What is the First 90 Days course about?
A tactical playbook for security leaders to establish trust, align controls to business outcomes, and expand influence across risk, compliance, and technology teams from day one Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
What situation is the First 90 Days for?
Security leaders enter high-stakes roles with deep technical knowledge but face a different challenge: translating controls into business value, aligning with risk and compliance calendars, and earning peer-level credibility across silos. Without a structured approach, early momentum stalls, stakeholders delay buy-in, and influence remains confined to technical teams.
Who is the First 90 Days course for?
Head of Information Security, CISO, or senior security leader in financial services , particularly superannuation, asset management, or retail banking , stepping into a new role or high-visibility initiative requiring cross-functional alignment.
What do you take away from the First 90 Days course?
Enter the first 90 days with a pre-built stakeholder engagement plan targeting risk, compliance, and business unit leads Align security control narratives to business outcomes like member protection and operational resilience Produce a first executive briefing that establishes authority and vision without rework Reduce time spent on cross-team alignment from weeks to structured, repeatable touchpoints Extend influence beyond IT into risk governance.
How does this map to your situation?
Onboarding into a new security leadership role Aligning security with business outcomes in finance Establishing executive credibility fast Extending influence across risk, compliance, and operations.
What's included with your purchase?
12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.
What does the First 90 Days cover on delivery and format?
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: 90 minutes per week over 12 weeks, or self-paced completion in 6, 8 weeks with deeper implementation focus.
How does this compare to the alternatives?
Generic security leadership courses focus on frameworks and theory. This course delivers an implementation-grade playbook with financial services-specific examples, templates, and stakeholder strategies used by top security leaders to build real influence from day one.
Closely related courses: First 90 Days as CISO, AI-Driven Leadership in the First 90 Days.
More answers: what you get with every course, refund policy, all help answers.
A tailored course, built for your situation
First 90 Days: Building Security Credibility in Financial Services
A tactical playbook for security leaders to establish trust, align controls to business outcomes, and expand influence across risk, compliance, and technology teams from day one
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
The situation this course is for
Security leaders enter high-stakes roles with deep technical knowledge but face a different challenge: translating controls into business value, aligning with risk and compliance calendars, and earning peer-level credibility across silos. Without a structured approach, early momentum stalls, stakeholders delay buy-in, and influence remains confined to technical teams.
Who this is for
Head of Information Security, CISO, or senior security leader in financial services , particularly superannuation, asset management, or retail banking , stepping into a new role or high-visibility initiative requiring cross-functional alignment.
Who this is not for
Individual contributors without leadership scope, auditors focused on compliance checklists, or security engineers looking for technical implementation guides.
What you walk away with
- Enter the first 90 days with a pre-built stakeholder engagement plan targeting risk, compliance, and business unit leads
- Align security control narratives to business outcomes like member protection and operational resilience
- Produce a first executive briefing that establishes authority and vision without rework
- Reduce time spent on cross-team alignment from weeks to structured, repeatable touchpoints
- Extend influence beyond IT into risk governance, third-party management, and board-level risk discussions
The 12 modules (with all 144 chapters)
- Identify the core risk domains in superannuation and asset management
- Break down APRA CPS 234, RG 234, and member data protection requirements
- Recognize how security outcomes link to business continuity and trust
- Map the key business units influencing and influenced by security
- Assess the risk appetite language used by executive teams in finance
- Locate where security controls intersect with customer experience
- Determine the audit and reporting cycles that drive credibility
- Understand how technology debt impacts security messaging
- Track the role of third-party vendors in trust erosion or enhancement
- Evaluate past incidents and their organizational memory
- Identify the informal decision influencers outside formal org charts
- Benchmark credibility gaps across peer financial institutions
- Prepare targeted questions for CFO, CRO, and technology leaders
- Identify what each executive measures as a security win
- Surface unspoken concerns about past breaches or near misses
- Map decision rights across compliance, risk, and IT governance
- Capture how security has been framed in past board papers
- Document the language used to describe risk tolerance
- Determine which past initiatives failed and why
- Assess the maturity of existing control reporting
- Uncover alignment points with privacy and fraud teams
- Identify upcoming regulatory milestones affecting security
- Gather intelligence from middle managers and team leads
- Synthesize findings into a credibility baseline
- Prioritize stakeholders by influence and vulnerability to risk
- Craft messaging tailored to risk, compliance, and business leads
- Schedule initial one-on-one meetings with clear objectives
- Prepare data-backed talking points on control effectiveness
- Document existing pain points in cross-functional workflows
- Identify shared goals between security and other functions
- Establish regular sync points with key partners
- Develop a feedback loop for early credibility signals
- Track alignment gaps and address them proactively
- Integrate stakeholder input into control design
- Build coalitions around common risk reduction goals
- Avoid common onboarding missteps that erode trust
- Reframe firewall rules as member data protection enablers
