How to Prepare for Agentic AI: A 30-60-90 Day Cyber Resilience Plan for Organizations and CII

As AI becomes increasingly capable of helping attackers discover systems, interpret results, and repeat actions at greater speed, organizations should not wait for large-scale cybersecurity projects to be completed before taking steps to reduce risk.

A more practical approach is to divide the work into phases, with clearly assigned owners, delivery timelines, and measurable outcomes that management can review.

Table of Contents

The 30-60-90 day plan has three primary objectives:

  • First 30 days: Address immediate risks and determine whether an active compromise may already exist.

  • Days 31-60: Improve visibility, strengthen access controls, and limit lateral movement across the environment.

  • Days 61-90: Test incident response, validate recovery capabilities, and build cyber resilience.

Phase 1: Within the First 30 Days

1. Establish a Governance Structure

Senior management should appoint a working group that includes:

  • Business or mission executives

  • IT management

  • Cybersecurity leadership

  • Owners of critical systems

  • Legal

  • Corporate communications

  • Internal audit

  • Relevant third-party service providers

The organization should clearly define who has decision-making authority during an incident, as well as executive-level and operational-level points of contact.

2. Identify Systems and Assets

Create an inventory of critical systems and internet-facing assets, including the system owner, administrator, and service provider for each asset.

Systems that should be reviewed first include:

  • VPN and remote access systems

  • RDP and SSH

  • Web management interfaces

  • Cloud administration consoles

  • End-of-support systems

  • Systems with no clearly identified owner

Unnecessary services should be disabled or their access scope reduced immediately.

3. Reduce Account and Credential Risk

At a minimum, organizations should:

  • Enable MFA for administrator accounts, VPN, email, and cloud services

  • Disable unused accounts

  • Change passwords for critical accounts

  • Review service accounts

  • Eliminate shared administrator accounts

  • Identify passwords, tokens, and API keys embedded in scripts

  • Separate accounts used for backup and management systems

4. Prioritize Patching Based on Risk

Patching should be prioritized in the following order:

  1. Internet-facing systems

  2. VPN and remote access systems

  3. Identity providers and domain controllers

  4. Web servers and middleware

  5. Databases

  6. Backup and management systems

5. Review Historical Logs

Review at least the previous 90 days of logs, or as much historical data as the organization has available, to identify:

  • Unusual login activity

  • Newly created accounts

  • Privilege changes

  • Reconnaissance activity

  • Lateral movement

  • Persistence mechanisms

  • Data transfers to external destinations

  • Connections from previously unseen locations or sources

6. Validate and Test Backups

Organizations must confirm that backups exist for critical systems, that backup accounts are separated from domain administrator accounts, and that production systems cannot easily delete or modify backup data.

Within the first 30 days, the organization should perform an actual recovery test for at least one system. A successful backup job status alone should not be treated as proof that recovery will work.

Management Deliverables Within 30 Days

Management should receive:

  • An inventory of critical and internet-facing systems

  • A list of critical vulnerabilities

  • A list of privileged accounts

  • Initial log review findings

  • Backup status and recovery test results

  • An incident contact list

  • An urgent risk report with assigned owners and remediation deadlines

Phase 2: Days 31-60

Improve Visibility, Strengthen Access Control, and Limit Lateral Movement

1. Strengthen Identity Security

Organizations should:

  • Expand MFA coverage to all critical accounts

  • Implement role-based access control

  • Apply the principle of least privilege

  • Review employee and contractor access rights

  • Establish a Joiner-Mover-Leaver process

  • Define expiration and rotation cycles for secrets

2. Segment the Network

At a minimum, organizations should separate:

  • User networks

  • Server networks

  • Database networks

  • Backup networks

  • Management networks

  • OT or mission-specific networks, where applicable

Connections between zones should have a clear business justification, an accountable owner, and documented approval.

3. Improve Endpoint and Log Visibility

Enable or expand EDR coverage for critical endpoints and collect logs from:

  • Firewalls

  • Servers

  • Identity systems

  • VPN

  • Email

  • Cloud services

  • Management systems

  • Backup systems

Log retention periods should be sufficient to support investigations. Organizations should also define who reviews alerts and how escalation is handled.

