vCISO & Security Leadership · 4 min read

What should a vCISO deliver in the first 90 days?

Define practical vCISO deliverables: a decision-ready risk register, an owned roadmap, a reporting cadence, and clear responsibility for security work.

Buy defined decisions and deliverables

A virtual chief information security officer, or vCISO, provides fractional security leadership. The title alone does not describe the hours, authority, implementation support, or incident availability included. A useful statement of work defines what leadership will receive, who will act on it, and how progress will be reviewed.

The 90-day sequence below is an example planning framework, not a promised delivery schedule or a requirement imposed by a standard. A small company with a clear inventory may move quickly; a complex organization may spend longer establishing scope and ownership. Agree on the starting conditions and acceptance criteria before selecting a retainer.

First: establish the business context and baseline

Start with the products, revenue dependencies, critical information, contractual commitments, and upcoming decisions. Interview the people who own IT, engineering, operations, finance, and legal or compliance work. Identify existing controls and unfinished projects before proposing another tool or framework.

A useful initial deliverable is a short baseline with scope, evidence reviewed, gaps in available information, and the most consequential risk scenarios. NIST CSF 2.0 can provide a shared vocabulary for cybersecurity outcomes; it does not choose your company’s priorities for you. [1]

  • An agreed program scope and stakeholder map
  • An inventory of important systems, data, and outside dependencies
  • A baseline that distinguishes evidence from assumptions
  • An owner and escalation route for urgent concerns

Next: turn findings into an owned roadmap

A risk register should describe a scenario, its business consequence, existing controls, the proposed response, and the person authorized to decide. “Improve cloud security” is too broad to manage. “Limit the production deployment identity and verify the denied paths” is a task an engineering owner can estimate and close.

NIST’s Organizational Profiles support comparing current and target cybersecurity outcomes. Use that comparison to explain why a proposed project belongs on the roadmap. Add dependencies, effort estimates, due dates, and a verification method. Document accepted risks with the decision maker and a review date. [2]

Example acceptance criteria for leadership deliverables
DeliverableWhat makes it usable
Risk registerNamed decision owner, evidence, proposed response, and review date
Prioritized roadmapOrdered work, dependencies, resourcing assumptions, and completion evidence
Leadership briefingMaterial changes, unresolved decisions, and specific resource requests
Responsibility mapClear ownership across the vCISO, internal teams, and outside providers

Then: make the operating rhythm repeatable

By the first review cycle, leadership should be able to see which priorities moved, which controls were verified, and which decisions remain blocked. Choose a few measures with a named owner and a reliable source: overdue high-priority remediation, access-review completion with exceptions, or recovery tests with documented outcomes. Explain the scope and denominator so a percentage cannot hide missing coverage.

Set a calendar for risk reviews, policy decisions, supplier issues, and incident-readiness exercises. Define what happens between meetings, which requests consume advisory hours, and how urgent matters are escalated. A vCISO engagement does not automatically include a help desk, a 24-hour response team, a compliance assessment, or hands-on remediation; specify those responsibilities in the scope.

At the 90-day discussion, evaluate whether decisions are clearer and work has accountable owners. The next scope should reflect the remaining risks and available delivery capacity, not merely renew a set of meetings.

References & further reading

  1. NIST: Cybersecurity Framework 2.0
  2. NIST: CSF 2.0 Organizational Profiles
START AT THE SOURCE

Bring this thinking to your environment.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security