Most organizations hiring a vCISO have a version of the same question underneath the formal evaluation: how quickly will anything actually change?
It’s a fair thing to ask. Security programs have a reputation for starting slow: assessments that take months, roadmaps that stay roadmaps, vendors who deliver reports without touching the problems they document. Before committing to an outsourced security leadership engagement, knowing what the first 90 days should look like gives you a way to evaluate providers on something more concrete than their proposals.
Here’s what a well-run vCISO engagement delivers in the first three months, and what the milestones along the way should look like.
Days 1 to 30: Understanding Your Environment Before Touching It
The first month is about building an accurate picture of where things stand. A vCISO who starts making changes before understanding your organization is going to make the wrong changes. Speed in the wrong direction isn’t progress.
Stakeholder discovery. The vCISO meets with leadership, IT, legal, compliance, and any existing security resources. The goal is understanding your business what you make or deliver, who your clients are, what regulatory environment applies, what past security efforts have produced, and what the current pressure points are. For CISOSHARE, this means understanding the drivers that led you here: a client asking security questions during the sales process, a compliance deadline, a departure of internal security leadership, or a board pushing for accountability.
Asset and system inventory. Before any risk assessment can be meaningful, someone needs to know what’s actually in the environment. This means mapping the systems that handle sensitive data, the vendors with access to your infrastructure, the cloud platforms and SaaS tools in use, and the gaps in visibility that exist. Many organizations discover systems or vendor relationships during this phase that nobody had formally tracked.
Baseline security assessment. A structured review of your current security posture against the frameworks and compliance requirements that apply to your business. For an organization pursuing SOC 2, the assessment maps existing controls against the Trust Services Criteria. The output is an honest gap analysis with every finding prioritized by risk level and business impact.
Quick wins addressed in parallel. A good vCISO doesn’t wait for the formal assessment to finish before addressing obvious, low-effort issues. Misconfigured access controls, missing MFA on critical systems, outdated policies that create audit risk — these get flagged and fixed during the discovery phase rather than queued for the roadmap.
By day 30, your organization should have a clear, documented picture of its current security posture and a prioritized list of what needs to happen in what order.
Days 31 to 60: Building the Foundation
The second month is where the program starts to take shape. With the assessment complete and risks prioritized, the vCISO shifts from understanding to building.
Security program roadmap. A detailed plan covering the next 6 to 12 months of security work, organized by priority and tied to your business goals. This isn’t a generic framework checklist — it reflects your specific environment, compliance requirements, resource constraints, and the business outcomes that security needs to support. For CISOSHARE engagements, the roadmap aligns directly with whether you’re trying to respond to customer security requests faster, achieve a certification, or build a program that can scale with the organization.
Policy and documentation development. The policies that govern your security program need to exist in writing and reflect what your organization actually does. An information security policy, acceptable use policy, data classification policy, access control policy, and incident response policy form the documented foundation that auditors, clients, and regulators will review. Policies get written during this phase, not after the program is running.
Compliance program setup. If your organization has active compliance requirements, the vCISO begins managing them now. For SOC 2, this means defining scope, identifying applicable trust services criteria, and setting up evidence collection processes that will run continuously through the observation period. For HIPAA, it means confirming business associate agreements are in place with all vendors handling protected health information and establishing the administrative safeguards the Security Rule requires.
First leadership report. By day 60, leadership should receive a clear report on where the organization stood at the start of the engagement, what has been addressed, what is in progress, and what the plan is for the next 30 days. This report uses business language — risk exposure, business impact, compliance status — rather than technical metrics that don’t translate to decisions.
Days 61 to 90: Program Running, Results Visible
The third month is where the engagement moves from setup to operation, and where the early results of the work start showing up in ways the organization can see and use.
Vulnerability management running. Regular scanning is underway, findings are being prioritized based on risk rather than CVSS scores alone, and remediation is being tracked with assigned owners and deadlines. The difference between a vulnerability management program and a vulnerability scan is accountability: someone owns each finding until it’s closed. By day 90, your organization should know exactly which vulnerabilities are open, which are in remediation, and which have been resolved since the engagement started.
Vendor risk management in place. A process exists for evaluating new vendors before they get access to your environment, and a review of existing vendors is underway for the high-risk relationships. For organizations that have never formally managed vendor risk, this often surfaces vendor relationships nobody had formally assessed — some of which carry meaningful risk that gets addressed during the 90-day period.
Customer security questionnaires handled. One of the most immediate and tangible outcomes for most organizations is being able to respond to client security questionnaires quickly and confidently. CISOSHARE specifically designs its CISO-as-a-Service to help clients respond quickly to customer security requests during the sales process. By day 90, the documentation and program structure built in the first two months gives your team what they need to answer questionnaires without a two-week scramble.
Incident response plan drafted. A documented, organization-specific incident response plan exists with named roles, communication protocols, regulatory notification timelines, and escalation procedures. It may not be tested yet; that comes in the next phase but it exists, and the key people know it does.
Clear line of sight into what’s next. The 90-day period closes with a program that is actively running and a roadmap that is being executed against. The leadership team understands the current risk posture, the progress made, and what the next quarter’s priorities are. Security has shifted from a concern to a managed function.
What This Looks Like With CISOSHARE
CISOSHARE’s CISOaaS is built around delivering immediate impact — their stated benefit from day one. The team they assign adapts to what the organization actually needs: if the 90-day priority is third-party risk management and security architecture, the team includes an analyst and an architect to support those activities specifically.
The Word & Brown Companies, a complex corporate family with multiple highly differentiated businesses, worked with CISOSHARE to build a security roadmap that didn’t constrain innovation while establishing a program that aligned with the company’s strategic direction. Their team learned the business first, built stakeholder buy-in, and delivered a foundation the organization’s internal security leadership built on.
For organizations that eventually want to bring security in-house, CISOSHARE builds programs in an operationalized, repeatable way so that internal team members can understand and take over relevant processes over time. The 90-day foundation isn’t built to create dependency — it’s built so the organization can own what was built.
For context on what the ongoing work looks like beyond the first 90 days, the week-in-the-life breakdown covers a typical vCISO week in detail. For a comparison of service models, the fractional CISO vs. part-time CISO guide explains how CISOaaS differs from a single-leader arrangement. And if you’re evaluating multiple providers, the outsourced CISO services evaluation guide covers what to ask and what red flags to watch for.
FAQ
How quickly can a vCISO make an impact?
Most organizations see meaningful, visible progress within 30 days — a completed baseline assessment, quick wins addressed, and a clear understanding of what the priority gaps are. By 90 days, the security program is running, and the first compliance and questionnaire-related outcomes are typically visible.
What should I expect at the end of the 90 days?
A documented security program with written policies, a current risk register, vulnerability management running, vendor risk processes in place, and a functioning incident response plan. Leadership should also have received at least two formal security reports. The organization should be able to answer client security questionnaires from the documentation built during this period.
Does the vCISO do the work or just direct it?
It depends on the service model. A vCISO (strategic leader only) guides your internal team but expects them to execute. CISO-as-a-Service includes a team that handles execution alongside the strategic leader. For organizations without internal security staff, the latter is the model that produces a running program in 90 days rather than a roadmap waiting for someone to act on.
What if our priorities shift during the first 90 days?
A good vCISO adapts. If a client sends an urgent security questionnaire or a compliance deadline moves up, the 90-day plan adjusts to address it. The roadmap is a plan, not a contract.
CISOSHARE’s vCISO and CISO-as-a-Service engagements are built to deliver immediate impact and a running security program within 90 days. Schedule a call to talk through what that looks like for your organization.


