First 90 days

Build a technology risk picture before you inherit a surprise.

A practical review for a manufacturing CFO who needs to understand what could interrupt production, distort numbers, or create an unplanned investment.

Start with business dependency. You do not need to personally catalogue every device. Ask the IT owner for a current inventory and its gaps. You need a defensible view of the systems, people, vendors, and sites that would interrupt orders, production, shipping, payroll, cash collection, or month-end close.

CFO decision promptsCan I trust the number before close? Are the workarounds known? If the provider changes, who owns the knowledge? What happens if the ERP or identity system is unavailable on a production day?

Days 1–30: establish the facts

  • Name the business systems that stop revenue, production, fulfillment, or close.
  • Identify the executive, business owner, and technical owner for each critical system.
  • Request the current IT budget, provider agreement, project list, asset lifecycle plan, and cyber-insurance questionnaire.
  • Ask where critical knowledge lives: internal staff, a provider, a consultant, or an undocumented workaround.

Days 31–60: test the evidence

  • For each critical system, ask for the last recovery test, its result, its owner, and its actual time to restore.
  • Review current vendor access, privileged accounts, and what happens when a person leaves.
  • Compare planned technology spend with open renewal, replacement, and implementation commitments.
  • Confirm the status of ERP integrations, manual imports, data ownership, and reconciliations.

Days 61–90: turn findings into decisions

DecisionEvidence to requestUseful output
Fund recoveryRestore-test record, RTO/RPO, system ownerPrioritized recovery plan
Change providerService history, access inventory, transition planRisk-managed transition decision
Approve ERP workDependencies, data-quality baseline, cutover planGo, pause, or phase decision
Set the budgetRun-rate, renewals, lifecycle, project estimates12-month investment roadmap

The goal is not a technical audit. It is a short decision file that makes ownership, evidence, timing, and financial exposure visible.

Ask the team for a decision file

The CFO sponsors this review; the people who run the work supply the evidence. Have the operations lead name the processes that cannot stop, the controller identify close and cash dependencies, and the IT lead or provider map the supporting systems. Ask each owner to sign off on what is known, what has not been tested, and what needs a decision.

OwnerWhat to bringCFO decision
OperationsCritical production steps, tolerable interruption, manual capacityWhich process gets recovery priority?
ControllerERP reconciliations, close workarounds, cash and order exposureWhat financial control needs repair?
IT lead or providerSystem inventory, dependencies, restore results, access exceptionsWhich gap needs funding or escalation?
Broker and counselPolicy terms, application answers, notice requirementsWhat exposure remains with the company?

Include insurance in the review

Ask the broker to walk through the current cyber policy with the controller, operations lead, and IT owner. Record limits, retention, business-interruption waiting period, covered loss categories, exclusions, notice deadlines, and whether a provider or plant-control incident would meet the policy wording. Have the IT owner verify that the controls described in the application match current practice. Coverage is a financing tool, not proof that a plant can recover.

Decision record: one page per material gap with owner, business effect, evidence date, cost range, decision, and revisit date. The CFO accounts for the exposure and allocates capital; the responsible team executes the fix.