase usually covers

A useful discovery phase typically examines the security environment, stakeholder expectations, operating constraints, and the most important dependencies around people, process, and technology. It may also include reviewing existing standards, reporting lines, backlog items, incidents, and recurring pain points.

For identity-heavy environments, discovery often has to extend into control ownership and lifecycle reality. NHIMG’s NHI Lifecycle Management Guide is a useful reference for understanding why visibility, ownership, and lifecycle hygiene matter before any remediation plan is credible.

Discovery is also where broad security issues begin to separate into patterns. The difference between a one-off process weakness and a systemic control gap is often only visible once multiple interviews, artefacts, and operating routines are compared side by side.

Why discovery matters before any redesign

Discovery protects against premature solutions. A team that moves straight to tooling, controls, or org-chart changes can easily solve the wrong problem, especially when the real issue is unclear accountability, inconsistent process execution, or missing inventory.

It also helps set the scope of later work. Some findings will be strategic, such as governance gaps or recurring ownership confusion, while others will be tactical, such as stale processes or undocumented exceptions. Separating those categories early makes later prioritisation more defensible.

For a transition leader, discovery is therefore the foundation for trust. It creates the evidence base needed to explain what is already present, what is missing, and what should be addressed first without overreacting to the loudest issue.

Risk and Threat Considerations

When discovery is weak, the transition can inherit hidden control gaps, unowned risk, and inaccurate assumptions about how security actually operates. That is especially dangerous in environments where visibility is poor and important processes are spread across multiple teams or systems.

Failure mechanism: incomplete interviews, shallow document review, or overreliance on formal process descriptions can leave critical dependencies, exceptions, and ownership gaps undiscovered until a control fails or an incident forces the issue.

Impact: the organisation may prioritise the wrong remediation work, miss systemic exposure, or continue operating with unresolved gaps in accountability, access governance, or operational resilience.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context Discovery establishes the organisation's operating context and stakeholder environment.
ID.RA-01 — Risk and Threats Identified and Documented Discovery surfaces current-state risks, dependencies, and control gaps before planning changes.
GV.RM-01 — Risk Management Strategy Established Discovery informs how leadership defines security priorities and decision criteria.
Recommendation — Document the organisation's security context before setting priorities or redesigning controls. Record observed risks and dependencies during discovery so later prioritisation is evidence-based. Use discovery findings to shape the risk-management approach before committing to a roadmap.
ISO/IEC 27001:2022 A.5.4 — Management responsibilities Discovery clarifies who is accountable for existing security decisions and control ownership.
A.5.9 — Inventory of information and other associated assets Discovery commonly depends on understanding what exists, who owns it, and where it sits.
Recommendation — Confirm management ownership and accountability during discovery before changing controls. Use discovery to validate the asset and control inventory that future remediation depends on.

Practitioner Guidance

Why practitioners should care: discovery is where a new security leader earns an accurate baseline. If the baseline is wrong, every later decision, from prioritisation to redesign, is built on a weaker foundation.

What to watch for: the main warning sign is inconsistency between what stakeholders say, what the documents show, and how decisions are actually made. That mismatch is often the clearest signal that the real control model is not yet understood.

Practitioner takeaway: treat discovery as a disciplined listening and validation exercise, not a light formality before “real work” begins.