The First 90 Days of a Trust, Security & AI Officer

Build trust, clarify risk, set decision rights, and show your board progress with evidence.

Tyson Martin

7/19/20267 min read

The First 90 Days of a Trust, Security & AI Officer
The First 90 Days of a Trust, Security & AI Officer

AI adoption is moving faster than ever, and modern digital transformation efforts mean cyber risk management is now a board-level priority. Your vendors, cloud systems, and data dependencies can disrupt revenue without warning. Your board wants clearer answers, and simply adding another security tool will not provide them.

A Trust, Security, and AI Officer, sometimes referred to as a Chief AI Officer, gives the organization one accountable leader for security, AI risk, decision rights, and evidence. The First 90 Days of a Trust, Security & AI Officer set the tone for the entire tenure. If you are stepping into the role, your first three months are critical. If you are hiring for it, those same months determine whether you have found a leader with the right judgment and performance.

The work is simple to state and hard to fake: build trust, find the real risks, establish who decides, and show early progress.

TL;DR

  • Start by listening and validating evidence. Do not reorganize teams or make large promises before you understand the business.

  • Prioritize risk by identifying the crown-jewel systems, data, vendors, and AI uses that could disrupt operations, financial reporting, or customer trust.

  • Set decision rights early. Management needs to know who can accept risk, approve exceptions, and escalate issues.

  • Pick a small number of quick wins that reduce real exposure, rather than focusing on an exhaustive list of security projects.

  • Provide board reporting that is decision-ready, clearly defining what has changed, what remains exposed, who owns the work, and what support is required.

What the First 90 Days Should Accomplish

A Trust, Security, and AI Officer connects cyber risk, AI use, privacy, recovery, vendor dependence, and customer trust to business decisions.

It is important to distinguish this role from a traditional Chief Information Security Officer. While a CISO is often focused on protecting the information technology infrastructure, the Trust, Security, and AI Officer role is not merely a technical security job with a broader title. It is not just a compliance owner or a policy writer who produces documents nobody uses. Instead, you are responsible for helping leadership make clear choices when tradeoffs are real.

That distinction matters because unclear accountability creates predictable failures. Security might own a risk that the product team created; Legal may find an AI concern after a tool is already live; or Procurement might sign a vendor contract without meaningful exit terms. Ultimately, the board may receive a polished dashboard but remain unable to tell what needs a decision.

Your first 90 days should follow a simple model to build a strategic roadmap that is clearly aligned with your organization's business objectives:

  1. Understand the risk. Find what matters, what could fail, and where claims lack proof.

  2. Clarify who decides. Set owners, approval rights, thresholds, and escalation paths.

  3. Prove that action is working. Use evidence, dates, and a small set of measures that show whether exposure is improving.

This work matters most when AI adoption is accelerating, leadership is changing, an acquisition is pending, third-party dependence is growing, or board scrutiny has increased. Symbolic reporting will not hold up in those moments. See Where Your Board Actually Stands if you need to test whether oversight produces real decisions.

Days 1 to 30: Listen, Map the Risk, and Earn Trust

Your first month is about learning how the business actually works. Do not begin with a reorganization. Do not promise a complete reset before you understand the current position.

You need a reliable picture of what the company protects, what it depends on, and where decisions stall.

Run a focused stakeholder engagement tour

Meet with the CEO, board or audit committee chair, CIO or CTO, security leader, general counsel, privacy lead, finance, operations, product, HR, internal audit, and major business owners.

Ask direct questions:

  • What must not fail for the business to operate?

  • Which Generative AI use cases are active, planned, or already used without formal approval?

  • What are the current gaps in cloud security and how are they being monitored?

  • Which vendors could disrupt revenue, service delivery, or customer trust?

  • Where are ownership, funding, and escalation unclear?

  • Which risks are accepted on purpose, and which are accepted because nobody has made a decision?

Keep the tone curious. You are not building a case against the team. You are learning where work gets stuck, where evidence is weak, and where the business has taken on more risk than it realizes.

Build a trustworthy risk assessment

A polished dashboard is not a baseline. A high-quality risk assessment includes artifacts that support management's claims.

Review the following during the first 30 days:

  • Crown-jewel systems, sensitive data, and critical business processes

  • Vendor management programs, including subcontractor terms, data deletion obligations, and exit support

  • Privileged access, identity controls, and recent access reviews

  • Backup status, restore-test results, and recovery targets

  • Open incidents, incident exercises, and unresolved corrective actions

  • AI use cases, data inputs, model providers, and human review practices

  • Policies, data security posture management, regulatory requirements, and cyber insurance commitments

  • Board reports, risk registers, and prior decisions that still lack closure

Ask for restore logs, access-review records, vendor contracts, incident after-action reports, and documented risk acceptances. Interviews show you what people believe. Evidence shows you what has been tested.

If you need stronger prompts for those conversations, Explore Boardroom AI and Cyber Risk Resources. The goal is not a perfect inventory. It is a clear starting position that leadership can inspect.

Days 31 to 60: Turn Findings Into Governance and Decisions

The second month is where you turn scattered findings into clear choices. Do not hand executive leadership a 60-page report. Instead, provide a concise risk assessment tied directly to business impact.

