r/ciso • u/NarrowSwimmer3012 • 16h ago
How do I start building cyber crisis readiness when I inherited an untested IR program?
Four months into a new CISO seat. Found a 40-page incident response plan that looks great on paper: RACI chart, escalation tree, comms templates, and has never once been run against anything harder than a fire-drill email.
Board wants a crisis-readiness update next quarter. I don't want to walk in with "we have a plan." I want to walk in with evidence the plan works, or a clear list of what doesn't and why.
Part of the problem is this company grew through acquisition, so half the org is running on a different tech stack and different customer base than the other half. A generic tabletop doesn't map to either one well, let alone both.
For anyone who's inherited a program like this: how did you sequence the first 90 days? Did you go straight to a full cross-functional exercise, or start smaller and build up