Inherited a Security Function? 6 Things Every CISO Should Review in Their First Year

Inherited a Security Function? 6 Things Every CISO Should Review in Their First Year

James Gallen

James Gallen

Published
8th October, 2026
5 minutes minute read
Jump to

    Inherited a Security Function? 6 Things Every CISO Should Review in Their First Year

    Joining a new organisation as a CISO brings a unique set of challenges, regardless of how many years you've spent in security leadership.

    You're not starting with a blank sheet of paper. You're inheriting a security function, technology estate, risk landscape, operating model and culture that have all evolved before you arrived. Some areas may be operating effectively, while others may have grown organically and no longer align with the organisation's objectives.

    One of the biggest questions many CISOs face in their first 12 months is:

    Do we have the right security team, structure and capabilities to support the business today and in the future?

    Before launching recruitment campaigns or restructuring teams, it's worth taking the time to understand exactly what you've inherited and where the real gaps exist.

    1. Assess the Current State Before Making Changes

    It's natural to want to put your stamp on the function, but meaningful improvements start with understanding how things work today.

    Take a close look at:

    • How security responsibilities are distributed across the organisation
    • Where the team spends the majority of its time
    • Which risks are currently being accepted, managed or overlooked
    • Existing skills, strengths and specialist knowledge within the team
    • Areas where projects, processes or security initiatives consistently slow down

    In many cases, you'll discover the issue isn't necessarily a lack of headcount.

    Instead, experienced security professionals may be spending too much time on operational tasks, firefighting incidents or filling gaps elsewhere in the business.

    The goal is to identify capability gaps rather than immediately assuming additional hires are needed.

    2. Look Beyond Headcount and Assess Capability

    One of the most common mistakes organisations make is measuring the maturity of a security function by the number of people in it.

    A team of ten doesn't automatically outperform a team of five.

    The real question is whether the organisation has the capabilities required to support its business objectives and risk profile.

    As you review the function, consider whether you have the right level of expertise across key areas such as:

    Security Engineering

    Security engineers are often responsible for an incredibly broad range of activities, including cloud security, vulnerability management, identity and access management, infrastructure security and tooling.

    If projects are delayed, remediation backlogs are growing or security tools aren't being fully utilised, the underlying issue may be engineering capacity rather than technology.

    Security Operations and Incident Response

    As organisations grow, so do monitoring requirements.

    Many CISOs find themselves evaluating whether their current approach to detection, response and monitoring remains fit for purpose.

    For some businesses, expanding internal capability makes sense.

    For others, partnering with a specialist provider can offer greater coverage, scalability and operational resilience.

    Security Architecture

    If the organisation is investing in cloud adoption, digital transformation or large-scale technology change, security architecture becomes increasingly important.

    Without architectural input early in projects, security teams often find themselves fixing problems after decisions have already been made.

    Governance, Risk and Compliance

    Governance activities often evolve gradually over time, particularly in growing organisations.

    Policies, risk registers, assurance activities and regulatory requirements may all exist, but not necessarily in a structured or scalable way.

    Strengthening GRC capability can sometimes deliver more value than making additional technical hires.

    3. Identify Where the Bottlenecks Are

    When reviewing a security function, it's important to understand not only what work is being done, but what isn't getting done.

    Ask yourself:

    • Which initiatives continue to be delayed?
    • Where are security teams overloaded?
    • What work is regularly deprioritised?
    • Which business stakeholders are waiting on security input?
    • Where are the most common sources of frustration?

    These bottlenecks often provide a clearer picture of capability gaps than organisational charts or headcount reports ever will.

    Sometimes the issue is resource.

    Sometimes it's process.

    And sometimes it's simply that responsibilities aren't clearly defined.

    4. Don't Assume Every Gap Requires a Permanent Hire

    One of the most valuable exercises during the first year is deciding which capabilities genuinely need to sit within the organisation.

    Not every challenge requires a permanent employee.

    Depending on your objectives, the right solution could be:

    • A permanent hire for long-term ownership
    • A contractor for a specific project or programme
    • A managed security service provider for operational support
    • Specialist consultancy expertise for a targeted piece of work

    The key is understanding which skills are strategic to the organisation and which can be delivered effectively through external expertise.

    As many CISOs will tell you, outsourcing an activity doesn't mean outsourcing accountability. Clear ownership within the business remains essential.

    5. Build Around Outcomes, Not Job Titles

    Security job titles can mean different things from one organisation to another.

    That's why the most successful hiring decisions are usually driven by outcomes rather than role names.

    Before discussing headcount, ask:

    • What problem are we trying to solve?
    • What risks are we attempting to reduce?
    • What outcomes are we looking to achieve?
    • Which capabilities are currently missing?
    • What skills already exist within the team?

    Once those questions are answered, the decision about whether you need a Security Engineer, Architect, GRC Specialist or SOC Analyst often becomes much clearer.

    6. Challenge the Existing Assumptions

    Every organisation develops assumptions over time.

    You may hear:

    • "We've always done it this way."
    • "That's a role we definitely need."
    • "We need another senior hire."
    • "We don't have the budget for that."

    Fresh leadership provides an opportunity to challenge those assumptions.

    Some organisations genuinely need additional investment and new capability.

    Others may achieve greater results through restructuring responsibilities, improving processes or making better use of the talent already within the business.

    The most effective security functions aren't necessarily the biggest. They're the ones where resources, skills and priorities are aligned with business objectives.

    Final Thoughts

    The first year in a new organisation is often about balancing quick wins with long-term strategy.

    Experienced CISOs understand that lasting improvements rarely start with simply adding more people. They start with understanding the current state, identifying genuine capability gaps and ensuring security investment is aligned with business needs.

    Sometimes the answer is a new hire.

    Sometimes it's specialist support.

    And sometimes it's unlocking more value from the people already in place.

    Whatever stage you're at, taking the time to assess the function objectively before making significant hiring decisions will almost always lead to better outcomes.

    If you're reviewing your security team structure, considering future hiring plans or simply looking for insight into the wider cyber security talent market, I'm always happy to have a conversation.

    Ready to talk?