Week-by-week plan
| Week | Phase | Key activities | Output |
|---|---|---|---|
| Weeks 1–3 | Assess | Maturity assessment against NIST CSF 2.0 and CIS Controls. | Signed-off assess pack and gate review |
| Weeks 4–6 | Strategy | 3-year roadmap with quantified business cases. | Signed-off strategy pack and gate review |
| Weeks 7–9 | Test | Penetration testing, red team, social engineering. | Signed-off test pack and gate review |
| Weeks 10–12 | Operate | vCISO, SOC, threat intel, incident response retainer. | Signed-off operate pack and gate review |
Gantt-style timeline titled "12-week delivery plan" over 12 Weeks with 4 phases: Assess from Week 1 to 3; Strategy from Week 4 to 6; Test from Week 7 to 9; Operate from Week 10 to 12.