Skip to content

For

New CISO

You have taken a security leadership seat and inherited a stack, a budget, and a set of commitments you did not make. The first decisions are about what to keep, what to fund, and what to stop.

These pieces are the decision mechanics rather than a maturity model: how evaluations reach a conclusion, what actually creates a budget line, how to sequence identity spend, and how to retire something without leaving a hole.

Read in this order

8 pieces, sequenced. Each line says why that one sits in that position, so you can stop when the sequence stops applying to you.

  1. What Actually Triggers a Security Budget Line

    Decision Brief

    Start here, because it governs everything below. What creates funding is rarely the risk you would rank first.

  2. The Identity Chapter of a Security Program, in Plain Budget Terms

    Decision Brief

    Read this second. Identity is usually the largest line you inherited and the one you will be asked to justify first.

  3. IGA, PAM, or ITDR First?

    Decision Brief

    Third: the sequencing decision inside that line, answered against the failure you can already evidence rather than a maturity model.

  4. Non-Human Identity Is a Governance Problem Before It Is a Tooling Problem

    Decision Brief

    Fourth, and worth reading before any vendor conversation, because this one is a governance decision that precedes a purchase.

  5. How to Run a Security Evaluation That Actually Decides

    Decision Brief

    Fifth. Once you know what to fund, this is how an evaluation actually reaches a decision instead of expiring.

  6. Should You Run a POC or Trust the Reference Call?

    Decision Brief

    Sixth, inside that evaluation: whether the proof of concept earns its cost or two reference calls would have told you more.

  7. The 30-Day Security Tool Rationalization Playbook

    Playbook

    Seventh, and the fastest budget you will find. It is a thirty-day pass over what you inherited.

  8. Killing a Tool: The Murder Board Nobody Runs

    Playbook

    Last, because removing something is harder than buying it and this is the part nobody documents.

Numbers worth having to hand

Each one carries its source, sample, and a sentence you can say out loud with your own figure beside it.

Common questions: new ciso

What should a new security leader decide first?
What to stop funding. A new leader inherits commitments made by someone else, and the fastest source of budget is usually the overlapping tools already owned rather than a new request. Deciding what to retire also reveals which commitments were never really owned by anyone.
Should a new CISO buy IGA, PAM, or ITDR first?
Buy against the failure you can already evidence. If access reviews are manual and audit findings repeat, IGA comes first. If standing administrative credentials exist in production, PAM comes first. Detection of identity attacks is worth little while the underlying entitlements remain ungoverned, which puts ITDR third for most organizations.
How much of an IT budget normally goes to security?
The IANS Research and Artico Search benchmark puts security at 10.9% of IT spend, down from 11.9% the prior year. Useful as a sanity check rather than a target, because the right share depends on regulatory exposure, what the organization builds, and how much risk the business has already accepted.

Also relevant, outside the sequence

Written with this reader in mind but not part of the ordered path.