The State of Cloud Remediation 2026 report is live Read Here

July 28, 2026

Your First 180 Days as a CISO: A Guide for New and Experienced CISOs

Eric Carriere

Copywriter, Tamnoon

Share:

The first 180 days set the tone for everything that follows in a CISO role. Get them right, and you build the trust, the relationships, and the credibility that make the rest of the job possible. Get them wrong, and you spend the next year digging out.

Learn how experienced CISOs actually put this into practice, from before day one through the first six months.

The methodology behind the guide

This guide is written for two types of CISOs:

  • New to the role: You were just promoted into your first CISO seat. Your challenge is growing into the title, building authority you have never held, and in some cases standing up a security program, and the role itself, for the first time.
  • New to the company: You have done this before, and now you are landing somewhere new. Your challenge is inheriting someone else’s program, reading a culture you did not grow up in, and working out why the seat came open in the first place.

Most of what follows applies to both. The first conversations you need to have, the way you earn a board’s trust, the pace of change that works: that is shared ground. Where the two paths genuinely split, we have labeled the advice so you can find yours.

Before Day One: Use the Interview for Intelligence Gathering

The work starts before your first day. The interview process is your best, and sometimes only, chance to learn what you are actually signing up for. Both CISOs treat it that way.

Esmond has seen the gap between the pitch and the reality more than once.

“There’s a common thing that happens when you step into a security role. The people interviewing you aren’t always able to be fully candid about what you’re walking into. You may not get to ease into the role, because day one, you’re already cleaning something up. On the flip side, if it is as they described, then you can step on the accelerator!”

His advice is to go in with your eyes open, not be cynical. They hired you for a reason. Prepare to learn things that were not communicated in advance, roll up your sleeves, and get to it. If you are air-dropped into a crisis, that is your chance to excel and build some bridges early.

New to the role

A lot of first-time CISOs do not realize the interview runs both ways. This is where you protect yourself, not just where you impress them.

“When you’re being interviewed, it’s also your chance to interview them. You want to know how they solve problems. Are they proactive or reactive? Are they going to stand behind you when the sun’s coming up during an incident? There’s been ample evidence over the last ten years of CISOs being held personally accountable, so you want to make sure you’re on the D&O insurance if they’ll allow it. You want an employment contract with clear separation terms. You want to know they’ll support a lawyer if you’re ever called to testify. These have unfortunately become standard things to ask about.”

Look at what happened around incidents like SolarWinds and Uber and it is easy to see why. The personal exposure is real, and the time to address it is before you sign.

New to the company

If you have done this before, use the interview to diagnose how mature the organization really is, and why the last person left.

Ryan asks for specifics:

“In my most recent role, one of my asks was to sit down and interview with the board and understand what they wanted. What were their expectations coming in? I’ll ask what framework they use to assess the program, what their insurance structure looks like, and whether the CISO is a named officer on their D&O. Those are useful data points on their own, but they’re also a really good indication of how well the business actually understands security.”

The questions do double duty. As much as they are interviewing you, you are interviewing your next place of employment. If things are not going well, they will give you some of that in the room. Nobody is going to tell you the ship is on fire, so you have to ask what is not going well and where the major gaps are. 

If you are not seeking to understand those things before you have even been offered the job, you are doing yourself a disservice.

Walking In: Learn What You’re Actually Inheriting

Your first job is to get oriented before you act. That means two maps: the technical one and the human one.

Esmond starts with the technical basics: asset management, endpoint, identity, data management, compliance, and vulnerability management. What has become more important lately is being able to move at speed, so automation and orchestration matter more than they used to. He puts identity at the center.

“Identity is the new perimeter. We’ve been saying it for a while. Attackers don’t break in. They log in. And for the foreseeable future, they’ll be logging in faster and running reconnaissance faster, so you need to understand quickly how you respond to an incident and how you contain it.”

The human map matters just as much. The political hierarchy is not always the operational one. You need to know how things actually get done and who the movers and shakers are. Esmond calls it layer eight: how the people are wired.

New to the role

If you are the first real CISO the company has had, you are building the program and the role at the same time.

“There’s a real quandary if you’re the inaugural CISO for a program. You’re building from the grassroots, but also parachuting down from the clouds. You have to work at a very tactical level and, at the same time, be working with the board and your senior executives. It’s a lot of work.”

New to the company

If you are inheriting a program, understand what is already running before you touch anything.

Ryan starts with an inventory:

“What are the policies and procedures in place? What are the tools, the processes, the players? If you’re inheriting a program, there are things happening already, and you need to understand what those cogs look like. Every interaction is a chance to see what’s happening and start building relationships. If they meet with every business unit leader monthly, great, can I sit in? If they’re triaging vulnerability scans, great, I want to be a fly on the wall. Some people like to start with a gap assessment, and that’s fair. But before that, you need to understand everything you’re already doing.”

