For
New CISO
You have taken a security leadership seat and inherited a stack, a budget, and a set of commitments you did not make. The first decisions are about what to keep, what to fund, and what to stop.
These pieces are the decision mechanics rather than a maturity model: how evaluations reach a conclusion, what actually creates a budget line, how to sequence identity spend, and how to retire something without leaving a hole.
Read in this order
8 pieces, sequenced. Each line says why that one sits in that position, so you can stop when the sequence stops applying to you.
What Actually Triggers a Security Budget Line
Decision Brief
Start here, because it governs everything below. What creates funding is rarely the risk you would rank first.
The Identity Chapter of a Security Program, in Plain Budget Terms
Decision Brief
Read this second. Identity is usually the largest line you inherited and the one you will be asked to justify first.
IGA, PAM, or ITDR First?
Decision Brief
Third: the sequencing decision inside that line, answered against the failure you can already evidence rather than a maturity model.
Non-Human Identity Is a Governance Problem Before It Is a Tooling Problem
Decision Brief
Fourth, and worth reading before any vendor conversation, because this one is a governance decision that precedes a purchase.
How to Run a Security Evaluation That Actually Decides
Decision Brief
Fifth. Once you know what to fund, this is how an evaluation actually reaches a decision instead of expiring.
Should You Run a POC or Trust the Reference Call?
Decision Brief
Sixth, inside that evaluation: whether the proof of concept earns its cost or two reference calls would have told you more.
The 30-Day Security Tool Rationalization Playbook
Playbook
Seventh, and the fastest budget you will find. It is a thirty-day pass over what you inherited.
Killing a Tool: The Murder Board Nobody Runs
Playbook
Last, because removing something is harder than buying it and this is the part nobody documents.
Numbers worth having to hand
Each one carries its source, sample, and a sentence you can say out loud with your own figure beside it.
Common questions: new ciso
- What should a new security leader decide first?
- What to stop funding. A new leader inherits commitments made by someone else, and the fastest source of budget is usually the overlapping tools already owned rather than a new request. Deciding what to retire also reveals which commitments were never really owned by anyone.
- Should a new CISO buy IGA, PAM, or ITDR first?
- Buy against the failure you can already evidence. If access reviews are manual and audit findings repeat, IGA comes first. If standing administrative credentials exist in production, PAM comes first. Detection of identity attacks is worth little while the underlying entitlements remain ungoverned, which puts ITDR third for most organizations.
- How much of an IT budget normally goes to security?
- The IANS Research and Artico Search benchmark puts security at 10.9% of IT spend, down from 11.9% the prior year. Useful as a sanity check rather than a target, because the right share depends on regulatory exposure, what the organization builds, and how much risk the business has already accepted.
Also relevant, outside the sequence
Written with this reader in mind but not part of the ordered path.