
My first day as CISO at Nation-E, someone handed me a laptop, pointed at a server room the size of a closet, and said: “Great, you’re the security guy now. Make us safe.” No handover document. No inventory. No policy. Just a blinking rack of machines and a room full of engineers who’d never once been asked what “safe” meant to them.
That’s the moment every brand-new CISO knows in their bones. You walk in and everyone expects you to be a magician — firewalls up by Tuesday, hackers gone by Friday. Nobody hands you a map. You’re standing in a dark server room holding a flashlight, and the temptation is to start swinging it at whatever looks scary first.
The 90-Day Myth
There’s a fantasy in this industry — the “90-day plan” — where the new CISO arrives, deploys an EDR, rolls out MFA, writes a shiny policy binder, and declares victory. I’ve seen this fail more times than I can count, and I’ve built it myself early in my career before I learned better.
Here’s the problem: security controls without business context are just expensive furniture. I once reviewed a mid-size fintech that had spent close to $400,000 on a best-in-class SIEM in year one — before anyone had mapped which systems actually processed customer payment data. The SIEM was collecting logs from a marketing CMS with more diligence than from the payment gateway. Beautiful dashboards. Wrong story.
The Compass Before the Map
What actually works — what I’ve rebuilt at Nation-E, taught inside BDO’s Security Academy, and drilled into every CAIO cohort I lecture — is deceptively unglamorous: you start with a Business Impact Analysis, not a tool.
A BIA asks one brutally simple question of every department: if this system, this data set, or this process disappeared for 24 hours, what would it cost us — in money, in regulation, in reputation? Ask finance. Ask ops. Ask the CEO. You’ll get wildly different answers, and that’s the point. The gaps between those answers are where your real risk lives.
At one insurance client, the BIA revealed something nobody in IT expected: the single most business-critical system wasn’t the core policy engine everyone assumed — it was a decade-old actuarial calculation server running on unsupported software, quietly feeding numbers into every quote the company issued. Nobody had patched it in three years because “it just runs.” That server became risk item number one on the roadmap, not because it was technically sexy, but because losing it for a day would have stopped underwriting cold.

From Chaos to Gap Assessment
Once you know what actually matters to the business, the second move is a structured gap assessment against a real framework — NIST CSF, ISO 27001, CMMI, whatever fits the regulatory reality you’re in. Not to collect a certificate for the lobby wall, but to translate “we feel insecure” into “we are missing 14 specific controls, and here’s what each one is worth in reduced exposure.”
This is where the Formula 1 mentality comes in, the same one I use when I explain security to boards: nobody buys F1 brakes because braking is glamorous. They buy them because the car can then go faster, safer, into corners it couldn’t otherwise take. A gap assessment does the same thing for a business — it doesn’t slow you down, it tells you exactly how hard you can push and where the wall actually is.
The Risk Register Nobody Wants to Read
The unglamorous middle step — the risk survey — is where most new CISOs lose the room. Executives don’t want fifty pages of red-amber-green matrices. They want three numbers: likelihood, financial impact, and time-to-fix. I learned this the hard way lecturing to a board of directors early in my career, watching eyes glaze over a 40-slide deck. Now I open with one line: “Here are the five risks that could cost us seven figures or our license to operate, and here’s what each fix costs.” That sentence gets funding approved in the same meeting.
Building the Roadmap — Not the Wishlist
Only after the BIA, the gap assessment, and the prioritized risk register do you build the actual roadmap — and it should read like a business plan, not a shopping list. Eighteen months, three phases, tied explicitly to the risks that scored highest in cost-of-inaction. At Nation-E, that meant ISO 27001 wasn’t the goal — it was the natural byproduct of fixing what the BIA told us mattered. The certificate came almost as an afterthought, eleven months in, once the underlying controls were already load-bearing.

The Ghosts You Don’t See on Day One
Here’s the quiet danger nobody warns new CISOs about: the org chart lies. Shadow IT, forgotten AWS buckets, an old contractor’s laptop still holding admin credentials three years after they left — these are the ghosts in the servers, and they never show up in an org chart or an asset inventory someone filled in from memory. The BIA process, done properly by interviewing actual process owners rather than reading documentation, is often the first time these ghosts get named out loud. I’ve had CFOs go pale in these interviews, realizing a “decommissioned” system was still quietly processing live customer data.
Practical Takeaways
- Interview before you install. Spend your first three weeks talking to process owners, not vendors. The BIA data you gather is worth more than any tool you could buy in that time.
- Price the silence. For every critical system, get a real number: what does one day of downtime cost, in dollars and in regulatory exposure? That number becomes your budget’s best argument.
- Frame findings in business language. Boards fund risk reduction measured in money and reputation, not CVSS scores. Translate every finding before you present it.
- Sequence certification, don’t chase it. Let frameworks like ISO 27001 or NIST CSF emerge as the natural result of fixing what the BIA proved mattered — not the finish line itself.
Back to the Server Closet
I think about that first day at Nation-E often — the blinking rack, the vague instruction to “make us safe.” I didn’t start swinging the flashlight that week. I spent it in meetings, asking people what would actually hurt if it broke. By the time I touched a single firewall rule, I already knew exactly which wall it was defending. That’s the whole difference between chaos and a compass: chaos reacts to whatever’s loudest in the room; a compass points at what actually matters, even when it’s quiet, unpatched, and sitting in a closet nobody’s opened in three years.
I write From the CISO’s Diary from 20 years across BDO, ThriveDX, the IDF and my own ventures. Let’s connect: Omri Sagron on LinkedIn.