What is the First 90 Days course about?
A step-by-step guide to building executive credibility in your first 90 days Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
What situation is the First 90 Days for?
New security leaders often enter with technical mastery but face unexpected friction when their control priorities don't align with executive expectations. The result? Delayed sign-offs, repeated briefings, and diluted authority in the critical first quarter.
Who is the First 90 Days course for?
First-time or recently promoted CISOs and security VPs in high-growth or post-acquisition tech environments who need to establish credibility fast with non-technical executives.
Who is the First 90 Days course not for?
This is not for compliance analysts, auditors, or consultants building programs for others. It’s for leaders who own the final decision on control scope, sequence, and narrative.
What do you take away from the First 90 Days course?
Define the first 20% of CIS Controls that deliver 80% of executive confidence Structure a 90-day rollout plan that preempts common executive objections Own the decision on which controls to implement, delay, or adapt, without escalation Produce a clear, non-technical narrative that links controls to business continuity Gain repeatable structure for future control expansions without re-proving value.
How does this map to your situation?
New security leader in high-growth environment First-time CISO with dual IT and security responsibilities Post-acquisition integration requiring control alignment Executive expectation for faster risk visibility.
What's included with your purchase?
12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.
What does the First 90 Days cover on delivery and format?
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: 90 minutes per week for four weeks, or binge in one weekend.
Closely related courses: First 90 Days as CISO, AI-Driven Leadership in the First 90 Days.
More answers: what you get with every course, refund policy, all help answers.
A tailored course, built for your situation
First 90 Days: Building Security Credibility with the Board and Executives
A step-by-step guide to building executive credibility in your first 90 days
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
The situation this course is for
New security leaders often enter with technical mastery but face unexpected friction when their control priorities don't align with executive expectations. The result? Delayed sign-offs, repeated briefings, and diluted authority in the critical first quarter.
Who this is for
First-time or recently promoted CISOs and security VPs in high-growth or post-acquisition tech environments who need to establish credibility fast with non-technical executives.
Who this is not for
This is not for compliance analysts, auditors, or consultants building programs for others. It’s for leaders who own the final decision on control scope, sequence, and narrative.
What you walk away with
- Define the first 20% of CIS Controls that deliver 80% of executive confidence
- Structure a 90-day rollout plan that preempts common executive objections
- Own the decision on which controls to implement, delay, or adapt, without escalation
- Produce a clear, non-technical narrative that links controls to business continuity
- Gain repeatable structure for future control expansions without re-proving value
The 12 modules (with all 144 chapters)
- The psychology of executive trust in new security leadership
- How your first control announcement sets the tone
- Three examples of CISOs who gained influence in 60 days
- Mapping technical control choices to business risk language
- Avoiding the 'overdue compliance' positioning trap
- Setting expectations without overpromising
- When to delay a control rollout for strategic gain
- How early wins create space for harder decisions later
- Balancing team credibility with executive alignment
- The role of speed versus completeness in first impressions
- Using data to justify control sequencing decisions
- Creating a decision log that builds confidence
- Which CIS Controls executives actually notice (and which they ignore)
- Control 1: Inventory and control of hardware assets
- Control 2: Inventory of software assets
- Control 4: Controlled use of administrative privileges
- Control 5: Secure configuration for hardware and software
- Control 6: Maintenance, monitoring, and analysis of audit logs
- Control 7: Email and web browser protections
- Control 8: Malware defenses
- Control 9: Limitation and control of network ports
- Control 10: Data recovery
- Control 11: Secure configuration for network devices
- Control 12: Boundary defense
- Why executives disengage from technical details
- The business outcome lens: availability, continuity, trust
- From 'we implemented MFA' to 'we reduced breach likelihood by X'
- Using analogies that resonate with non-technical leaders
- Creating a one-page control impact summary
- How to talk about risk without sounding alarmist
- Framing delays as strategic choices, not failures
- Linking control progress to product or revenue timelines
- Telling the story of improvement over time
- Using visuals that clarify, not confuse
- Anticipating the top five executive questions
- Preparing answers that reinforce authority
- Defining your decision boundary with engineering leads
- When to hold firm on a control implementation
- How to document a justified control delay
- Creating a stakeholder map for each control
