18/06/2026
The honest answer to "what would we actually get from a CISO" is rarely satisfying when it comes back as a list of responsibilities. The role makes more sense when it gets framed as a workplan with phases, dates, and outputs.
A defensible 90-day playbook looks roughly like this.
Days 1 to 30 are discovery and assessment. The CISO maps stakeholders across the business, runs a current-state assessment against a chosen framework (ISO 27001, NIST CSF, cybersecurity governance frameworks, the Essential Eight, or whatever fits the regulatory context), inventories assets and classifies them, reviews existing policies and incident history, and audits the tools, vendor, and cyber insurance footprint. The output is a clear picture of where the program actually sits today.
Days 31 to 60 are strategy and roadmap. A formal gap analysis against the chosen framework. A risk register with named owners against each top risk, not generic departments. A multi-year cybersecurity roadmap with budget attached. Three to five quick wins scoped for immediate ex*****on. The first incident response tabletop run, even at a small scale. The output is a board-ready plan and the credibility that comes with it.
Days 61 to 90 are ex*****on setup. Priority policies updated or created, starting with the ones that will be tested first in audit or by an incident. The awareness training program designed and ready to roll out. A vendor security assessment program documented. A security metrics and reporting framework that defines what gets reported monthly and quarterly. And the first board report delivered against the framework, not against activity. The output is a function that runs, rather than a person who runs around.
That's the work. It's the same work whether the practitioner is full-time, fractional, or on retainer. The only variables are when it starts and what it costs.
Our vCISO (Virtual Chief Information Security Officer) service is built to deliver that 90-day playbook on retainer instead of salary, with a senior practitioner from day one and a practice behind them.
Read the full service description: riskprofs.com/virtual-chief-information-security-officer/