Security Roadmap Template: A 12-Month Plan in 7 Phases

8 min read ยท 2026-10-09

A security roadmap template is a plan that turns your security goals into ordered phases, steps and milestones over a set period, usually 12 months. The template below is for a company building its first real security program. It starts with who owns what. Then it covers identity, devices, logging, incident response and training, and ends with a review.

This one is filled in: every phase has a goal, steps and a milestone. Copy it as it is. Then shorten or stretch the phases to fit your team size, your risks and any audit dates you already have. You can build it online in the tool you already use, such as Excel, PowerPoint or Notion, or in a roadmap maker.

The roadmap at a glance

Goal: Build a working security program within 12 months. It should protect accounts, devices and data, detect problems early and help you recover from incidents. Duration: 12 months

  1. Baseline and Ownership (Weeks 1 to 4)

    Know what you have, what matters most, and who is responsible for it.

    • Name one security owner and one executive sponsor.
    • List all systems, cloud services and devices, and the data each one holds.
    • Rank your top 10 risks by likelihood and business impact.
    • Pick a reference framework to measure against, such as NIST CSF 2.0 or CIS Controls.
    • Score where you stand today on that framework.

    Milestone: A signed-off asset list, a top 10 risk register and a baseline score.

  2. Identity and Access Quick Wins (Month 2)

    Close the gaps attackers use most often: weak logins and too many permissions.

    • Turn on multi-factor authentication for email, cloud consoles and admin accounts.
    • Remove the accounts of people who have left, and shared accounts nobody owns.
    • Roll out a company password manager.
    • Limit admin rights to the people who need them for daily work.

    Milestone: Multi-factor authentication active on every admin and email account, with a list of exceptions and an end date for each one.

  3. Device and Data Protection (Months 3 to 4)

    Make sure every laptop, phone and server is managed, patched and backed up.

    • Enroll company devices in a device management tool and turn on disk encryption.
    • Set a patching rhythm: critical updates within a fixed number of days, the others monthly.
    • Classify data into three levels, such as public, internal and confidential.
    • Set up backups for critical systems and keep one copy offline or locked against changes.
    • Run a first restore test from backup.

    Milestone: All managed devices encrypted and patched, and one successful restore test documented.

  4. Logging and Detection (Months 5 to 6)

    See suspicious activity before it becomes a crisis.

    • Turn on logs for identity, email, cloud and critical servers.
    • Send those logs to one central place with a set retention period.
    • Write 5 to 10 alert rules for your top risks, such as impossible logins or mass downloads.
    • Decide who reviews alerts and how often.

    Milestone: Central logging live for critical systems, with alerts reviewed on a written schedule.

  5. Incident Response and Recovery (Months 7 to 8)

    Know exactly what to do in the first hours of an incident.

    • Write an incident response plan with roles, a contact list and decision rights.
    • Prepare short playbooks for phishing, ransomware, a lost device and leaked credentials.
    • With your legal adviser, list your legal and contract duties to report incidents.
    • Run a tabletop exercise with leadership on one realistic scenario.

    Milestone: An approved incident plan and one completed tabletop exercise, with action items logged.

  6. People, Vendors and Policies (Months 9 to 10)

    Reduce the risk from human error and from the companies you depend on.

    • Run security awareness training for all staff, then a phishing simulation.
    • List your critical vendors and review their security answers or reports.
    • Publish short policies on acceptable use, access control, data handling and incident reporting.
    • Add security checks to onboarding and offboarding.

    Milestone: All staff trained and every critical vendor reviewed.

  7. Review and Plan Year Two (Months 11 to 12)

    Measure progress and decide what comes next.

    • Score yourself again on the framework you chose in phase one.
    • Update the risk register: what is closed, what is reduced, what is new.
    • Present results and gaps to leadership.
    • Draft the year two roadmap. It could include formal certification, penetration testing or a 24/7 monitoring service.

    Milestone: Leadership approves the year one review and the year two priorities.

What a security roadmap is, and what it is not

A security roadmap is a time-based plan. It shows which security improvements you will make, in what order and by when. It links each piece of work to a risk or a business goal. It is not a list of tools to buy, and it is not a policy document. A good roadmap answers three questions: where are we today, where do we need to be, and what do we do first?

