Skip to main content
Image coming soon

SEC6728 First 90 Days: Building Security Credibility in Nonprofit Leadership

$199.00
Adding to cart… The item has been added

What is the First 90 Days course about?

A step-by-step implementation path for IT and security leaders establishing authority in mission-driven organizations Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

What situation is the First 90 Days for?

New security leaders in nonprofits often face a credibility gap: strong technical judgment but limited buy-in during early stakeholder reviews. The result is last-minute rework of control justifications, delayed sign-offs, and weakened positioning, especially under audit or donor scrutiny. This course eliminates that gap by teaching how to build a defensible, mission-aligned rationale from day one.

Who is the First 90 Days course for?

IT and security executives transitioning into leadership roles within mission-driven or nonprofit organizations, where technical decisions must be justified in terms of stewardship, transparency, and public trust.

What do you take away from the First 90 Days course?

Walk into any leadership meeting with a clear, source-backed rationale for control choices Reduce stakeholder rework in security onboarding by anchoring decisions in COBIT and mission risk Build unassailable credibility in the first 90 days through structured documentation and precedent Align security initiatives with nonprofit governance expectations and donor accountability Shift from technical expert to trusted leadership advisor with a repeatable credibility.

How does this map to your situation?

Week 1: Entry and assessment Weeks 2, 4: Stakeholder alignment and documentation Weeks 5, 8: Control justification and budget planning Weeks 9, 12: Audit prep, incident readiness, and long-term positioning.

What's included with your purchase?

12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.

What does the First 90 Days cover on delivery and format?

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: 90 minutes per week over 12 weeks, with flexible pacing and immediate access to all materials.

How does this compare to the alternatives?

Unlike generic security leadership courses, this program is specifically designed for nonprofit contexts, with COBIT implementation, mission-risk framing, donor audit alignment, and credibility-building artifacts that standard frameworks overlook.

Closely related courses: First 90 Days as CISO, AI-Driven Leadership in the First 90 Days, Building Credibility in Crucial Conversations, Building Credibility in Team Building Dataset.

More answers: what you get with every course, refund policy, all help answers.

A tailored course, built for your situation

First 90 Days: Building Security Credibility in Nonprofit Leadership

A step-by-step implementation path for IT and security leaders establishing authority in mission-driven organizations

$199 one-time
30-day money-back guarantee Verified against latest insights, updated access provided within 24h

Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Security onboarding narratives that stall during alignment cycles

The situation this course is for

New security leaders in nonprofits often face a credibility gap: strong technical judgment but limited buy-in during early stakeholder reviews. The result is last-minute rework of control justifications, delayed sign-offs, and weakened positioning, especially under audit or donor scrutiny. This course eliminates that gap by teaching how to build a defensible, mission-aligned rationale from day one.

Who this is for

IT and security executives transitioning into leadership roles within mission-driven or nonprofit organizations, where technical decisions must be justified in terms of stewardship, transparency, and public trust

Who this is not for

Junior security analysts, auditors focused solely on compliance checklists, or consultants selling one-size-fits-all frameworks without nonprofit context

What you walk away with

  • Walk into any leadership meeting with a clear, source-backed rationale for control choices
  • Reduce stakeholder rework in security onboarding by anchoring decisions in COBIT and mission risk
  • Build unassailable credibility in the first 90 days through structured documentation and precedent
  • Align security initiatives with nonprofit governance expectations and donor accountability
  • Shift from technical expert to trusted leadership advisor with a repeatable credibility framework

The 12 modules (with all 144 chapters)

