The first 90 days: an execution plan for teams

Part 1 made the argument; part 2 gave you the playbooks. This part is for the moment someone says "fine — show me the plan." It turns the five controls into a 90-day schedule with names, dates, a meeting cadence, and the three decisions only leadership can make. It assumes one to three people doing the work alongside their actual jobs, which is the honest operating condition of nearly every small organization.

The plan applies the Pareto principle to the calendar, not just the controls. Three rules keep it from becoming every other failed project plan:

  • Finish before starting. Nothing new enters flight until the current item is at its "done means" line. Five controls at full coverage beat twenty at 40% — the same is true of weeks.
  • Evidence is captured at completion, not reconstructed later. The export, the screenshot, the dated note — they take two minutes in the moment and two days at audit time.
  • Leadership decisions are pre-booked. The plan's three decision points go on executive calendars in week one, so the work never stalls waiting for a meeting that doesn't exist yet.

Three phases: see, lock, prove

Days 0–30 build visibility — you cannot Pareto an environment you can't see. Days 31–60 deploy the locks at full coverage. Days 61–90 prove it: test, document, brief, and convert the project into a routine. Week thirteen is deliberately empty; the unplanned-work tax is real, and a plan with no slack is a promise to disappoint someone.

The 90-day plan: see, lock, prove A 90-day timeline in three phases. Days 0 to 30, See: two inventories, external exposure check, leadership's recovery answers. Days 31 to 60, Lock: MFA to 100 percent, kill legacy auth, admin separation, 3-2-1 backups. Days 61 to 90, Prove: restore test, evidence folder, seed the risk register, leadership briefing. Phase gates fall at weeks 4, 8 and 12; week 13 is buffer by design. Day 0 Day 30 Day 60 Day 90 SEE build visibility LOCK deploy at full coverage PROVE test · document · routine wk13 buffer wk 4 gatewk 8 gatewk 12 gate • Two inventories • External exposure check • Leadership's recovery answers • MFA to 100% • Kill legacy auth • Admin separation • 3-2-1 backups • Restore test • Evidence folder • Seed risk register • Leadership briefing
Days 0–30 you can't Pareto what you can't see. Days 31–60 deploy the locks at full coverage. Days 61–90 prove it — and book the quarterly cycle. The checkmarks are the week-4/8/12 phase gates; week 13 is buffer, by design.
WeekFocusDone looks like
1–2The two inventories; external exposure check; leadership answers "how long can we be down, how much can we lose"Nothing important missing from either list; surprises from the outside scan removed or ticketed
3MFA pilot (IT + one friendly department); measure legacy auth; export privileged rolesPilot feedback in hand; you know exactly what blocking legacy auth will break
4MFA enforced for all admins and for everyone's email; edge cleanup from the exposure checkPhase gate: inventories complete, admin and email MFA enforced
5–6MFA enforcement to 100% of users; remediate legacy-auth dependents (the scanner, the old client)Exception list fits on one screen, every entry has an expiry
7Block legacy auth; finish admin separation; create and store the break-glass accountZero legacy sign-ins; privileged list fits on one hand
8Backups to 3-2-1 with one offline/immutable copy; backup console behind MFA + separate adminPhase gate: all five controls deployed; coverage verified, not assumed
9–10Full restore test, timed and documented; write the one-page recovery order; edge patch SLA and advisory subscriptions runningA dated restore log that matches leadership's recovery answer — or a gap now visible and priced
11Assemble the evidence folder; seed the risk register with 8–15 risks from the library, re-scored to your anchorsEverything claimable is provable; the register reflects your actual situation
12Leadership briefing: results, the three decisions, "good enough" defined out loud; book the quarterly cyclePhase gate: decisions recorded; recurring calendar in place
13Buffer. It will be consumed. That's what it's for.The plan survives contact with reality

Who does what

Small-team RACI charts collapse under their own weight, so this plan uses three roles: a driver (does the work, exactly one name), a decider (makes the call when the driver can't), and informed (finds out before it affects them, not after). The most common 90-day failure isn't technical — it's a control stalling for three weeks because nobody was explicitly the driver.

WorkstreamDriverDeciderInformed
Inventories & exposure checkIT leadIT leadLeadership
MFA + legacy auth (one project)Identity adminLeadership, for exceptions onlyAll staff — one short "why" note before enforcement
Admin separationIdentity adminLeadership — who keeps privilege is an access decision, not a technical oneEveryone losing admin rights, personally and beforehand
Backups & restore testIT leadLeadership — recovery priorities are a business decisionDepartment heads of the systems being tested
Edge patchingIT lead (or MSP, verified in writing)IT leadAnyone affected by maintenance windows
Evidence & registerWhoever owns complianceLeadership signs risk acceptances

The weekly 25 minutes

One standing meeting, 25 minutes, same time every week, three questions: What reached "done means" since last week? What's blocked, and is it blocked on work or on a decision? What decision do we need from someone in this room? Anything that hasn't moved in two weeks gets named out loud as blocked or abandoned — naming which one is usually the meeting's most useful moment. Keep the notes; dated weekly notes from a security rollout are themselves evidence that the program operates.

The three decisions only leadership can make

Book these in week one. Frame each as a choice between named options — decisions, not dashboards:

  • Recovery priorities (week 1–2). "If everything went down tonight, what comes back first, how fast, and how much data loss is survivable?" Their answers size the backup spend — and if the answers are expensive, that's a fact about the business, not a failure of the plan.
  • Exceptions and acceptances (weeks 4–7). Every MFA exemption, every account keeping admin rights, every system left out of scope is a risk acceptance. Named owner, written reason, expiry date, leadership signature. The signature is the control.
  • The spend rule and its exceptions (week 12). Nothing new gets bought until the five are done — and the briefing is where leadership either re-affirms that rule for quarter two or consciously makes an exception. If money must move early, backups are the one defensible place.

When the plan slips

It will. The Pareto answer is to protect coverage, not the schedule: a finished control two weeks late beats two controls at 70% on time. If you must cut, cut in this order — week-13 buffer first, then stretch the prove phase, then stretch the lock phase. Never trade away full coverage of MFA, legacy auth, or the restore test; those three are where most of the risk reduction lives. And if the slip is caused by unplanned operational work, log the hours — that number is the staffing argument you'll want later.

The 90-day checklist

Every "done means" line from the plan, in one place. It works as a team scoreboard in the weekly 25 minutes — and each ticked box should have a dated artifact behind it in the evidence folder.

90-day execution checklist

Days 0–30 · See

Days 31–60 · Lock

Days 61–90 · Prove

Progress is saved only in your own browser — nothing is sent anywhere, ever.

Day 91 isn't the end of security — it's the end of security as a project. What remains is a small routine (the quarterly cycle) and a question: is the 20% you locked actually staying locked? Measuring that is part 4.

The 80/20 security program

  1. 1. Start here: the argument and the vital few
  2. 2. The playbooks: deploying the five controls
  3. 3. The first 90 days: an execution plan for teams You are here
  4. 4. Proving it works: five numbers and a quarterly review