What gets done, in what order, by whom and at what cost, laid out across a calendar the board can approve and defend.
Almost every organisation knows it has to improve its security. The sticking point comes with the specifics: there are scattered initiatives, budgets half approved, and a list of pending items that each area orders its own way.
A master plan puts that in a single document with a horizon of several financial years. What is most urgent stops being argued at every meeting, because it has already been decided and written down with its reasoning.
They want to know what security will cost over the next two or three years and there is no way to answer without making it up.
IT prioritises one thing, quality another and legal a third. Without a shared plan, whoever pushes hardest wins rather than whatever reduces the most risk.
There is an audit, or a client report, and its conclusions have gone months without turning into projects with dates on them.
The content is adjusted to your size and to the horizon you need, normally two to three financial years.
Where the organisation stands before planning anything.
Where you want to get to and what it takes to get there.
When each thing happens and what it costs.
A plan written without talking to the areas involved is a plan nobody executes. These four phases exist to avoid that.
Gathering the starting point: maturity, risks, obligations and what is already under way. If there is a recent audit, it becomes the basis.
Defining the level to reach and by when, tested against the board so that it is achievable rather than aspirational.
Ordering the initiatives by the risk they reduce, the effort and the dependencies between them. This is where the plan becomes executable.
Roadmap by financial year, defined projects, estimated investment and indicators. Presented to the board for approval.
A document that can be approved, and a short version to defend it with.
Scope of the serviceThe plan defines the projects and their order; executing each initiative is contracted separately, afterwards. It is written precisely so that you can commission that from whoever you like: the prioritisation and the estimates stand on their own, without depending on the implementation ending up mine.
Not always, but a starting point is needed. If you already have a recent audit or a usable risk analysis, we start from there and the plan comes out faster. If there is nothing, the first phase of the plan does that assessment, lighter than a full audit.
Two or three financial years is the norm. Beyond three, planning turns into fiction: the business, the regulation and the tools all change. That is exactly why the plan includes periodic reviews.
That is one of the reasons it exists. Each initiative carries the risk it reduces and its estimated effort, so the conversation stops being "we need to invest in security" and becomes "with this amount we cover these three things and these other two move to next year".
Yes, and it is usually more efficient than treating each framework as a separate project. The plan takes the obligations that apply to you and turns them into initiatives within the same calendar, instead of opening one project per framework. A good part of the work is common to all three.
It gets revised. A master plan is not a contract: it is an ordered hypothesis. If a new client arrives with different demands, or the regulation shifts, the remaining initiatives are reordered on the same criteria used the first time.
Tell me what horizon you are being asked for, what is already done and what budget you have. One conversation is enough to see whether you need a full master plan or something considerably shorter.
I reply personally within 24 working hours · No commitment