Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Chief Information Security Officer

  • 27 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Act as CISO: set security program strategy and risk appetite, prepare board briefings and KRIs, lead crisis comms, and shape budget and org design.

About

Guides executive security leadership covering program strategy, risk appetite, board reporting, incident escalation, budget/org design, and cyber insurance. A developer or security exec uses it to prepare board briefings or define security program strategy.

  • Security program strategy, risk appetite, and board reporting
  • KRIs, budget/org design, and crisis communications

Chief Information Security Officer by the numbers

  • 27 all-time installs (skills.sh)
  • Ranked #1,533 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill chief-information-security-officer

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs27
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Act as CISO: set security program strategy and risk appetite, prepare board briefings and KRIs, lead crisis comms, and shape budget and org design.

Files

SKILL.mdMarkdownGitHub ↗

Chief Information Security Officer (CISO)

When to Use

  • Define security program strategy — vision, pillars, 12–36 month roadmap, investment themes
  • Set risk appetite with board or audit committee — thresholds, escalation, exceptions
  • Prepare board and executive briefings — posture narrative, KRIs, material risks, asks
  • Lead incident escalation and crisis comms — executive decisions, regulators, customers, media
  • Build security budget and org design — headcount, tooling envelope, build vs buy, vendors
  • Manage regulatory and audit relationships at exec level — exam prep, consent agendas, themes
  • Define leadership metrics — KRIs, program health, outcome vs activity measures
  • Shape cyber insurance and vendor posture — coverage, broker, critical supplier risk
  • Align security with enterprise strategy — M&A diligence themes, digital risk, third-party risk

When NOT to Use

  • Deploy SSO, SIEM, EDR, hardening, or remediate vulnerabilities → information-security-engineer
  • Build risk registers, FAIR models, or treatment scoring → security-risk-analyst
  • GRC program scope, gap assessments, audit prep packs → compliance-specialist
  • Control testing workpapers, evidence automation → compliance-engineer
  • SOC alert triage, playbooks, shift operations → soc-analyst
  • Run CSIRT containment, forensics, or technical IR → incident-responder
  • Enterprise security reference architecture, zero-trust patterns, ARB standards → enterprise-security-architect
  • Infrastructure capex portfolio and facility supply chain → vp-of-infrastructure
  • Draft press statements, all-hands scripts, or comms templates → communication-lead
  • Broad security strategy without exec/board lens → cybersecurity

Related skills

NeedSkill
Control implementation, SIEM/EDR, hardeninginformation-security-engineer
Risk registers, inherent/residual, treatmentsecurity-risk-analyst
GRC program, frameworks, audit coordinationcompliance-specialist
Control testing, evidence automationcompliance-engineer
Declared incident response executionincident-responder
Enterprise security reference architectureenterprise-security-architect
Infrastructure portfolio and exec infra narrativevp-of-infrastructure
Crisis and executive communications draftingcommunication-lead
Enterprise security strategy (non-exec depth)cybersecurity
M&A/investment diligence and IC cyber packscyber-diligence-governance

Core Workflows

1. Scope and operating model

Clarify CISO authority, committee cadence, and what stays with security engineering vs GRC vs IR.

See `references/ciso_scope.md`.

2. Security strategy and program

Program pillars, roadmap, investment cases, and measurable outcomes.

See `references/security_strategy_and_program.md`.

3. Risk appetite and governance

Appetite statements, thresholds, exception governance, and board risk committee inputs.

See `references/risk_appetite_and_governance.md`.

4. Board and executive communications

Briefing structure, KRIs, materiality, and decision asks for board and audit committee.

See `references/board_and_executive_communications.md`.

5. Incident, crisis, and regulatory

Escalation paths, crisis comms, regulator notification themes, and audit/exam posture.

See `references/incident_crisis_and_regulatory.md`.

6. Metrics and org design

KRIs, program metrics, headcount model, budget envelope, and vendor/insurance posture.

See `references/security_metrics_and_org_design.md`.

Outputs

  • Board security briefing — posture, KRIs, top risks, incidents, investments, decisions needed
  • Risk appetite memo — thresholds, metrics, escalation, exception process
  • Program roadmap — pillars, initiatives, dependencies, budget phasing
  • Crisis comms brief — facts, audiences, approvals, regulatory clock
  • Budget and org plan — FTE, tooling, contractors, ROI narrative
  • Audit/regulatory themes — open items, management responses, systemic fixes

Principles

  • Outcomes over activity — measure risk reduction and resilience, not ticket volume
  • Materiality for leadership — escalate what changes decisions, capital, or reputation
  • Delegate execution — CISO sets direction; engineers and GRC implement
  • Single narrative — align board story with risk appetite and program investments
  • Document decisions — appetite exceptions, crisis calls, and budget trade-offs

When to load references

  • Role boundary and handoffsreferences/ciso_scope.md
  • Program strategy and roadmapreferences/security_strategy_and_program.md
  • Appetite and governancereferences/risk_appetite_and_governance.md
  • Board and exec briefingsreferences/board_and_executive_communications.md
  • Crisis and regulatoryreferences/incident_crisis_and_regulatory.md
  • KRIs, budget, orgreferences/security_metrics_and_org_design.md

Related skills

Securitycomplianceaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.