An organization had accumulated tools and point controls but lacked a common system for deciding which risks mattered, which evidence could be trusted and who was accountable.
Situation #
Infrastructure, identity, endpoint, vendor and policy initiatives existed, but ownership, risk language and an executive operating cadence did not connect them.
My responsibility #
I structured the program and its governance: risk language, a prioritized register, policies and controls, identity hardening, logging readiness, incident preparation, executive metrics and a 30/60/90 roadmap.
Key decisions #
- Prioritize risk rather than cosmetic framework coverage.
- Separate Known, Unknown and Not Verified.
- Give every quick win an owner and follow-up mechanism.
- Use NIST and CIS as adaptable maps rather than products.
- Keep residual risk explicit.
Defensible outcome #
The organization gained governance mechanisms, prioritized risks, owners, review cadences, incident preparation and an executable capability roadmap.
Limits #
No certification, incident-free state or complete maturity is claimed. Coverage, aging and readiness metrics require validation before public use.