Your First Three Conversations

Both CISOs have a clear view of who to talk to first. They chose differently, and both lists are worth borrowing from.

Ryan goes team first, then leadership, then the ground floor:

“First, the existing security team, whoever makes it up. Get an understanding of what’s in flight and what they’re struggling with. You’re in charge of that ship now, and they’re looking to you to guide them. Second, the executive leadership team, as a group. You want tight relationships with legal and with HR. And finance can be tremendously helpful, and not just for budgets. Finance is often the best way to find out what’s really happening in the organization: shadow IT, shadow AI, shadow whatever. The data lives with them. Third, the business stakeholders. Executives will tell you the big theme for the year, but that glosses over the friction. So go to the heads of IT and engineering, and the directors, the people living the day-to-day. They’re going to be your biggest implementers.”

Esmond’s first three center on one question: how does the business see risk?

“I’m starting with the CEO, then the CTO or CIO, and finally legal and compliance. I want to know how the business operates and how they see risk. What do they think is necessary for success in this role, and what do they see as not worth the investment? The biggest question is how they see risk and how I can help them address it. Then I’m asking how often we should meet, and who else they think I should talk to.”

Days 30 to 90: Quick wins and Earning the Board’s Trust

Now you start to act, carefully. The goal is a few real wins that build trust while you keep learning what is actually true behind the polished version everyone gives a new boss.

Esmond runs what he hears through a simple filter:

“I’m a big believer in radical candor. I’d rather learn something unpleasant up front than reactively. So you’re looking for data that speaks to real measures. You may have product X, but is it well instrumented and rolled out everywhere? From there, it comes down to three questions. What needs to continue? What can I tweak or support? And what should we stop? Some things are just security theater, performative work that isn’t really helping the business. Sometimes you’re spending a hundred thousand dollars to solve a ten thousand dollar problem.”

Ryan’s warning for this stretch is about metrics. New CISOs reach for a dashboard when they should be building understanding.

“This is one of the things new CISOs overlook. They think, now I have to report to the board, so I need my 47 metrics on time to resolution and tickets. That so misses what our job actually is. Our job is to make sure the business can succeed, and to overlay the right controls for the risk environment we’re in. For a 50-person startup, the level of risk acceptance is very different from a 10,000-person, multi-billion-dollar company.”

When you do face the board, both agree: speak to the business in language the board understands. Ryan adds:

“Our job is to speak the language of the business and understand the value drivers. Have some assessment that’s measurable, but make it human-readable. No board wants to argue about whether they’re a two or a three on some scale. Spell it out. Here’s where we are, here’s what that means in practical terms, and here’s the plan to move forward. You’ve got to give them the forward-looking view.”

Shaping the Team You Inherited

Ask either CISO what the hardest part of the job is, and neither of them says technology.

“The human aspect of security is probably the single hardest part, and it’s the most important. The most secure computer is one that’s off, sitting in a closet, but that’s not how we use computers.” (Ryan)

New to the role

If you are forming a team or defining roles for the first time, lead like a coach.

“I see myself very much as a coach. My job is to lay out the strategy, but they’re the ones who win the game. So I need to understand each person: their strengths, where they want to grow, whether they want to move into management or stay a lifelong individual contributor. Then I look at the team as a whole. Do we have too many managers? Too many people wearing too many hats? People burn out when they’re doing duplicative work with no clear roles. And you have to get the team to build trust with each other, not just with you. When you get into an incident, and you will, you need to know you can rely on the person next to you.” (Ryan)

New to the company

If you are inheriting a team with history, learn it before you change it.

“I like to have conversations with everyone, and I do skip levels. I want to see the evidence: what people are doing, their performance, their growth, their background. Then you put together a development roadmap. No amount of good technology or AI solves for not having good people to implement and maintain it. Executing without a vision is a nightmare. And I always prefer to mature an incumbent before I look externally. They have the institutional knowledge and the tribal know-how, and that’s hard to replace.” (Esmond)

Both are candid about the role taking a toll. Esmond shares a hard-won lesson from earlier in his career, where he inherited a large security budget and almost no staff after his predecessor quit within a week. He turned the culture of a major organization around in six months, working seven days a week to do it, and paid for it with his health.

“I’m proud of that work. But by the same measure, don’t forget to take some time for yourself.” (Esmond)

Making Your Mark: Authority and Your Playbook

Before you change anything, know what you are actually allowed to change, and how this place is different from the last one.

Esmond frames the shift in what the security function is for:

“We’re not the department of no anymore. We’re the department of let’s have a conversation and make sure you have what you need. How do we empower the business? That’s a huge transformation, and it changes how you carry your authority.”

New to the role

First-time CISOs often overestimate their authority. Many are advisory only.

