What is the First 90 Days course about?
A step-by-step implementation path to build trusted, auditable security leadership from day one Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
What situation is the First 90 Days for?
New security leaders in regulated insurance environments often enter with technical mastery but lack a repeatable method to demonstrate control, alignment, and stakeholder trust early. This gap leads to reactive cycles, last-minute audit scrambles, and missed opportunities to position security as an enabler. Without a structured credibility plan, even strong performers struggle to translate effort into visible influence.
Who is the First 90 Days course for?
Chief Information Security Officer or senior security executive entering or recently in a leadership role within a regulated insurance or financial services organization. Focused on establishing trust, passing regulatory scrutiny, and aligning security with business outcomes from day one.
Who is the First 90 Days course not for?
Individuals looking for high-level compliance theory or general cybersecurity awareness training. This course is not for junior analysts, support staff, or teams seeking broad policy templates without implementation context.
What do you take away from the First 90 Days course?
Establish a documented, NIST CSF-aligned credibility plan within the first 30 days Produce auditable evidence packages that minimize rework and stakeholder chasing Turn regulatory requirements into visible leadership wins Build a reusable delivery pattern that compounds trust across audit cycles Shift from technical executor to recognized strategic leader.
How does this map to your situation?
Day 1, 30: Assessment and listening Day 31, 60: Early wins and evidence building Day 61, 90: Narrative shaping and stakeholder alignment Day 91+: Sustained influence and compounding IP.
What's included with your purchase?
12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.
What does the First 90 Days cover on delivery and format?
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: Approximately 90 minutes per module, designed for completion over 12 weeks with one module per week.
Closely related courses: First 90 Days as CISO, AI-Driven Leadership in the First 90 Days.
More answers: what you get with every course, refund policy, all help answers.
A tailored course, built for your situation
First 90 Days: Building Security Credibility in a Regulated Insurance Organization
A step-by-step implementation path to build trusted, auditable security leadership from day one
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
The situation this course is for
New security leaders in regulated insurance environments often enter with technical mastery but lack a repeatable method to demonstrate control, alignment, and stakeholder trust early. This gap leads to reactive cycles, last-minute audit scrambles, and missed opportunities to position security as an enabler. Without a structured credibility plan, even strong performers struggle to translate effort into visible influence.
Who this is for
Chief Information Security Officer or senior security executive entering or recently in a leadership role within a regulated insurance or financial services organization. Focused on establishing trust, passing regulatory scrutiny, and aligning security with business outcomes from day one.
Who this is not for
Individuals looking for high-level compliance theory or general cybersecurity awareness training. This course is not for junior analysts, support staff, or teams seeking broad policy templates without implementation context.
What you walk away with
- Establish a documented, NIST CSF-aligned credibility plan within the first 30 days
- Produce auditable evidence packages that minimize rework and stakeholder chasing
- Turn regulatory requirements into visible leadership wins
- Build a reusable delivery pattern that compounds trust across audit cycles
- Shift from technical executor to recognized strategic leader
The 12 modules (with all 144 chapters)
- Mapping the informal power structure in regulated insurance
- Identifying early-win opportunities without overpromising
- Assessing inherited control gaps without assigning blame
- Benchmarking current posture against NIST CSF baseline
- Documenting existing risk narratives and their owners
- Understanding the rhythm of audit and reporting cycles
- Locating silent friction points in cross-functional workflows
- Capturing unwritten compliance expectations
- Classifying stakeholder urgency versus influence
- Building a 30-day listening tour agenda
- Creating a stakeholder sentiment dashboard
- Synthesizing findings into a leadership positioning memo
- Translating Identify function into stakeholder alignment
- Using Protect to highlight visible control improvements
- Positioning Detect as proactive risk visibility
- Framing Respond to show command during incidents
- Using Recover to demonstrate business continuity foresight
- Mapping CSF subcategories to insurance regulatory expectations
- Prioritizing CSF actions with highest credibility ROI
- Building a CSF gap heatmap for leadership review
- Linking control objectives to business outcomes
- Creating a CSF communication ladder for different audiences
- Avoiding overcommitment in early CSF roadmaps
- Validating CSF alignment with peer security leaders
- Selecting evidence types that satisfy both ops and audit
- Documenting walkthroughs with process owners
- Capturing baseline metrics without perfect systems
- Creating dated observation logs with context
- Producing before-and-after snapshots of control states
- Assembling a portfolio that tells a credibility story
- Using screen annotations to add narrative clarity
- Versioning evidence for traceability
- Organizing files for future audit access
- Integrating evidence into recurring reporting
- Sharing portfolio selectively to build trust
- Updating portfolio with minimal weekly effort
