Free template
90-Day Cyber Action Plan
A structured template for CISOs who want to build or rebuild their security program — from baseline to first board report. Designed for SMEs and mid-market companies.
12 weeks14 deliverablesPDF + template
Get the template — book a demoThe template is shared during our 30-minute demo.
What's inside the template
01
Baseline & Governance
Days 1–30
Understand the current state, identify priority risks, formalize governance.
Week 1
Asset mapping→ Critical asset inventory
Week 2
Existing posture analysis→ Current state report
Week 3
Priority risk analysis→ Risk matrix (3×3 or 5×5)
Week 4
Governance→ Signed security policy + RACI + review calendar
Target KRIs at end of month 01
✓100% critical assets inventoried
✓Critical risks documented
✓Security policy signed by management
✓Periodic reviews scheduled
02
Remediation & Protection
Days 31–60
Address priority risks, strengthen basic protections, prepare for compliance.
Weeks 5–6
Priority risk remediation→ Risk treatment plan with weekly status
Weeks 5–6
Security baseline→ Cyber hygiene dashboard
Weeks 7–8
NIS2/DORA compliance→ Gap analysis + remediation plan
Weeks 7–8
Critical suppliers→ Supplier risk tracking table
Target KRIs at end of month 02
✓>80% priority risks in treatment
✓>95% endpoints EDR coverage
✓<15 days critical patch delay
✓>50% critical suppliers assessed
03
Governance & Reporting
Days 61–90
Set up continuous monitoring, structure board reporting, prepare for first audit.
Weeks 9–10
Continuity & incidents→ Documented BCP + tested incident procedure
Weeks 9–10
Governance dashboard→ Cyber dashboard v1 + KRI definitions
Weeks 11–12
Day 90 board report→ D90 report + D91–D180 plan
Weeks 11–12
Audit preparation→ Organized, accessible evidence file
Target KRIs at end of month 03
✓>90% risks treated or in progress
✓BCP tested and documented
✓Dashboard operational
✓>60% NIS2 compliance covered
14 deliverables in 90 days
01Critical asset inventory
02Current state report
03Risk matrix
04Signed security policy
05Cyber RACI
06Risk treatment plan
07Cyber hygiene dashboard
08NIS2/DORA gap analysis
09Supplier risk tracking
10Documented BCP
11Incident procedure
12Cyber dashboard v1
13Day 90 board report
14Audit evidence file
Get the full template
The complete PDF template (with all checklists, KRI tables, and report frameworks) is shared during a free 30-minute session with our team.
Book a free 30-minute session