The new IT leader's first 90 days

by
Dawid Winiarski
Last update:
July 17, 2026

The first quarter pulls you toward speed. You want a win on the board. Someone hands you a list of fires. A founder asks, in the first week, what you are going to fix. The instinct is to act fast, look decisive, buy a tool, pick a framework and announce it.

That instinct is the trap. The single most expensive mistake a new IT leader makes in the first quarter is moving fast on the wrong thing. Your first job is to earn the right to know what is worth fixing, which usually means resisting the urge to fix anything visible right away. Sequence beats speed. What follows is three movements rather than three dated phases. They overlap. Think in terms of what has to be true before the next move, rather than which week you are in.

  • The most expensive first-quarter mistake is moving fast on the wrong thing. Understanding has to come before judgment, and judgment before action.
  • Start with the business, not the systems. Learn how it makes money, its risk appetite, and what would actually hurt it before proposing anything.
  • You inherit a team and a set of prior commitments before you inherit a system. Map real capacity and the contracts, audit findings, and recovery readiness already in place.
  • Visibility into access, SaaS, and AI converts "I think" into "I know" early. Most environments hold more than their owners believe, and that picture is the foundation prioritization rests on.
  • Prioritize by material business impact, not the loudest alarm. A maturity-versus-risk plot puts attention where maturity is low and risk is high, and gives you a method to defend priorities.
  • Identity and access controls tend to give the most risk reduction per unit of effort early, so they often rise to the top of an honest prioritization rather than being assumed.

movement one: understand the ground you stand on

The discipline here is simple to state and hard to hold: understand before you judge. Spend the first stretch collecting reality.

the business first

Before any technical opinion, learn how the business makes money, where its risk tolerance sits, and what would actually hurt it. Assaf Keren, who has built security functions at scale, runs the same three questions on every leader he meets. What does a good day look like for you. What does a bad day look like. What can my function do to give you more good days than bad days. The answers surface what each executive is measured on and where your work connects to theirs.

If you cannot describe how revenue flows, which systems the business cannot run without, and what a day of downtime costs, you are not yet equipped to recommend where money should go. Read the board deck. Ask the CFO how the company makes and spends money. Ask the COO what breaks operations.

Risk appetite is the piece new leaders most often skip, and it shapes everything downstream. A company three months from a funding round and a company managing a regulated customer base have different tolerances for the same exposure, and both are legitimate. Your job is to learn the appetite that already exists, not to impose your own. You can argue to change it later, with evidence.

the people

You inherit a team before you inherit a system. Find your strong performers early. They know where the bodies are buried because they buried some of them. Then be honest about capacity. Count the real hours against the real workload before you add a single initiative. A team running at full stretch cannot absorb your ambition, and discovering that in month three is worse than knowing it in week two.

A genuine early win is often improving things for your own team: fixing a title that has lagged for two years, correcting pay that drifted below market, untangling a reporting line that makes no sense. These cost little and build the trust that makes everything else possible. The capacity picture also tells you something about every plan you will later propose. A control you cannot staff amounts to a line in a policy document that fails silently the first time it is tested.

what you inherited

Some of your runway is already spent before you arrive. Map it. Find the multi-year commitments, the licenses that auto-renew, the hardware on a depreciation schedule. Prior audit findings come with open action items that are now yours. Business continuity deserves an honest look early: ask one direct question, when did anyone last restore from backup and confirm it worked. The answer is often a long pause.

There is a useful map of the terrain. Walk the process areas one by one: risk management, security monitoring, incident response, vulnerability management, identity and access, data loss prevention, vendor risk, security training, policy, governance, application security, cloud posture. Walk them to understand the terrain, not to close them in a quarter.

the environment, and where visibility enters

The rule is plain: establish context before you assess risk. You cannot characterize a risk on systems, identities, and tools you cannot see. So build the picture. Identify the crown jewels, the data and systems the business cannot survive losing, and trace where that data lives and where it moves.

This is where access, SaaS, and shadow AI visibility belong in the arc. An identity and access view, who can reach what, which applications are connected to your core systems, what AI tools are actually in use, is one of the fastest ways to convert "I think" into "I know" early. Most environments hold more than their owners believe: a former contractor who still has repo access, a directory that looks clean until you check the OAuth grants and connected apps that never appear in a user list, a pile of SaaS trials that quietly became production, an AI assistant wired into a sales inbox that no one wrote down. The evidence says these gaps are the norm, not the exception. Getting this view does not commit you to any architecture. It is reversible, it is fast, and it gives you something concrete to reason from.

put a deadline on understanding

Listening has a failure mode. Information gathering with no end date becomes an endless process. You can spend the entire quarter on a listening tour and emerge with nothing decided. So set the boundary in advance. Decide when understanding stops being the main activity and decisions begin.

movement two: decide what actually matters

Understanding tells you what is true. The next discipline is deciding what is worth your finite attention. Prioritize by material business impact, not by the loudest technical alarm.

risk, threat, and vulnerability are not the same word

Ransomware is a threat. An unpatchable legacy system is a vulnerability. The risk is the business loss that results when a threat meets a vulnerability that matters. Boards care about material impact on the business. Determining what risks are material, and how to reduce material risk, is the entire game. A long inventory of vulnerabilities ranked by raw severity confuses motion with progress.

a method that fits a first quarter

You do not need a heavy risk-quantification program in your first ninety days. Plot each area on two axes: how mature it is and how much risk it carries. Score each domain you walked in movement one, place it on the grid, and put your attention where maturity is low and risk is high. Keep one scale and stick to it. The value is in the consistency, not the precision.

