Executive Summary

Eleven articles ago, this series opened with a claim that has since been argued from every angle: cybersecurity is no longer an IT issue — it is an enterprise risk owned in the boardroom, and the difference between believing your controls work and proving they do is the difference on which organisations now stand or fall. Along the way the series has built the complete apparatus: the assurance map, the accountable board, the integrated audit, the mandatory standard, honest testing, ransomware resilience, sector calibration, verified closure and the continuous rhythm. One question remains — the one every reader has been entitled to ask since the first article: where, precisely, do we begin?

This finale answers it with a roadmap measured in days, not aspirations: ninety of them, in three deliberate phases. Days one to thirty: see clearly — date your evidence, run the diagnostic, build the first assurance map, and brief the board. Days thirty-one to sixty: fix what matters — stand up the closure engine, take the quick wins, verify the fundamentals, and draft the decisions no one should make at 2 a.m. Days sixty-one to ninety: build the rhythm — the quarterly calendar, the first retest cycle, the executive tabletop, and the standing evidence file, opened. Ninety days does not finish the journey; it ends the drift — and on day ninety-one, the organisation is no longer starting. It is operating.

 

Why Ninety Days — and Why the Enemy Is Drift, Not Difficulty

Nothing in this series is beyond any organisation reading it. The disciplines are known, the frameworks are free, the questions are written down — the previous eleven articles contain, quite literally, the checklists. What defeats Caribbean organisations is rarely difficulty; it is drift: the briefing that impresses and expires, the assessment scheduled for the quarter that never quite arrives, the tracker opened with resolve and abandoned by December. Drift thrives on open-endedness — and the cure for open-endedness is a calendar.

Ninety days is the deliberate length. It is long enough to build every foundation this series has specified, and short enough that a single executive sponsor can hold the whole arc in view without a change of budget year, board composition or attention. It also matches the way the external world now moves: somewhere in the next ninety days, most organisations will face a renewal, a questionnaire, an examination or a customer’s security schedule — and each lands differently on an organisation ninety days into the work than on one still meaning to start. The roadmap below assumes nothing but a start date and a sponsor. Everything else, it builds.

Days 1–30: See Clearly

The first month replaces impressions with facts. Date your evidence — the afternoon exercise of Article 11: every piece of independent cyber evidence the organisation holds, listed with its age; this single page usually makes the rest of the programme self-arguing. Run the diagnostic — the fixed-scope, framework-anchored assessment of Article 1, aimed at the organisation’s two or three genuine loss scenarios rather than a thousand-row generic checklist: what would actually hurt, and what stands in the way today? Build assurance map, version one — Article 2’s instrument: material cyber risks in rows; who assures each, at what depth, how recently, in columns; blank spaces left honestly blank, because the blanks are the point. And brief the board — Article 3’s session: the enterprise-risk case, the map with its blanks, the dashboard skeleton, and the ninety-day plan itself, so that governance owns the programme from its first month rather than receiving it as a fait accompli in its third.

 

Days 31–60: Fix What Matters

The second month converts findings into motion — correctly, from the first day. Stand up the closure engine before remediation begins, not after: Article 10’s register with every finding from the diagnostic carried in, each with a named owner, a committed date and the dual rating of Article 6, so that nothing born in this programme can ever die by assertion. Take the quick wins the diagnostic surfaced — every assessment yields fixes that are days of effort against material exposure, and early verified closures teach the organisation what finishing feels like. Verify the fundamentals rather than assuming them: multi-factor authentication genuinely everywhere that matters, backup copies genuinely beyond production credentials, privileged access genuinely limited to those who need it — the three disciplines that decide most real events, per Article 7, checked in the environment rather than in the policy. And draft the 2 a.m. decisions in daylight: the escalation protocol — who convenes whom, within what hours — and the ransom decision framework, written, counselled and approved while it is still a document rather than a crisis.

THE SEQUENCING RULE

The register before the remediation; the closure standard before the first closure; the escalation protocol before the incident. Ninety days is short — but it is long enough to do things in the right order, and the order is most of the value.

