Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should a new CISO structure the first…
Governance, Ownership & Risk

How should a new CISO structure the first 91 days to build credibility without creating unnecessary change risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

A strong first 91 days balances restraint with visible progress. Start by learning the business, its risk profile, and where security work is already working or failing. Then pick a few low-cost, high-trust improvements that show momentum, while deferring deeper changes until you understand dependencies. The goal is to build confidence, earn stakeholder support, and create a practical foundation for longer-term programme delivery.

How a new CISO earns credibility in the first 91 days

The first 91 days are less about proving how much can be changed and more about proving judgment. A new CISO builds credibility by learning the business first, understanding where security already supports delivery, and making a few visible improvements that reduce friction or risk without destabilising dependent teams. That balance signals control, not hesitation.

Credibility comes from showing that security decisions are tied to business priorities, operating realities, and known constraints. Early wins should be small enough to land quickly, but real enough to matter to stakeholders who are watching for whether the new leader can listen, prioritise, and follow through.

For a CISO, this usually means separating urgent stabilisation from structural transformation. Stabilisation work can start immediately, but deeper changes should wait until the organisation's dependencies, informal decision paths, and sources of repeated failure are clearer.

What to learn before trying to change anything

The first phase should focus on understanding how the organisation actually operates, not how prior decks described it. That includes the risk profile of the business, the crown-jewel systems, the most important delivery teams, and where security is already functioning well enough to preserve. It also means identifying which controls, processes, and relationships are most likely to create delay if altered too early.

This is where a new CISO earns trust from both executives and practitioners. Listening tours, incident review, control walkthroughs, and stakeholder interviews are not ceremonial if they surface the places where security work creates hidden operational drag. The point is to understand leverage points before making commitments that later collide with the way work really gets done.

Good early diagnostics should distinguish between visible noise and material weakness. A backlog of complaints is not the same as a structural risk, and a system that is unpopular is not necessarily the system that is fragile. The CISO's job in this period is to map those distinctions quickly enough to avoid reshaping the wrong thing.

Where to create momentum without creating change risk

The safest early improvements are those that are low-cost, easy to explain, and clearly connected to reducing confusion, manual effort, or avoidable exposure. Typical examples are clarifying ownership, tightening a recurring approval step, improving a report that leaders actually use, or fixing a control that causes repeated rework without delivering much protection. These changes show momentum while keeping the blast radius small.

That same restraint applies to larger programme moves. A new CISO should be careful about broad policy rewrites, tool replacements, and centralisation efforts in the first quarter unless the environment already has a known failure mode that demands it. The fastest way to lose credibility is to create a lot of activity before the organisation has confidence in the diagnosis.

When an early change touches a CISO 90 day plan for emerging AI agent identity risk, the same principle still applies: first make the risk understandable to the business, then decide whether the control gap justifies a broader intervention. Early leadership is often about sequencing, not ambition.

Risk and Threat Considerations

A new CISO can damage confidence by changing too much before the organisation understands the trade-offs. The main risk is not just operational disruption, but loss of stakeholder trust if early actions are perceived as disconnected from business reality or if they accidentally weaken controls that were supporting critical workflows.

Failure mechanism: Overly broad change in the first 91 days can disrupt dependencies, create control gaps during transition, and trigger resistance from teams that feel their constraints were not understood.

Impact: The programme can inherit avoidable friction, slower adoption, and a reputation for being directive rather than credible, which makes later security improvements harder to land.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextHelps the CISO learn business context before changing controls
GV.RM-01 — Risk Management StrategySupports sequencing low-risk early wins and deferring larger changes
GV.RR-01 — Risk Roles, Responsibilities, and AuthoritiesClarifies ownership and decision rights needed to avoid change conflict
Recommendation — Define the business context and align early security priorities to it. Set a risk-based prioritization approach for the first 91 days. Confirm decision owners before altering security processes or controls.
ISO/IEC 27001:2022A.5.1 — Policies for information securityRelevant to introducing policy changes cautiously and with business fit
A.5.2 — Information security roles and responsibilitiesSupports early clarification of ownership and accountability
Recommendation — Review policy gaps before rewriting or expanding security policy. Assign clear responsibilities for security decisions and follow-through.

Practitioner Guidance

What to prioritise: Build an honest view of where the organisation is already resilient, where it is brittle, and which issues are genuinely worth solving now. If a problem is painful but not material, defer it; if it is material but localised, contain it before trying to redesign the broader programme.

Decision rule: If an early action changes ownership, access, escalation, or a workflow used by many teams, treat it as a change-risk decision, not a housekeeping task. Make the smallest change that proves the point and preserve a rollback path.

What to verify: Before trusting any proposed improvement, verify who will absorb the operational cost, what dependency it touches, and how success will be observed by the business. A good early move is one that improves clarity or control without introducing a new coordination burden.

Practitioner takeaway: The first 91 days are won by reducing uncertainty faster than you create it, so credibility should come from disciplined observation, selective action, and visible restraint.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org