Entering a company as a new CISO can be intimidating, overwhelming and stressful from day one.

With high-profile breaches occurring every day and increasing scrutiny from regulatory bodies, organizations expect results — fast. This amid a talent shortage and tightened budgets.

“The CISO role sounds like a lot of impossible requirements for one human,” Merritt Baer, field CISO for DevOps, container and cloud security company Lacework, told SDxCentral. “It feels increasingly, impossibly, a chase for perfectionism.”

However, CISOs can take deliberate, specific steps in their first 90 days on the job — and build on those well beyond — to help ensure they are successful in their roles and that their organizations are secure.

“The intimidation of security as a field, it’s sort of where do I start?” said Baer. “A lot of times the answer is ‘start somewhere.’”

Days 1–60: Listen, learn, assess

While it can be tempting to dive in headlong and start mapping out strategies and roadmaps, Baer advises new CISOs to take it slow and perform a thorough, initial assessment.

“Come in, find out what the state of play is, the technology stuff that you can quickly address,” she said.

There is power in listening, so ask a lot of questions in the initial weeks — before taking any strong actions. Firefighting serious problems is a necessity of course, Baer said; do the quick-hit stuff to get it out of the way first.

After addressing those, focus on understanding how the organization works and how the security team gets things done (or doesn’t) and who works together (and well) and who doesn’t. Also analyze the current security budget and identify existing tools (or lack thereof), processes, priorities and hierarchies.

Baer pointed out that many enterprises claim to be “flat” with complete lines of communication to leadership, “but the reality is all organizations have hierarchy,” as well as formalities and rituals, of sorts. It’s important to be clear on who makes decisions around business priorities, budgeting and hiring and firing.

In doing so, be sure to get on calendars for leaders in legal, finance, product and HR departments, as well as the C-suite, Baer advised. Find out what they care about and what they think hasn’t been working. Knowing what metrics fellow leaders are using to hold security teams accountable is critical, too.

On the technical side, perform an inventory of assets and a vendor review, ensure that an incident response plan is in place, identify what the organization is doing around access (including for third-party apps) and begin preparing to respond to regulatory compliance questions, Baer emphasized.

A sampling of questions to ask:

  • Where are root credentials stored and how are they protected?
  • Who has super-admin access and what is the process for obtaining that?
  • Is the organization encrypting — by default — data at-rest and in-transit?
  • Have any former employees’ permissions been revoked?

“You’re probably not best off making huge changes in your first few weeks,” Baer wrote in a blog post, adding that one of her best practices is writing notes to herself and setting them aside for later. “In other words, save those ‘fresh eyes’ insights and decide when — and how — to question the status quo after a few months.”

Days 60–90: Broadening to short-term action plans

After gaining a strong understanding of processes, chains of command, tools and day-to-day workings — which Baer says should take a good 60 days — CISOs can begin crafting longer-term plans.

This includes developing incident runbooks and playbooks, gathering metrics for reporting to the board and training and upskilling the security team. By a couple of months in, security leaders should have a strong grasp of the security tools in place (and what’s lacking), whether vendors are delivering on their promises and what tools are being paid for but aren’t being used. With C-suite and board approval, they can now begin to act on those insights.

“It’s setting more of a vision, starting to do those paved roads,” said Baer.

With those initial assessment months behind you, you can start getting tactical, consolidating tools, and establishing cadence with patching and automating as much as possible, she advised.

“The day you come in, you’re not going to change manual processes to automation,” Baer said. “At 60 days you should be looking at that.”

When beginning to implement changes, CISOs should ensure that they aren’t hindering innovation or preventing developers from building effectively. The goal is reasonable constraints, Baer emphasized.

“Those bumps should feel reasonable,” she said.

Furthermore, at this critical juncture, security leaders must begin showing their department’s progress.

“Within 60 days, you’re going to have to present some external metrics, what you’re spending time on, how you can elevate that,” said Baer.

90 days and beyond: Tackling long-term strategy

It’s not until a good 90 days in that CISOs should begin mapping out long-term strategy, according to Baer.

This is when security leaders should define their metrics for success, both short-term (such as the timeframe for addressing a ticket item) and long-term (reducing development cycles, for instance).

These should be presented in a business-oriented manner to non-security leaders and employees. For example, what does improvement in response time do for business continuity? Or, what is the real cost of downtime? At the same time, you should record and communicate your wins.

Be sure to look at the makeup of the board if there is one, Baer added, and suggest security representation if it’s noticeably absent from the table.

Furthermore, she said, embedding a security engineer in continuous integration and continuous delivery (CI/CD) teams can minimize AppSec review times and more closely align the goals of developer teams (and their focus on “make it work”) with those of the security teams (and their focus on “make it secure”).

For continuous improvement, allow both skepticism and growth, as well as mechanisms for customer feedback; keep an eye on emerging technologies — ahem, AI — and new attack vectors and methods and ensure that your team isn’t getting burnt out.

“You can get to the point where you’re refining some of the machinery that you have put in place,” said Baer. “You can continue the good stuff you’ve started, making a ritual flywheel.”

A creative field with artistry, subjectivity

Security is a sensitive space, and there is tremendous pressure on CISOs to deliver, Baer noted.

It can all be a bit too much: A recent study, in fact, found that almost a third (32%) of CISOs or IT cybersecurity leaders in the U.S. and UK were considering leaving their current organization. Nine out of 10 CISOs also report that they are “moderately” or “tremendously” stressed, and the average CISO tenure is just two years and two months.

“It kind of feels like there’s no winning in the CISO world,” said Baer. “The role of the CISO is lonely; part of that is it is hard to acknowledge or advertise that you don’t know all the answers. In reality no one knows all the answers.”

While there is “tepid guidance” out there that “tells truisms” — such as the old adage ‘good leaders delegate’ — those are not “implementable nor novel,” said Baer.

Her goal, therefore, is to provide true, working guidance, from CISOs to CISOs, to help them navigate their complex jobs in a field that she described as creative and full of artistry and subjectivity.

At the end of the day, Baer said, “what I want is for [security] to be accessible to all smart people who think differently and want to take it on.”