Cybersecurity Master Plan & Roadmap

What gets done, in what order, by whom and at what cost, laid out across a calendar the board can approve and defend.

When it makes sense

When there is willingness to improve and no plan

Almost every organisation knows it has to improve its security. The sticking point comes with the specifics: there are scattered initiatives, budgets half approved, and a list of pending items that each area orders its own way.

A master plan puts that in a single document with a horizon of several financial years. What is most urgent stops being argued at every meeting, because it has already been decided and written down with its reasoning.

The board is asking for numbers

They want to know what security will cost over the next two or three years and there is no way to answer without making it up.

Each area pulls its own way

IT prioritises one thing, quality another and legal a third. Without a shared plan, whoever pushes hardest wins rather than whatever reduces the most risk.

You have an assessment gathering dust

There is an audit, or a client report, and its conclusions have gone months without turning into projects with dates on them.

What's included

What the plan contains

The content is adjusted to your size and to the horizon you need, normally two to three financial years.

Starting point

Where the organisation stands before planning anything.

  • Assessment of the current situation
  • Maturity level by domain
  • Risks identified and assessed
  • Obligations that already apply

Objectives and initiatives

Where you want to get to and what it takes to get there.

  • Objectives and the maturity level to reach
  • Identification of initiatives
  • Prioritisation by risk, effort and dependencies
  • Definition of the projects

Calendar and investment

When each thing happens and what it costs.

  • Roadmap by financial year
  • Investment planning
  • Indicators for tracking progress
  • Periodic review of progress
How I work

How it gets built

A plan written without talking to the areas involved is a plan nobody executes. These four phases exist to avoid that.

  1. Situation

    Gathering the starting point: maturity, risks, obligations and what is already under way. If there is a recent audit, it becomes the basis.

  2. Objectives

    Defining the level to reach and by when, tested against the board so that it is achievable rather than aspirational.

  3. Prioritisation

    Ordering the initiatives by the risk they reduce, the effort and the dependencies between them. This is where the plan becomes executable.

  4. Plan

    Roadmap by financial year, defined projects, estimated investment and indicators. Presented to the board for approval.

What you get

What stays with you at the end

A document that can be approved, and a short version to defend it with.

  • Complete master plan, with its reasoning
  • Assessment of the starting situation
  • Catalogue of prioritised initiatives
  • Roadmap by financial year
  • Estimated investment per initiative
  • Presentation for the board

Scope of the serviceThe plan defines the projects and their order; executing each initiative is contracted separately, afterwards. It is written precisely so that you can commission that from whoever you like: the prioritisation and the estimates stand on their own, without depending on the implementation ending up mine.

Frequently asked questions

What people usually ask before engaging

Do we need an audit first?

Not always, but a starting point is needed. If you already have a recent audit or a usable risk analysis, we start from there and the plan comes out faster. If there is nothing, the first phase of the plan does that assessment, lighter than a full audit.

What horizon does it cover?

Two or three financial years is the norm. Beyond three, planning turns into fiction: the business, the regulation and the tools all change. That is exactly why the plan includes periodic reviews.

Does it help justify budget to the board?

That is one of the reasons it exists. Each initiative carries the risk it reduces and its estimated effort, so the conversation stops being "we need to invest in security" and becomes "with this amount we cover these three things and these other two move to next year".

Does it work for NIS2, ISO 27001 or ENS?

Yes, and it is usually more efficient than treating each framework as a separate project. The plan takes the obligations that apply to you and turns them into initiatives within the same calendar, instead of opening one project per framework. A good part of the work is common to all three.

What if priorities change halfway through?

It gets revised. A master plan is not a contract: it is an ordered hypothesis. If a new client arrives with different demands, or the regulation shifts, the remaining initiatives are reordered on the same criteria used the first time.

Where to go next

Let's talk

Have to present a plan and don't know where to start it?

Tell me what horizon you are being asked for, what is already done and what budget you have. One conversation is enough to see whether you need a full master plan or something considerably shorter.

I reply personally within 24 working hours · No commitment