- Managing pushback from product teams on timing
- Building consensus without ceding control
- Setting thresholds for when to escalate
- Owning the decision on tooling for control enforcement
- Choosing between build, buy, or adapt for control support
- Deciding which controls require policy updates
- Setting the scope for internal control audits
- Communicating roadmap changes without losing credibility
- Week 1, 2: Discovery and stakeholder alignment
- Week 3, 4: Prioritizing first controls with quick wins
- Week 5, 6: Implementing and validating control effectiveness
- Week 7, 8: Reporting early results to leadership
- Week 9, 10: Expanding control scope based on feedback
- Week 11, 12: Formalizing the control operating model
- Setting measurable milestones for each phase
- Creating a dashboard that shows progress clearly
- Using third-party benchmarks to validate pace
- Incorporating team feedback into the timeline
- Adjusting for unexpected delays without losing trust
- Finalizing the plan for post-90-day sustainability
- The anatomy of a one-pager that clears the room
- How to structure a control status report
- Choosing the right metrics for executive consumption
- Avoiding jargon in written deliverables
- Designing a control maturity heatmap
- Using before-and-after comparisons effectively
- Including risk context without overcomplicating
- Formatting for readability in 90 seconds or less
- Creating a living document that evolves
- Version control for executive artifacts
- Ensuring documents are audit-ready from day one
- Building a template library for future use
- Setting the agenda to reflect your priorities
- Preparing for common质疑 and concerns
- Using data to support every claim
- How to handle 'why not more' questions
- Positioning delays as strategic trade-offs
- Getting confirmation, not just feedback
- Following up with clear next steps
- Documenting decisions to prevent re-litigation
- Building in mechanisms for ongoing review
- Creating a rhythm for future updates
- Establishing your role as the final decision point
- Exiting the meeting with momentum
- Defining what constitutes a valid control exception
- Creating a formal exception request process
- Requiring business justification for delays
- Setting expiration dates for all exceptions
- Tracking exceptions in a central register
- Reporting exception trends to leadership
- Using exceptions to highlight resource constraints
- Negotiating temporary vs. permanent changes
- Ensuring exceptions don’t become permanent workarounds
- Auditing exception compliance regularly
- Closing exceptions with validation evidence
- Reinforcing control standards after adaptation
- Communicating the 'why' behind each control
- Linking control work to engineering incentives
- Creating clear ownership at the team level
- Providing tools and templates to reduce friction
- Recognizing early adopters publicly
- Holding regular syncs without micromanaging
- Using retrospectives to improve control rollout
- Incorporating feedback into future planning
- Balancing control rigor with development velocity
- Addressing burnout from compliance work
- Building internal champions across teams
- Measuring team adoption and adjusting approach
- Evaluating what worked in the first quarter
- Identifying areas for refinement
- Planning the next phase of control expansion
- Incorporating lessons into team onboarding
- Updating documentation to reflect current state
- Setting quarterly review cycles
- Measuring control effectiveness over time
- Integrating with risk and audit functions
- Scaling the model to new business units
- Preparing for acquisition or expansion
- Maintaining executive visibility without over-communicating
- Reinforcing decision ownership as new challenges arise
- Selecting the right benchmark for your stage
- Using CIS Controls benchmarks to justify pace
- Engaging assessors to validate your roadmap
- Incorporating findings without losing control
- Responding to gaps with action, not defensiveness
- Sharing positive results strategically
- Using peer comparisons to set realistic goals
- Preparing for auditor questions in advance
- Building assessment readiness into the timeline
- Creating a continuous evidence collection process
- Reducing last-minute scrambles before audits
- Turning assessments into credibility assets
- 90-day control rollout timeline template
- Executive one-pager template with placeholders
- Control prioritization matrix
- Stakeholder communication plan
- Control exception register
- Weekly progress tracker
- Risk narrative builder
- Dashboard template for executive reporting
- Team alignment checklist
- Meeting agenda for first executive review
- Post-review follow-up email templates
- Implementation playbook with step-by-step guidance
How this maps to your situation
- New security leader in high-growth environment
- First-time CISO with dual IT and security responsibilities
- Post-acquisition integration requiring control alignment
- Executive expectation for faster risk visibility
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: 90 minutes per week for four weeks, or binge in one weekend.
How this compares to the alternatives
Unlike generic compliance courses, this program is built specifically for first-time security leaders who need to establish credibility fast. It’s not about passing an audit, it’s about owning the narrative, the roadmap, and the decisions from day one.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.