4. Develop Incident Response Playbooks

At a minimum, playbooks should be prepared for:

  • Account compromise

  • Malware

  • Ransomware

  • Data breaches

  • Web server compromise

  • Cloud account compromise

  • Critical service disruption

Management Deliverables Within 60 Days

Management should receive:

  • Network and data flow diagrams

  • An access rights matrix for critical systems

  • The percentage of critical accounts protected by MFA

  • EDR coverage

  • A list of key log sources and alerts

  • An Incident Response Playbook

  • A residual risk report

Phase 3: Days 61-90

Test Readiness and Build Recovery Capability

1. Conduct a Tabletop Exercise

Organizations should simulate scenarios such as:

  • AI-assisted intrusion

  • Ransomware

  • Credential theft

  • Critical service disruption

  • Unauthorized access to sensitive data or preparation for data exfiltration

Executives and business or mission owners should participate in these exercises. They should not be treated as technical-only tests because decisions may involve service shutdowns, regulatory notifications, public communications, and risk acceptance.

2. Test Recovery Capabilities

Select critical systems for recovery testing and measure:

  • Recovery Time Objective (RTO)

  • Recovery Point Objective (RPO)

Recovery tests should use backups that are separated from production systems. Any problems identified during testing should be used to improve the recovery runbook.

3. Assess Cybersecurity Risk and Security Posture

At a minimum, organizations should conduct:

  • Vulnerability assessments

  • Testing of internet-facing systems

  • Cloud configuration reviews

  • Third-party service provider assessments

  • Risk register development

  • Risk owner assignment and remediation deadlines

4. Establish an AI Security Governance Policy

The policy should define:

  • Which AI tools are authorized

  • Which types of data must not be submitted to external AI services

  • Who is allowed to install or connect AI agents

  • Which systems AI agents are permitted to access

  • Which actions require human approval

  • How prompts, actions, and audit logs must be recorded

  • How AI agents can be stopped or have their access revoked

Management Deliverables Within 90 Days

Management should receive:

  • Tabletop exercise results

  • Backup recovery test results

  • Vulnerability assessment reports

  • A risk register with remediation plans

  • An AI security policy

  • A long-term roadmap and budget

Guidance for CII Organizations

Critical Information Infrastructure (CII) organizations have responsibilities that go beyond deploying security tools. They must also maintain the continuity of services that may affect the public, the economy, and national security.

ThaiCERT summarizes key responsibilities as follows.

Before an Incident Occurs

Government agencies, regulatory or supervisory bodies, and CII organizations must establish cybersecurity codes of practice and standards. At a minimum, these should include an annual risk assessment plan and a cyber threat response plan.

Organizations must designate executive-level and operational-level points of contact, establish monitoring mechanisms, and participate in readiness assessments organized by the Office.

CII organizations must conduct a cybersecurity risk assessment and cybersecurity audit at least once a year and submit a summary of the results to the Office within 30 days after completion.

When a Cyber Threat Occurs or Is Expected

Organizations must:

  • Examine relevant information, computer systems, and surrounding events

  • Assess whether a cyber threat has occurred

  • Take preventive, response, and risk-reduction measures

  • Preserve evidence required for investigation

  • Notify the Office and relevant regulatory or supervisory bodies as soon as possible

If a threat has a significant impact on a CII organization’s systems, the organization must report it to the Office and relevant regulators and respond in accordance with applicable requirements.

When an Organization Has Limited Personnel or Technology

ThaiCERT states that organizations may request assistance from the Office when they face obstacles in preventing, responding to, or reducing cyber risk.

Budget or staffing constraints should therefore lead to coordinated requests for support. They should not become a reason for having no controls, no accountable owner, or no incident reporting process.

Turning CII Responsibilities into Operational Processes

To make these responsibilities actionable, organizations should define in advance:

  • Which events must be escalated to an incident

  • Who has decision-making authority

  • Who coordinates with the NCSA, regulators, and Sectoral CERT

  • Who is responsible for preserving evidence

  • Which systems may be isolated or taken offline

  • Which communication channels will be used if email or core systems are unavailable

  • How quickly third-party service providers must report incidents and provide logs

Executive Liability That Should Not Be Overlooked

The source material refers to legal provisions related to failure to report incidents, failure to comply with orders during serious or critical cyber threat situations, and potential liability for directors, managers, or persons responsible for the operations of a legal entity in certain circumstances.

However, being attacked does not automatically create legal liability for an organization or its executives. Liability depends on the organization’s legal status, applicable duties, relevant orders, actions or omissions, and the facts of each incident.

Any section discussing penalties should be reviewed by legal counsel before publication, especially where specific statutory provisions, fine amounts, or personal liability are mentioned.

Guidance for Small Organizations or Organizations with Limited Budgets

Smaller organizations do not need to begin by building a full SOC/CSOC or immediately purchasing large-scale SIEM and XDR platforms.

