
Chief Information Security Officer
- 27 installs
- 7 repo stars
- Updated May 20, 2026
- daemon-blockint-tech/agentic-enteprises-skill
Act as CISO: set security program strategy and risk appetite, prepare board briefings and KRIs, lead crisis comms, and shape budget and org design.
About
Guides executive security leadership covering program strategy, risk appetite, board reporting, incident escalation, budget/org design, and cyber insurance. A developer or security exec uses it to prepare board briefings or define security program strategy.
- Security program strategy, risk appetite, and board reporting
- KRIs, budget/org design, and crisis communications
Chief Information Security Officer by the numbers
- 27 all-time installs (skills.sh)
- Ranked #1,533 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill chief-information-security-officerAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 27 |
|---|---|
| repo stars | ★ 7 |
| Last updated | May 20, 2026 |
| Repository | daemon-blockint-tech/agentic-enteprises-skill ↗ |
What it does
Act as CISO: set security program strategy and risk appetite, prepare board briefings and KRIs, lead crisis comms, and shape budget and org design.
Files
Chief Information Security Officer (CISO)
When to Use
- Define security program strategy — vision, pillars, 12–36 month roadmap, investment themes
- Set risk appetite with board or audit committee — thresholds, escalation, exceptions
- Prepare board and executive briefings — posture narrative, KRIs, material risks, asks
- Lead incident escalation and crisis comms — executive decisions, regulators, customers, media
- Build security budget and org design — headcount, tooling envelope, build vs buy, vendors
- Manage regulatory and audit relationships at exec level — exam prep, consent agendas, themes
- Define leadership metrics — KRIs, program health, outcome vs activity measures
- Shape cyber insurance and vendor posture — coverage, broker, critical supplier risk
- Align security with enterprise strategy — M&A diligence themes, digital risk, third-party risk
When NOT to Use
- Deploy SSO, SIEM, EDR, hardening, or remediate vulnerabilities →
information-security-engineer - Build risk registers, FAIR models, or treatment scoring →
security-risk-analyst - GRC program scope, gap assessments, audit prep packs →
compliance-specialist - Control testing workpapers, evidence automation →
compliance-engineer - SOC alert triage, playbooks, shift operations →
soc-analyst - Run CSIRT containment, forensics, or technical IR →
incident-responder - Enterprise security reference architecture, zero-trust patterns, ARB standards →
enterprise-security-architect - Infrastructure capex portfolio and facility supply chain →
vp-of-infrastructure - Draft press statements, all-hands scripts, or comms templates →
communication-lead - Broad security strategy without exec/board lens →
cybersecurity
Related skills
| Need | Skill |
|---|---|
| Control implementation, SIEM/EDR, hardening | information-security-engineer |
| Risk registers, inherent/residual, treatment | security-risk-analyst |
| GRC program, frameworks, audit coordination | compliance-specialist |
| Control testing, evidence automation | compliance-engineer |
| Declared incident response execution | incident-responder |
| Enterprise security reference architecture | enterprise-security-architect |
| Infrastructure portfolio and exec infra narrative | vp-of-infrastructure |
| Crisis and executive communications drafting | communication-lead |
| Enterprise security strategy (non-exec depth) | cybersecurity |
| M&A/investment diligence and IC cyber packs | cyber-diligence-governance |
Core Workflows
1. Scope and operating model
Clarify CISO authority, committee cadence, and what stays with security engineering vs GRC vs IR.
See `references/ciso_scope.md`.
2. Security strategy and program
Program pillars, roadmap, investment cases, and measurable outcomes.
See `references/security_strategy_and_program.md`.
3. Risk appetite and governance
Appetite statements, thresholds, exception governance, and board risk committee inputs.
See `references/risk_appetite_and_governance.md`.
4. Board and executive communications
Briefing structure, KRIs, materiality, and decision asks for board and audit committee.
See `references/board_and_executive_communications.md`.
5. Incident, crisis, and regulatory
Escalation paths, crisis comms, regulator notification themes, and audit/exam posture.
See `references/incident_crisis_and_regulatory.md`.
6. Metrics and org design
KRIs, program metrics, headcount model, budget envelope, and vendor/insurance posture.
See `references/security_metrics_and_org_design.md`.
Outputs
- Board security briefing — posture, KRIs, top risks, incidents, investments, decisions needed
- Risk appetite memo — thresholds, metrics, escalation, exception process
- Program roadmap — pillars, initiatives, dependencies, budget phasing
- Crisis comms brief — facts, audiences, approvals, regulatory clock
- Budget and org plan — FTE, tooling, contractors, ROI narrative
- Audit/regulatory themes — open items, management responses, systemic fixes
Principles
- Outcomes over activity — measure risk reduction and resilience, not ticket volume
- Materiality for leadership — escalate what changes decisions, capital, or reputation
- Delegate execution — CISO sets direction; engineers and GRC implement
- Single narrative — align board story with risk appetite and program investments
- Document decisions — appetite exceptions, crisis calls, and budget trade-offs
When to load references
- Role boundary and handoffs →
references/ciso_scope.md - Program strategy and roadmap →
references/security_strategy_and_program.md - Appetite and governance →
references/risk_appetite_and_governance.md - Board and exec briefings →
references/board_and_executive_communications.md - Crisis and regulatory →
references/incident_crisis_and_regulatory.md - KRIs, budget, org →
references/security_metrics_and_org_design.md
Board and executive communications
Table of contents
1. Briefing cadence 2. Deck structure 3. KRIs for leadership 4. Materiality and asks
Briefing cadence
| Audience | Typical cadence | Focus |
|---|---|---|
| Full board | Quarterly or semi-annual | Posture, material risks, major incidents, investments |
| Audit committee | Quarterly | Control effectiveness, audit findings, appetite, incidents |
| CEO / exec team | Monthly or ad hoc | Operational metrics, blockers, crisis |
| Crisis cell | As needed | Facts, decisions, comms, regulatory |
Coordinate with communication-lead for external messaging; Legal owns regulatory filings.
Deck structure
Recommended 8–12 slides (adjust for material events):
1. Executive summary — 3 bullets: posture, top risk, ask 2. Threat and context — sector trends, relevant incidents (peer or sector) 3. Posture snapshot — maturity or framework alignment (high level) 4. KRIs — trend charts, RAG status, threshold breaches 5. Top risks — enterprise-linked, treatment status 6. Incidents — material only; lessons and systemic fixes 7. Program progress — roadmap milestones vs plan 8. Audit and regulatory — open themes, exam status 9. Investments — spend vs plan, ROI narrative 10. Decisions needed — appetite change, budget, policy, disclosure
Avoid tool screenshots and alert counts; board cares about decisions and material outcomes.
KRIs for leadership
Distinguish KRIs (risk indicators) from KPIs (program activity):
| Type | Examples |
|---|---|
| KRI | Critical vuln aging, phishing click rate, privileged account count, backup failure rate |
| KPI | Training completion, scans run, tickets closed |
Show 12-month trend and threshold; explain one corrective action per red metric.
Materiality and asks
Materiality lens (coordinate with Legal and Finance):
- Impact on operations, customers, financial statements
- Regulatory notification obligations
- Reputational and contractual exposure
Clear asks at end of briefing:
- Approve budget or headcount
- Endorse appetite or policy change
- Acknowledge material incident for disclosure path
- Prioritize enterprise project dependency
Pre-read 48–72h before meeting; appendix for detail; main deck stays decision-focused.
CISO scope
Table of contents
1. Role boundary 2. Authority and committees 3. Questions CISO answers 4. Handoffs
Role boundary
| chief-information-security-officer | Partner |
|---|---|
| Program strategy, board narrative, appetite | information-security-engineer — deploy controls, SIEM, hardening |
| Exec incident escalation, crisis comms | incident-responder — CSIRT execution, containment |
| Budget, org design, vendor/insurance posture | soc-analyst — alert triage, shift ops |
| Board KRIs and material risk themes | security-risk-analyst — registers, scoring, FAIR |
| Regulatory/audit exec relationships | compliance-specialist — GRC program, audit prep |
| Control testing workpapers | compliance-engineer |
| Reference architecture, zero trust standards | enterprise-security-architect |
| Broad security strategy (less exec) | cybersecurity |
CISO sets direction and accountability; does not own consoles, parsers, or control test scripts.
Authority and committees
Typical CISO interfaces:
| Forum | CISO role |
|---|---|
| Board / audit committee | Periodic security briefing; material incidents; appetite |
| Executive committee | Digital risk, major investments, crisis decisions |
| Risk committee | Appetite alignment; top risk themes; exception trends |
| Crisis management | Security lead; comms and legal coordination |
| Vendor council | Critical supplier and MSSP posture (exec view) |
Document RACI: who approves exceptions, who signs regulator notices, who owns budget.
Questions CISO answers
- What is our 18-month security program and what do we stop doing?
- What risk are we willing to accept vs mitigate vs transfer?
- What do we tell the board after a material incident?
- How much should we spend, and on what headcount vs tools?
- Are we exam-ready, and what are the top systemic audit themes?
- Is our cyber insurance adequate for our risk profile?
Handoffs
| After decision | Owner |
|---|---|
| Deploy controls, integrate SIEM/EDR | information-security-engineer |
| Hunt, detect, tune rules | defensive-security-analyst |
| IR runbook execution | incident-responder |
| Gap plans, audit evidence packs | compliance-specialist |
| Architecture standards and ARB | enterprise-security-architect |
| Risk register updates | security-risk-analyst |
| External statements and media | communication-lead (+ Legal) |
Incident, crisis, and regulatory
Table of contents
1. Escalation matrix 2. CISO role in crisis 3. Crisis communications 4. Regulatory and audit exec
Escalation matrix
Define severity with business impact, not technical detail:
| Severity | Examples | CISO involvement |
|---|---|---|
| SEV-1 | Customer data breach, ransomware production halt, regulatory trigger | Lead exec war room; board notification path |
| SEV-2 | Limited data exposure, major control failure | Approve comms and external counsel; brief CEO |
| SEV-3 | Contained malware, single-system compromise | Monitor; delegate to incident-responder |
| SEV-4 | Policy violations, low-impact events | Dashboard only |
Technical execution stays with incident-responder, digital-forensics-analyst, and SOC partners.
CISO role in crisis
First 24 hours:
1. Confirm facts vs assumptions; single incident commander (often IR lead) 2. Activate crisis roster — Legal, PR/comms, HR, business owner 3. Preserve evidence chain; approve containment that affects customers 4. Start regulatory clock assessment with Legal 5. Brief CEO; prepare board notification if material
After stabilization:
- Root cause and systemic fix themes (not blame)
- Control and investment implications for program roadmap
- Lessons for tabletop and appetite review
Crisis communications
| Audience | Owner | CISO input |
|---|---|---|
| Employees | HR / Comms | Facts, safe behaviors, phishing watch |
| Customers | Comms + Legal | Breach scope, remediation, support channel |
| Regulators | Legal | Notification content, timing |
| Media | Comms | Approved messaging only |
| Board | CISO + CEO | Materiality, timeline, systemic fixes |
Use communication-lead for drafts; CISO validates technical accuracy. No speculative attribution in external statements.
Regulatory and audit exec
| Activity | CISO role | Delegate |
|---|---|---|
| Supervisory exam | Exec sponsor; theme prep | compliance-specialist packs |
| Audit committee | Present findings and management responses | Internal audit liaison |
| Customer security questionnaires | Policy on tier-1 responses | GRC + engineering SMEs |
| Breach notification | Decision support with Legal | IR evidence |
Track repeat findings as program failures—fund systemic fixes in next budget cycle, not point remediations only.
Risk appetite and governance
Table of contents
1. Appetite statement 2. Thresholds and metrics 3. Exception governance 4. Board risk alignment
Appetite statement
Risk appetite is how much risk the organization chooses to accept to pursue objectives—not zero risk.
Draft appetite across domains (tailor to industry):
| Domain | Appetite example (illustrative) |
|---|---|
| Customer data breach | Very low — mandatory controls, no unapproved exceptions |
| Ransomware | Low — immutability, IR tested quarterly |
| Third-party access | Low — tier-1 vendors assessed annually |
| Legacy technical debt | Moderate — time-boxed exceptions with sunset |
| Innovation / shadow IT | Moderate with guardrails — approved sandboxes only |
Link appetite to control tiers in enterprise-security-architect standards where applicable.
Thresholds and metrics
Translate appetite into measurable thresholds:
- Critical vulns open > X days on internet-facing assets
- MFA coverage < Y% for workforce
- Privileged accounts without PAM > Z
- Material incidents per year
- Audit findings rated high open > N days
Escalate to CISO when thresholds breach; to board when material to financial or reputational statements.
Delegate register maintenance to security-risk-analyst; CISO owns appetite breaches and systemic themes.
Exception governance
Exception record minimum fields:
- Control requirement and compensating controls
- Risk owner (business), approver (CISO or delegate)
- Expiry date (max 12 months unless board-approved)
- Evidence of monitoring
Report exception volume and aging to audit committee quarterly—rising exceptions signal appetite drift.
Board risk alignment
| Input | Source |
|---|---|
| Top enterprise risks including cyber | ERM + security-risk-analyst |
| Appetite breaches | Security metrics |
| Incident materiality | IR + Legal |
| Regulatory change | Compliance + Legal |
CISO does not replace ERM; align cyber narrative to enterprise risk taxonomy and rating scales.
Security metrics and org design
Table of contents
1. Metrics framework 2. Sample KRIs 3. Budget envelope 4. Org design 5. Vendors and insurance
Metrics framework
| Layer | Purpose | Audience |
|---|---|---|
| KRIs | Early warning of rising risk | Board, audit committee, CISO |
| Program KPIs | Initiative delivery | CISO, direct reports |
| Operational metrics | SOC/engineering tuning | Security leadership only |
Review quarterly: retire metrics that do not drive decisions; add metrics linked to appetite thresholds.
Sample KRIs
Tailor to industry and tech stack:
| KRI | Notes |
|---|---|
| % critical assets with EDR coverage | Coverage gaps = appetite breach |
| Mean time to contain (SEV-1/2) | Trend vs prior year |
| Internet-facing critical vulns > SLA | Link to appetite |
| MFA coverage (workforce + privileged) | Split metrics |
| Phishing simulation failure rate | Training effectiveness |
| Third-party critical findings open | Vendor tier 1 only |
| Backup success / restore test pass rate | Resilience |
| Security awareness completion | Supporting, not sufficient alone |
Pair each red KRI with one accountable owner and corrective plan in board pack.
Budget envelope
Typical security opex categories:
- Personnel (FTE, contractors)
- Tools (SIEM, EDR, IAM, GRC, scanning)
- MSSP / MDR
- Training and certifications
- Assessments (pentest, red team, audits)
- Insurance premiums
Build 3-year phased plan aligned to roadmap; show deferral risk for unfunded initiatives.
Coordinate with vp-of-infrastructure when security spend sits inside broader infra budget.
Org design
Sizing considerations:
| Driver | Implication |
|---|---|
| Regulated industry | Higher GRC and audit liaison FTE |
| Global footprint | Follow-the-sun SOC or MSSP |
| Heavy engineering | AppSec and security engineering embedded |
| M&A velocity | Integration and IAM surge capacity |
Define spans: CISO → (Engineering, GRC, SOC/IR, IAM program lead). Avoid combining CISO and CIO without explicit board mandate.
Vendors and insurance
Critical vendors: tier by data access and blast radius; exec review annually for tier 1.
Cyber insurance: align limits to scenario modeling (ransomware, notification costs, legal); review annually with broker; document exclusions.
CISO approves material security contracts; engineering evaluates technical fit.
Security strategy and program
Table of contents
1. Program pillars 2. Roadmap structure 3. Investment case 4. Operating model
Program pillars
Map initiatives to a small set of pillars (example):
| Pillar | Outcomes |
|---|---|
| Identity and access | MFA coverage, privileged access reduction, review discipline |
| Data protection | Classification tiers, encryption coverage, DLP maturity |
| Resilience | IR readiness, backup/immutability, crisis exercises |
| Secure engineering | SSDLC gates, vuln SLA adherence, third-party code |
| Detection and response | MTTD/MTTR trends, coverage, tabletop frequency |
| Third party and supply chain | Critical vendor tiering, assurance cadence |
Avoid pillar sprawl; each pillar needs an owner and 2–3 measurable outcomes.
Roadmap structure
Horizon framing:
- 0–6 months — quick wins, regulatory deadlines, incident-driven fixes
- 6–18 months — platform upgrades, org hires, major tool replacements
- 18–36 months — structural changes (zero trust, segmentation, identity modernization)
Per initiative document: problem, outcome, dependencies, cost, risk if deferred.
Investment case
Executive investment memo sections:
1. Risk or compliance driver — what breaks if we do nothing 2. Options — minimum viable vs target vs accelerated 3. Cost — capex/opex, FTE, MSSP, license growth 4. Benefit — risk reduction, audit finding closure, efficiency 5. Metrics — how success is measured in 12 months 6. Ask — budget, headcount, policy exception, board awareness
Pair with enterprise-security-architect for technical option compare; CISO owns the decision narrative.
Operating model
| Function | Typical home | CISO sets |
|---|---|---|
| Security engineering | CISO or CIO dotted | Priorities, SLAs, architecture alignment |
| GRC / compliance | CISO or Legal dotted | Appetite, audit themes, framework scope |
| SOC / detection | CISO | Coverage targets, escalation, MSSP model |
| IR / CSIRT | CISO | Severity matrix, crisis linkage |
| IAM program | CISO + iam-specialist | Policy, review cadence, PAM mandate |
Review annually: federated vs central model per BU, acquisition integration.