All recipes

Secure & Govern · Prompt

The vCISO Roadmap Builder — Design a Security Governance Roadmap

Generate a 12-month risk-based security roadmap for MSP clients that aligns with compliance and business goals.

Lifecycle Manager
ControlMap

User prompt

10 inputs to fill
You are a world-class vCISO building a 12-month security governance roadmap for a managed services client. You understand that a great security roadmap is not a list of tools to buy — it is a structured plan that makes risk visible, trade-offs intentional, and progress measurable. Every item on the roadmap must connect to a business outcome: revenue protection, compliance achievement, insurance posture, operational resilience, or growth enablement.

Here is my client's situation:
- Client: [CLIENT NAME], [INDUSTRY], [# EMPLOYEES]
- Current security maturity: [LOW / DEVELOPING / INTERMEDIATE / ADVANCED]
- Known gaps or exposures: [LIST KEY FINDINGS FROM ASSESSMENT OR OBSERVATION]
- Compliance requirements: [HIPAA / SOC 2 / CYBER ESSENTIALS / NIST / PCI / NONE]
- Cyber insurance status: [IN PLACE / RENEWAL COMING / NOT IN PLACE]
- Recent incidents or near-misses: [LIST OR "NONE"]
- Business context (growth plans, M&A, new locations, remote work changes): [NOTES]
- Approximate budget range: [RANGE OR "UNKNOWN"]

Build a 12-month security governance roadmap organized into three phases:

**Phase 1 — Establish the Baseline** (typically Q1)
- Risk assessment, policy framework, critical control gaps
- Initial executive reporting cadence
- Quick wins that demonstrate immediate, visible risk reduction

**Phase 2 — Build the Structure** (Q2–Q3)
- Control mapping to relevant compliance framework(s)
- Continuous monitoring, patch and vulnerability management
- Third-party and vendor risk baseline

**Phase 3 — Mature and Lead** (Q3–Q4)
- Executive and board-level reporting rhythm
- Insurance alignment and renewal preparation
- M&A readiness or growth-related security considerations
- Annual strategy review and roadmap renewal

For each initiative include:
- Plain-language name and one-sentence business justification
- Priority: 🔴 Critical / 🟡 Important / 🟢 Strategic
- Quarter (Q1–Q4)
- Who owns it (vCISO / MSP delivery / client)
- Success metric — how will we know it's done?

End with a one-paragraph executive framing I can use to introduce this roadmap: position it as a business governance plan, not a security project list.

This prompt acts as an AI-powered security consultant to help vCISOs generate a structured, 12-month governance roadmap for MSP clients. It shifts the conversation from "buying tools" to "managing business risk" by aligning security initiatives with compliance, insurance, and operational resilience.

How to use:

  1. 1.Copy the prompt into your preferred LLM (Claude, ChatGPT, etc.).
  2. 2.Fill in the bracketed client details, including industry, maturity level, and common gaps.
  3. 3.Run the prompt to generate a phased roadmap (Baseline, Structure, Mature).
  4. 4.Use the output to present a professional, business-aligned security strategy during your next QBR or onboarding session.

Recipes are starting points. Adapt them to your environment and validate the output before putting one into practice.

Request a recipe

More in Secure & Govern