The plot does a second thing: it gives you a way to defend your priorities to people who disagree with them. When a stakeholder pushes for attention on their pet concern, you can show where it sits on the grid and why it ranks below something else. A new leader with a visible method has something to point at.

context turns a number into a priority

The same vulnerability score means different things depending on context. A high score on an isolated test box is noise. The same score on a crown-jewel system, in a sector being actively exploited, is a priority. Rank by impact across real dimensions: financial exposure, operational breakage, legal or regulatory consequence, reputation and trust.

why identity tends to rise to the top

Run this prioritization honestly and identity and access often rise to the top on their own merits: the controls in that domain tend to give the most risk reduction per unit of effort early on. Multi-factor authentication is the clearest example, with effectiveness against credential-based attacks well established across the major incident datasets. A structured MFA rollout, basic privileged access management, and governance over OAuth grants repeatedly land in the high-risk, low-maturity quadrant for mid-market companies, and they tend to be tractable in a single quarter. Present this as a conclusion the prioritization reaches, not a foregone answer you brought with you.

movement three: move on the few things that buy down real risk

Now you act. The discipline here is restraint.

quick wins that build credibility

Some call it pulling the thorn. Find a small, visible, painful problem, the one a specific person complains about, and solve it fast. The VPN that drops every afternoon. The access request that takes two weeks. None of these are your strategic priorities. All of them earn you the trust that lets you make bigger moves later. Choose thorns that are reversible, low-risk, and relationship-building. The best quick wins do double duty: fixing the slow access request process buys goodwill and teaches you how access actually flows through the company.

the discipline of what not to decide yet

Frame decisions as one-way doors and two-way doors. A two-way door is reversible; these deserve a bias to action. A one-way door is irreversible, or expensive enough to be effectively so; these deserve deliberation. Most of the irreversible decisions, rearchitecting the identity stack, a major multi-year vendor commitment, a reorganization, a heavy compliance framework, should not happen in the first quarter. Name them as decisions you are deliberately deferring, which is itself a sign of judgment.

do not buy tools before you understand the gap

The tooling trap catches new leaders often: products bought to solve a problem that was never clearly defined. Buy capability after you know the gap, not before. If you cannot state, in one sentence, the specific gap a purchase closes and how you will know it worked, you are not ready to buy it. And inventory what is already licensed and unused first: most mid-market companies have paid for capabilities they never turned on. Switching on capability the company already pays for delivers risk reduction at zero incremental cost.

close the quarter with a plan, not a problem list

End on a single principle: state reality, then inspire hope. Name the real state plainly, then give a confident, concrete plan to improve it. A briefing that ends with a catalogue of everything broken leaves the room anxious. A briefing that ends with a prioritized plan and a business case leaves the room with a decision to make. Keep the plan short. Three priorities a leadership team can hold in their heads beat a list of fifteen. Tie each one to the business language from movement one, and put a number on it where you honestly can.

the thread underneath: trust as the operating system

Relationships are the infrastructure everything else runs on. Build a regular one-to-one cadence with peers and stakeholders before you need it. Do what you say you will do, on time, every time. Become the function that finds a way to say yes safely, rather than the department of no. Say no often enough and the business stops asking, which means it stops telling you what it is doing. Speak the business's language: revenue protected, downtime avoided, a deal unblocked, a regulator satisfied. And build the relationships before the crisis, because the incident is the worst possible moment for a first introduction.

the horizon: where this is heading

A maturing program travels toward zero trust and identity-centric access, where access is granted per request, verified continuously, and assumes no implicit trust from network location. That is the destination, not a first-quarter deliverable. Naming the horizon early tells leadership that your first-quarter recommendations are steps on a deliberate path. Zero-trust frameworks describe it as a migration that unfolds over years, starting with discovery and visibility, the same understanding-first work of movement one. The visibility you build in your first quarter forms the first step of that long arc.

Subscribe to unshadowed.

Subscribe to receive the latest blog posts to your inbox and stay up to date with

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

let's start with a conversation

Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.

Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.

We'll take it from there

Julian Machowski
Head of Technical Sales
+48 783 762 997
julian@unshadowit.com
Let's connect on LinkedIn
Message received. We'll be in touch soon.
Something failed. Try again or call us directly.