A 12-month security roadmap turns a long list of gaps into a sequenced plan you can fund, staff and deliver. The process is straightforward: baseline your current state against a framework, rank the gaps by risk reduction and effort, group the work into quarterly phases with quick wins up front, and match it to realistic budget and staffing. Then map dependencies, choose metrics and review the plan every month so it stays current.
With most organizations finalizing 2026 budgets now, this is the right time to build one. Here's how we approach it with small and mid-sized organizations.
Why build a 12-month security roadmap?
Without a roadmap, security work tends to be driven by whatever is loudest: the latest audit finding, a customer questionnaire, a vendor pitch. A roadmap gives you:
- A defensible order of work based on risk, not urgency
- A basis for budget requests tied to specific outcomes
- A way to say no, or "not this quarter," to lower-priority requests
- A shared view for IT, leadership and the board of what's happening and why
Twelve months is a useful horizon. It aligns with most budget cycles and is long enough for meaningful projects. It's also short enough that the plan stays grounded in current conditions.
How do you baseline your current security posture?
You can't plan a route without knowing where you're starting. Assess your current state against a recognized framework so the results are structured and comparable year to year.
Using NIST CSF 2.0
The NIST Cybersecurity Framework 2.0, published in February 2024, is a good fit for most organizations. It organizes outcomes into six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern was new in 2.0, and it covers the areas many roadmaps overlook, such as risk strategy, roles and responsibilities, policy and supply chain risk management.
CSF 2.0 supports this kind of planning directly through Organizational Profiles. You describe a Current Profile (where you are) and a Target Profile (where you want to be), and the gaps between them become your roadmap inputs. NIST also publishes quick-start guides, including one aimed at small businesses.
Organizations with limited resources may find the CIS Critical Security Controls, and specifically Implementation Group 1, a more concrete place to start. The two approaches can be mapped to each other, so you don't have to pick one forever.
Doing the assessment
- Assess at the Category level. For most mid-sized organizations, rating each CSF Category is detailed enough. Going deeper takes much longer and rarely changes priorities.
- Ask for evidence. Base ratings on what you can show, such as configurations, reports and records, not on what people believe is in place.
- Talk to the right people. Include IT operations, key business owners, HR and finance, not just the security team.
- Time-box it. Two to four weeks is usually enough. A baseline that takes three months delays the roadmap it's meant to feed.
How do you turn gaps into initiatives?
A gap assessment might produce 40 or 50 findings. Don't put them all on the roadmap as separate items. Group related gaps into initiatives, each with a clear outcome.
For example, findings about missing MFA on some systems, shared admin accounts and slow removal of leavers' accounts might become a single initiative: "Strengthen identity and access management."
For each initiative, write down:
- The outcome in one sentence
- The gaps and risks it addresses
- An accountable owner
- Rough effort (people time) and cost
- Dependencies on other work
How should you prioritize by risk and effort?
Score each initiative on two dimensions, using a simple 1-to-5 scale:
- Risk reduction: How much does this lower the likelihood or impact of your top risks?
- Effort: How much time, money and disruption will it take?
Then place each one in a quadrant:
| Low effort | High effort | |
|---|---|---|
| High risk reduction | Quick wins: do first | Major projects: plan and fund carefully |
| Low risk reduction | Fill-ins: do when capacity allows | Defer or drop |
Layer hard constraints on top. Regulatory deadlines, contractual commitments to customers and requirements from your cyber insurer may force some items forward regardless of their score.
Keep the scoring rough. The goal is a sensible order, not precision. If two initiatives score similarly, pick the one that unblocks other work.
What are good security quick wins?
Quick wins build momentum and reduce risk early. Common candidates:
- Enforce MFA on remaining accounts, starting with administrators, remote access and email
- Remove stale accounts, including leavers, unused service accounts and old vendor access
- Separate admin accounts from everyday user accounts
- Test a restore of a critical system from backup, not just the backup job
- Close exposed management interfaces, such as remote desktop or admin consoles reachable from the internet
- Patch internet-facing systems against vulnerabilities in CISA's Known Exploited Vulnerabilities catalog
- Turn on and extend logging for identity and cloud platforms, so you have data when you need it
- Update incident response contacts, including out-of-hours numbers
Most of these take days or weeks rather than months. Put them in the first quarter.
How do you structure the roadmap into quarterly phases?