- Link access controls to operational resilience and fraud prevention
- Position patch management as a continuity risk mitigator
- Translate incident response plans into business recovery timelines
- Align security KPIs with business performance metrics
- Use financial language to describe risk reduction value
- Build narratives around third-party vendor risk and fund stability
- Connect cloud security to investment platform reliability
- Frame phishing prevention as a customer trust safeguard
- Present security as a business enabler, not a blocker
- Create repeatable messaging for different audience levels
- Test narratives with trusted cross-functional peers
- Define the core message: security as a value protector
- Select three high-impact control areas to highlight
- Include evidence of alignment with business priorities
- Incorporate stakeholder feedback from early meetings
- Use visuals to show risk reduction over time
- Anticipate and address likely executive questions
- Include a clear 60-day action plan with milestones
- Link initiatives to regulatory and audit timelines
- Attach simplified control validation summaries
- Add testimonials or support from early allies
- Ensure tone balances confidence with collaboration
- Finalize distribution list and follow-up protocol
- Select three high-visibility controls for initial validation
- Define evidence requirements aligned with auditor expectations
- Engage compliance teams early in evidence collection
- Standardize evidence formats across teams
- Conduct dry runs with internal stakeholders
- Address gaps without escalating concerns
- Document remediation steps transparently
- Produce a validation summary for executive review
- Share outcomes with peer leaders to build momentum
- Incorporate feedback into control refinement
- Establish a repeatable validation rhythm
- Highlight reduction in rework and last-minute fixes
- Identify upcoming projects needing security input
- Position security as a design partner, not a gatekeeper
- Embed in project kickoffs for digital transformation
- Contribute to vendor selection and contract reviews
- Co-develop risk narratives for executive updates
- Join cross-functional risk working groups
- Influence third-party risk assessment criteria
- Collaborate on business continuity planning
- Shape incident response communication protocols
- Support regulatory submission reviews
- Expand security representation in operational forums
- Measure influence by participation in peer-led initiatives
- Design a standard executive briefing template
- Create a stakeholder engagement tracking sheet
- Develop a control validation checklist
- Build a risk-to-business-outcome mapping table
- Standardize incident reporting summaries
- Create a vendor security assessment scorecard
- Develop a cross-functional audit readiness calendar
- Build a security initiative impact dashboard
- Design a stakeholder feedback collection form
- Create a playbook for new security leaders
- Document escalation paths and decision triggers
- Package artifacts for team adoption
- Map key regulatory reporting deadlines across the year
- Align control validation to APRA, ASIC, and privacy cycles
- Prepare evidence packages ahead of auditor requests
- Coordinate with internal audit on scope and timing
- Position security as a proactive partner, not a source of findings
- Document control improvements with source-backed evidence
- Anticipate common auditor questions and prepare answers
- Use audit outcomes to demonstrate leadership impact
- Share positive findings with executive sponsors
- Turn compliance requirements into business risk narratives
- Build a reputation for audit readiness
- Reduce last-minute scrambles with proactive planning
- Identify pain points in current cross-team workflows
- Propose solutions that reduce their workload or risk
- Co-own risk reduction initiatives with peer leads
- Celebrate joint wins in team meetings and updates
- Offer support during their high-pressure cycles
- Share security insights that help their decision-making
- Avoid blaming or highlighting failures publicly
- Build trust through consistent follow-through
- Use data to show mutual benefit of collaboration
- Address conflicts with private, solution-focused conversations
- Create shared dashboards for cross-functional risk
- Establish peer recognition for collaborative efforts
- Prepare a crisis communication protocol for security
- Build relationships with comms and legal teams in advance
- Develop holding statements for common incident types
- Position security as a source of clarity during uncertainty
- Support change management with risk-informed guidance
- Stay visible but measured during high-pressure events
- Protect credibility by avoiding over-promising
- Use past credibility to gain early seat at incident tables
- Document lessons without assigning blame
- Reinforce trust through consistent, calm presence
- Leverage past successes to gain decision influence
- Rebuild momentum after disruptions with clear action
- Identify high-impact initiatives outside IT security
- Position security as a design enabler for new products
- Influence investment decisions with risk-reward analysis
- Shape third-party governance frameworks
- Join executive working groups on digital transformation
- Co-develop risk appetite statements with business leads
- Advise on customer experience changes with security input
- Support M&A due diligence with security assessments
- Influence talent strategy with security capability planning
- Shape innovation labs with embedded security principles
- Become the trusted advisor for risk-informed leadership
- Measure success by influence in non-security forums
How this maps to your situation
- Onboarding into a new security leadership role
- Aligning security with business outcomes in finance
- Establishing executive credibility fast
- Extending influence across risk, compliance, and operations
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: 90 minutes per week over 12 weeks, or self-paced completion in 6, 8 weeks with deeper implementation focus.
How this compares to the alternatives
Generic security leadership courses focus on frameworks and theory. This course delivers an implementation-grade playbook with financial services-specific examples, templates, and stakeholder strategies used by top security leaders to build real influence from day one.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.