Module 1. Establishing Security Credibility in Mission-Driven Organizations
Understand the unique expectations of security leadership in nonprofits, where technical decisions must reflect stewardship and public trust.
12 chapters in this module
  1. Why security credibility differs in nonprofit versus for-profit environments
  2. Mapping stakeholder expectations: board, donors, auditors, and program teams
  3. The role of transparency in building early leadership trust
  4. How donor scrutiny shapes security decision timelines
  5. Balancing urgency with due process in mission-critical environments
  6. Defining 'success' for a new CISO in a nonprofit context
  7. Common credibility pitfalls in the first 60 days
  8. The importance of narrative consistency across security communications
  9. Using mission alignment to preempt resistance to controls
  10. How to audit your own credibility trajectory in week one
  11. Benchmarking against peer nonprofit security rollouts
  12. Setting credibility milestones for weeks 1, 30, 60, and 90
Module 2. COBIT Framework Foundations for Nonprofit Security
Master the core COBIT domains and governance objectives with emphasis on nonprofit applicability.
12 chapters in this module
  1. Overview of COBIT the current cycle governance and management objectives
  2. Selecting relevant COBIT domains for nonprofit IT environments
  3. Adapting COBIT performance management for limited-resource settings
  4. How COBIT supports compliance with nonprofit-specific regulations
  5. Mapping COBIT goals to mission risk and accountability
  6. Integrating COBIT with existing nonprofit policies and controls
  7. Using COBIT to justify security investments to non-technical leaders
  8. COBIT and the alignment of IT with organizational purpose
  9. Common misapplications of COBIT in nonprofit settings
  10. How to simplify COBIT for executive consumption without losing rigor
  11. COBIT's role in audit readiness and donor reporting
  12. Building a nonprofit-specific COBIT implementation checklist
Module 3. Security Onboarding: The First 14 Days
Execute a structured entry plan that establishes presence, listens strategically, and sets early priorities.
12 chapters in this module
  1. Day 1: Setting the tone through internal communications
  2. Mapping key stakeholders and influence networks in week one
  3. Conducting a mission-risk informed security landscape review
  4. Identifying quick wins that reinforce credibility without overreach
  5. Scheduling foundational meetings with program and finance leaders
  6. How to document observations without triggering defensiveness
  7. Creating a visibility plan: what to share and when
  8. Using COBIT to frame initial assessment findings
  9. Avoiding the 'fixer' trap in early engagements
  10. Building a listening-first narrative across teams
  11. Establishing baseline metrics that matter to leadership
  12. Preparing your first 30-day update for executive review
Module 4. Stakeholder Alignment Through Control Rationale
Develop and deliver justifications for security controls that resonate with non-technical audiences.
12 chapters in this module
  1. Why technical correctness isn't enough for stakeholder buy-in
  2. Translating control requirements into mission risk language
  3. Using COBIT to structure defensible decision narratives
  4. Common stakeholder objections and how to preempt them
  5. Building a library of precedent-based justification examples
  6. How to use donor audit findings as alignment leverage
  7. Creating one-pagers for key controls with COBIT citations
  8. Tailoring messaging for program, finance, and communications leads
  9. Running alignment sessions without sounding defensive
  10. Documenting rationale for future review cycles
  11. How to handle 'Why do we need this?' with confidence
  12. Reinforcing rationale through consistent repetition
Module 5. Documentation That Builds Trust
Produce artifacts that serve as both operational tools and credibility signals.
12 chapters in this module
  1. Designing security documentation for executive readability
  2. The credibility value of version-controlled rationale logs
  3. Creating a master control register with COBIT mappings
  4. Using templates to standardize justification language
  5. How documentation reduces rework during audit cycles
  6. Building a public-facing security summary for donor review
  7. Internal dashboards that demonstrate progress without alarm
  8. Archiving decisions to prevent 're-litigation' in meetings
  9. Linking documentation to COBIT governance objectives
  10. Ensuring accessibility without compromising sensitivity
  11. Versioning and approval workflows for key artifacts
  12. Using documentation to train new team members efficiently
Module 6. Security Budgeting and Resource Justification
Frame investments in terms of stewardship, risk reduction, and donor confidence.
12 chapters in this module
  1. Translating technical needs into budget narrative language
  2. Using COBIT to justify tooling and headcount decisions
  3. Benchmarking nonprofit security spending against peers
  4. How to present trade-offs without sounding alarmist
  5. Building a phased investment roadmap with clear milestones
  6. Aligning budget requests with donor reporting cycles
  7. Using past incidents (even near-misses) as justification
  8. Creating a 'security stewardship' section in annual reports
  9. How to handle budget cuts without sacrificing core controls
  10. Partnering with finance to model risk-based investment cases
  11. Documenting opportunity cost of deferred initiatives
  12. Preparing for Q4 budget reviews with preemptive artifacts
Module 7. Audit and Donor Review Preparation
Turn external scrutiny into credibility reinforcement through preparation and narrative control.
12 chapters in this module
  1. Understanding donor audit expectations and timelines
  2. Mapping common donor audit questions to COBIT controls
  3. Preparing evidence packages that tell a coherent story
  4. How to position your team as audit enablers, not gatekeepers
  5. Running internal dry runs with non-security stakeholders
  6. Creating a response playbook for common findings
  7. Using past audits to refine your credibility framework
  8. Balancing transparency with risk exposure in reporting
  9. How to handle unexpected findings during live reviews
  10. Documenting corrective actions with ownership and deadlines
  11. Building a post-audit summary for leadership distribution
  12. Turning audit success into ongoing credibility
Module 8. Incident Response and Public Trust
Manage security events in a way that preserves institutional trust and leadership confidence.
12 chapters in this module
  1. Why incident response in nonprofits is a credibility moment
  2. Designing response playbooks with public communication in mind
  3. COBIT alignment for incident detection and reporting
  4. Stakeholder notification sequences: who, when, how
  5. Creating pre-approved messaging templates for common scenarios
  6. Handling media inquiries without a dedicated PR team
  7. Documenting response decisions for later review
  8. Conducting post-incident reviews that strengthen trust
  9. Using incidents to justify overdue investments
  10. Balancing transparency with legal and reputational risk
  11. Rebuilding credibility after a breach or near-miss
  12. Integrating lessons into ongoing security narrative
Module 9. Vendor and Third-Party Risk Communication
Frame third-party risk management as a stewardship function.
12 chapters in this module
  1. Why vendor reviews matter to donors and auditors
  2. Using COBIT to structure third-party assessments
  3. Creating a vendor risk tiering system for resource prioritization
  4. Communicating vendor risks to non-technical stakeholders
  5. Documenting due diligence for high-risk partners
  6. Handling vendor incidents with donor transparency
  7. Building a vendor attestation process with clear standards
  8. Using third-party risk as a teaching moment for leadership
  9. Aligning vendor reviews with procurement timelines
  10. Creating a public-facing vendor security statement
  11. Managing open source and SaaS tools under nonprofit scrutiny
  12. Archiving vendor decisions for audit continuity
Module 10. Security Awareness as Credibility Building
Use training programs to demonstrate leadership reach and cultural influence.
12 chapters in this module
  1. Designing awareness content that reflects nonprofit values
  2. Measuring engagement beyond completion rates
  3. Using storytelling to make security relatable to mission
  4. Tailoring messaging for staff, volunteers, and contractors
  5. Creating leadership-facing summaries of awareness impact
  6. Linking training outcomes to reduced incident risk
  7. Involving program teams in security message development
  8. Running tabletop exercises that build cross-functional trust
  9. Documenting awareness progress for donor reporting
  10. Using success stories to reinforce credibility
  11. Integrating awareness into onboarding and performance reviews
  12. Scaling programs with limited internal resources
Module 11. Long-Term Credibility Maintenance
Sustain influence beyond the first 90 days through consistency, visibility, and iteration.
12 chapters in this module
  1. Establishing a rhythm of security updates for leadership
  2. Using metrics that reflect mission alignment and risk reduction
  3. Avoiding over-communication that leads to fatigue
  4. Reinforcing credibility during leadership transitions
  5. Updating control rationales as threats evolve
  6. Incorporating feedback without appearing inconsistent
  7. Building coalitions with peer functional leaders
  8. Using external speaking opportunities to elevate internal standing
  9. Maintaining a living COBIT alignment map
  10. Conducting quarterly credibility self-assessments
  11. Documenting wins without sounding self-promotional
  12. Preparing for succession while preserving institutional knowledge
Module 12. The Hand-Built Implementation Playbook
Deliverable package to launch and sustain the credibility framework.
12 chapters in this module
  1. How to use the personalized implementation playbook
  2. Customizing the 90-day roadmap for your organization
  3. Populating stakeholder maps with your team’s context
  4. Adapting COBIT mappings to your existing controls
  5. Setting up documentation templates in your environment
  6. Using the rationale library with real nonprofit examples
  7. Integrating the budget justification toolkit
  8. Running the first internal dry run using the audit prep kit
  9. Launching the awareness program with starter content
  10. Tracking progress with the credibility milestone checklist
  11. Updating the playbook as your role evolves
  12. Sharing select components without compromising security