Quarterly phases give you natural checkpoints and match how most organizations report. A typical shape for 2026:
| Quarter | Theme | Example initiatives |
|---|---|---|
| Q1 2026 | Foundations and quick wins | Quick wins above, asset inventory with owners, identity cleanup |
| Q2 2026 | Visibility | Centralized logging for key systems, a regular vulnerability management cycle, vendor inventory |
| Q3 2026 | Resilience and response | Incident response plan update and tabletop exercise, recovery testing for critical systems, assessments of critical vendors |
| Q4 2026 | Governance and planning | Policy review, risk register refresh, updated Current Profile, 2027 roadmap |
Major projects often span two or three quarters. Show them as bars across the quarters they cover, with a milestone in each.
Don't fill every quarter to capacity. Reserve roughly 20% of the team's time for unplanned work: incidents, audit requests, urgent vendor changes and the things nobody predicted.
How do you plan budget and staffing?
For each initiative, estimate:
- One-time costs: implementation, consulting, hardware
- Recurring costs: subscriptions, support, ongoing staff time
- Internal effort: hours from security, IT operations and business teams
Internal effort is often the biggest constraint and the one most often underestimated. A project that needs 200 hours from a two-person IT team will crowd out other work unless you plan for it.
Be realistic about concurrency. A small security function can usually run two or three significant initiatives at a time alongside operational work. Trying to run eight at once tends to mean all eight finish late.
Where you lack skills or capacity, decide early whether to hire, train or bring in outside help, because each has different lead times. Hiring can take a full quarter or more.
When presenting the budget, link each line to the risks it reduces and the metrics it should move. That makes the conversation about trade-offs rather than a single yes or no.
How do you map dependencies?
Some work can't start until other work is done. Missing a dependency is one of the most common reasons roadmaps slip.
Typical dependencies:
- Asset inventory comes before vulnerability management coverage and endpoint protection coverage can be measured.
- Identity cleanup comes before tighter access policies and single sign-on rollouts.
- Centralized logging comes before meaningful detection and alerting.
- Data classification comes before data loss prevention rules.
- Contract renewals set the timing for replacing or adding tools.
- Hiring comes before any initiative that depends on the new role.
Also note calendar constraints, such as change freezes at year-end or during peak trading periods, audit windows and major business events.
A simple list of "X depends on Y" is usually enough. For larger roadmaps, a basic dependency diagram helps identify the critical path.
What metrics show the roadmap is working?
Track two kinds of metrics.
Delivery metrics show whether you're doing what you planned:
- Initiatives on track, at risk or late
- Milestones completed versus planned each quarter
Outcome metrics show whether risk is actually going down:
- MFA coverage across all accounts and critical systems
- Median time to remediate critical vulnerabilities on internet-facing systems
- Share of assets in the inventory with a named owner
- Critical systems with a successful restore test in the last 12 months
- Critical vendors assessed
- Movement in your CSF Current Profile ratings
Record a baseline for each outcome metric at the start of the year and set a target for each quarter. Delivering every project on time while outcome metrics stay flat means the projects were the wrong ones.
How do you keep the roadmap alive?
Most roadmaps are presented in January and forgotten by March. Build in a rhythm:
- Monthly: A 30-minute review of progress, blockers and upcoming milestones with initiative owners.
- Quarterly: Re-plan the next quarter based on what was delivered, what changed and what you've learned. Report progress to leadership.
- Event-driven: Revisit priorities after a significant incident, an acquisition, a new regulatory requirement, a major vendor change or a big shift in the business.
Keep a short change log so everyone can see what moved and why. Publish a one-page view that leadership can read in a minute. Mark completed initiatives as done and record their outcome metrics, which gives you evidence for next year's budget conversation.
Frequently asked questions
Should we use NIST CSF 2.0 or the CIS Controls?
Either can work. CSF 2.0 is broader and includes governance, which suits roadmap planning and board reporting. The CIS Controls are more prescriptive, which helps smaller teams that want a concrete checklist. Many organizations use CSF 2.0 for structure and the CIS Controls for implementation detail.
How detailed should the roadmap be?
Detailed enough to assign owners and estimate effort for each initiative, but not a full project plan. Keep task-level detail in your project tools and the roadmap at the initiative and milestone level.
What if we can't get budget for everything?
Fund the highest-risk items first and document which risks remain unaddressed as a result. Explicit risk acceptance by leadership is a legitimate outcome, and it's far better than an unfunded plan that everyone assumes is happening.
How do we handle unplanned work?
Reserve capacity for it from the start, around 20% of team time. If unplanned work consistently exceeds that, it's a sign the roadmap is overcommitted or staffing is short.
Next steps
- Run a time-boxed baseline against NIST CSF 2.0 or the CIS Controls.
- Group the gaps into initiatives with owners, effort estimates and dependencies.
- Score each by risk reduction and effort, and schedule quick wins for Q1 2026.
- Lay out quarterly phases with 20% capacity held back.
- Tie budget lines to risks and metrics.
- Set up a monthly review and a quarterly re-plan before the year starts.