The first priority should be to identify and protect no more than five of the most critical systems, such as:

  • Citizen-facing or customer-facing service systems

  • Financial systems

  • Human resources systems

  • Email systems

  • Backup systems

Then prioritize cost-effective controls:

  1. Enable MFA

  2. Disable unnecessary services

  3. Patch internet-facing systems

  4. Disable unused accounts

  5. Separate backup accounts

  6. Enable logging

  7. Test data recovery

  8. Create an incident contact list

Organizations should also check whether existing licenses and platforms already include capabilities such as endpoint protection, firewall logging, email anti-phishing, conditional access, cloud security alerts, and backup alerts, and ensure that these capabilities are actually enabled.

If staffing is insufficient, organizations can consider a Shared SOC, Sectoral SOC, Managed Detection and Response service, or Managed Security Service Provider. However, there should still be an internal point of contact with the authority to make decisions and direct response actions.

Long-Term Roadmap: From Cybersecurity to Cyber Resilience

The long-term objective is not simply to prevent systems from being compromised. Organizations must also be able to:

  • Detect incidents quickly

  • Limit the scope of damage

  • Maintain critical missions and services

  • Recover services

  • Learn from incidents and continuously improve

A long-term approach should cover the following areas.

Zero Trust Architecture

Develop Zero Trust capabilities progressively based on risk across identity, device, network, application, data, and monitoring. Organizations do not need to implement everything as a single large-scale project.

Security Operations Appropriate to the Organization’s Size

Large organizations may develop internal SOC and threat hunting capabilities, while smaller organizations can use a Shared SOC or Managed Detection and Response service.

Continuous Security Validation

Establish an ongoing cycle of:

  • Vulnerability Assessment

  • Penetration Testing

  • Configuration Review

  • Breach and Attack Simulation

  • Purple Team Exercises

  • Tabletop Exercises

  • Backup Recovery Tests

Supply Chain Security

Include cybersecurity requirements in contracts, such as:

  • Incident notification timelines

  • Disclosure of subcontractors

  • Restrictions on remote access

  • MFA requirements

  • Log delivery requirements

  • Support for investigations and recovery

AI Security Readiness

Organizations should prepare for risk from both external threats and internal AI use.

External threats:

  • AI-assisted attacks

  • Automated reconnaissance

  • AI-generated phishing

  • Deepfakes

  • Automated exploit chaining

Internal AI use:

  • Shadow AI

  • Data leakage

  • Excessive agent privileges

  • Unauthorized tool execution

  • AI supply chain risk

Role-Based Workforce Development
  • Executives: Decision-making, risk, and service continuity

  • System owners: Accountability and risk acceptance

  • IT personnel: Hardening, patching, and monitoring

  • Users: Phishing, credential security, and data handling

  • Procurement: Cybersecurity requirements in contracts

Monthly Metrics Management Should Receive

An executive dashboard should track at least:

  1. Number of critical systems with clearly assigned system owners

  2. Percentage of critical accounts protected by MFA

  3. Number of critical vulnerabilities that have exceeded SLA

  4. Percentage of critical endpoints covered by EDR

  5. Number of privileged accounts

  6. Mean Time to Detect (MTTD)

  7. Mean Time to Respond (MTTR)

  8. Number of systems that have successfully passed recovery testing

  9. Number of incidents reported within required timelines

  10. Number of high-risk items with no assigned owner or remediation plan

  11. Status of the annual risk assessment

  12. Status of exercises and remediation of identified gaps

Executive Action Items

Management should require the following actions:

  1. Appoint executive-level and operational-level owners

  2. Create an inventory of critical and internet-facing systems

  3. Enable MFA and review privileged accounts

  4. Disable unnecessary services and ports

  5. Patch high-risk systems based on priority

  6. Review historical logs to identify possible compromise

  7. Validate and test backups

  8. Develop or review the cyber threat response plan

  9. Define procedures for notifying the Office and relevant regulators

  10. Report progress within 30 days

  11. Execute the 60-day and 90-day plans with monthly follow-up

  12. Develop a long-term roadmap based on the organization’s risks and available resources

Conclusion

Organizations do not need to have every type of security tool in place before they can begin preparing for Agentic AI.

What matters more is knowing which systems are critical, who owns the risk, which accounts have elevated privileges, which connections are unnecessary, which events require escalation, and whether the organization can actually recover its services.

As threats become faster and more automated, organizational response must also become clearer, more consistent, and more accountable.

The ultimate goal is not to make an organization impossible to attack. It is to make the organization harder to compromise, faster at detecting incidents, better at limiting damage, and more capable of restoring critical operations with confidence.

References


Interested in Assessing Your Organization’s Cybersecurity Readiness or Exploring Cybersecurity Solutions?

Contact BMSP

Contact BMSP to discuss practical cybersecurity solutions for your organization.

Share

Related Content

Get in touch with us. We’re here to assist you.

08. Home Bottom (EN)

Learn how we helped 100 top brands gain success