What is the First 90 Days course about?
A proven path to establish trusted authority in security leadership during your first 90 days Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
What situation is the First 90 Days for?
New security leaders face silent expectations: demonstrate control fluency, align stakeholders, and deliver audit-ready evidence, all before the first formal review. Without a structured approach, even experienced hires waste cycles reconciling narratives, chasing attestations, and rebuilding trust.
Who is the First 90 Days course for?
VP of IT / CISO in a financial services firm stepping into a high-visibility security leadership role with cross-functional accountability.
What do you take away from the First 90 Days course?
Enter your role with a pre-built credibility roadmap aligned to PCI DSS expectations Produce stakeholder-ready control narratives in the first 30 days Eliminate last-minute audit package rework with a structured evidence pipeline Position yourself as the consistent source of truth on payment security Turn compliance execution into a visible leadership signal across the business.
How does this map to your situation?
Week 1: Assessing current state and building stakeholder map Weeks 2-4: Establishing communication rhythm and control fluency Weeks 5-8: Delivering first artifacts and alignment wins Weeks 9-12: Preparing for and leading through first review cycle.
What's included with your purchase?
12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.
What does the First 90 Days cover on delivery and format?
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: 90 minutes of focused reading and planning, designed to be completed in segments over the first 90 days.
How does this compare to the alternatives?
Unlike generic compliance courses, this program focuses exclusively on the leadership and perception challenges new CISOs face in financial services, with PCI DSS as the anchor for credibility.
Closely related courses: First 90 Days as CISO, AI-Driven Leadership in the First 90 Days.
More answers: what you get with every course, refund policy, all help answers.
A tailored course, built for your situation
First 90 Days: Building Security Credibility in a Financial Services Firm
A proven path to establish trusted authority in security leadership during your first 90 days
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
The situation this course is for
New security leaders face silent expectations: demonstrate control fluency, align stakeholders, and deliver audit-ready evidence, all before the first formal review. Without a structured approach, even experienced hires waste cycles reconciling narratives, chasing attestations, and rebuilding trust.
Who this is for
VP of IT / CISO in a financial services firm stepping into a high-visibility security leadership role with cross-functional accountability
Who this is not for
Those maintaining existing programs, individual contributors without leadership scope, or professionals outside financial services with no PCI DSS mandate
What you walk away with
- Enter your role with a pre-built credibility roadmap aligned to PCI DSS expectations
- Produce stakeholder-ready control narratives in the first 30 days
- Eliminate last-minute audit package rework with a structured evidence pipeline
- Position yourself as the consistent source of truth on payment security
- Turn compliance execution into a visible leadership signal across the business
The 12 modules (with all 144 chapters)
- Defining success for a new CISO in financial services
- Mapping key stakeholders: who needs to trust you first
- The role of PCI DSS in shaping internal credibility
- Aligning with firm risk appetite and executive priorities
- Establishing your first communication rhythm
- Navigating cultural expectations in financial sector security
- Benchmarking current program maturity without sounding judgmental
- Positioning yourself as an enabler, not a gatekeeper
- Building early wins that resonate with leadership
- Setting realistic expectations for the first 90 days
- Understanding hidden compliance debt in legacy systems
- Creating your personal onboarding dashboard
- Internalizing the 12 requirements without memorization
- Translating controls into business impact language
- Identifying high-visibility domains for early focus
- Common misalignments in scoping and how to correct them
- Control 1: Firewalls and network segmentation expectations
- Control 3: Protecting stored cardholder data effectively
- Control 8: Strong authentication practices in practice
- Control 10: Logging and monitoring that holds up under scrutiny
- Control 11: Regular testing with real-world evidence
- Control 12: Policy fluency and enforcement credibility
- Handling compensating controls with confidence
- Using the PCI DSS Self Assessment Questionnaire as a roadmap
- Defining three measurable credibility milestones
- Aligning your plan with fiscal and audit calendars
- Choosing early focus areas with high visibility
- Creating a stakeholder engagement schedule
- Documenting baseline status without blame
- Setting up bi-weekly progress signals
- Designing your first executive update
- Incorporating team feedback loops
- Tracking control maturity over time
- Highlighting progress without overpromising
- Adjusting for regulatory or business shifts
- Locking down your first-quarter narrative
- Mapping influence beyond formal reporting lines
- Conducting credibility interviews with key partners
- Translating security needs into business terms
- Creating shared ownership of control outcomes
- Running effective cross-functional alignment sessions
