Enter your keyword

← All Projects  ›  Greenfield Cybersecurity Program Build
Flagship Project - Project 01

Greenfield Cybersecurity Program Build

Community Financial Institution

Built the institution's first cybersecurity program from zero as the sole security leader, covering strategy, policies, governance, and regulatory examination, in 12 to 18 months.

Greenfield programSole security leaderNIST CSFISO 27001CBN examinationBoard governanceVulnerability managementSecurity awareness
4
Low-risk findings
30+
Policies authored
18mo
Zero to board-ready
97%
Awareness completion
The Challenge
Problem Statement

A financial institution regulated by the CBN had no existing security function: no policies, no board reporting, no vulnerability management program, and no security awareness capability. The CBN had recently issued a cybersecurity framework requiring compliance from financial institutions, and a full examination was already scheduled. As the sole security hire, I had 12 to 18 months to build a complete, defensible, auditable cybersecurity program from absolute zero and satisfy both requirements.

The Approach
How I Solved It

I started with governance before controls, securing Board sponsorship and a budget-approved program roadmap before writing a single policy. I mapped the CBN's new cybersecurity framework against our starting position to identify which gaps carried the shortest compliance runway, then built the policy framework around NIST CSF and ISO 27001 so the same control set satisfied both the framework requirement and the broader examination scope. Controls implementation followed in risk priority order: access management, vulnerability management, incident response, and security awareness. I established quarterly Board Risk Committee reporting with 12 KRIs, giving the Board its first visibility into cyber risk. Roughly six weeks before the actual CBN examination, I ran an internal mock examination using the same scope and evidence standard examiners would apply. That exercise surfaced the four low-risk items early enough to remediate them on my own timeline instead of the examiners', which is what let the actual exam close as cleanly as it did. Throughout, I tracked framework compliance milestones alongside the CBN examination relationship, presenting remediation status to examiners and closing all prior findings with documented evidence packages.

Frameworks & Standards
NIST CSF v1.1
ISO 27001:2022
FFIEC CAT
CBN Examination Standards
NIST SP 800-53
Tools & Platforms
NIST CSF · ISO 27001 · FFIEC CAT · Tenable/Nessus · KnowBe4 · CBN Examination · Board Reporting
Category
GRC · Program Build · CBN Examination
What Was Delivered
Outcomes & Results
CBN cybersecurity examination cleared with four low-risk findings, all remediated within the exam response window
30+ information security policies and procedures authored with formal control ownership
NIST Cybersecurity Framework implemented across all five functions
ISO 27001-aligned ISMS designed including formal risk assessment (ISO 27005) and Statement of Applicability
Quarterly Board Risk Committee reporting established - 12 KRI dashboard, first board-level cyber governance in institution history
Vulnerability management program deployed - Tenable/Nessus, risk-tiered remediation SLAs, 200+ findings remediated in first cycle
Security awareness program launched achieving 97% staff completion rate and reducing phishing click rate from 34% to 6%
Examination Findings

The four low-risk items were standard for a first-year program and closed within the exam response window:

  • Third-party risk assessments incomplete for two lower-tier vendors - closed by completing both assessments and adding a vendor onboarding gate to the TPRM process
  • Formal incident response tabletop exercise not yet conducted given the program's timeline - closed by running the first tabletop and scheduling it as a recurring control
  • Security awareness completion tracking not centralized for contractor and temporary-staff accounts - closed by extending LMS enrollment to all non-employee accounts
  • Asset inventory reconciliation with the configuration management database still partially manual - closed by deploying an automated reconciliation script
Key Lesson
A security program is organizational change with technology components - not the other way around. Getting Board mandate and risk appetite defined first determines whether everything built afterward is sustainable or decorative. The CBN exam bore that out: the same 12-to-18-month roadmap that got the Board reporting structure built also produced the 30+ policies and the control set examiners reviewed.
// Evidence vault
All project artifacts are available in the Evidence Vault.
Policies, playbooks, workbooks, and dashboards - downloadable evidence from real programs.