As AI becomes increasingly capable of helping attackers discover systems, interpret results, and repeat actions at greater speed, organizations should not wait for large-scale cybersecurity projects to be completed before taking steps to reduce risk.
A more practical approach is to divide the work into phases, with clearly assigned owners, delivery timelines, and measurable outcomes that management can review.
Table of Contents
The 30-60-90 day plan has three primary objectives:
First 30 days: Address immediate risks and determine whether an active compromise may already exist.
Days 31-60: Improve visibility, strengthen access controls, and limit lateral movement across the environment.
Days 61-90: Test incident response, validate recovery capabilities, and build cyber resilience.
Phase 1: Within the First 30 Days
1. Establish a Governance Structure
Senior management should appoint a working group that includes:
Business or mission executives
IT management
Cybersecurity leadership
Owners of critical systems
Legal
Corporate communications
Internal audit
Relevant third-party service providers
The organization should clearly define who has decision-making authority during an incident, as well as executive-level and operational-level points of contact.
2. Identify Systems and Assets
Create an inventory of critical systems and internet-facing assets, including the system owner, administrator, and service provider for each asset.
Systems that should be reviewed first include:
VPN and remote access systems
RDP and SSH
Web management interfaces
Cloud administration consoles
End-of-support systems
Systems with no clearly identified owner
Unnecessary services should be disabled or their access scope reduced immediately.
3. Reduce Account and Credential Risk
At a minimum, organizations should:
Enable MFA for administrator accounts, VPN, email, and cloud services
Disable unused accounts
Change passwords for critical accounts
Review service accounts
Eliminate shared administrator accounts
Identify passwords, tokens, and API keys embedded in scripts
Separate accounts used for backup and management systems
4. Prioritize Patching Based on Risk
Patching should be prioritized in the following order:
Internet-facing systems
VPN and remote access systems
Identity providers and domain controllers
Web servers and middleware
Databases
Backup and management systems
5. Review Historical Logs
Review at least the previous 90 days of logs, or as much historical data as the organization has available, to identify:
Unusual login activity
Newly created accounts
Privilege changes
Reconnaissance activity
Lateral movement
Persistence mechanisms
Data transfers to external destinations
Connections from previously unseen locations or sources
6. Validate and Test Backups
Organizations must confirm that backups exist for critical systems, that backup accounts are separated from domain administrator accounts, and that production systems cannot easily delete or modify backup data.
Within the first 30 days, the organization should perform an actual recovery test for at least one system. A successful backup job status alone should not be treated as proof that recovery will work.
Management Deliverables Within 30 Days
Management should receive:
An inventory of critical and internet-facing systems
A list of critical vulnerabilities
A list of privileged accounts
Initial log review findings
Backup status and recovery test results
An incident contact list
An urgent risk report with assigned owners and remediation deadlines
Phase 2: Days 31-60
Improve Visibility, Strengthen Access Control, and Limit Lateral Movement
1. Strengthen Identity Security
Organizations should:
Expand MFA coverage to all critical accounts
Implement role-based access control
Apply the principle of least privilege
Review employee and contractor access rights
Establish a Joiner-Mover-Leaver process
Define expiration and rotation cycles for secrets
2. Segment the Network
At a minimum, organizations should separate:
User networks
Server networks
Database networks
Backup networks
Management networks
OT or mission-specific networks, where applicable
Connections between zones should have a clear business justification, an accountable owner, and documented approval.
3. Improve Endpoint and Log Visibility
Enable or expand EDR coverage for critical endpoints and collect logs from:
Firewalls
Servers
Identity systems
VPN
Email
Cloud services
Management systems
Backup systems
Log retention periods should be sufficient to support investigations. Organizations should also define who reviews alerts and how escalation is handled.
4. Develop Incident Response Playbooks
At a minimum, playbooks should be prepared for:
Account compromise
Malware
Ransomware
Data breaches
Web server compromise
Cloud account compromise
Critical service disruption
Management Deliverables Within 60 Days
Management should receive:
Network and data flow diagrams
An access rights matrix for critical systems
The percentage of critical accounts protected by MFA
EDR coverage
A list of key log sources and alerts
A residual risk report
Phase 3: Days 61-90
Test Readiness and Build Recovery Capability
1. Conduct a Tabletop Exercise
Organizations should simulate scenarios such as:
AI-assisted intrusion
Credential theft
Critical service disruption
Unauthorized access to sensitive data or preparation for data exfiltration
Executives and business or mission owners should participate in these exercises. They should not be treated as technical-only tests because decisions may involve service shutdowns, regulatory notifications, public communications, and risk acceptance.
