What the monthly CISO work looks like
It is not a dashboard login and a PDF of CVEs. It is a named person who already knows how a 20-person office actually runs: the shared mailbox, the imaging PC that cannot be patched this week, the cyber application the owner signed last year without reading.
Month one is honesty: MFA, backups that restore, who has global admin, whether email forwarding rules exist, and whether the last “security training” was a video nobody finished. Then a written list — what is actually dangerous versus what a vendor is trying to sell. After that, the monthly review keeps the list honest.
If you need a document for an insurer, a hospital partner, or counsel, that is the BCP / DR engagement above. If you need CMMC or a SPRS number, that is CMMC readiness and DefensibleScore — not a vCISO sticker on a half-finished SSP.
Clinics and law offices: see healthcare and professional practices. Mid-incident: call IR, do not start a retainer.