Each top risk should explain the likely effect on revenue, operations, legal exposure, customer trust, safety, or financial reporting. It should also state the current control position, the accountable business owner, the next milestone, and the specific decision required.

Set decision rights and risk appetite

You should not personally own every control. You should make ownership visible and hold it to clear dates and evidence.

Write down who can accept risk, who approves exceptions, and when a matter goes to the CEO, audit committee, or full board. Define thresholds in business terms, ensuring they align with existing regulatory requirements. Examples include unacceptable downtime for a critical service, an untested recovery capability, exposure of sensitive customer data, or an AI use case that makes high-impact decisions without human review.

Many organizations track activity counts, such as patches applied, training completed, and meetings held. While these numbers show effort, they do not indicate whether the business is truly safer.

Use a small set of outcome measures instead:

  • Time to fix critical exposure in important systems

  • Tested recovery times for crown-jewel services

  • Coverage and concentration risk among critical vendors

  • Unresolved risk exceptions past their review date

  • AI use cases reviewed before deployment

  • Issues found and closed after incident exercises

Put AI governance into normal management work

AI governance is not a policy document sitting in a shared drive. You must build an inventory and tier use cases by impact. When tiering, categorize dual-use foundation models differently than simple automation tools. Set clear rules for human review, sensitive data, vendor terms, monitoring, and escalation to ensure trustworthy AI.

A customer-facing AI tool that handles personal data needs more scrutiny than a low-risk internal writing assistant. Both still need an owner and clear operating rules focused on artificial intelligence safety. Directors who need practical oversight questions can Download the AI Boardroom Question Pack.

Your board reporting model can stay simple:

What changed? What could happen? Who owns the response? What decision or support is needed now?

That is the difference between a dashboard dump and a useful governance conversation.

Days 61 to 90: Deliver Visible Progress and Set the Operating Rhythm

By day 90, you should demonstrate a credible reset. Avoid presenting a long wish list of theoretical improvements. Instead, focus on two or three quick wins that provide a clear effect on business risk and offer a realistic path to completion. These early successes are vital for building momentum and establishing the foundation for a long-term strategic roadmap for your cybersecurity program.

The right choices depend on your baseline, but they often include tightening privileged access, testing recovery for a critical system, closing a material vendor gap, or clarifying incident response and escalation procedures. You might also consider cleaning up legacy risk exceptions or placing guardrails around a high-impact AI use case.

For each action, define the owner, target date, expected reduction in exposure, cost range, dependency, and proof of completion. If vendor evidence is thin, be transparent about it. Then, explain the compensating action, such as limiting access, segmenting systems, implementing data governance policies, applying privacy-enhancing technologies, or increasing monitoring.

Give leadership a 90-day readout they can use

Your executive and board readout should cover the starting position, what changed, what remains uncertain, risks accepted, decisions made, investment needed, and the next 90 days of your strategic roadmap.

Avoid claiming that all risks are controlled. Strong leadership reports uncertainty without drama. It states what you know, what you do not know yet, and when you will return with evidence.

Set a repeatable rhythm after the readout. Hold monthly management risk reviews. Report to the board quarterly. Review AI governance on a regular schedule. Run tabletop exercises, test system restores, review critical vendors, and update risk appetite annually to keep your cybersecurity program aligned with business objectives.

Questions leaders ask after 90 days

What if the organization expects a complete transformation in 90 days?
Set the expectation early. You can establish control, priorities, and early progress in 90 days. Large technology and operating changes require sustained ownership beyond the initial window.

What if management resists transparency?
Request evidence, owners, and dates. Escalate material gaps through the agreed governance path. Comfort is not a substitute for readiness.

How should you balance interim leadership with permanent hiring?
Use the first 90 days to stabilize the work and document the operating model. A permanent hire should inherit clear priorities, decision rights, and a working cadence.

What proves the first 90 days worked?
You can name the top risks, show evidence, identify accountable owners, close selected gaps, and bring leadership clear decisions instead of vague updates.

Related reading

If your board has a serious oversight gap, Get Board-Ready on AI and Cyber Risk.

The Standard for a Strong First 90 Days

Success is not about having a perfect security program, a finished AI policy, or an all-green dashboard. True success is being able to explain the risks that matter, name the owners, show the evidence, state what risk has been accepted, and identify the next decision.

For you in the role, that creates credibility and a practical roadmap. For the CEO and board, it creates clearer visibility, fewer surprises, and a stronger basis for defensible decisions. Ultimately, you succeed by integrating compliance and security into a broader strategy for cyber resilience. By aligning these efforts, your cybersecurity program becomes a foundational element that supports organizational growth while ensuring leadership can make informed, defensible decisions with confidence.

Tyson Martin is the executive public and pre-IPO companies in financial services, AI/data, SaaS, and cloud hire to make trust a measurable asset, one accountable answer to Is it secure? Is it resilient? Is the AI governed?

© 2026. All rights reserved.

Navigation

Free Resources

Contact

Stay ahead of your next board agenda

Sign up for Reports & Learnings From the Boardroom. Plain-English AI and cyber governance insights, biweekly. No pitch.