2. Test Recovery Capabilities
Select critical systems for recovery testing and measure:
Recovery Time Objective (RTO)
Recovery Point Objective (RPO)
Recovery tests should use backups that are separated from production systems. Any problems identified during testing should be used to improve the recovery runbook.
3. Assess Cybersecurity Risk and Security Posture
At a minimum, organizations should conduct:
Vulnerability assessments
Testing of internet-facing systems
Cloud configuration reviews
Third-party service provider assessments
Risk register development
Risk owner assignment and remediation deadlines
4. Establish an AI Security Governance Policy
The policy should define:
Which AI tools are authorized
Which types of data must not be submitted to external AI services
Who is allowed to install or connect AI agents
Which systems AI agents are permitted to access
Which actions require human approval
How prompts, actions, and audit logs must be recorded
How AI agents can be stopped or have their access revoked
Management Deliverables Within 90 Days
Management should receive:
Tabletop exercise results
Backup recovery test results
Vulnerability assessment reports
A risk register with remediation plans
An AI security policy
A long-term roadmap and budget
Guidance for CII Organizations
Critical Information Infrastructure (CII) organizations have responsibilities that go beyond deploying security tools. They must also maintain the continuity of services that may affect the public, the economy, and national security.
ThaiCERT summarizes key responsibilities as follows.
Before an Incident Occurs
Government agencies, regulatory or supervisory bodies, and CII organizations must establish cybersecurity codes of practice and standards. At a minimum, these should include an annual risk assessment plan and a cyber threat response plan.
Organizations must designate executive-level and operational-level points of contact, establish monitoring mechanisms, and participate in readiness assessments organized by the Office.
CII organizations must conduct a cybersecurity risk assessment and cybersecurity audit at least once a year and submit a summary of the results to the Office within 30 days after completion.
When a Cyber Threat Occurs or Is Expected
Organizations must:
Examine relevant information, computer systems, and surrounding events
Assess whether a cyber threat has occurred
Take preventive, response, and risk-reduction measures
Preserve evidence required for investigation
Notify the Office and relevant regulatory or supervisory bodies as soon as possible
If a threat has a significant impact on a CII organization’s systems, the organization must report it to the Office and relevant regulators and respond in accordance with applicable requirements.
When an Organization Has Limited Personnel or Technology
ThaiCERT states that organizations may request assistance from the Office when they face obstacles in preventing, responding to, or reducing cyber risk.
Budget or staffing constraints should therefore lead to coordinated requests for support. They should not become a reason for having no controls, no accountable owner, or no incident reporting process.
Turning CII Responsibilities into Operational Processes
To make these responsibilities actionable, organizations should define in advance:
Which events must be escalated to an incident
Who has decision-making authority
Who coordinates with the NCSA, regulators, and Sectoral CERT
Who is responsible for preserving evidence
Which systems may be isolated or taken offline
Which communication channels will be used if email or core systems are unavailable
How quickly third-party service providers must report incidents and provide logs
Executive Liability That Should Not Be Overlooked
The source material refers to legal provisions related to failure to report incidents, failure to comply with orders during serious or critical cyber threat situations, and potential liability for directors, managers, or persons responsible for the operations of a legal entity in certain circumstances.
However, being attacked does not automatically create legal liability for an organization or its executives. Liability depends on the organization’s legal status, applicable duties, relevant orders, actions or omissions, and the facts of each incident.
Any section discussing penalties should be reviewed by legal counsel before publication, especially where specific statutory provisions, fine amounts, or personal liability are mentioned.
Guidance for Small Organizations or Organizations with Limited Budgets
Smaller organizations do not need to begin by building a full SOC/CSOC or immediately purchasing large-scale SIEM and XDR platforms.
