In this article:

The First 90 Days With a Fractional CISO

Cybersecurity
/
July 13, 2026
The First 90 Days With a Fractional CISO

A well-run first 90 days with a fractional CISO follows a fixed arc: assess in weeks 1 through 4, prioritize in weeks 5 through 8, operate in weeks 9 through 12. By day 30 you should hold an asset and data inventory, a control baseline scored against whichever framework applies to you, and a list of open risks nobody had written down before. By day 60 that list should be a ranked risk register with owners, costs, and dates that a board member can read in ten minutes. By day 90 the quick wins should be closed, the policy set ratified by named owners, and an incident response plan exercised at least on paper. If those artifacts do not exist at those marks, the engagement has stalled, and the fix is a scope conversation rather than more time.

The week before week one

The clock starts badly when access does not exist. Before day one, the engagement needs read access to the identity provider, the cloud consoles, the endpoint management tool, the ticketing system, and any compliance platform already in use, plus a calendar hold with the executive sponsor and an introduction to the company that says what the fractional CISO is authorized to decide. That last item does more for the first month than any tool access.

Set the reporting line at the same time. The fractional CISO should report to the CEO, COO, or CFO, not into IT. If the person who owns the systems being assessed also controls what gets escalated, the assessment will be politely incomplete.

Weeks 1 to 4: assess

The first month is reconnaissance, and it produces facts rather than opinions. Expect 8 to 15 stakeholder interviews across engineering leadership, IT, HR, finance, sales, legal, and the executive team, each 45 to 60 minutes, each asking the same underlying question: what would hurt most if it went wrong, and who would notice.

Two inventories come out of that work. The asset inventory covers cloud accounts, SaaS applications, endpoints, identity providers, code repositories, and production data stores. At a company of 100 to 300 people the discovered SaaS count is routinely 30 to 50 percent higher than the list IT maintains, because departments buy tools with a credit card. The data inventory is the one that generates the uncomfortable findings: production data copied into an analytics warehouse, customer records in a support tool nobody classified, a storage bucket from a 2021 project still holding exports.

Alongside the inventories comes a control baseline, scored against whichever framework the business is already accountable to, whether that is the SOC 2 trust services criteria, ISO 27001 Annex A, or NIST CSF 2.0. A company that has never done this typically scores 40 to 70 percent of controls as partially in place, which is a normal and not alarming starting point. What matters is the evidence question: not whether a control exists, but whether someone can show it working today.

The last input is the pile of things already known and unresolved: prior penetration test reports, current vulnerability scan output, audit findings, exceptions logged on customer security questionnaires, and every incident from the past 24 months. Most companies are sitting on 20 to 40 documented issues that never got an owner. Collecting them is fast and reliably produces the first quick wins.

Weeks 5 to 8: prioritize

The second month converts findings into a risk register the board can read, and the word that matters is ranked. A useful register holds 20 to 40 entries, not 200. Each entry names a scenario in business terms, states likelihood and impact with a dollar figure or a downtime estimate where one can be defended, lists the controls currently in place, records the treatment decision, and carries a named owner with a date. A register that lists 180 technical findings is an export, not a decision tool, and executives stop reading it by row 12.

Alongside the register comes a 12 month roadmap divided into four quarters, each with one defined outcome rather than a list of activities. Costs get separated at this stage too. In most first-year programs, 60 to 70 percent of the work is process and configuration change that costs internal time and no budget, and the remaining 30 to 40 percent needs funding, commonly $40,000 to $150,000 depending on tooling gaps and whether a penetration test or an audit sits in the plan.

The deliverable of month two is not the spreadsheet. It is a two hour session where the leadership team agrees on the top 10 risks, accepts the ones it is choosing to accept in writing, and assigns owners to the rest. Written risk acceptance is the single most underrated artifact of the first 90 days, because it converts security from a nagging function into a business decision with a signature on it.

Weeks 9 to 12: operate

The third month is when the engagement stops describing and starts changing things. Quick wins come first, and there are almost always 6 to 12 available with no budget: closing multifactor authentication gaps on remaining accounts and administrative paths, fixing an offboarding process that leaves access live for weeks, inventorying and reducing standing administrator accounts, running an actual restore test rather than trusting the backup dashboard, turning on logging for the systems that matter most, and reconciling the vendor list against what finance is paying for.

Policy ratification runs in parallel. Most companies of this size need 8 to 14 policies, each with a named owner and an annual review date, written to describe how the company actually works. A 40 document library imported from a template pack is worse than nothing, because auditors and customers can tell, and staff learn quickly that the policies do not describe reality.

Incident readiness is the third piece: severity definitions, a contact tree that includes legal and the cyber insurer, notification triggers mapped to the contracts and regulations that apply, and one 90 minute tabletop exercise with the people who would actually be in the room. The first tabletop nearly always surfaces two or three practical gaps, most often that nobody knows who declares an incident and nobody has the insurer's number.

What good looks like at each mark

  • Day 30. Asset and data inventories exist and are reconciled against finance and the identity provider. A control baseline is scored with evidence notes. Every known open issue is in one list. You have met the named CISO at least four times and engineering has met them at least twice.
  • Day 60. A ranked risk register of 20 to 40 entries with owners, dates, and impact estimates. A four quarter roadmap with one outcome per quarter. A funded budget request with real numbers. Documented risk acceptance decisions signed by an executive.
  • Day 90. Six or more quick wins closed and verifiable in the systems themselves. A ratified policy set of 8 to 14 documents with owners. A tested incident response plan and a completed tabletop with written findings. A monthly metrics pack delivered at least once and a board summary ready to send.

What a stalled engagement looks like

Stalled engagements share a look. At day 30 the only artifact is a gap assessment spreadsheet that clearly came from a template, with no inventory behind it, because nobody logged into your environment. At day 60 the risk register has 150 rows and no owners, which means no prioritization happened, only collection. Policies arrive as a document pack that mentions a defined term your company does not use. Meetings are status updates rather than decisions, and the standing question, what changed since last month, has no answer that a system could confirm.

Three more signals are worth watching. The named individual keeps changing, which means you bought a queue rather than a person. Nothing has been touched in production, which means the engagement is advising around the edges instead of driving change. And engineering has never met the CISO, which is the clearest indicator of all.

The response to a stall is not patience. It is a 30 minute conversation naming the missing artifacts and the dates they are now due, followed by a decision about scope. Comparing the day rate you are paying against the arc described above is a fair test, and our breakdown of fractional versus full-time CISO economics covers what each tier should reasonably deliver.

Some of the failure modes sit on your side of the table. If the executive who signed the contract cannot spend an hour a month on it, decisions queue and nothing gets assigned. And an engagement measured only on getting an audit report over the line will deliver exactly that, leaving the underlying risks in place, because that is what was asked for.

Where BD Emerson fits

Our fractional CISO engagements run this arc deliberately, with a named operator, a defined day commitment, and the day 30, 60, and 90 artifacts written into the scope so both sides can check progress against something specific. For distributed teams and companies without a central office, the virtual CISO model delivers the same sequence remotely. The first quarter sets whether security becomes an operating function or another vendor relationship, so it is worth measuring closely while it happens.

About the author

Leslie Sakal is a Managing Director at BD Emerson focused on cybersecurity, enterprise risk management, and regulatory compliance. She brings over a decade of experience advising organizations across technology, financial services, education, and other regulated industries on implementing organization-wide goals and programs that align with their broader business objectives.
Leslie Sakal
Leslie Sakal
Managing Director