Introduction
By Stephen Hermanson
A sample 90-day plan — tested in action — when embarking on building a new threat intelligence, public policy and government relations team for critical national infrastructure.
By no means perfect, and certainly not the only model. I simply offer it as a reference having been through the journey first hand.
For context, this was a blank sheet — building something from first principles. We inherited some structure and process but, for the most part we decided to leverage the rare opportunity to start afresh.
The scope was security (cyber, physical and people). We stood in relative isolation at the start, and other teams were building alongside us too. Steady integration and consolidation with Corporate Affairs, Strategy, Risk and others would follow.
It Begins
You’ve passed the interview, been offered the role and you’ve arrived in post. Most people in this situation will have a plan in mind and the 90-Day plan, modelled to a large extent on new political appointments and administrations, seems de rigueur.
You’re conscious that it’s critical national infrastructure and there needs to be evidence of a methodical and considered plan to orientate and understand the business, the people, the history, the risks, the politics, the funding, the external threats, the commercial partners, the commitments and technology you’ve inherited and the list goes on — you get the idea.
You may be fortunate enough to have an induction plan. If so, bolt the plans together and leverage the induction to get early agenda time with the stakeholders you’ll be working with. It’s not uncommon in these early days and weeks to rattle through a raft of introductions whilst juggling early tasking and deadlines.
Invest time in these early introductions, don’t rush them. Have an agenda or plan, even a simple one such as “What are you working on, what are you expecting from me, what decisions sit with you?”. Most importantly, don’t disappear into the trenches. Schedule follow-ups as weeks and months down the line, you’ll likely have more (and smarter) questions. If it feels like heavy lifting, then it’s likely one or both sides isn’t sure what the relevance is. Understanding the quid-pro-quo, regardless of the personalities and agendas at play, is super important.
For Threat Intelligence, Security Public Policy and Government Relations, you’re trying to discern priority intelligence requirements, priority policy dossiers and priority government relationships. The aim is to support business agendas and provide authoritative counsel and intervention on matters of security and resilience.
Understanding how business stakeholders use and respond to intelligence and policy assessments will usually need a few iterations. It’s possible to encounter arm-chair experts that believe the daily media brief is sufficient to keep abreast of the issues and risks. The plan is designed to get into the guts of the business and focus very quickly on what’s important and where to add value.
The Plan
Some of this includes traditional administration and set-up (a check-list of sorts). Bear in mind that some elements may fall into place automatically and in some cases it’s pre-determined and not open for review (observations and suggestions can come later).
Much depends on whether you’re building from scratch or arriving in an arena that’s already mature. The main purpose is to understand each of these elements and how they combine, interact and shape your agenda and strategy.
I’ve kept this intentionally compact and it doesn’t pretend to provide an exhaustive manual. Some elements are the subject of detailed study and volumes of guidance. It’s simply the sketch I start with when embarking on a new role.
Role
| Role | |
|---|---|
| Comms and logical access | You have credentials and permissions to relevant desktop systems, channels and groups. |
| Devices and physical access | You have relevant physical access and devices required. |
| System/Application access | You have access to relevant reporting, tooling and 3rd party services. |
| Recruitment | Review and sign-off on new/existing role profiles and funding if you’re hiring. |
| Battle rhythm & reporting | Agree timing and agendas for 1-1s, team calls and the content/structure of weekly/monthly reporting packs with direct reports, peers and manager. |
| Clearances/Vetting | Transfer or apply for relevant national security vetting if required. |
| Corporate policies | Know where to find corporate policies such as Security, Travel, Expenses Hospitality, Communications and Procurement. Understand them. Now is the time to ask and clarify. |
| Induction training | You’re aware of the relevant courses you need to complete such as Anti-Trust, Security and Health & Safety. Get them out the way. |
| Delegation of Authority (DoA) | Check circumstances and thresholds for DoA both up and down. |
| Important contacts | e.g. Security Operations Centre, Media Team, IT Helpdesk, ExCo PAs, Committee Chairs & Secretariats. |
Team
| Team | |
|---|---|
| Introductions & role profiles | Meet the team, understand their roles, what they’re working on, how they prefer to collaborate, build rapport. |
| Objectives & Strategy (current FY) | May need drafting in a greenfield scenario. Either way, review it and get to grips with the scope, the risks being addressed, and dependencies. How is achievement measured and how is the team performing? |
| Key stakeholders | Identify internal and external customers, providers (inputs) and influencers. Are requirements understood and reflected in objectives and strategy? |
| Policies | What policies (if any) does the team own or contribute to? What level of assurance does the team provide?1 |
| Products/Services | Purpose, audience and cadence. What did the last round of feedback say? Is it clear how they are being used and to what effect? |
