daemon-blockint-tech/agentic-enteprises-skill

chief-information-security-officer

Guides executive security leadership—security program strategy and operating model, risk appetite and board or audit-committee reporting, KRIs and leadership metrics, incident escalation and crisis communications, security budget and org design, regulatory and audit relationships at exec level, and cyber insurance and vendor posture. Use when acting as CISO, preparing board security briefings, defining security program strategy or risk appetite, security metrics for board, crisis comms, securit…

First seen May 20, 2026

Installation

$ npx skills add daemon-blockint-tech/agentic-enteprises-skill --skill chief-information-security-officer

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from daemon-blockint-tech/agentic-enteprises-skill · top by installs.

npx skills add daemon-blockint-tech/agentic-enteprises-skill

Browse all from daemon-blockint-tech/agentic-enteprises-skill

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 8
Default branch main
Open issues 0
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 6,081 B
  • docs SUMMARY.md 908 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 30 installs

SKILL.md

Chief Information Security Officer (CISO)

When to Use

  • Define security program strategy — vision, pillars, 12–36 month roadmap, investment themes
  • Set risk appetite with board or audit committee — thresholds, escalation, exceptions
  • Prepare board and executive briefings — posture narrative, KRIs, material risks, asks
  • Lead incident escalation and crisis comms — executive decisions, regulators, customers, media
  • Build security budget and org design — headcount, tooling envelope, build vs buy, vendors
  • Manage regulatory and audit relationships at exec level — exam prep, consent agendas, themes
  • Define leadership metrics — KRIs, program health, outcome vs activity measures
  • Shape cyber insurance and vendor posture — coverage, broker, critical supplier risk
  • Align security with enterprise strategy — M&A diligence themes, digital risk, third-party risk

When NOT to Use

  • Deploy SSO, SIEM, EDR, hardening, or remediate vulnerabilities → information-security-engineer
  • Build risk registers, FAIR models, or treatment scoring → security-risk-analyst
  • GRC program scope, gap assessments, audit prep packs → compliance-specialist
  • Control testing workpapers, evidence automation → compliance-engineer
  • SOC alert triage, playbooks, shift operations → soc-analyst
  • Run CSIRT containment, forensics, or technical IR → incident-responder
  • Enterprise security reference architecture, zero-trust patterns, ARB standards → enterprise-security-architect
  • Infrastructure capex portfolio and facility supply chain → vp-of-infrastructure
  • Draft press statements, all-hands scripts, or comms templates → communication-lead
  • Broad security strategy without exec/board lens → cybersecurity

Related skills

Need Skill
Control implementation, SIEM/EDR, hardening information-security-engineer
Risk registers, inherent/residual, treatment security-risk-analyst
GRC program, frameworks, audit coordination compliance-specialist
Control testing, evidence automation compliance-engineer
Declared incident response execution incident-responder
Enterprise security reference architecture enterprise-security-architect
Infrastructure portfolio and exec infra narrative vp-of-infrastructure
Crisis and executive communications drafting communication-lead
Enterprise security strategy (non-exec depth) cybersecurity
M&A/investment diligence and IC cyber packs cyber-diligence-governance

Core Workflows

1. Scope and operating model

Clarify CISO authority, committee cadence, and what stays with security engineering vs GRC vs IR.

See references/ciso_scope.md.

2. Security strategy and program

Program pillars, roadmap, investment cases, and measurable outcomes.

See references/securitystrategyand_program.md.

3. Risk appetite and governance

Appetite statements, thresholds, exception governance, and board risk committee inputs.

See references/riskappetiteand_governance.md.

4. Board and executive communications

Briefing structure, KRIs, materiality, and decision asks for board and audit committee.

See references/boardandexecutive_communications.md.

5. Incident, crisis, and regulatory

Escalation paths, crisis comms, regulator notification themes, and audit/exam posture.

See references/incidentcrisisand_regulatory.md.

6. Metrics and org design

KRIs, program metrics, headcount model, budget envelope, and vendor/insurance posture.

See references/securitymetricsandorgdesign.md.

Outputs

  • Board security briefing — posture, KRIs, top risks, incidents, investments, decisions needed
  • Risk appetite memo — thresholds, metrics, escalation, exception process
  • Program roadmap — pillars, initiatives, dependencies, budget phasing
  • Crisis comms brief — facts, audiences, approvals, regulatory clock
  • Budget and org plan — FTE, tooling, contractors, ROI narrative
  • Audit/regulatory themes — open items, management responses, systemic fixes

Principles

  • Outcomes over activity — measure risk reduction and resilience, not ticket volume
  • Materiality for leadership — escalate what changes decisions, capital, or reputation
  • Delegate execution — CISO sets direction; engineers and GRC implement
  • Single narrative — align board story with risk appetite and program investments
  • Document decisions — appetite exceptions, crisis calls, and budget trade-offs

When to load references

  • Role boundary and handoffsreferences/ciso_scope.md
  • Program strategy and roadmapreferences/securitystrategyand_program.md
  • Appetite and governancereferences/riskappetiteand_governance.md
  • Board and exec briefingsreferences/boardandexecutive_communications.md
  • Crisis and regulatoryreferences/incidentcrisisand_regulatory.md
  • KRIs, budget, orgreferences/securitymetricsandorgdesign.md