How this maps to your situation

  • Week 1: Entry and assessment
  • Weeks 2, 4: Stakeholder alignment and documentation
  • Weeks 5, 8: Control justification and budget planning
  • Weeks 9, 12: Audit prep, incident readiness, and long-term positioning

Before vs. after

Before
Security leaders enter nonprofit roles with technical strength but face rework, skepticism, and delayed influence due to misaligned narratives and undocumented rationales.
After
They establish unassailable credibility in 90 days with a COBIT-grounded, mission-aligned, and precedent-backed framework that withstands stakeholder scrutiny and audit cycles.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: 90 minutes per week over 12 weeks, with flexible pacing and immediate access to all materials.

If nothing changes
Without a structured credibility approach, even technically sound decisions face repeated challenges, delay implementation, erode trust, and expose the organization to preventable risk during donor and audit reviews.

How this compares to the alternatives

Unlike generic security leadership courses, this program is specifically designed for nonprofit contexts, with COBIT implementation, mission-risk framing, donor audit alignment, and credibility-building artifacts that standard frameworks overlook.

Frequently asked

Is this course only for CISOs?
No. It's designed for IT and security leaders in mission-driven organizations, including CISOs, IT directors, and technology executives establishing credibility in nonprofit environments.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Does the course include live support or office hours?
No. The course is self-paced and text-based, with comprehensive templates and a hand-built implementation playbook for immediate application.
$199 one-time. 90 minutes per week over 12 weeks, with flexible pacing and immediate access to all materials..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours