What is the First 90 Days course about?
A step-by-step implementation path for IT and security leaders establishing authority in mission-driven organizations Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
What situation is the First 90 Days for?
New security leaders in nonprofits often face a credibility gap: strong technical judgment but limited buy-in during early stakeholder reviews. The result is last-minute rework of control justifications, delayed sign-offs, and weakened positioning, especially under audit or donor scrutiny. This course eliminates that gap by teaching how to build a defensible, mission-aligned rationale from day one.
Who is the First 90 Days course for?
IT and security executives transitioning into leadership roles within mission-driven or nonprofit organizations, where technical decisions must be justified in terms of stewardship, transparency, and public trust.
What do you take away from the First 90 Days course?
Walk into any leadership meeting with a clear, source-backed rationale for control choices Reduce stakeholder rework in security onboarding by anchoring decisions in COBIT and mission risk Build unassailable credibility in the first 90 days through structured documentation and precedent Align security initiatives with nonprofit governance expectations and donor accountability Shift from technical expert to trusted leadership advisor with a repeatable credibility.
How does this map to your situation?
Week 1: Entry and assessment Weeks 2, 4: Stakeholder alignment and documentation Weeks 5, 8: Control justification and budget planning Weeks 9, 12: Audit prep, incident readiness, and long-term positioning.
What's included with your purchase?
12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.
What does the First 90 Days cover on delivery and format?
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: 90 minutes per week over 12 weeks, with flexible pacing and immediate access to all materials.
How does this compare to the alternatives?
Unlike generic security leadership courses, this program is specifically designed for nonprofit contexts, with COBIT implementation, mission-risk framing, donor audit alignment, and credibility-building artifacts that standard frameworks overlook.
Closely related courses: First 90 Days as CISO, AI-Driven Leadership in the First 90 Days, Building Credibility in Crucial Conversations, Building Credibility in Team Building Dataset.
More answers: what you get with every course, refund policy, all help answers.
A tailored course, built for your situation
First 90 Days: Building Security Credibility in Nonprofit Leadership
A step-by-step implementation path for IT and security leaders establishing authority in mission-driven organizations
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
The situation this course is for
New security leaders in nonprofits often face a credibility gap: strong technical judgment but limited buy-in during early stakeholder reviews. The result is last-minute rework of control justifications, delayed sign-offs, and weakened positioning, especially under audit or donor scrutiny. This course eliminates that gap by teaching how to build a defensible, mission-aligned rationale from day one.
Who this is for
IT and security executives transitioning into leadership roles within mission-driven or nonprofit organizations, where technical decisions must be justified in terms of stewardship, transparency, and public trust
Who this is not for
Junior security analysts, auditors focused solely on compliance checklists, or consultants selling one-size-fits-all frameworks without nonprofit context
What you walk away with
- Walk into any leadership meeting with a clear, source-backed rationale for control choices
- Reduce stakeholder rework in security onboarding by anchoring decisions in COBIT and mission risk
- Build unassailable credibility in the first 90 days through structured documentation and precedent
- Align security initiatives with nonprofit governance expectations and donor accountability
- Shift from technical expert to trusted leadership advisor with a repeatable credibility framework
The 12 modules (with all 144 chapters)
- Why security credibility differs in nonprofit versus for-profit environments
- Mapping stakeholder expectations: board, donors, auditors, and program teams
- The role of transparency in building early leadership trust
- How donor scrutiny shapes security decision timelines
- Balancing urgency with due process in mission-critical environments
- Defining 'success' for a new CISO in a nonprofit context
- Common credibility pitfalls in the first 60 days
- The importance of narrative consistency across security communications
- Using mission alignment to preempt resistance to controls
- How to audit your own credibility trajectory in week one
- Benchmarking against peer nonprofit security rollouts
- Setting credibility milestones for weeks 1, 30, 60, and 90
- Overview of COBIT the current cycle governance and management objectives
- Selecting relevant COBIT domains for nonprofit IT environments
- Adapting COBIT performance management for limited-resource settings
- How COBIT supports compliance with nonprofit-specific regulations
- Mapping COBIT goals to mission risk and accountability
- Integrating COBIT with existing nonprofit policies and controls
- Using COBIT to justify security investments to non-technical leaders
- COBIT and the alignment of IT with organizational purpose
- Common misapplications of COBIT in nonprofit settings
- How to simplify COBIT for executive consumption without losing rigor
- COBIT's role in audit readiness and donor reporting
- Building a nonprofit-specific COBIT implementation checklist
- Day 1: Setting the tone through internal communications
- Mapping key stakeholders and influence networks in week one
- Conducting a mission-risk informed security landscape review
- Identifying quick wins that reinforce credibility without overreach
- Scheduling foundational meetings with program and finance leaders
- How to document observations without triggering defensiveness
- Creating a visibility plan: what to share and when
- Using COBIT to frame initial assessment findings
- Avoiding the 'fixer' trap in early engagements
- Building a listening-first narrative across teams
- Establishing baseline metrics that matter to leadership
- Preparing your first 30-day update for executive review
- Why technical correctness isn't enough for stakeholder buy-in
- Translating control requirements into mission risk language
- Using COBIT to structure defensible decision narratives
- Common stakeholder objections and how to preempt them
- Building a library of precedent-based justification examples
- How to use donor audit findings as alignment leverage
- Creating one-pagers for key controls with COBIT citations
- Tailoring messaging for program, finance, and communications leads
- Running alignment sessions without sounding defensive
- Documenting rationale for future review cycles
- How to handle 'Why do we need this?' with confidence
- Reinforcing rationale through consistent repetition
- Designing security documentation for executive readability
- The credibility value of version-controlled rationale logs
- Creating a master control register with COBIT mappings
- Using templates to standardize justification language
- How documentation reduces rework during audit cycles
- Building a public-facing security summary for donor review
- Internal dashboards that demonstrate progress without alarm
- Archiving decisions to prevent 're-litigation' in meetings
- Linking documentation to COBIT governance objectives
- Ensuring accessibility without compromising sensitivity
- Versioning and approval workflows for key artifacts
- Using documentation to train new team members efficiently
- Translating technical needs into budget narrative language
- Using COBIT to justify tooling and headcount decisions
- Benchmarking nonprofit security spending against peers
- How to present trade-offs without sounding alarmist
- Building a phased investment roadmap with clear milestones
- Aligning budget requests with donor reporting cycles
- Using past incidents (even near-misses) as justification
- Creating a 'security stewardship' section in annual reports
- How to handle budget cuts without sacrificing core controls
- Partnering with finance to model risk-based investment cases
- Documenting opportunity cost of deferred initiatives
- Preparing for Q4 budget reviews with preemptive artifacts
- Understanding donor audit expectations and timelines
- Mapping common donor audit questions to COBIT controls
- Preparing evidence packages that tell a coherent story
- How to position your team as audit enablers, not gatekeepers
- Running internal dry runs with non-security stakeholders
- Creating a response playbook for common findings
- Using past audits to refine your credibility framework
- Balancing transparency with risk exposure in reporting
- How to handle unexpected findings during live reviews
- Documenting corrective actions with ownership and deadlines
- Building a post-audit summary for leadership distribution
- Turning audit success into ongoing credibility
- Why incident response in nonprofits is a credibility moment
- Designing response playbooks with public communication in mind
- COBIT alignment for incident detection and reporting
- Stakeholder notification sequences: who, when, how
- Creating pre-approved messaging templates for common scenarios
- Handling media inquiries without a dedicated PR team
- Documenting response decisions for later review
- Conducting post-incident reviews that strengthen trust
- Using incidents to justify overdue investments
- Balancing transparency with legal and reputational risk
- Rebuilding credibility after a breach or near-miss
- Integrating lessons into ongoing security narrative
- Why vendor reviews matter to donors and auditors
- Using COBIT to structure third-party assessments
- Creating a vendor risk tiering system for resource prioritization
- Communicating vendor risks to non-technical stakeholders
- Documenting due diligence for high-risk partners
- Handling vendor incidents with donor transparency
- Building a vendor attestation process with clear standards
- Using third-party risk as a teaching moment for leadership
- Aligning vendor reviews with procurement timelines
- Creating a public-facing vendor security statement
- Managing open source and SaaS tools under nonprofit scrutiny
- Archiving vendor decisions for audit continuity
- Designing awareness content that reflects nonprofit values
- Measuring engagement beyond completion rates
- Using storytelling to make security relatable to mission
- Tailoring messaging for staff, volunteers, and contractors
- Creating leadership-facing summaries of awareness impact
- Linking training outcomes to reduced incident risk
- Involving program teams in security message development
- Running tabletop exercises that build cross-functional trust
- Documenting awareness progress for donor reporting
- Using success stories to reinforce credibility
- Integrating awareness into onboarding and performance reviews
- Scaling programs with limited internal resources
- Establishing a rhythm of security updates for leadership
- Using metrics that reflect mission alignment and risk reduction
- Avoiding over-communication that leads to fatigue
- Reinforcing credibility during leadership transitions
- Updating control rationales as threats evolve
- Incorporating feedback without appearing inconsistent
- Building coalitions with peer functional leaders
- Using external speaking opportunities to elevate internal standing
- Maintaining a living COBIT alignment map
- Conducting quarterly credibility self-assessments
- Documenting wins without sounding self-promotional
- Preparing for succession while preserving institutional knowledge
- How to use the personalized implementation playbook
- Customizing the 90-day roadmap for your organization
- Populating stakeholder maps with your team’s context
- Adapting COBIT mappings to your existing controls
- Setting up documentation templates in your environment
- Using the rationale library with real nonprofit examples
- Integrating the budget justification toolkit
- Running the first internal dry run using the audit prep kit
- Launching the awareness program with starter content
- Tracking progress with the credibility milestone checklist
- Updating the playbook as your role evolves
- Sharing select components without compromising security
How this maps to your situation
- Week 1: Entry and assessment
- Weeks 2, 4: Stakeholder alignment and documentation
- Weeks 5, 8: Control justification and budget planning
- Weeks 9, 12: Audit prep, incident readiness, and long-term positioning
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: 90 minutes per week over 12 weeks, with flexible pacing and immediate access to all materials.
How this compares to the alternatives
Unlike generic security leadership courses, this program is specifically designed for nonprofit contexts, with COBIT implementation, mission-risk framing, donor audit alignment, and credibility-building artifacts that standard frameworks overlook.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.