A useful first planning cycle should give the organisation a clearer basis for making security decisions. Before buying a list of activities, agree which decisions need support, who makes them, and what evidence is available. That becomes the foundation for a vCISO scope your business can evaluate. The starting point might be an enterprise customer review, an expanding product, an unresolved risk register, or a leadership team seeking a more consistent view. Be specific. “Improve security” is difficult to scope; “understand the controls and owners around our new customer-facing service” gives the work a practical boundary.
Establish the business context
Begin with the services, information, and relationships that matter most. Ask the business owner what disruption would mean and which changes are already planned. Identify the people responsible for technology, operations, privacy, procurement, and finance. A roadmap should account for their constraints as well as the security team’s concerns. NIST CSF 2.0 offers a shared set of cybersecurity outcomes for understanding and communicating risk, while leaving organisations to choose how they achieve them. That makes it a useful reference for a planning discussion, rather than a ready-made project plan.
Make the baseline inspectable
Ask for a short account of what was reviewed, what evidence supported the conclusions, and what remains uncertain. A policy document, a configured system, and a successfully rehearsed process provide different kinds of evidence. Record the distinction so leadership can see where confidence is justified and where follow-up is needed. The first deliverable can be modest: a prioritised issue register with business context, an owner, a proposed action, and an evidence reference. An honest baseline is more useful for planning than a detailed score whose inputs cannot be explained.
Turn priorities into decisions
For each proposed workstream, record the expected outcome, dependencies, available capacity, and decision needed. One item may require engineering work; another may require a policy owner or a commercial discussion with a supplier. Identify who can approve expenditure, accept residual risk, or change the scope. For example, an illustrative access-review workstream might name the systems in scope, the approving manager, the accounts to be reviewed, and the record needed to close the action. It should also say how exceptions will be revisited. The example is a planning pattern, not evidence that a review has occurred.
Agree the operating rhythm
Decide how often priorities and risk decisions will be reviewed, what will be reported, and who maintains the action register between meetings. Choose measures that reflect agreed work, such as actions completed with supporting evidence or overdue decisions awaiting an owner. Keep activity counts separate from improvements that have been validated. The commercial scope should state the vCISO’s responsibilities, time allocation, availability, deliverables, and boundaries. Advisory support does not automatically provide incident response, legal advice, independent certification, or implementation capacity. Those needs can be identified and scoped separately. A well-defined engagement makes the next decision easier and gives your own team a structure it can maintain.
A starting checklist.
- Name the business decision, important services, and planned changes.
- Record the baseline evidence, reviewed scope, and unresolved questions.
- Assign each priority an owner, dependencies, and approval authority.
- Agree delivery responsibilities, availability, and services outside the scope.
- Set a review cadence, evidence of completion, and exception review dates.
This guide provides general planning questions. Adapt them to your environment and agreed assessment requirements.