When I moved from advising on cyber risk to running a company, I discovered something uncomfortable: most of what I had told CEOs over the years was correct, and almost none of it was practical.
The advice was sound – cyber is a business risk, tone from the top matters, invest in the basics. But it did not tell a new CEO, with a hundred other things on fire, what to actually do in the first weeks. So this is the article I wish I had been handed.
It is written for the CEO who is not a technologist and does not want to become one. That is the right ambition. Your job is not to understand the firewall. Your job is to make sure the company's exposure is known, owned and deliberately accepted.
Week one to two: find out what you have inherited
Start with questions, not a review. Ask your CIO, CISO or whoever holds the role – and if no one does, that is your first finding – to walk you through three things in plain language:
What are the systems, data and suppliers that, if they failed or were breached, would stop the company or destroy its credibility? What has actually happened in the last two years – incidents, near misses, audit findings? And what would we do tomorrow morning if we were locked out of everything?
Listen for confidence that is not backed by evidence. "We have never had an incident" usually means "we have never detected one". "We are ISO certified" is useful evidence about the management system in scope; it does not, by itself, tell you how resilient the organisation will be under pressure.
Week three to six: establish ownership
One of the most persistent causes of cyber failure is not technology. It is unclear ownership: no one with sufficient authority owns the risk.
Make it explicit. Someone on your executive team is accountable for cyber risk – not for the technology, but for the risk. If that is the CIO, be aware that you have asked the person who runs the systems to also judge them. If that is the CFO or COO, make sure they have a competent security lead reporting to them. Either can work. What does not work is "it's IT's job".
Then decide what you are willing to accept. You will not fund everything. Say out loud which risks you are running deliberately and which you are not prepared to run at all. Write it down. Share it with the board. This is the decision only you can make, and it is the one most CEOs avoid.
Week seven to twelve: check the basics and set the tone
An uncomfortable truth of cyber is that serious incidents often involve basic weaknesses that were already known, insufficiently controlled or left unresolved. Multi-factor authentication not switched on everywhere. Backups never tested. Administrator rights handed out and never removed. A supplier with access to your systems and no one checking what they do with it.
Ask for a plain report on the basics, and ask when each was last verified – not configured, verified. Then ask what it would cost to close the gaps. It is usually less than the leadership team fears and more than the security team has been given.
And set the tone. The organisation watches what the CEO does with security, not what the policy says. If you forward suspicious emails to be checked, others will. If you ask for exceptions "just for me", you have just told everyone that the rules are for other people.
Do and don't
Do ask for a one-page view of the company's critical assets, top exposures and what is being done about them. Insist that it is written for you, not for an auditor.
Do name the executive who owns cyber risk and put it in their objectives.
Do decide and document what risk you are accepting. Silence is not acceptance; it is neglect with deniability.
Do run a leadership-level incident exercise in your first hundred days. Ninety minutes, one realistic scenario, no slides. You will learn more about your organisation than in any strategy offsite.
Do meet your most critical suppliers' security people, or at least know who they are.
Don't delegate the topic to IT and stop thinking about it. Reporting lines do not transfer accountability.
Don't ask for a maturity assessment as your first move. It will take months, cost money and tell you what you could have learned by asking better questions in week one.
Don't measure security by spend. Spending more is easy. Spending on the right things requires knowing what matters.
Don't treat the board as a place to reassure. Bring them the real picture, including the risks you have chosen to accept. They will thank you the day something goes wrong.
Don't grant yourself exceptions. Ever.
A reminder
You will never be the cyber expert, and you should not try. But you are the only person who can decide what the company is willing to risk, and the only person whose behaviour the whole organisation copies.
Own those two things in the first hundred days, and most of the rest will follow.
---
Maj Britt Arberg is the founder of House of Moon. She has advised leadership teams on cyber and privacy in Big Four advisory, has served as CEO in the energy transition sector, and has held board and advisory board roles.