- Crafting your first 1:1 agenda with key peers
- Running a low-friction security intake meeting
- Delivering your first cross-functional update
- Responding to urgent requests without losing focus
- Sharing small wins without sounding boastful
- Asking for feedback in a way that builds goodwill
- Demonstrating follow-through on minor commitments
- Introducing yourself in executive forums
- Handling skepticism with data, not defensiveness
- Building a stakeholder newsletter that sticks
- Scheduling recurring touchpoints with influence
- Measuring stakeholder sentiment over time
- Defining the credibility arc: from observer to influencer
- Identifying pivotal moments to showcase progress
- Using executive summaries to frame early wins
- Avoiding jargon in leadership communications
- Aligning narrative tone with company culture
- Incorporating stakeholder quotes as social proof
- Linking actions to business resilience outcomes
- Creating a credibility timeline for onboarding new leaders
- Anticipating narrative pitfalls and how to avoid them
- Using storytelling to preempt criticism
- Adapting narrative for different audiences
- Measuring narrative effectiveness through engagement
- Breaking down annual audit requirements into monthly tasks
- Creating a living SoA that evolves with control changes
- Documenting control owners with signed attestations
- Building evidence libraries with metadata tags
- Scheduling quarterly control walkthroughs
- Using checklists to ensure consistency
- Integrating evidence collection into routine work
- Training team members to capture proof daily
- Automating evidence aggregation where possible
- Running mock audits with junior staff
- Refining deliverables based on past feedback
- Reducing revision cycles through early reviews
- Mapping NIST CSF to insurance regulator focus areas
- Tracking regulatory guidance updates systematically
- Attending regulator webinars as a listening tool
- Identifying common inspection triggers in your domain
- Preparing position papers on emerging risks
- Engaging legal and compliance on interpretation
- Conducting internal mock regulator interviews
- Documenting rationale for control decisions
- Building a response playbook for information requests
- Sharing regulator insights with internal stakeholders
- Positioning yourself as the internal subject matter expert
- Turning regulatory alignment into a leadership differentiator
- Designing a standard incident response briefing
- Creating a vendor risk assessment template
- Standardizing security review checklists
- Building a change advisory board agenda
- Drafting repeatable policy exception justifications
- Developing an onboarding security checklist
- Creating a security metrics dashboard
- Standardizing risk register entries
- Building a training completion tracker
- Documenting architecture review patterns
- Creating a common response library for audits
- Versioning and maintaining artifact libraries
- Linking control improvements to reduced downtime
- Quantifying risk reduction in financial terms
- Mapping security initiatives to product launches
- Showing how controls enable faster partnerships
- Connecting posture to insurance premium outcomes
- Demonstrating resilience during business stress tests
- Highlighting security's role in customer trust
- Using customer feedback as validation
- Aligning with ESG and sustainability goals
- Presenting security as an enabler of M&A readiness
- Tying maturity to board-level risk appetite
- Creating outcome dashboards for executive review
- Training team leads to speak confidently on controls
- Creating a security ambassador program
- Delegating evidence collection with quality checks
- Building cross-functional security champions
- Hosting monthly security office hours
- Developing talking points for non-security roles
- Creating a knowledge base for common questions
- Running tabletop exercises with business units
- Measuring team confidence over time
- Recognizing peer contributions publicly
- Scaling communication without increasing meetings
- Institutionalizing credibility beyond one leader
- Planning the post-90-day credibility transition
- Setting up recurring review cycles for control health
- Incorporating feedback from peers and auditors
- Adjusting priorities based on business shifts
- Maintaining visibility without over-communicating
- Celebrating team wins to reinforce culture
- Documenting lessons learned for onboarding
- Building a succession plan for leadership continuity
- Updating credibility artifacts annually
- Aligning with strategic planning cycles
- Reinforcing security as a steady business function
- Avoiding credibility decay after initial surge
- Organizing your IP library for quick retrieval
- Tagging artifacts by use case and audience
- Creating a master index of reusable content
- Sharing templates across peer CISO networks
- Contributing to industry working groups
- Publishing non-sensitive insights externally
- Building a personal brand through consistent output
- Using past deliverables to accelerate new roles
- Leveraging your library in board-level discussions
- Passing knowledge to successors systematically
- Measuring the reuse rate of your artifacts
- Turning experience into a personal leadership asset
How this maps to your situation
- Day 1, 30: Assessment and listening
- Day 31, 60: Early wins and evidence building
- Day 61, 90: Narrative shaping and stakeholder alignment
- Day 91+: Sustained influence and compounding IP
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 90 minutes per module, designed for completion over 12 weeks with one module per week.
How this compares to the alternatives
Unlike generic NIST CSF overviews or compliance checklists, this course delivers a phase-specific, implementation-grade plan tailored to the first 90 days of a security leader in a regulated insurance environment, focused on credibility, not just controls.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.