Greenfield Cybersecurity Program Build
Built the institution's first cybersecurity program from zero as the sole security leader, covering strategy, policies, governance, and regulatory examination, in 12 to 18 months.
A financial institution regulated by the CBN had no existing security function: no policies, no board reporting, no vulnerability management program, and no security awareness capability. The CBN had recently issued a cybersecurity framework requiring compliance from financial institutions, and a full examination was already scheduled. As the sole security hire, I had 12 to 18 months to build a complete, defensible, auditable cybersecurity program from absolute zero and satisfy both requirements.
I started with governance before controls, securing Board sponsorship and a budget-approved program roadmap before writing a single policy. I mapped the CBN's new cybersecurity framework against our starting position to identify which gaps carried the shortest compliance runway, then built the policy framework around NIST CSF and ISO 27001 so the same control set satisfied both the framework requirement and the broader examination scope. Controls implementation followed in risk priority order: access management, vulnerability management, incident response, and security awareness. I established quarterly Board Risk Committee reporting with 12 KRIs, giving the Board its first visibility into cyber risk. Roughly six weeks before the actual CBN examination, I ran an internal mock examination using the same scope and evidence standard examiners would apply. That exercise surfaced the four low-risk items early enough to remediate them on my own timeline instead of the examiners', which is what let the actual exam close as cleanly as it did. Throughout, I tracked framework compliance milestones alongside the CBN examination relationship, presenting remediation status to examiners and closing all prior findings with documented evidence packages.
The four low-risk items were standard for a first-year program and closed within the exam response window:
- Third-party risk assessments incomplete for two lower-tier vendors - closed by completing both assessments and adding a vendor onboarding gate to the TPRM process
- Formal incident response tabletop exercise not yet conducted given the program's timeline - closed by running the first tabletop and scheduling it as a recurring control
- Security awareness completion tracking not centralized for contractor and temporary-staff accounts - closed by extending LMS enrollment to all non-employee accounts
- Asset inventory reconciliation with the configuration management database still partially manual - closed by deploying an automated reconciliation script