| Diary (Meetings/Events/etc) | Where do you need to be (calls, meetings or events) and what are you (your team) expected to report or contribute? |
| Executive Committee (ExCo) / Board papers and timetables | What contribution or insert is required and who participates in the drafting and reviews to ensure it’s ready by the deadline. Review previous inserts. |
| Funding, Budgets & Financial Planning | How are your people and operations funded? What’s the opex/capex ratio and what suppliers and framework agreements apply? What did the last efficiency challenge require? |
| Business Cases | Are there any business cases in progress or needed to support objectives and strategy? What’s the governance process and who decides? |
| Incident History | Depending on the nature of the role, it’s useful to understand the incident or event history and findings from post incident reviews (and whether new/amended risks were introduced). |
| External Monitoring | How do you understand the external landscape, collect and process data to provide meaningful and timely intelligence that’s packaged in the right way, and continue to calibrate the lens and partners used to maintain situational awareness. Specifically, what are your intelligence requirements and why? |
| Certifications | Does the team require and/or maintain 3rd party certifications such as ISO2/CAF3 in relation to policy, processes or technology? |
| Tooling | What specific systems/services are in play (beyond general purpose corporate IT and advisory), what do they provide, and when did the last service review with the vendor take place? |
| Performance | What are the standing KPIs and targets? Do they make sense and how is the team performing? Has an external benchmarking exercise been conducted and when would this be useful to repeat? |
Internal Stakeholders
| Internal Stakeholders | |
|---|---|
| Operating model and RACI | How are you expected to work and collaborate with your immediate function and broader organisation. |
| ExCo sponsor/s | Who represents your agenda at ExCo and how do they prefer to be briefed? An absence of clear ExCo patronage is cause for priority investigation and clarification. |
| Governance | Understand the various Steering Committees, Board Committees etc that you’re expected to attend and support, and the last set of notes and actions for each. |
| Commercial partners | Understand current supply chains relevant to your objectives and strategy — contracts, spend, deliverables, RFPs, etc. |
| Strategic programmes & investments | What big bets is the organisation making and how does this influence your priorities. This includes mergers and acquisitions (past, underway and planned). |
| Corporate narrative & strategy | Look over the latest Annual Report and the Public/Media lines to calibrate your objectives, priorities, tone and narrative. Understand how you tie into the corporate purpose and mission. Who approves public positions and external comms. |
| Corporate Risk Register | Pay close attention to the headline corporate risks such as Security & Resilience, Trade Controls & Sanctions, Emerging Technology, Regulation etc. What is the threat assessment calling for. Are your objectives responding to risk? What risks does your ExCo sponsor own and how does your role support mitigation or avoidance. Absence of any link to risk is cause for priority investigation and clarification. |
| Critical assets, locations and data | Understand what you’re protecting and where risk will manifest. Understand physical/geographical layout, logical/systems layout, data sets and where they are hosted. |
| Regulatory reporting | Look over previous submissions and understand the timetable and governance for future returns. Do your objectives map to any compliance obligations? Does your role provide any support to regulatory aims/asks? |
| Market structure, supply chain and ecosystem | Understand the sector and market/s — customers, revenue, commercial model, competitors, and supply chains. |
External Stakeholders
| External Stakeholders | |
|---|---|
| Industry counterparts | Scout for equivalent or similar teams, understand their messages, evidence and stance. Make contact. |
| Stakeholder Map | Understand relevance, relationship, priorities and access. Build stakeholder profiles. |
| Events & Platforms | Understand purpose, agenda, attendees, your message and funding. |
| Engagement Tracker | Build a system to maintain records, actions, follow-ups, and consistency. |
| Engagement Plan | Decide who, why, when, where and the message required. Who will engage (role and seniority) and prepare talking points. |
| Government & Agency contacts | Understand the role, agenda, priorities and relationship with relevant government stakeholders. Make contact, build trust. |
| Regulatory contacts | Understand the role, agenda, priorities and relationship with relevant regulatory stakeholders. Who owns the relationship? |
| Industry Associations / Interest Groups | Understand the purpose, agenda, attendees, message, anti-trust and funding. |
| Standards Bodies | Understand the role, influence and agendas. Who attends? |
Conclusion
These are the headlines from a longer list. Feel free to contact me if you’d like to get into the detail and swap insights, and I’m always happy to receive ideas on useful elements to add.
In summary, no plan survives contact with reality. The plan is quickly subsumed by formal top-down objectives and strategy.
If nothing else, understand the team (morale, insights and challenges), operations (scope, threat, risk, controls and events), governance (decision making, reporting, compliance, opex/capex, commercial partners) and strategy (public affairs, communication, reputation).
- The three lines of defence for assurance and reassurance, Good Governance Institute. good-governance.org.uk ↩
- ISO – Standards. iso.org ↩
- Cyber Assessment Framework, National Cyber Security Centre. ncsc.gov.uk ↩
Leave a comment