The first priority should be to identify and protect no more than five of the most critical systems, such as:
Citizen-facing or customer-facing service systems
Financial systems
Human resources systems
Email systems
Backup systems
Then prioritize cost-effective controls:
Enable MFA
Disable unnecessary services
Patch internet-facing systems
Disable unused accounts
Separate backup accounts
Enable logging
Test data recovery
Create an incident contact list
Organizations should also check whether existing licenses and platforms already include capabilities such as endpoint protection, firewall logging, email anti-phishing, conditional access, cloud security alerts, and backup alerts, and ensure that these capabilities are actually enabled.
If staffing is insufficient, organizations can consider a Shared SOC, Sectoral SOC, Managed Detection and Response service, or Managed Security Service Provider. However, there should still be an internal point of contact with the authority to make decisions and direct response actions.
Long-Term Roadmap: From Cybersecurity to Cyber Resilience
The long-term objective is not simply to prevent systems from being compromised. Organizations must also be able to:
Detect incidents quickly
Limit the scope of damage
Maintain critical missions and services
Recover services
Learn from incidents and continuously improve
A long-term approach should cover the following areas.
Zero Trust Architecture
Develop Zero Trust capabilities progressively based on risk across identity, device, network, application, data, and monitoring. Organizations do not need to implement everything as a single large-scale project.
Security Operations Appropriate to the Organization’s Size
Large organizations may develop internal SOC and threat hunting capabilities, while smaller organizations can use a Shared SOC or Managed Detection and Response service.
Continuous Security Validation
Establish an ongoing cycle of:
Vulnerability Assessment
Penetration Testing
Configuration Review
Breach and Attack Simulation
Purple Team Exercises
Tabletop Exercises
Backup Recovery Tests
Supply Chain Security
Include cybersecurity requirements in contracts, such as:
Incident notification timelines
Disclosure of subcontractors
Restrictions on remote access
MFA requirements
Log delivery requirements
Support for investigations and recovery
AI Security Readiness
Organizations should prepare for risk from both external threats and internal AI use.
External threats:
AI-assisted attacks
Automated reconnaissance
AI-generated phishing
Deepfakes
Automated exploit chaining
Internal AI use:
Shadow AI
Data leakage
Excessive agent privileges
Unauthorized tool execution
AI supply chain risk
Role-Based Workforce Development
Executives: Decision-making, risk, and service continuity
System owners: Accountability and risk acceptance
IT personnel: Hardening, patching, and monitoring
Users: Phishing, credential security, and data handling
Procurement: Cybersecurity requirements in contracts
Monthly Metrics Management Should Receive
An executive dashboard should track at least:
Number of critical systems with clearly assigned system owners
Percentage of critical accounts protected by MFA
Number of critical vulnerabilities that have exceeded SLA
Percentage of critical endpoints covered by EDR
Number of privileged accounts
Mean Time to Detect (MTTD)
Mean Time to Respond (MTTR)
Number of systems that have successfully passed recovery testing
Number of incidents reported within required timelines
Number of high-risk items with no assigned owner or remediation plan
Status of the annual risk assessment
Status of exercises and remediation of identified gaps
Executive Action Items
Management should require the following actions:
Appoint executive-level and operational-level owners
Create an inventory of critical and internet-facing systems
Enable MFA and review privileged accounts
Disable unnecessary services and ports
Patch high-risk systems based on priority
Review historical logs to identify possible compromise
Validate and test backups
Develop or review the cyber threat response plan
Define procedures for notifying the Office and relevant regulators
Report progress within 30 days
Execute the 60-day and 90-day plans with monthly follow-up
Develop a long-term roadmap based on the organization’s risks and available resources
Conclusion
Organizations do not need to have every type of security tool in place before they can begin preparing for Agentic AI.
What matters more is knowing which systems are critical, who owns the risk, which accounts have elevated privileges, which connections are unnecessary, which events require escalation, and whether the organization can actually recover its services.
As threats become faster and more automated, organizational response must also become clearer, more consistent, and more accountable.
The ultimate goal is not to make an organization impossible to attack. It is to make the organization harder to compromise, faster at detecting incidents, better at limiting damage, and more capable of restoring critical operations with confidence.
References
Interested in Assessing Your Organization’s Cybersecurity Readiness or Exploring Cybersecurity Solutions?