 

Days 61–90: Build the Rhythm

The third month makes the work permanent. Put the quarterly calendar in writing — Article 11’s cadence, dated for the next four quarters with owners attached: the retest bundle, the board dashboard with its three trend lines, the assurance-map review. Schedule the first retest cycle to verify the quarter’s closures — by someone independent of the fixers — so the closure standard operates before the programme’s first quarter ends. Define the event triggers: the five or six changes — new core system, major migration, significant vendor change — that will automatically scope an assessment. Run the executive tabletop of Article 7: half a day, the realistic scenario, the decision-makers present, the drafted frameworks exercised. Open the evidence file of Article 8 — diagnostic, map, closures, retests, exercise records — as a standing asset that answers the next questionnaire from the file rather than from a scramble. And scope the year’s deep work: the integrated review of Article 4 aimed at the leading loss scenario, and — where an internal audit function exists — its path to the conformance of Article 5.

Three Starting Points, One Roadmap

The roadmap flexes to where an organisation actually stands. The organisation starting from little runs it exactly as written — and should take heart: ninety days separates it not from perfection but from the drifting majority, and the evidence-dating exercise will show the distance travelled faster than any other measure. The organisation assessed but stalled — the commonest Caribbean position, holding a report and a dormant tracker — compresses phase one: refresh rather than repeat the diagnostic, carry the existing findings into the new register on day one, and spend the recovered weeks on closure, because its gap is not knowledge but finishing, per Article 10. And the mature but episodic organisation — assessed annually, remediating decently, still navigating between photographs — treats the ninety days as Article 11’s crawl made concrete: its emphasis falls on the third phase, the cadences, the triggers and the standing file, because its gap is not effort but rhythm.

What Day Ninety-One Looks Like

On day ninety-one, nothing dramatic happens — which is precisely the achievement. The register is simply consulted, because it is where findings live. The next quarterly retest bundle is simply on the calendar, because the calendar exists. The board’s next pack simply contains the dashboard, because it did last quarter. A customer’s security questionnaire arrives and is answered in an afternoon from the file. Somewhere in the following months the first event trigger fires — a system change scopes an assessment — and no one has to argue for it, because it was agreed in writing on a calmer day. This is what the entire series has meant by assurance as a condition rather than an event: not a heroic annual effort, but an organisation in which the verifying of cyber confidence has become, in the quietest sense of the word, ordinary.

And the compounding begins. The second quarter’s trend lines give the board its first honest view of trajectory. The first repeat finding — there will be one — triggers the root-cause discipline instead of a shrug. The crawl year of Article 11 completes itself largely on schedule, because its components were laid in the right order. Organisations that run these ninety days do not merely start well; they become difficult to knock off course, because rhythm, once established, defends itself.

The Dawgen Global Perspective: Closing the Series

Twelve articles ago, The Cyber Assurance Advantage™ set out to move one conversation: from “we have cybersecurity” to “we can prove our controls work.” The series has made that argument to boards and audit committees, to internal auditors and their new mandatory standard, to buyers of testing and readers of reports, to the survivors of the region’s hardest scenario, to its most trusted sector and the sectors beyond it, and finally to the disciplines — closure and rhythm — that turn all of it from documents into a condition. If one sentence survives the series, let it be this: assurance is not what an organisation buys once a year; it is how an organisation runs.

Dawgen Global built its cyber assurance practice — and wrote this series — for organisations ready to make that shift, and the ninety-day roadmap is deliberately the practice’s front door: a defined, sponsored, calendar-bound engagement that ends with the foundations standing and the rhythm running. The series’ launch arc closes here, but the work continues — in sector campaigns, executive briefings, webinars and the articles ahead — because the threat landscape will not stop moving and neither will the standard of proof. To every reader who has travelled the twelve articles: the frameworks are yours, the checklists are yours, and the only thing this series cannot supply is the start date. That part was always going to be yours too.

Ten Commitments to Make on Day One

  1. Name the executive sponsor who owns the ninety days — one person, not a committee.
  2. Put the date-your-evidence exercise on this week’s calendar.
  3. Commission the diagnostic — scoped to our real loss scenarios, not a generic checklist.
  4. Book the board briefing for within thirty days, before results exist to soften.
  5. Stand up the register before the first remediation begins.
  6. Adopt the closure standard in writing: no finding closes by assertion.
  7. Verify the three fundamentals in the environment: MFA, survivable backups, privileged access.
  8. Draft the escalation protocol and ransom framework before they are needed.
  9. Date the quarterly rhythm for four quarters — with named owners.
  • Open the evidence file — and commit that it will never again be more than a quarter old.

Frequently Asked Questions

We have almost nothing in place. Is ninety days genuinely realistic?

