Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Vendor Cyber Risk Analyst

  • 26 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Run third-party cyber risk: TPRM intake and tiering, security questionnaire scoring, SOC 2/ISO evidence review, continuous monitoring, and remediation tracking.

About

Guides third-party and vendor cyber risk: TPRM intake and tiering, questionnaire analysis, evidence and attestation review, continuous monitoring, and executive risk reporting. Used for vendor security assessments and TPRM program operations.

  • Tier vendors by data, access, criticality, substitutability, concentration
  • Review SOC 2, ISO 27001, and pen-test evidence; track remediation

Vendor Cyber Risk Analyst by the numbers

  • 26 all-time installs (skills.sh)
  • Ranked #1,547 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill vendor-cyber-risk-analyst

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs26
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Run third-party cyber risk: TPRM intake and tiering, security questionnaire scoring, SOC 2/ISO evidence review, continuous monitoring, and remediation tracking.

Files

SKILL.mdMarkdownGitHub ↗

Vendor Cyber Risk Analyst

When to Use

  • Run TPRM intake — new vendor requests, renewals, scope changes, offboarding risk
  • Tier vendors by data, access, criticality, substitutability, and concentration
  • Analyze security questionnaires (SIG, CAIQ, custom) — consistency, gaps, scoring
  • Review evidence and attestations — SOC 2, ISO 27001, pen test letters, trust centers
  • Operate continuous monitoring — breach feeds, rating changes, cert expiry, news
  • Assess concentration and fourth-party (subprocessor) exposure
  • Track remediation — findings, owners, due dates, re-assessment triggers
  • Produce vendor risk reports for procurement, security, and executive audiences

When NOT to Use

  • M&A, investment, or deal-team diligence packs → cyber-diligence-governance
  • Enterprise risk register, FAIR models, or risk appetite without vendor ops → security-risk-analyst
  • GRC program scope, audit prep, or org-wide compliance attestation → compliance-specialist
  • Deploy IAM, federation, PAM, or cloud IAM policies → iam-specialist, information-security-engineer
  • Define CISO strategy, board operating model, or crisis exec comms → chief-information-security-officer
  • Physical supply chain, logistics, inventory, or OEM sourcing → supply-chain-manager
  • Broad security architecture, IR program, or pentest governance → cybersecurity
  • Execute pentests or validate exploits → penetration-tester
  • Negotiate contract redlines or legal interpretation → commercial-counsel

Related skills

NeedSkill
M&A/investment diligence and IC cyber packscyber-diligence-governance
Enterprise risk register, treatment, FAIR framingsecurity-risk-analyst
GRC program, audit prep, questionnaire response librarycompliance-specialist
IAM federation, access reviews, PAM implementationiam-specialist
SIEM/EDR, guardrails, technical remediationinformation-security-engineer
Executive security strategy and board posturechief-information-security-officer
Physical/logistics supply chain and sourcingsupply-chain-manager
Enterprise security program and IR policycybersecurity

Core Workflows

1. Intake and tiering

Capture vendor context, data flows, integrations, and business owner. Assign tier and assessment depth before deep review.

See `references/tprm_intake_and_tiering.md`.

2. Questionnaire analysis

Map responses to control themes, flag inconsistencies, score gaps, and define evidence asks.

See `references/questionnaire_scoring.md`.

3. Evidence and attestation review

Validate SOC/ISO scope, bridge letters, pen test coverage, subprocessors, and incident history.

See `references/evidence_and_attestation_review.md`.

4. Continuous monitoring and incidents

Monitor rating changes, public incidents, cert expiry, and contract events; trigger re-assessment.

See `references/continuous_monitoring_and_incidents.md`.

5. Reporting and remediation

Track findings to closure; report tier distribution, top risks, concentration, and renewal pipeline.

See `references/vendor_risk_reporting.md`.

Outputs

  • Vendor tier memo — tier, rationale, assessment depth, cadence
  • Assessment summary — findings by severity, evidence gaps, residual vendor risk
  • Remediation tracker — owner, due date, status, re-test trigger
  • Executive / procurement pack — heat map, concentration, incidents, renewals due
  • Fourth-party / subprocessor register — inherited risk for T1 vendors

Principles

  • Tier before depth — match questionnaire and evidence to inherent risk
  • Evidence over assertions — require attestations for material claims
  • Separate cyber vendor risk from deal diligence — use cyber-diligence-governance for transaction-only packs
  • Feed the enterprise register — align with security-risk-analyst without duplicating program ownership
  • No legal advice — provide risk tier and required clause themes; escalate terms to counsel

When to load references

TopicReference
Role boundariesreferences/vendor_cyber_risk_analyst_scope.md
Intake and tieringreferences/tprm_intake_and_tiering.md
Questionnaire scoringreferences/questionnaire_scoring.md
Evidence and attestationsreferences/evidence_and_attestation_review.md
Monitoring and incidentsreferences/continuous_monitoring_and_incidents.md
Reporting and remediationreferences/vendor_risk_reporting.md

Related skills

Securitycomplianceaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.