The first 90 days: an execution plan for teams
Part 1 made the argument; part 2 gave you the playbooks. This part is for the moment someone says "fine — show me the plan." It turns the five controls into a 90-day schedule with names, dates, a meeting cadence, and the three decisions only leadership can make. It assumes one to three people doing the work alongside their actual jobs, which is the honest operating condition of nearly every small organization.
The plan applies the Pareto principle to the calendar, not just the controls. Three rules keep it from becoming every other failed project plan:
- Finish before starting. Nothing new enters flight until the current item is at its "done means" line. Five controls at full coverage beat twenty at 40% — the same is true of weeks.
- Evidence is captured at completion, not reconstructed later. The export, the screenshot, the dated note — they take two minutes in the moment and two days at audit time.
- Leadership decisions are pre-booked. The plan's three decision points go on executive calendars in week one, so the work never stalls waiting for a meeting that doesn't exist yet.
Three phases: see, lock, prove
Days 0–30 build visibility — you cannot Pareto an environment you can't see. Days 31–60 deploy the locks at full coverage. Days 61–90 prove it: test, document, brief, and convert the project into a routine. Week thirteen is deliberately empty; the unplanned-work tax is real, and a plan with no slack is a promise to disappoint someone.
| Week | Focus | Done looks like |
|---|---|---|
| 1–2 | The two inventories; external exposure check; leadership answers "how long can we be down, how much can we lose" | Nothing important missing from either list; surprises from the outside scan removed or ticketed |
| 3 | MFA pilot (IT + one friendly department); measure legacy auth; export privileged roles | Pilot feedback in hand; you know exactly what blocking legacy auth will break |
| 4 | MFA enforced for all admins and for everyone's email; edge cleanup from the exposure check | Phase gate: inventories complete, admin and email MFA enforced |
| 5–6 | MFA enforcement to 100% of users; remediate legacy-auth dependents (the scanner, the old client) | Exception list fits on one screen, every entry has an expiry |
| 7 | Block legacy auth; finish admin separation; create and store the break-glass account | Zero legacy sign-ins; privileged list fits on one hand |
| 8 | Backups to 3-2-1 with one offline/immutable copy; backup console behind MFA + separate admin | Phase gate: all five controls deployed; coverage verified, not assumed |
| 9–10 | Full restore test, timed and documented; write the one-page recovery order; edge patch SLA and advisory subscriptions running | A dated restore log that matches leadership's recovery answer — or a gap now visible and priced |
| 11 | Assemble the evidence folder; seed the risk register with 8–15 risks from the library, re-scored to your anchors | Everything claimable is provable; the register reflects your actual situation |
| 12 | Leadership briefing: results, the three decisions, "good enough" defined out loud; book the quarterly cycle | Phase gate: decisions recorded; recurring calendar in place |
| 13 | Buffer. It will be consumed. That's what it's for. | The plan survives contact with reality |
Who does what
Small-team RACI charts collapse under their own weight, so this plan uses three roles: a driver (does the work, exactly one name), a decider (makes the call when the driver can't), and informed (finds out before it affects them, not after). The most common 90-day failure isn't technical — it's a control stalling for three weeks because nobody was explicitly the driver.
| Workstream | Driver | Decider | Informed |
|---|---|---|---|
| Inventories & exposure check | IT lead | IT lead | Leadership |
| MFA + legacy auth (one project) | Identity admin | Leadership, for exceptions only | All staff — one short "why" note before enforcement |
| Admin separation | Identity admin | Leadership — who keeps privilege is an access decision, not a technical one | Everyone losing admin rights, personally and beforehand |
| Backups & restore test | IT lead | Leadership — recovery priorities are a business decision | Department heads of the systems being tested |
| Edge patching | IT lead (or MSP, verified in writing) | IT lead | Anyone affected by maintenance windows |
| Evidence & register | Whoever owns compliance | Leadership signs risk acceptances | — |
The weekly 25 minutes
One standing meeting, 25 minutes, same time every week, three questions: What reached "done means" since last week? What's blocked, and is it blocked on work or on a decision? What decision do we need from someone in this room? Anything that hasn't moved in two weeks gets named out loud as blocked or abandoned — naming which one is usually the meeting's most useful moment. Keep the notes; dated weekly notes from a security rollout are themselves evidence that the program operates.
The three decisions only leadership can make
Book these in week one. Frame each as a choice between named options — decisions, not dashboards:
- Recovery priorities (week 1–2). "If everything went down tonight, what comes back first, how fast, and how much data loss is survivable?" Their answers size the backup spend — and if the answers are expensive, that's a fact about the business, not a failure of the plan.
- Exceptions and acceptances (weeks 4–7). Every MFA exemption, every account keeping admin rights, every system left out of scope is a risk acceptance. Named owner, written reason, expiry date, leadership signature. The signature is the control.
- The spend rule and its exceptions (week 12). Nothing new gets bought until the five are done — and the briefing is where leadership either re-affirms that rule for quarter two or consciously makes an exception. If money must move early, backups are the one defensible place.
When the plan slips
It will. The Pareto answer is to protect coverage, not the schedule: a finished control two weeks late beats two controls at 70% on time. If you must cut, cut in this order — week-13 buffer first, then stretch the prove phase, then stretch the lock phase. Never trade away full coverage of MFA, legacy auth, or the restore test; those three are where most of the risk reduction lives. And if the slip is caused by unplanned operational work, log the hours — that number is the staffing argument you'll want later.
The 90-day checklist
Every "done means" line from the plan, in one place. It works as a team scoreboard in the weekly 25 minutes — and each ticked box should have a dated artifact behind it in the evidence folder.
90-day execution checklist
Days 0–30 · See
Days 31–60 · Lock
Days 61–90 · Prove
Progress is saved only in your own browser — nothing is sent anywhere, ever.
Day 91 isn't the end of security — it's the end of security as a project. What remains is a small routine (the quarterly cycle) and a question: is the 20% you locked actually staying locked? Measuring that is part 4.
The 80/20 security program
- 1. Start here: the argument and the vital few
- 2. The playbooks: deploying the five controls
- 3. The first 90 days: an execution plan for teams You are here
- 4. Proving it works: five numbers and a quarterly review