← Back to Insights DISP and Defence

DISP onboarding: your first 90 days as a new member

By Aaron Kelder

New DISP members face a steep learning curve. The first 90 days set the tone for whether cyber compliance becomes sustainable or a recurring scramble.

Days 1–30: Understand your obligations

  • Confirm your DISP membership level and associated cyber requirements
  • Identify who owns cyber security reporting internally
  • Conduct a baseline assessment against the DISP Cyber Security Framework

Days 31–60: Close critical gaps

  • Prioritise controls with the shortest remediation timelines
  • Establish incident reporting procedures aligned with DISP timeframes
  • Document personnel security requirements for cleared staff

Days 61–90: Build the rhythm

  • Schedule quarterly self-assessments
  • Integrate DISP requirements into existing Essential Eight tracking where possible
  • Brief leadership on ongoing obligations, not just onboarding tasks

DISP membership is a continuous program. The organisations that treat it that way from day one avoid costly remediation later.