“Day one, you need to know what you can do. Some CISOs have no P&L and no operational exposure. They’re purely advisory. So you have to work through influence rather than authority, and get things done through other people. It’s not always the permission set you assume you have, so go in with your best guess and adjust as you learn.” (Esmond)

New to the company

If you have run programs before, the trap is assuming what worked last time will work here.

“Just because you’ve had past success with a specific model doesn’t mean it works this time. Every organization is its own dichotomy: a whole set of personalities, people, history, and culture. So I try not to walk in and stamp my way of doing things as the only way.” (Ryan)

Days 90 to 180: When to Make Structural Changes

The shared rule is simple. Do not make big changes early. Earn the right first.

“My strong thesis is no major changes in the first 90 days. Find some quick wins, find things that are meaningful to the organization, and get them rolled out. That builds trust, both with your team and with the organization.” (Ryan)

So, how do you know when you are ready to make bigger moves? The organization will tell you:

“When people start coming to you voluntarily, ‘Hey, what are we doing with this?’ or ‘We’ve got this big thing coming, I want to make sure we’re aligned,’ those conversations you didn’t start are a pretty good sign you’ve built the trust.” (Ryan)

The failure mode splits depending on where you came from.

New to the role

The first-timer’s risk is acting on too little. Esmond has a vivid way of putting it:

“The biggest mistake I see new CISOs make is thinking they understand the whole universe of a problem and then making a radical change on unsubstantiated information. Guaranteeing a business outcome without really understanding the problem. It’s like dropping a bomb. Unless you understand the blast radius, you don’t know what the splash damage is going to be.”

New to the company

The experienced CISO’s risk is the opposite: moving too fast because you already know the playbook. Ryan has felt the pressure to do exactly that:

“I’ve had people ask me, what are you waiting for? And my answer is, because if we do that right now, here’s what happens. Anyone who’s been in this role has lived that not going well. Big changes need to be communicated well and sequenced. One major change a month, or two a quarter, so people stay comfortable.”

The AI Curveball Every CISO Faces

One force is reshaping the role faster than anything before it, and it lands on both readers the same way.

Ryan puts the pace in perspective:

“The hardest part right now is that we’re navigating a brand new set of technology with AI, and the pace of adoption is greater than almost anything we’ve seen. The move to cloud took the better part of 10 or 15 years. We went from practically nobody using AI to everybody using AI inside of two years.”

His concern is what that speed does in untrained hands:

“We’re putting real power in the hands of people who don’t fully understand it. ‘Cool, it can help me write emails.’ Sure. But it’s a little like handing someone who’s never fired a gun an Apache attack helicopter and saying, good luck. And the technology is clearly helping attackers find vulnerabilities faster than ever.”

Esmond measures the change with a different approach:

“We used to talk about things in iPhone or iPad life cycles. Now you’re measuring in LLM life cycles. Every other week, there’s a new version of something. That forces you to question accepted wisdom and retest things you thought were settled. Identity has become even more important because there’s now a wealth of knowledge available to every AI platform and every person using one. You have to be conscious of what you’re exposing and why: need to know, minimum necessary. Healthcare has lived this for years, and the rest of the industry is catching up.”

The Through-Line of It All

This guide contains deep insights from experienced CISOs, two different starting points, and largely the same core advice: 

  • Understand the people and the business before you touch the tools. 
  • Prove value early with small wins that do not break anything. 
  • Change deliberately, and only once you have earned the room to do it.

Ryan summed it up when he looked back on our conversation:

“How many times did I mention KPIs? It’s not about benchmarks and vulnerabilities. All of that matters, but if you don’t get the people and the business right, you can roll out every control and every tool available, and you’ll still fail.”

That is also where the day-to-day gets hard. A new CISO needs quick, safe wins and a shrinking MTTR, usually with a small team and a backlog of alerts that a CNAPP is very good at surfacing. 

Closing those alerts safely, at the root cause, without overloading the team, is where Tamnoon comes in. It is the remediation layer that acts on what your detection tools find, so the wins you are chasing in your first 180 days are wins you can actually deliver.

For more on where remediation tends to break down, and how teams are closing that gap, the 2026 State of Cloud Remediation report has the data.

Special Thanks to Our Contributors

We’d like to thank both Ryan Davis and Esmond Kane for sharing their valuable CISO experiences and insights with the broader cybersecurity community.

Esmond Kane
LinkedIn Logo

Esmond Kane is the CISO at Advarra and a seasoned security leader who has stepped into cybersecurity programs at varying stages of maturity.

Ryan Davis
LinkedIn Logo

Ryan Davis is the CISO of New Charter Technologies, a four-time CISO, and someone who has a history of building successful security programs.

Discover the Latest From Tamnoon

There’s always more to learn, see our resources center

Scroll to Top

CNAPP Decoded: Alerts, Remediations, and CNAPP Best Practices 1x a Month

Join 10,000+ Cloud Security leaders looking to master their CNAPP with expert remediation tips and best practices to test in your own CNAPP today.