First 30 days: inherited security function checklist The aim is not to produce a finished strategy in 30 days. It is to build a reliable view of what needs protecting, what needs fixing and what cannot wait. Understand - Confirm formal and practical decision rights. - Identify the most material known risks, incidents and overdue actions. - Map near-term regulatory, contractual and customer commitments. - Identify critical knowledge held by individuals. Test - Test incident and out-of-hours escalation routes. - Review recovery ownership and recent exercise evidence. - Map critical suppliers, their access, expected outcomes and escalation contacts. - Identify controls that are imperfect but currently dependable. Decide and record - Separate urgent containment from structural redesign. - Record assumptions, owners, dates and trade-offs. - Agree how provisional findings will be communicated. - Protect useful capability while the longer-term model is developed. Article: https://mantasmarcinkevicius.com/writing/preserve-what-works/ Modern CISO Mantas Marcinkevicius