Yes — for the foundations, which is what the roadmap builds. It does not promise a finished programme; it promises the map, the engine, the fundamentals verified, the decisions drafted and the rhythm dated. That is a transformed position, and every element is sized to be achievable by a sponsored programme in a mid-sized organisation — the phases exist precisely so nothing depends on doing everything at once.

Who should own the ninety days?

A single accountable executive sponsor — typically the CEO, CFO or COO in mid-sized organisations — with the board receiving the plan in month one and the dashboard from month three. Cyber assurance is an enterprise-risk programme; parking it below the executive level is how it drifts, per this series’ very first article.

We completed an assessment last year. Do we start over?

No — you start ahead. Carry last year’s findings into the register on day one, refresh rather than repeat the diagnostic, and spend the recovered time on verified closure and the rhythm. An existing report is an asset precisely once it enters a governed engine; until then it is the stalled position this series has described.

What does the programme cost?

It scales with size and starting point, and the honest framing is the one Article 11 gave: measured against emergency engagements, questionnaire scrambles, crash remediation and incident exposure, the sequenced programme is consistently the cheaper way to buy the same outcomes — and the evidence-dating exercise on day one has a way of making the business case internally, at no cost at all.

Move From Cybersecurity Assumptions to Independent Cyber Assurance

Dawgen Global combines cyber governance, risk-based internal audit, penetration testing, resilience assessment and remediation validation to help Caribbean organisations determine whether their cybersecurity controls are properly designed and operating effectively. The ninety-day roadmap in this article is delivered as a defined, sponsored programme — diagnostic to rhythm, with the evidence file standing at the end. To set your organisation’s start date, request a confidential first-ninety-days scoping discussion.

About Dawgen Global

Dawgen Global is an independent, integrated multidisciplinary professional services firm headquartered at 47 Trinidad Terrace, New Kingston, Jamaica, serving more than 15 territories across the Caribbean. Founded and led by Dr. Dawkins Brown, Executive Chairman, the firm is independent and not affiliated with any international network. It delivers a full suite of professional services under one roof: audit and assurance; tax advisory; IT and digital transformation; risk management; cybersecurity; actuarial and insurance regulatory advisory; HR advisory; mergers and acquisitions; corporate recovery; business advisory and strategy; accounting BPO and virtual CFO services; and legal process outsourcing.

The proposition is simple: big-firm capability without the big-firm price. Dawgen Global’s integrated approach is built for the specific complexities and opportunities of the Caribbean market, helping organizations make sharper, better-informed decisions that drive measurable progress.

To explore a partnership, reach out:

by Dr Dawkins Brown

Dr. Dawkins Brown is the Executive Chairman of Dawgen Global , an integrated multidisciplinary professional service firm . Dr. Brown earned his Doctor of Philosophy (Ph.D.) in the field of Accounting, Finance and Management from Rushmore University. He has over Twenty three (23) years experience in the field of Audit, Accounting, Taxation, Finance and management . Starting his public accounting career in the audit department of a “big four” firm (Ernst & Young), and gaining experience in local and international audits, Dr. Brown rose quickly through the senior ranks and held the position of Senior consultant prior to establishing Dawgen.

https://www.dawgen.global/wp-content/uploads/2023/07/Foo-WLogo.png

Dawgen Global is an integrated multidisciplinary professional service firm in the Caribbean Region. We are integrated as one Regional firm and provide several professional services including: audit,accounting ,tax,IT,Risk, HR,Performance, M&A,corporate recovery and other advisory services

Where to find us?
https://www.dawgen.global/wp-content/uploads/2019/04/img-footer-map.png
Dawgen Social links
Taking seamless key performance indicators offline to maximise the long tail.
https://www.dawgen.global/wp-content/uploads/2023/07/Foo-WLogo.png

Dawgen Global is an integrated multidisciplinary professional service firm in the Caribbean Region. We are integrated as one Regional firm and provide several professional services including: audit,accounting ,tax,IT,Risk, HR,Performance, M&A,corporate recovery and other advisory services

Where to find us?
https://www.dawgen.global/wp-content/uploads/2019/04/img-footer-map.png
Dawgen Social links
Taking seamless key performance indicators offline to maximise the long tail.

© 2023 Copyright Dawgen Global. All rights reserved.

© 2024 Copyright Dawgen Global. All rights reserved.