Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Security Risk Analyst

  • 26 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Guides information security risk analysis: risk registers, inherent/residual scoring, threat-control mapping, treatment recommendations, third-party risk, and board risk narratives.

About

Guides information security risk analysis covering risk identification and scoring, risk registers, threat/control mapping, treatment recommendations, third-party risk framing, and executive risk narratives aligned with ISO 27005 and NIST RMF. An analyst uses it for risk assessments, register maintenance, or board risk reporting.

  • Scores inherent and residual risk with likelihood x impact or FAIR-style framing
  • Frames third-party and supply-chain risk tiers and executive heat maps

Security Risk Analyst by the numbers

  • 26 all-time installs (skills.sh)
  • Ranked #1,547 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill security-risk-analyst

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs26
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Guides information security risk analysis: risk registers, inherent/residual scoring, threat-control mapping, treatment recommendations, third-party risk, and board risk narratives.

Files

SKILL.mdMarkdownGitHub ↗

Security Risk Analyst

When to Use

  • Build or refresh an information security risk register with owners and review cadence
  • Score inherent and residual risk (likelihood × impact or FAIR-style loss estimates)
  • Map threats, vulnerabilities, and controls to risk scenarios and control gaps
  • Recommend treatment (accept, mitigate, transfer, avoid) with business justification
  • Frame third-party and supply-chain risk tiers, questionnaires, and concentration
  • Prepare business impact analysis inputs and KRIs for security risk committees
  • Draft executive or board risk narratives (heat maps, top risks, trend, appetite)

When NOT to Use

  • Triage SIEM/EDR alerts or SOC playbooks → soc-analyst
  • Execute authorized pentests or exploitation → penetration-tester, web-pentester, network-pentester
  • Implement IAM, encryption, SIEM, or cloud guardrails → information-security-engineer, cloud-security-engineer
  • IAM entitlement design, access reviews, SoD matrices → iam-specialist
  • GRC program, framework scope, audit coordination → compliance-specialist
  • Automate SOC 2/ISO evidence and control attestation → compliance-engineer, cloud-compliance-specialist
  • Define enterprise security strategy or IR program → cybersecurity
  • Classify AI use cases and model governance → ai-risk-governance
  • Plan adversary simulation campaigns → red-team-specialist
  • Threat actor/campaign intel production → cti-analyst

Related skills

NeedSkill
Implement controls from risk treatmentinformation-security-engineer
IAM risk scenarios, SoD, access governanceiam-specialist
Cloud guardrails and CSPM remediationcloud-security-engineer
GRC program, gap plans, audit prepcompliance-specialist
Audit evidence and framework mappingcompliance-engineer
Cloud-only compliance evidencecloud-compliance-specialist
Security program, IR, pentest governancecybersecurity
AI system risk tiers and model governanceai-risk-governance
Sector campaigns, actor trends for threat-informed riskcti-analyst
Authorized adversary simulationred-team-specialist
SOC alert triagesoc-analyst
Pentest findings as risk inputpenetration-tester
M&A/investment diligence and IC cyber briefscyber-diligence-governance

Core Workflows

1. Risk assessment intake

1. Define scope (business unit, system, vendor, program) 2. Identify assets, data classes, and dependencies 3. Capture threat events and vulnerabilities (see references) 4. Document existing controls and their effectiveness 5. Score inherent risk (before controls) and residual (after controls) 6. Compare to risk appetite and escalation thresholds

See `references/risk_identification_and_scoring.md`.

2. Risk register maintenance

Maintain one row per material risk scenario:

FieldPurpose
Risk IDStable identifier
ScenarioWhat could go wrong
OwnerAccountable business or tech lead
Inherent / residualScores and rationale
Treatmentaccept / mitigate / transfer / avoid
Target dateFor mitigation or acceptance expiry
KRIMeasurable indicator

Review quarterly minimum; re-score on major change, incident, or audit finding.

See `references/security_risk_analyst_scope.md` for boundaries.

3. Threat–vulnerability–control mapping

threat actor/event → vulnerability/condition → impact → existing controls → gap → residual risk

Link pentest, vuln scan, audit, and threat intel inputs without duplicating execution work.

See `references/threat_vulnerability_control_mapping.md`.

4. Treatment and acceptance

For each risk above appetite:

1. Propose treatment option(s) with cost, effort, and residual risk 2. Obtain risk owner and risk committee decision where required 3. Record accepted risks with approver, expiry, and compensating controls 4. Track mitigation tasks to closure; re-score residual on completion

See `references/treatment_and_acceptance.md`.

5. Third-party and supply-chain risk

Tier vendors by data access, criticality, and concentration. Align questionnaire depth to tier. Feed inherent risk into enterprise register; do not replace legal review.

See `references/third_party_and_supply_chain_risk.md`.

6. Reporting and governance

Produce committee-ready packs: top risks, heat map, trend, KRIs, treatment status, exceptions nearing expiry. Separate risk analysis from compliance attestation narratives.

See `references/reporting_and_governance.md`.

When to load references

  • Scope and role boundariesreferences/security_risk_analyst_scope.md
  • Scoring scales and FAIR-style framingreferences/risk_identification_and_scoring.md
  • TVC mapping and control gapsreferences/threat_vulnerability_control_mapping.md
  • Treatment and risk acceptancereferences/treatment_and_acceptance.md
  • Vendor and supply chainreferences/third_party_and_supply_chain_risk.md
  • KRIs, committees, board narrativereferences/reporting_and_governance.md

Related skills

Securitycomplianceaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.