Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should security leaders do first when they…
Governance, Ownership & Risk

What should security leaders do first when they need to improve cyber safety across the business?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Security leaders should start with a clear assessment of current security posture. That means reviewing staffing, training, systems, incident response, and business continuity, then comparing those controls against today’s threat environment. The goal is to find gaps before they become failures, because a plan without an honest baseline often looks stronger on paper than it is in practice.

What security leaders should do first

The first job is to establish an honest baseline of the current security posture. That baseline should cover people, process, and technology together, because cyber safety breaks down when leaders fix one layer while assuming the others are already sound. The goal is not a perfect scorecard, but a decision-ready view of where the business is exposed.

A useful baseline is operational, not theoretical. It should tell leaders what is staffed, what is trained, what is monitored, what is recoverable, and where the organisation is depending on informal workarounds. That is the difference between a programme that sounds mature and one that can actually absorb pressure.

How to build a baseline that leadership can trust

Start by checking whether the organisation can answer four questions without guessing: who owns the control, what evidence proves it works, when it was last tested, and what happens if it fails. That forces the review away from slideware and toward observable reality. A strong baseline usually includes incident response readiness, backup and recovery confidence, access governance, and the state of critical systems.

This is also where current threat conditions matter. A baseline is only useful if it is compared with the threats the business faces now, not last year’s assumptions. Teams should ask whether the current control set matches today’s attack paths, business dependencies, and recovery expectations, then separate true capability from assumed capability.

What leaders should look for once the baseline is set

The first pass should identify gaps that create immediate business fragility: understaffed functions, training that does not match actual responsibilities, controls that exist on paper but are not exercised, and recovery arrangements that have never been tested under realistic conditions. Security leaders should also look for single points of failure in operations, because those often become the fastest route from a local issue to a business-wide outage.

That review should lead to prioritisation, not a long wish list. A baseline only helps if it shows where the organisation can reduce exposure fastest, where resilience is weakest, and which failures would have the broadest operational impact. For practical response planning, teams can anchor this work in CISA cyber threat advisories to keep the baseline aligned with active threat patterns, and use NCSC UK Advice and Guidance for operational control checks and board-level framing.

Risk and Threat Considerations

An incomplete baseline creates a false sense of safety, which is often more dangerous than openly known weakness. If leaders do not understand current exposure, they may underinvest in the controls that matter most, miss weak recovery assumptions, or discover too late that an apparently solid control fails under real attack or outage conditions.

Failure mechanism: The business treats untested controls, stale training, and undocumented dependencies as evidence of protection, so gaps remain hidden until an incident forces them into the open.

Impact: The likely result is avoidable disruption, slower response, and a wider blast radius when a security event or operational failure occurs.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyA current baseline is the foundation of business cyber risk prioritisation.
ID.RA-01 — Asset Vulnerabilities are Identified and DocumentedThe answer centers on reviewing current posture to find gaps before they fail.
RC.RP-01 — Recovery Plan is executed during or after an incidentBusiness continuity and recovery testing are part of the baseline leaders must assess.
Recommendation — Define a current risk baseline before selecting security priorities. Inventory current gaps and document where exposure exists. Validate recovery assumptions through tested response and continuity plans.
NIST SP 800-53 Rev 5RA-3 — Risk AssessmentThe question asks leaders to assess current posture against today’s threats.
CP-2 — Contingency PlanBusiness continuity is explicitly part of the baseline leaders should review.
Recommendation — Perform a current risk assessment before setting security priorities. Review and test contingency plans for critical business functions.
CIS Controls v8CIS-17 — Incident Response ManagementIncident response readiness is a core part of the first posture assessment.
CIS-11 — Data RecoveryRecovery capability is part of the baseline needed for cyber safety.
Recommendation — Validate incident response roles, playbooks, and escalation paths. Test restoration capability and confirm recovery objectives are realistic.
ISO/IEC 27001:2022A.5.24 — Information security incident management planning and preparationThe answer includes incident response preparedness as a baseline element.
Recommendation — Prepare and test incident response arrangements before relying on them.

Practitioner Guidance

What to prioritise: Put the first review effort into the systems and processes that would most quickly stop the business from operating if they failed, especially recovery, response, and critical access paths. If the organisation cannot demonstrate that those controls work under test, treat them as open risk rather than established protection.

What to verify: Verify that every major control has an accountable owner, a recent test, and evidence that the result changed something operational. If the answer is only narrative, the baseline is not yet decision-ready.

Practitioner takeaway: The safest first move is not to launch more controls, but to make existing exposure visible enough that leadership can prioritise where failure would hurt the business most.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org