- Handling resistance with empathy and data
- Using pilot initiatives to demonstrate value
- Building a coalition of early supporters
- Communicating progress without overburdening teams
- Managing expectations during integration phases
- Turning compliance requirements into joint wins
- Maintaining momentum after initial enthusiasm fades
- Designing the attestation package for clarity and completeness
- Creating living control narratives instead of static documents
- Using templates that accelerate evidence collection
- Versioning and storing artifacts for traceability
- Aligning evidence with PCI DSS testing procedures
- Incorporating screenshots, logs, and policy references
- Standardizing stakeholder sign-off workflows
- Automating status tracking without overengineering
- Preparing for internal audit inquiries in advance
- Handling evidence gaps transparently
- Documenting compensating controls effectively
- Reviewing artifacts with a third-party lens
- Structuring updates for time-constrained leaders
- Using metrics that matter to business stakeholders
- Balancing transparency with discretion
- Highlighting forward progress, not just issues
- Creating visual summaries that stick
- Anticipating and answering likely questions
- Managing escalation narratives with poise
- Turning risk findings into action plans
- Documenting decisions and rationale clearly
- Maintaining consistency across communication channels
- Adjusting tone for different audiences
- Building a reputation for calm, credible leadership
- Assessing vendor compliance posture efficiently
- Using standardized questionnaires with flexibility
- Identifying critical vendors early
- Conducting targeted follow-ups on high-risk areas
- Documenting due diligence thoroughly
- Handling vendors with partial or outdated certifications
- Negotiating security terms from a position of strength
- Integrating vendor controls into your overall narrative
- Monitoring ongoing compliance without micromanaging
- Escalating issues with data and precedent
- Building trusted relationships with vendor counterparts
- Creating a repeatable third-party review process
- Understanding the audit timeline and key milestones
- Preparing your team for document requests
- Coordinating evidence collection efficiently
- Running internal mock reviews
- Anticipating common findings and questions
- Responding to observations with ownership
- Maintaining team morale under pressure
- Using the audit as a credibility-building opportunity
- Documenting corrective actions effectively
- Communicating results to leadership
- Incorporating feedback into your ongoing plan
- Turning audit outcomes into forward momentum
- Engaging early in product and system launches
- Integrating security checkpoints into project lifecycles
- Using risk assessments to guide design decisions
- Creating lightweight review templates for fast-moving teams
- Balancing security with speed and innovation
- Documenting trade-offs with rationale
- Building trust with engineering and product leaders
- Running security design sessions effectively
- Measuring influence beyond compliance checkmarks
- Scaling your reach through enablement
- Recognizing and rewarding secure practices
- Positioning security as a business enabler
- Evaluating your first 90 days with honesty and insight
- Identifying long-term credibility goals
- Refining your communication rhythm
- Expanding your stakeholder network
- Taking ownership of broader risk initiatives
- Mentoring junior team members effectively
- Sharing knowledge without undermining authority
- Staying visible on high-impact issues
- Balancing strategic and operational demands
- Continuously updating your control knowledge
- Adapting to evolving threats and standards
- Reinforcing your role as the go-to security voice
- Establishing your escalation response protocol
- Gathering facts quickly and calmly
- Communicating status without speculation
- Coordinating cross-functional response efforts
- Documenting decisions and actions thoroughly
- Managing executive inquiries under pressure
- Taking ownership without accepting blame prematurely
- Learning from each escalation to improve processes
- Maintaining team confidence during crises
- Using post-mortems to demonstrate leadership
- Rebuilding trust after high-visibility issues
- Turning challenges into credibility-building moments
- Compiling your most effective templates and examples
- Documenting your communication strategy
- Capturing lessons from the first 90 days
- Standardizing your stakeholder engagement process
- Creating a living control knowledge base
- Building a vendor assessment accelerator kit
- Designing your audit preparation checklist
- Developing a new hire onboarding module for your team
- Incorporating feedback into your leadership style
- Sharing your playbook selectively to build influence
- Positioning your approach as a firm standard
- Preparing for your next leadership challenge
How this maps to your situation
- Week 1: Assessing current state and building stakeholder map
- Weeks 2-4: Establishing communication rhythm and control fluency
- Weeks 5-8: Delivering first artifacts and alignment wins
- Weeks 9-12: Preparing for and leading through first review cycle
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: 90 minutes of focused reading and planning, designed to be completed in segments over the first 90 days.
How this compares to the alternatives
Unlike generic compliance courses, this program focuses exclusively on the leadership and perception challenges new CISOs face in financial services, with PCI DSS as the anchor for credibility.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.