A security roadmap is also different from a security strategy. The strategy explains why and sets the direction, for example "protect customer data so we can sell to large companies". The roadmap is the how and the when. If your company has no written strategy yet, phase one of the template gives you enough to write a short one: your risks, your assets and your target level.

How to set priorities in your security roadmap

Order the work by risk, not by what is easiest or most visible. A simple method: score each risk from 1 to 5 on likelihood and on impact, then multiply the two. The highest scores go first. This is why identity work sits in month 2. Weak logins are common, and the damage can be large.

Add business deadlines too. If a customer contract requires a security review in month 6, move the policy and vendor work earlier. Real deadlines will rewrite a roadmap that ignores them.

Use a framework so you do not miss whole areas. Three are widely used:

  • NIST Cybersecurity Framework 2.0: six functions (Govern, Identify, Protect, Detect, Respond, Recover). The phases above follow this order.
  • CIS Controls: a ranked list of controls, with a first group of basic safeguards meant for smaller teams.
  • ISO/IEC 27001: an international standard you can be certified against. Large customers often ask for it.

How to adapt this security roadmap template to your situation

The 12-month plan fits a small or mid-sized company where one person or a small team is in charge of security. The time frames in the template are only an example. Change the pace to match your team, your risks and your deadlines.

  • Startup with no security person: keep phases 1 to 3 and do them in 3 months. Write a one-page incident plan. Push logging and vendor reviews to later.
  • Company preparing for a certification audit: start from the audit date and work backwards. Move policies and evidence collection earlier, and add a gap assessment to phase one.
  • Team with an existing program: skip the baseline. Start from your last assessment and use the phases as a checklist for weak spots.
  • Regulated sector: before phase one ends, ask your legal or compliance team which rules apply. They can change your priorities.

How to present a security roadmap to leadership

Leaders want to know which risks go down, what it costs in time and money, and what they need to decide. Show the roadmap as phases on a timeline, not as a list of 60 tasks. For each phase, give one line on the risk it reduces and one line on the help you need, such as budget, a new hire or time from other teams.

Show what changes for staff. Multi-factor authentication, device management and training all affect daily work. Say when each change will happen and how you will explain it. Employees push back on projects that surprise them, and pushback causes delays.

Finally, ask for a clear decision at the end: approve the plan, approve the budget, or choose between two options. A roadmap meeting with no decision often ends with no plan.

How to keep the roadmap alive

A security roadmap is only useful if it changes when reality changes. Review it once a month with the security owner and once a quarter with the executive sponsor. Mark each step as done, in progress, blocked or moved, and write down why.

When an incident, a new customer demand or a new regulation appears, change the order of the phases. Moving a step is normal. Dropping one without telling anyone is how gaps come back.

Track a few signals that show progress without inventing targets:

  • Share of admin accounts with multi-factor authentication.
  • Share of devices enrolled, encrypted and patched.
  • Date of the last successful backup restore test.
  • Number of open high risks in the register.
  • Share of staff who completed training.

Common mistakes to avoid

  • Starting with tool purchases. Buy a tool only after phase one shows which risks it reduces.
  • Planning everything at once. Limit each phase to a few steps a small team can finish.
  • Leaving out ownership. Put one named person on every phase and milestone.
  • Vague milestones like "improve security". Write milestones you can check, such as "restore test passed on this date".
  • Skipping backup restore tests. Run one in phase three and again before the year ends.
  • Hiding the roadmap from other teams. Share the timeline with IT, HR and leadership early.

Frequently asked questions

What should a security roadmap template include?

It should include a goal, a duration, phases with clear objectives, concrete steps, an owner for each phase and milestones you can check. It should also show which risk each phase reduces. A risk register and a framework reference help keep the plan complete.

How long should a security roadmap be?

Most teams plan 12 months in detail and the following year at a high level. Startups that need protection quickly can use shorter plans of 3 to 6 months. Longer plans are hard to keep accurate because threats and business needs change.

What is the difference between a security roadmap and a cybersecurity strategy?

The strategy sets the direction and explains why security matters to the business. The roadmap is the dated plan of work that delivers that strategy. You can start with a roadmap and write the strategy from what phase one teaches you.

Can I build a security roadmap in Excel or PowerPoint?

Yes. Excel works well for tracking steps, owners and status. PowerPoint works well for showing phases on a timeline to leadership. Many teams keep a detailed tracker and a one-page visual version side by side.

Generate this roadmap with AI