Illustrative sample · Anonymized

The First 90 Days — Executive Roadmap

Engagement Fractional CISO + diagnostic Context New leadership / post-close Framework NIST CSF 2.0

A repeatable path from executive concern to a board-ready roadmap — diagnosing what's urgent, baselining against a recognized framework, and leaving the institution with a sequenced plan and a governance rhythm that holds.

01
Days 0–30
Establish & stabilize

Understand the business and the risks in front of leadership, and act on anything genuinely urgent.

Key activities

  • Executive interviews and a stakeholder / decision map
  • Inventory of assets, data, and the institution's "crown jewels"
  • Review of prior assessments, audit findings, and exam history
  • Rapid triage of urgent exposure — privileged access, internet-facing services, backup integrity

Deliverables

Engagement charterStakeholder & decision mapTop-10 urgent risk listQuick-win actions underway
Outcome: leadership aligned on scope, urgency, and the questions the board needs answered.
02
Days 31–60
Assess & prioritize

Establish an objective baseline against NIST CSF 2.0 and separate real risk from noise.

Key activities

  • Maturity assessment across the six CSF functions
  • Third-party and critical-service mapping — concentration and Nth-party exposure
  • Control and evidence review against the target profile
  • Tabletop exercise — ransomware or wire-fraud scenario
  • Business-impact view of the top risks

Deliverables

NIST CSF 2.0 baselineCritical-service & vendor mapPrioritized risk registerTabletop after-action
Outcome: a defensible, evidence-based picture of where the institution stands and what matters most.
03
Days 61–90
Board-ready roadmap

Translate findings into a sequenced, costed plan and a governance cadence that sticks.

Key activities

  • 90-day / 12-month / 24-month remediation sequencing
  • Investment estimates and resourcing options
  • Key risk indicators and risk-appetite statements
  • Reporting cadence, decision rights, and committee rhythm
  • Prepare and deliver the first risk-committee package

Deliverables

Board-ready roadmap & narrativeInvestment planKRI / appetite setFirst risk-committee dashboard
Outcome: board confidence, a prioritized roadmap tied to enterprise value, and a governance rhythm that continues past day 90.
Beyond 90 days
Months 4–12

Execute & govern

Work the roadmap, run the reporting cadence, close priority gaps, and evidence progress for examiners, auditors, and insurers.

Months 12–24

Mature & optimize

Raise maturity toward target tier, fold in AI and third-party governance, and shift from remediation to sustained, measured oversight.

Typical engagement outcomes
Risk visibility
Top risks quantified in business terms
Regulatory
Exam-readiness gaps identified & sequenced
Governance
Board reporting cadence established
Execution
Remediation roadmap approved & resourced

Illustrative composite. This sample reflects how NorthBridge structures an initial engagement. Activities and deliverables are tailored to each institution; it contains no client data.