Free template

90-Day Cyber Action Plan

A structured template for CISOs who want to build or rebuild their security program — from baseline to first board report. Designed for SMEs and mid-market companies.

12 weeks14 deliverablesPDF + template
Get the template — book a demo

The template is shared during our 30-minute demo.

What's inside the template

01
Baseline & Governance
Days 1–30

Understand the current state, identify priority risks, formalize governance.

Week 1
Asset mappingCritical asset inventory
Week 2
Existing posture analysisCurrent state report
Week 3
Priority risk analysisRisk matrix (3×3 or 5×5)
Week 4
GovernanceSigned security policy + RACI + review calendar
Target KRIs at end of month 01
100% critical assets inventoried
Critical risks documented
Security policy signed by management
Periodic reviews scheduled
02
Remediation & Protection
Days 31–60

Address priority risks, strengthen basic protections, prepare for compliance.

Weeks 5–6
Priority risk remediationRisk treatment plan with weekly status
Weeks 5–6
Security baselineCyber hygiene dashboard
Weeks 7–8
NIS2/DORA complianceGap analysis + remediation plan
Weeks 7–8
Critical suppliersSupplier risk tracking table
Target KRIs at end of month 02
>80% priority risks in treatment
>95% endpoints EDR coverage
<15 days critical patch delay
>50% critical suppliers assessed
03
Governance & Reporting
Days 61–90

Set up continuous monitoring, structure board reporting, prepare for first audit.

Weeks 9–10
Continuity & incidentsDocumented BCP + tested incident procedure
Weeks 9–10
Governance dashboardCyber dashboard v1 + KRI definitions
Weeks 11–12
Day 90 board reportD90 report + D91–D180 plan
Weeks 11–12
Audit preparationOrganized, accessible evidence file
Target KRIs at end of month 03
>90% risks treated or in progress
BCP tested and documented
Dashboard operational
>60% NIS2 compliance covered

14 deliverables in 90 days

01Critical asset inventory
02Current state report
03Risk matrix
04Signed security policy
05Cyber RACI
06Risk treatment plan
07Cyber hygiene dashboard
08NIS2/DORA gap analysis
09Supplier risk tracking
10Documented BCP
11Incident procedure
12Cyber dashboard v1
13Day 90 board report
14Audit evidence file

Get the full template

The complete PDF template (with all checklists, KRI tables, and report frameworks) is shared during a free 30-minute session with our team.

Book a free 30-minute session
90-Day Cyber Action Plan — Free Template for CISOs | Eyako