TechKnowSurge
NIST CSF GV.PO-01 NIST 800-53 PM-1 ISC2 CC 1.3 NIST CSF GV.RM-01 NIST NICE K0798 NIST NICE K0799 DoD 8140 OG-WRL-005
InteractiveSecurityFree

The New Security Lead's First 90 Days

You're the first security lead at a six-clinic dental chain after an incident. Make seven decisions in 90 days and watch the functions you skip come back to bite.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

What you're doing: playing through the first 90 days of a new security lead at Brightside Dental, a six-clinic chain that holds patient health records, takes card payments and has just been hit by a fake invoice email. Seven times you choose what to do next. One choice builds a part of a cybersecurity program; the others are shortcuts that feel productive but skip it. Why it matters: the lesson's point is that security fails across a whole organization, not one computer at a time, and that a strong tool or a single fix cannot cover for missing risk assessment, regulations nobody checked, rules nobody wrote down, staff nobody trained or policies nobody enforces. The story makes that concrete. A function you skip in week 3 comes back as an incident in week 8, so you see the cost of the gap rather than being told about it. It also tests the two structural ideas from the lesson: a program is launched like a project but never finishes, and the ideal security function is separate from IT so that one team is not checking its own work. How to use it: before you pick, ask which choice would still be protecting the company a year from now. Read the feedback after every choice, then use the program health screen at the end to see what is missing. Choices are shuffled each time you play, so a replay tests the idea rather than the button.

How to play

You are the first security lead at Brightside Dental, six clinics that just had a security incident. You have 90 days to build a cybersecurity program.

  • At each decision, pick one choice. One builds a program function from the lesson; the others are shortcuts that skip it.
  • Feedback after every choice names the function and explains why.
  • Later weeks show what happens next. Functions you skipped come back as problems.

The last screen shows your program's health. Build at least 6 of the 7 functions to pass. Choices are shuffled each time you play.

What you'll learn

Aligned to

NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders.
NIST 800-53
PM-1 Information Security Program Plan
ISC2 CC
1.3 Understand governance concepts
NIST NICE
K0798 Knowledge of program management principles and practices
K0799 Knowledge of project management principles and practices
DoD 8140
OG-WRL-005 Executive Cyber Leader

Key terms

Cybersecurity Program
An ongoing organizational function that encompasses risk assessment, policy development, regulatory compliance, employee training, and accountability to protect the organization continuously.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Regulatory Compliance
The adherence to laws, government regulations, and industry standards that mandate how an organization must protect data and systems. Failure to meet regulatory requirements can result in fines, legal liability, and reputational damage.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Security Awareness Training
An ongoing program that educates employees about cybersecurity threats, safe practices, and organizational policies to reduce human-based risk. Effective training covers topics like phishing recognition, password hygiene, and social engineering.
Accountability
The obligation of an individual or department to answer for the custody, use, and safekeeping of an assigned asset.
Separation of Duties
SoD
Separation of Duties is a security control principle requiring that critical or sensitive tasks be divided among multiple individuals to prevent fraud, collusion, and unauthorized actions by any single person.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.

Topics

Interactive Scenario

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →