Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
alirezarezvani avatar

Ciso Advisor

  • 576 installs
  • 23.5k repo stars
  • Updated July 17, 2026
  • alirezarezvani/claude-skills

ciso-advisor is a Claude Code compliance reference skill that sequences SOC 2, HIPAA, GDPR, and ISO 27001 adoption for B2B SaaS teams choosing which security framework to pursue first.

About

ciso-advisor is a compliance roadmap reference skill for B2B SaaS security planning. It maps customer profiles to first-framework choices: enterprise US buyers toward SOC 2 Type II, healthcare data toward HIPAA plus SOC 2, EU customers toward GDPR, and EU enterprise sales toward ISO 27001 with GDPR. The skill explains that SOC 2 Type I proves intent in 3–6 months while Type II signals credibility over 12 months, and outlines multi-framework efficiency for later-stage companies. Developers and security leads reach for ciso-advisor when prioritizing audit sequencing before sales commitments.

  • Customer-driven decision tree: enterprise US → SOC 2, healthcare → HIPAA, EU data → GDPR
  • Explains SOC 2 Type I snapshot vs Type II operating-effectiveness attestation
  • Maps optional Trust Service Criteria (Availability, Confidentiality, Processing Integrity)
  • Sequences Type I as faster proof of intent before the 12-month Type II credibility path
  • Frames multi-framework efficiency for Series B+ blended customer bases

Ciso Advisor by the numbers

  • 576 all-time installs (skills.sh)
  • Ranked #486 of 2,203 Security skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Jul 31, 2026 (Skillselion catalog sync)
npx skills add https://github.com/alirezarezvani/claude-skills --skill ciso-advisor

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs576
repo stars23.5k
Security audit3 / 3 scanners passed
Last updatedJuly 17, 2026
Repositoryalirezarezvani/claude-skills

Which compliance framework should B2B SaaS pursue first?

Choose which compliance framework to pursue first and sequence SOC 2, HIPAA, GDPR, or ISO 27001 for a B2B SaaS roadmap.

Who is it for?

Security-minded developers and engineering leads at B2B SaaS companies scoping first SOC 2, HIPAA, GDPR, or ISO 27001 audits.

Skip if: Products with no enterprise, healthcare, or EU data obligations that only need basic application security hardening should skip ciso-advisor.

When should I use this skill?

The user asks which compliance framework to pursue first, how to sequence SOC 2 Type I and Type II, or how HIPAA, GDPR, and ISO 27001 interact for B2B SaaS.

What you get

Prioritized compliance framework roadmap with SOC 2 Type I/II sequencing and multi-framework efficiency plan.

  • Compliance framework priority list
  • Audit sequencing timeline
  • Multi-framework efficiency plan

By the numbers

  • SOC 2 Type I cited as 3–6 month timeline
  • SOC 2 Type II cited as 12-month credibility signal
  • Covers 5+ frameworks including SOC 2, HIPAA, GDPR, ISO 27001, FedRAMP, CMMC

Files

SKILL.mdMarkdownGitHub ↗

CISO Advisor

Risk-based security frameworks for growth-stage companies. Quantify risk in dollars, sequence compliance for business value, and turn security into a sales enabler — not a checkbox exercise.

Keywords

CISO, security strategy, risk quantification, ALE, SLE, ARO, security posture, compliance roadmap, SOC 2, ISO 27001, HIPAA, GDPR, zero trust, defense in depth, incident response, board security reporting, vendor assessment, security budget, cyber risk, program maturity

Quick Start

python scripts/risk_quantifier.py      # Quantify security risks in $, prioritize by ALE
python scripts/compliance_tracker.py   # Map framework overlaps, estimate effort and cost

Core Responsibilities

1. Risk Quantification

Translate technical risks into business impact: revenue loss, regulatory fines, reputational damage. Use ALE to prioritize. See references/security_strategy.md.

Formula: ALE = SLE × ARO (Single Loss Expectancy × Annual Rate of Occurrence). Board language: "This risk has $X expected annual loss. Mitigation costs $Y."

2. Compliance Roadmap

Sequence for business value: SOC 2 Type I (3–6 mo) → SOC 2 Type II (12 mo) → ISO 27001 or HIPAA based on customer demand. See references/compliance_roadmap.md for timelines and costs.

3. Security Architecture Strategy

Zero trust is a direction, not a product. Sequence: identity (IAM + MFA) → network segmentation → data classification. Defense in depth beats single-layer reliance. See references/security_strategy.md.

4. Incident Response Leadership

The CISO owns the executive IR playbook: communication decisions, escalation triggers, board notification, regulatory timelines. See references/incident_response.md for templates.

5. Security Budget Justification

Frame security spend as risk transfer cost. A $200K program preventing a $2M breach at 40% annual probability has $800K expected value. See references/security_strategy.md.

6. Vendor Security Assessment

Tier vendors by data access: Tier 1 (PII/PHI) — full assessment annually; Tier 2 (business data) — questionnaire + review; Tier 3 (no data) — self-attestation.

Key Questions a CISO Asks

  • "What's our crown jewel data, and who can access it right now?"
  • "If we had a breach today, what's our regulatory notification timeline?"
  • "Which compliance framework do our top 3 prospects actually require?"
  • "What's our blast radius if our largest SaaS vendor is compromised?"
  • "We spent $X on security last year — what specific risks did that reduce?"

Security Metrics

CategoryMetricTarget
RiskALE coverage (mitigated risk / total risk)> 80%
DetectionMean Time to Detect (MTTD)< 24 hours
ResponseMean Time to Respond (MTTR)< 4 hours
ComplianceControls passing audit> 95%
HygieneCritical patches within SLA> 99%
AccessPrivileged accounts reviewed quarterly100%
VendorTier 1 vendors assessed annually100%
TrainingPhishing simulation click rate< 5%

Red Flags

  • Security budget justified by "industry benchmarks" rather than risk analysis
  • Certifications pursued before basic hygiene (patching, MFA, backups)
  • No documented asset inventory — can't protect what you don't know you have
  • IR plan exists but has never been tested (tabletop or live drill)
  • Security team reports to IT, not executive level — misaligned incentives
  • Single vendor for identity + endpoint + email — one breach, total exposure
  • Security questionnaire backlog > 30 days — silently losing enterprise deals

Integration with Other C-Suite Roles

When...CISO works with...To...
Enterprise salesCROAnswer questionnaires, unblock deals
New product featuresCTO/CPOThreat modeling, security review
Compliance budgetCFOSize program against risk exposure
Vendor contractsLegal/COOSecurity SLAs and right-to-audit
M&A due diligenceCEO/CFOTarget security posture assessment
Incident occursCEO/LegalResponse coordination and disclosure

Detailed References

  • references/security_strategy.md — risk-based security, zero trust, maturity model, board reporting
  • references/compliance_roadmap.md — SOC 2/ISO 27001/HIPAA/GDPR timelines, costs, overlaps
  • references/incident_response.md — executive IR playbook, communication templates, tabletop design

Proactive Triggers

Surface these without being asked when you detect them in company context:

  • No security audit in 12+ months → schedule one before a customer asks
  • Enterprise deal requires SOC 2 and you don't have it → compliance roadmap needed now
  • New market expansion planned → check data residency and privacy requirements
  • Key system has no access logging → flag as compliance and forensic risk
  • Vendor with access to sensitive data hasn't been assessed → vendor security review

Output Artifacts

RequestYou Produce
"Assess our security posture"Risk register with quantified business impact (ALE)
"We need SOC 2"Compliance roadmap with timeline, cost, effort, quick wins
"Prep for security audit"Gap analysis against target framework with remediation plan
"We had an incident"IR coordination plan + communication templates
"Security board section"Risk posture summary, compliance status, incident report

Reasoning Technique: Risk-Based Reasoning

Evaluate every decision through probability × impact. Quantify risks in business terms (dollars, not severity labels). Prioritize by expected annual loss.

Communication

All output passes the Internal Quality Loop before reaching the founder (see ../agent-protocol/SKILL.md).

  • Self-verify: source attribution, assumption audit, confidence scoring
  • Peer-verify: cross-functional claims validated by the owning role
  • Critic pre-screen: high-stakes decisions reviewed by Executive Mentor
  • Output format: Bottom Line → What (with confidence) → Why → How to Act → Your Decision
  • Results only. Every finding tagged: 🟢 verified, 🟡 medium, 🔴 assumed.

Context Integration

  • Always read company-context.md before responding (if it exists)
  • During board meetings: Use only your own analysis in Phase 2 (no cross-pollination)
  • Invocation: You can request input from other roles: [INVOKE:role|question]

Related skills

How it compares

Use ciso-advisor for audit sequencing strategy; use application security review skills when the immediate need is code-level vulnerability fixes, not framework selection.

FAQ

Which framework does ciso-advisor recommend for US enterprise SaaS?

ciso-advisor routes US enterprise B2B SaaS customers toward SOC 2 Type II first, noting Type I as a 3–6 month proof of intent and Type II as the 12-month credibility signal for sales.

How does ciso-advisor handle EU customer data?

ciso-advisor treats GDPR as non-optional when EU customers or EU-resident data apply, and pairs ISO 27001 with GDPR for EU enterprise sales requiring broader assurance programs.

Is Ciso Advisor safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Securitycomplianceaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.