Organizations engage a fractional CISO for a small number of reasons: a customer or regulator has asked a question the organization cannot answer, an incident has shown that no one owned the response, an audit is approaching, or leadership recognizes that security risk is not being managed. The first 90 days should produce measurable progress on whichever of these prompted the engagement.

One risk is spending the first month on an extensive control assessment that does not change how the organization operates. Assessment is necessary, but it should be scoped to a decision. NIST CSF 2.0 reflects this emphasis: its Govern function addresses how an organization establishes and communicates its cybersecurity risk management strategy, expectations, and policy.1

Days 1 to 30: Confirm obligations and the primary constraint

The opening phase answers one question: what currently prevents the organization from being secure and able to demonstrate it? Four activities support that answer.

  • Review existing commitments. Customer contracts, security exhibits, examination findings, and cyber insurance applications define what the organization has already promised.
  • Interview across functions. Differences between what IT, product, sales, and executive leadership believe to be true identify where the program needs attention.
  • Inventory core capabilities. Identity provider configuration, endpoint coverage, backup and restore testing, logging and retention, and the asset and vendor inventories.
  • Assess against the governing framework. Use the framework the organization is measured against. For a HIPAA covered entity or business associate, this includes the required risk analysis, "an accurate and thorough assessment of the potential risks and vulnerabilities" to electronic protected health information.25

CSF 2.0 describes Current and Target Organizational Profiles, which provide a consistent structure for recording the results of this assessment and the gaps between the two states.1 Using that structure early allows later progress to be measured against the same baseline.

The primary deliverable is a one-page summary for leadership: the top five risks in plain language, their likely business impact, the effort required to address each, and a recommendation.

Days 31 to 60: Secure decisions and build core documentation

The second phase pairs leadership decisions with foundational documents. The decisions include who holds security decision authority, the organization's risk appetite for specific issues such as legacy systems, the target outcome and date (a named audit or a general improvement in posture), and the budget, including staff time.

Several regulations make these decisions explicit. The HIPAA Security Rule requires identification of a security official responsible for security policies and procedures.2 The FTC Safeguards Rule requires a designated Qualified Individual, who may be employed by a service provider provided the institution retains responsibility for compliance and designates senior personnel to oversee that individual.3 Both provisions apply directly to fractional arrangements.

In parallel, the fractional CISO produces a working set of documents: an information security policy that reflects actual operations, an incident response plan with named roles and decision criteria, a risk register sized to the organization, and an access review procedure that internal staff can run without assistance. NIST SP 800-61 Rev. 3 provides current guidance for integrating incident response across the CSF 2.0 functions.4

The risk register deserves particular care. Each entry should record the risk in business terms, its likelihood and impact, a named owner, and a treatment decision: mitigate, transfer, avoid, or accept. A register limited to risks that leadership recognizes and will act on is more useful than an extensive list imported from a tool, and it gives the board report in the final phase a clear basis.

Days 61 to 90: Operate each process and report

The final phase confirms that the new processes work in practice. Run one cycle of each: an access review, a vendor assessment, and a vulnerability triage meeting. Conduct a tabletop exercise with the people who would respond to a real incident; these exercises can reveal unclear authority, such as who may approve taking a production system offline.

Close the phase with a 12- to 18-month roadmap that assigns owners and estimated costs, sequenced by dependency. Brief the board or ownership on the program's starting point, current status, planned investments, and risks being formally accepted. Financial institutions subject to the Safeguards Rule must provide such a report in writing at least annually.3

Expected outcomes at day 90

At the end of the first quarter, an internal owner holds defined security authority. The incident response plan has been exercised. Top risks are documented and either funded for remediation or formally accepted by an authorized executive. The next audit or customer assessment has an owner and a date. Knowledge of the program is documented and held by internal staff, so that the organization's capability does not depend on the continued presence of the fractional CISO.

Practical takeaways

  • Scope the initial assessment to the decision leadership must make.
  • Document security accountability in terms that satisfy applicable regulations.
  • Test each new process once before the end of the first quarter.
  • Deliver a sequenced roadmap with owners, costs, and accepted risks.

References

  1. National Institute of Standards and Technology, "The NIST Cybersecurity Framework (CSF) 2.0," NIST CSWP 29, February 26, 2024. nvlpubs.nist.gov
  2. 45 CFR 164.308, Administrative safeguards (HIPAA Security Rule). ecfr.gov
  3. 16 CFR 314.4, Elements (FTC Standards for Safeguarding Customer Information). ecfr.gov
  4. National Institute of Standards and Technology, "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile," NIST SP 800-61 Rev. 3, April 2025. csrc.nist.gov
  5. U.S. Department of Health and Human Services, "Guidance on Risk Analysis." hhs.gov
Discuss this topic

DefenseLogix supports regulated and trust-sensitive organizations with this work. To discuss your organization's situation, start a conversation or review the vCISO Services service.