top of page

What the first 90 days of a cyber security plan looks like

Writer: Ray Delany
Ray Delany
2 minutes ago
6 min read

Your leadership team has agreed that something needs to happen about cyber security. Now you need to determine what, and by when. Three months sounds like a reasonable amount of time to implement something, so the question is what you can actually promise at the end of it.


In our view, three months is long enough to find out what your real risks are, get the worst of them fixed, and have something honest to put in front of your leadership team. It isn’t long enough to be finished, and anyone promising a complete cyber security programme in ninety days is setting the wrong expectation.


The pace will also depend on the people available to help, the condition of your existing systems and, inevitably, the budget. A 20-person organisation with one IT contractor will move at a different pace from a larger practice with an internal IT team.


But the sequence should remain broadly the same:

  • Understand the organisation

  • Deal with the obvious material gaps

  • Establish the plan and reporting that keeps the work moving


The first 30 days: Find out what you're dealing with


The first month is about knowledge. You can’t prioritise what you haven’t mapped, and this is the month that stops you spending money in the wrong place.


Start with the systems and services the organisation depends on. Identify their business owners, what data they hold, where that data lives, who supports them, and what would happen if they stopped working.


For the critical services, begin agreeing how quickly each one would need to be restored and how much data the organisation could afford to lose. These become your initial Recovery Time Objectives and Recovery Point Objectives.


Define a simple data-classification approach so people have a common way of distinguishing public information from internal, confidential and particularly sensitive information.


Then start building a prioritised restore plan. If several systems disappear at once, what comes back first?


At the same time, look underneath the business picture at what’s actually happening operationally. Are the systems still supported? Are security patches being applied, and how quickly? Are backups being taken, and more importantly, has anyone successfully restored from them? That last question is the one we ask early on, because a backup nobody has restored from is a plan nobody has tested.


Turn on multi-factor authentication as early as you practically can, and mandate it wherever possible. Administrative access deserves early attention too. IT staff and suppliers should have separate privileged accounts for work requiring elevated access, rather than using administrative privileges for everyday activity. That privileged activity should be logged.

You should also begin preparing staff for what’s coming. Don’t surprise them in a month or two with new security requirements without explaining why.


At roughly day 30, you’ve got a usable picture of the organisation:

  • An initial asset and service inventory

  • Named business owners

  • Initial recovery time and data loss requirements for critical services

  • A data-classification scheme

  • An early restore priority

  • A clear view of support, patching, backups, multi-factor authentication and privileged access


It doesn't need to be perfect. It just needs to be useful.


Days 30-60: Fix the material gaps


The second month is where understanding starts turning into action.


Begin staff cyber security awareness training. This should go beyond phishing. People now need practical guidance on AI tools, where organisational information can and can’t be entered, unapproved applications, shadow IT, passwords and what to do when something feels wrong.


Start applying the data classifications defined in the first month. This often exposes useful questions about who has access to what, where copies have ended up and whether sensitive data is being handled appropriately. Refine the restore plan as business owners become more involved, because they’ll tell you thinks the technical view never shows.

By now the obvious gaps in software support and patching are moving towards resolution. Multi-factor authentication should be substantially complete, with stronger approaches considered for privileged or particularly sensitive access.


Password controls and the user experience should be considered together. Security that makes ordinary work unnecessarily difficult encourages workarounds. Where practical, single sign-on can reduce the number of credentials users have to manage while giving the organisation better control over access.


Think about password controls and the user experience together. Security that makes day-to-day work unnecessarily difficult encourages workarounds. Where it’s practical, a single sign-on reduces the number of credentials people have to manage while giving the organisation better control over access.


This is also the point to widen the asset view to include important suppliers:

  • Which suppliers hold your data or provide services you can't operate without?

  • What do their security policies say?

  • What assurances or certifications can they provide?

  • What does your contract require them to do if they have an incident?

  • Can you get your data back if the relationship ends?


By around day 60, you should also have an initial risk summary: not hundreds of entries in a risk register, but a manageable view of the risks that genuinely deserve attention.


Days 60-90: Turn the work into a programme


Month three is about making the improvements sustainable.


You need policies to reflect how the organisation actually intends to operate, and then be accepted, published and incorporated into normal business processes rather than living unread in a folder.


HR processes should support them. Joining, changing roles and leaving the organisation should each result in the correct access being granted or removed, because security responsibilities shouldn’t depend on somebody remembering to email IT.


The review mechanism also needs to be documented:

  • Who reviews the cyber risks?

  • How often?

  • What does leadership receive?

  • Which issues require escalation?

  • Who checks that actions have actually been completed?


Your data-classification work should be substantially further advanced by this point, and the prioritised restore plan should have been refined and, critically, tested where practical.


This is also an appropriate stage to bring in external security testing such as penetration testing. You now know which systems matter, what controls should exist, and what a weakness in those systems would actually cost the organisation. The test results can therefore feed into a considered plan rather than simply becoming another list of technical findings.


The 90-day plan you hand upward


The main output at the end of the ninety days is the cyber security roadmap for the following year. This is the piece that goes up to your leadership team or the board to get funded.


It should sequence the work, show what needs funding, identify regular reviews and testing, assign responsibilities, and give leadership a clear picture of what happens next.


Alongside it, confirm the reporting cadence: what leadership sees, how often, and what would prompt a conversation before the next scheduled one. Your board will rarely read a security report directly. They’ll read it as an appendix to the operational risk report, so write it so that it can be lifted and passed up without anyone having to rework it first.


What should not happen in 90 days


You should not expect to have eliminated cyber risk. You almost certainly won’t have built a mature security programme, completed every policy, replaced every ageing system, or worked through every supplier.


Unless there is a genuine business requirement, you also don’t need to spend three months creating a vast risk register or chasing certification simply to demonstrate activity. We see both fairly often, and they tend to absorb precious time that should have gone on the things that actually reduce risk.


The goal of the first ninety days is intended to be much more useful than that. You now know what you’re protecting, what could seriously hurt the organisation, what needs fixing first, and what the next year looks like.


Who does what?


None of this is a solo effort. Your IT provider will be central to much of the technical work. Along the way business owners, HR and leadership will have responsibilities too. Bringing in a fractional CISO (also known as a vCISO) or another independent security adviser can be helpful to bring all the pieces together, challenge priorities, and make sure risk rather than technology drives the plan.


Ninety days doesn’t get you finished, but it does get you in control.



Not sure where to begin? Download the 10 questions every health leader should be asking about cyber risk checklist, or get in touch to have a chat about how our Fractional CISO service could help.

 
 
bottom of page