Priorities for a new CISO
The first months of a new CISO in an organization are crucial and represent a critical timeframe to align the organization’s business goals and objectives with cyber risks. It is during this period that a CISO establishes their credibility throughout the organization.
It is the establishment of this core cyber foundation that allows the CISO to create a security roadmap that includes mitigation controls that aligns with the organization’s risk appetite and business goals.
But first, it is critical for the CISO to understand the existing environment and culture of the organization before designing any strategy. For the CISO, the avenue to do this is in understanding the cyber challenges the organization faces, and what approaches the business has taken (or not) to mitigate them.