JOEY VICTORINO Independent Technical Judgment

Field Notes · Security Leadership · 6 min read

What the first 90 days of security leadership should actually produce.

Whether the role is full-time, fractional, or interim, the first quarter of security leadership has one job: convert an ambiguous situation into decisions the company can act on. The output is a small set of concrete artifacts, a defensible risk position, named ownership, a commitments inventory, a working escalation path, and a short prioritized plan with reasoning attached. It is not a maturity program, a tool rollout, or a reorganization. This note lists the artifacts, the failure modes they replace, and how an executive team should evaluate the leader at day 90.

What the period is for

A new security leader inherits a company mid-motion: systems built under previous constraints, commitments already made to customers, risks already being accepted implicitly by default configurations and unexamined vendors. The first quarter's purpose is calibration and decision, in that order. Calibration means establishing what is actually true: what exists, what has been promised, what is exposed, what is unknown. Decision means converting that picture into a small number of explicit choices leadership endorses: what matters most, what will be done first, what is being consciously accepted for now.

Everything else, the multi-year roadmap, the tooling estate, the team design, depends on those two steps and is premature before them. A leader who arrives with conclusions has skipped calibration; a leader who is still calibrating at day 90 has skipped decision. Both failure modes are common enough to plan against explicitly.

The failure modes the artifacts replace

Three patterns account for most disappointing first quarters, and none of them stems from low effort:

  • The encyclopedic roadmap. A long maturity assessment mapped to a framework, scoring dozens of domains, recommending improvement everywhere. It is defensible, comprehensive, and inert: it ranks nothing sharply, so it decides nothing, and it quietly dies in a drive folder while the company continues on momentum.
  • The tool-first quarter. Procurement of visible platforms before the risk position exists to justify them. Spending precedes prioritization, and the tools generate obligations (alerts, agents, dashboards) that consume the team the strategy was supposed to direct.
  • The silent quarter. Heads-down technical immersion with nothing surfaced to leadership. Whatever its private value, it leaves the executive team unable to distinguish progress from absence, which corrodes the role's authority precisely when it is being established.

The common defect is the same: no decisions reached leadership. The corrective is to define the quarter's output as decision-bearing artifacts, agreed in advance.

The artifacts

Six items, each short enough to be read and current enough to be trusted. Together they constitute decision clarity:

  1. A risk position. One or two pages stating the company's material security risks in business terms, ranked, with the reasoning visible: what could seriously hurt this company, through what path, with what consequence. Not a risk register with eighty rows; a position leadership can state from memory and defend to a board.
  2. Explicit acceptances. The subset of risks the company is consciously choosing to carry for now, written down and endorsed by the executives who own them. This artifact does the quiet work: it converts implicit acceptance, which is how unowned risk actually accumulates, into governed acceptance.
  3. An ownership map. Who decides and who operates, by area: customer security commitments, access, vendors, incident declaration, disclosure. Where the answer today is nobody, the map says so; unowned areas are findings, not blanks to hide.
  4. A commitments inventory. What the company has already represented to customers, auditors, and insurers about its security, collected from questionnaires, contracts, and policies, with the places where representation and reality diverge flagged for decision rather than quietly patched.
  5. A working escalation path. Who declares an incident, who runs it, who informs customers and counsel, tested at least once on paper against a plausible scenario. Not the audit-ready document; the two pages people would actually use at 02:00.
  6. The 90-day-forward plan. A short, ordered list of what happens next quarter, each item traceable to the risk position, with cost and owner. Its brevity is the point: a plan with nine items is a plan; a plan with forty is an inventory.

Alongside the artifacts, one operating habit should exist by day 90: a recurring, brief leadership touchpoint where security surfaces decisions and requests rather than status. The cadence, not the documents, is what keeps the artifacts alive past the quarter.

Where calibration evidence comes from

The quality of the artifacts depends on where the underlying picture came from, and the three available sources disagree with each other in predictable ways. Documents describe the intended state: policies, diagrams, prior assessments. They age silently and tend to record aspiration. Interviews reveal the operating state: who actually makes which decisions, where the friction is, which risks people privately worry about. They carry each person's vantage point and incentives. Systems show the actual state: who really has access, what is really exposed, what the logs really capture. They are the least ambiguous source and the most expensive to consult thoroughly.

A first quarter built on documents alone produces a confident restatement of the company's self-image. The discipline that makes the risk position defensible is triangulation: material claims in the artifacts should be traceable to at least two of the three sources, and the places where the sources contradict each other, where the policy says one thing and the configuration shows another, are usually the most important findings of the quarter. Where verification was not possible in the time available, the artifact should say so rather than silently promoting an interview answer to a fact. An executive team reading the risk position is entitled to know which statements were verified and which were reported.

What not to expect by day 90

Boundaries stated plainly, because inflated expectations produce the encyclopedic-roadmap failure by demand: do not expect completed compliance certification, re-architecture, a hired team, or measurable risk reduction across the board. Ninety days is enough time to know what is true, decide what matters, and start the first few items. A leader who claims more is usually describing motion rather than change; an executive team that demands more is usually buying documents rather than decisions.

Evaluating the leader at day 90

The evaluation follows directly from the artifacts, which is the reason to agree on them at day zero. Ask four questions:

  1. Can leadership now state the company's material security risks and current acceptances without the leader in the room? If the knowledge leaves when the leader does, calibration happened but transfer did not.
  2. Were any real decisions made this quarter: something declined, something deprioritized, a commitment refused, an acceptance signed? A quarter in which nothing was ever ruled out produced analysis, not leadership.
  3. Does the plan's ordering have visible reasoning? Any ordering can be defended after the fact; the test is whether the reasoning was written before the ordering was challenged.
  4. Did the escalation path get exercised, even as a tabletop walk-through? An untested path is a document; a tested one is a capability with known weak points.

Strong answers to these four justify continuing investment, full-time or fractional. Weak answers at day 90 rarely improve at day 180 without a changed mandate, because the cause is usually the mandate rather than the calendar.

Boundary conditions

Scale changes the shape. In a company with an existing security team and regulatory depth, the first quarter adds team assessment and regulator-facing obligations, and the artifacts grow accordingly; the principle that output must be decision-bearing survives the added scope. An active crisis also overrides the sequence: a leader who arrives mid-incident runs the incident first, and the calibration quarter starts when the fire is out. And where the role is fractional, the artifact list is the same while the depth of operational involvement differs, which is consistent with what the role should and should not own, treated at length in the note on when a company actually needs a fractional CISO.

Conclusion

The first 90 days of security leadership are a calibration exercise with a decision deadline. The deliverable is clarity the company keeps: a stated risk position, governed acceptances, named owners, known commitments, a tested escalation path, and a short plan whose ordering can be defended. An executive team that agrees on those outputs at day zero gets two benefits at once: a usable security program earlier, and an unambiguous way to know whether it hired judgment or motion.

Standing security leadership, sized to the need

This operating pattern, calibration, explicit decisions, and a leadership cadence, is how I run standing engagements. Fractional CISO / Standing Independent Advisory: Strategic at $8,500/month, Embedded at $12,500/month, 90-day initial term. I hold at most two standing relationships at a time.

Know an executive team about to bring in security leadership? Send them this note before the first day, not after the first quarter.

← All Field Notes