Blog

Your CISO Just Gave Notice. Here Are the First 30 Days.

The resignation letter lands and the clock starts.

Someone still owns the PCI assessment that kicks off next month. Someone still approves the SOC 2 evidence sitting in your compliance platform. Someone still presents the security slide to the board in six weeks. And the incident response plan has the departing CISO’s cell number at the top of the call tree.

A replacement search for a senior security leader routinely runs two quarters. Auditors, regulators, and attackers keep their own calendars. The first 30 days after a CISO leaves decide whether the gap is an inconvenience or a finding.

What breaks when the CISO leaves

When a CISO leaves, a set of decisions loses its owner.

Risk acceptance

Every security program runs on exceptions: the legacy server that can’t be patched, the vendor that failed the questionnaire but got approved anyway, the MFA carve-out for the warehouse. The CISO signed those. Without an owner, exceptions either pile up unreviewed or get refused by someone who doesn’t know why they were granted.

Audit and certification calendars

PCI, SOC 2, HIPAA, ISO 27001, and CMMC all run on dates. Evidence collection, control owners, and auditor relationships usually route through the security leader. Miss a window and the cost shows up in a sales cycle when a customer asks for a current report.

Incident response

Most IR plans name the CISO as incident commander. The plan also assumes that person knows the IR retainer firm, the cyber insurance notification clause, and outside counsel. If an incident starts in week three of the vacancy, those are the first three phone calls, and nobody has the numbers.

Board and regulatory reporting

Public companies have a specific problem. Regulation S-K Item 106 requires the 10-K to describe the management positions responsible for assessing and managing cybersecurity risk and the relevant expertise of the people in them (SEC final rule). A vacancy at filing time changes what you can say. Private companies backed by private equity face a softer version of the same question from their sponsor.

Tool and vendor ownership

Admin credentials, MSSP escalation paths, and license renewals often live with one person. Offboarding a CISO is itself a privileged-access event.

Interim CISO

Keep Every Deadline While You Search

A former CISO steps into the seat and owns your audits, incident response, and board reporting from week one.

Book a Consult Explore Fractional Services →

Four ways to cover the gap

Name an acting leader internally

This is fast and keeps continuity. It works when a strong security manager or director is ready to step up. It fails when the internal candidate is an analyst or engineer who now has to brief the board, negotiate with auditors, and run the team they were on last week.

Hire full-time immediately

The right answer for some organizations, and a search should start regardless. Rushing it is the risk. A CISO hired to end a vacancy is often a different hire than one chosen for where the program needs to go.

Bring in an interim CISO

A senior practitioner steps into the seat, with authority, for a defined period, usually three to six months. The interim holds the program steady, keeps audit dates, owns incident response, and prepares the organization for the permanent leader.

Move to a fractional or vCISO model

Some companies discover during the vacancy that they don’t need 40 hours a week of CISO. They need executive judgment, board reporting, and program ownership at a level of effort that fits their size, backed by engineers who do the evidence and tooling work. A vacancy is a good moment to test that honestly.

These options combine. An interim engagement that turns into a fractional model, or that ends with the interim helping select the full-time hire, is common.

The first 30 days of an interim CISO

Week 1: authority, access, and inventory

The interim needs a written mandate from the CEO or CIO stating what they can approve, who they report to, and how long the engagement runs. Then access: the risk register, the exception log, the audit calendar, the IR plan, the tool consoles, and the vendor contracts. By Friday the interim should know every date on the calendar for the next 90 days.

Week 2: fix the incident response chain

Update the call tree. Confirm the IR retainer, the insurance carrier’s notification requirements, and outside counsel. Rotate or transfer every credential the departing leader held. If the organization hasn’t run a tabletop in the last year, schedule one.

Week 3: take ownership of the obligations

Meet the auditors. Confirm evidence owners for every open control. Review open exceptions and either re-approve them with a date or close them. Walk the team’s current projects and stop anything that doesn’t map to a real risk or a real deadline.

Week 4: brief leadership

Give the executive team and, where appropriate, the board a plain assessment: where the program stands against its framework (NIST CSF 2.0 is the common baseline), the top five risks, what’s on track for the next quarter, and a recommendation for the permanent role. That last item matters most. A good interim tells you honestly whether you need a full-time CISO, a fractional model, or a different org structure.

What to hand the interim on day one

  • The current risk register and exception log
  • The audit and certification calendar, with auditor contacts
  • The IR plan, IR retainer agreement, and cyber insurance policy
  • The last two board or executive security reports
  • A current org chart for security and IT, including MSP and MSSP contacts
  • The security budget and renewal schedule
  • The departing CISO, for a structured handoff, if the departure allows it

If some of these don’t exist, the interim’s first finding is already written.

Missing Pieces

Build the Handoff Package Together

If parts of that list don’t exist yet, we can help assemble them in the first two weeks.

Book a Conversation vCISO or CISO? →

How to choose an interim

Look for someone who has held the permanent seat. Running a program is a different job from assessing one. Ask candidates what they would stop doing in their first month, since triage is most of the job. Ask how they handle the handoff to a permanent hire, and whether they will help you run that search. Confirm there is a team behind the individual, so the engagement doesn’t stall when one person is on a plane.

Be honest about the steelman for skipping interim entirely: if a strong internal deputy exists and the audit calendar is quiet, an acting leader plus a fast search can be the right, cheaper answer. The interim model earns its cost when the calendar is full, the team is junior, or the board is asking questions.

How SideChannel handles it

SideChannel places former CISOs into interim and fractional roles, backed by a delivery pod of GRC and security engineers and the RealCISO platform for program tracking. The same team can hold the seat during the vacancy, help you decide what the permanent role should be, and stay on in a fractional model if that turns out to be the better fit.

Experienced security leadership that meets your team where they are and builds from there.

Cover the Gap, Then Choose What Comes Next

Talk with a former CISO about holding the seat now and shaping the permanent role.

Book a Consult
Back to Resource Center