Why sequence beats effort
Most first security pushes fail the same way: an energetic sprint across ten fronts at once, a wall of scanner output, and burnout by week six with nothing demonstrably safer. The fix is sequencing. Security work compounds when each phase feeds the next — you cannot protect identities you haven't enumerated, and you cannot close exposures on assets you don't know exist. Ninety days is enough time to run that sequence once, properly.
Days 1–30: visibility
The first month has one deliverable: an inventory you believe. Connect every cloud account with read-only access — including the experimental one someone spun up in 2023. Pull device inventories from whatever already sees them, deploy agents to the laptops and servers nothing sees, and put a discovery agent on each office network segment to surface the devices nobody enrolled — printers, cameras, the NAS under someone's desk. Connect your identity provider so every user account, human and service, is on the list.
Resist the urge to fix things mid-inventory beyond true emergencies. The point of this month is a defensible answer to "what do we have?" — because every later decision inherits its quality.
Days 31–60: identity
Identity is where modern breaches start, so it goes second, not third. Drive MFA coverage to 100% of humans, starting with admins — an admin without MFA is a standing invitation. Inventory privileged access and revoke what isn't needed for the job being done today. Audit service accounts and API keys: owner, purpose, last use, rotation date. Close the offboarding loop so departure means same-day access removal, verified rather than assumed.
Identity work is also the fastest visible win for leadership: "MFA coverage went from 71% to 100%, and we removed 14 unused admin accounts" is a sentence a board understands.
Days 61–90: exposure — and evidence throughout
Month three attacks the external surface: close public buckets, pull management ports (SSH/RDP/database) off the internet, patch the vulnerabilities that are internet-reachable and known-exploited, and retire end-of-life systems or isolate the ones you can't. Rank ruthlessly — the goal is the shortest path to "an automated scan of us finds nothing easy," not a zero-findings dashboard.
Running underneath all ninety days: evidence. Track findings to resolution, keep the inventory current, and let documentation generate from reality — because the roadmap's final deliverable is proof. A 90-day report showing inventory growth, MFA at 100%, and exposure findings closed is what converts a security push into a security budget. Cybermatic produces exactly that trail: live posture, ranked findings, remediation history, and executive reports written for the people who approved the time.
Related on the platform