Step 1Map the work
What security work exists, who does it now, what's missing.
ATALAIAHere is every security task you have today, and who does it.
CISOFive of them are nobody. Detection is one.
Leaves the roomWork map: 14 tasks, 5 unowned
Step 2Draw the teams
Offensive, SOC, AppSec, CTI, managers and the CISO.
ATALAIAAppSec, SOC, offensive and CTI. Managers own budget; the CISO owns policy and risk.
CTOThat's a lot of people for our size.
Leaves the roomTeams: AppSec, SOC, Offensive, CTI
Step 3Order the hires
Which role first, and what to buy as a service meanwhile.
ATALAIANot all at once. AppSec first, because most of your risk is in the code.
CISOAnd detection until we hire?
ATALAIAA service for twelve months, then a SOC lead.
Leaves the roomHire order: AppSec first
Step 4Set the measures
KPIs and budget lines per team.
MANAGERBudget: people first, then services, tools last.
ATALAIAAnd one KPI page per team, so the CISO sees all of it.
Leaves the roomKPIs per team, budget split
- ATALAIA
- CISO
- CTO
- MANAGER