daemon-blockint-tech/agentic-enteprises-skill

vendor-cyber-risk-analyst

Guides third-party and vendor cyber risk—TPRM intake and tiering, security questionnaire analysis and scoring, evidence and attestation review (SOC 2, ISO 27001, pen test summaries), continuous vendor monitoring, concentration and fourth-party risk, remediation tracking, and executive or procurement risk reporting. Use for vendor security assessments, SIG/CAIQ/custom questionnaire review, vendor tiering, inherent vendor cyber risk, vendor incident or breach impact, subprocessors and fourth part…

First seen May 20, 2026

Installation

$ npx skills add daemon-blockint-tech/agentic-enteprises-skill --skill vendor-cyber-risk-analyst

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from daemon-blockint-tech/agentic-enteprises-skill · top by installs.

npx skills add daemon-blockint-tech/agentic-enteprises-skill

Browse all from daemon-blockint-tech/agentic-enteprises-skill

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 8
Default branch main
Open issues 0
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 5,687 B
  • docs SUMMARY.md 1,028 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 30 installs

SKILL.md

Vendor Cyber Risk Analyst

When to Use

  • Run TPRM intake — new vendor requests, renewals, scope changes, offboarding risk
  • Tier vendors by data, access, criticality, substitutability, and concentration
  • Analyze security questionnaires (SIG, CAIQ, custom) — consistency, gaps, scoring
  • Review evidence and attestations — SOC 2, ISO 27001, pen test letters, trust centers
  • Operate continuous monitoring — breach feeds, rating changes, cert expiry, news
  • Assess concentration and fourth-party (subprocessor) exposure
  • Track remediation — findings, owners, due dates, re-assessment triggers
  • Produce vendor risk reports for procurement, security, and executive audiences

When NOT to Use

  • M&A, investment, or deal-team diligence packs → cyber-diligence-governance
  • Enterprise risk register, FAIR models, or risk appetite without vendor ops → security-risk-analyst
  • GRC program scope, audit prep, or org-wide compliance attestation → compliance-specialist
  • Deploy IAM, federation, PAM, or cloud IAM policies → iam-specialist, information-security-engineer
  • Define CISO strategy, board operating model, or crisis exec comms → chief-information-security-officer
  • Physical supply chain, logistics, inventory, or OEM sourcing → supply-chain-manager
  • Broad security architecture, IR program, or pentest governance → cybersecurity
  • Execute pentests or validate exploits → penetration-tester
  • Negotiate contract redlines or legal interpretation → commercial-counsel

Related skills

Need Skill
M&A/investment diligence and IC cyber packs cyber-diligence-governance
Enterprise risk register, treatment, FAIR framing security-risk-analyst
GRC program, audit prep, questionnaire response library compliance-specialist
IAM federation, access reviews, PAM implementation iam-specialist
SIEM/EDR, guardrails, technical remediation information-security-engineer
Executive security strategy and board posture chief-information-security-officer
Physical/logistics supply chain and sourcing supply-chain-manager
Enterprise security program and IR policy cybersecurity

Core Workflows

1. Intake and tiering

Capture vendor context, data flows, integrations, and business owner. Assign tier and assessment depth before deep review.

See references/tprmintakeand_tiering.md.

2. Questionnaire analysis

Map responses to control themes, flag inconsistencies, score gaps, and define evidence asks.

See references/questionnaire_scoring.md.

3. Evidence and attestation review

Validate SOC/ISO scope, bridge letters, pen test coverage, subprocessors, and incident history.

See references/evidenceandattestation_review.md.

4. Continuous monitoring and incidents

Monitor rating changes, public incidents, cert expiry, and contract events; trigger re-assessment.

See references/continuousmonitoringand_incidents.md.

5. Reporting and remediation

Track findings to closure; report tier distribution, top risks, concentration, and renewal pipeline.

See references/vendorriskreporting.md.

Outputs

  • Vendor tier memo — tier, rationale, assessment depth, cadence
  • Assessment summary — findings by severity, evidence gaps, residual vendor risk
  • Remediation tracker — owner, due date, status, re-test trigger
  • Executive / procurement pack — heat map, concentration, incidents, renewals due
  • Fourth-party / subprocessor register — inherited risk for T1 vendors

Principles

  • Tier before depth — match questionnaire and evidence to inherent risk
  • Evidence over assertions — require attestations for material claims
  • Separate cyber vendor risk from deal diligence — use cyber-diligence-governance for transaction-only packs
  • Feed the enterprise register — align with security-risk-analyst without duplicating program ownership
  • No legal advice — provide risk tier and required clause themes; escalate terms to counsel

When to load references

Topic Reference
Role boundaries references/vendorcyberriskanalystscope.md
Intake and tiering references/tprmintakeand_tiering.md
Questionnaire scoring references/questionnaire_scoring.md
Evidence and attestations references/evidenceandattestation_review.md
Monitoring and incidents references/continuousmonitoringand_incidents.md
Reporting and remediation references/vendorriskreporting.md