$37
A role-aware advisory skill that provides security and architecture guidance tailored to your perspective. Covers threat modelling, risk assessment, compliance mapping, and document generation.
This is the free, open-source edition. For the full skill with 8 roles, 8 frameworks, 8 templates, and 5 checklists, see CyberSorted Skills Pro.
| Role | Focus | Output Style |
|---|---|---|
| CISO | Strategic risk, board reporting, programme governance, budget justification | Executive summaries, risk heatmaps, business impact |
| CTO | Technology strategy, platform security, build-vs-buy, technical debt | Architecture decisions, technical depth with business context |
| Security Architect | Threat modelling, security patterns, controls design, reference architectures | Technical diagrams, control specifications, design patterns |
Determine the user's role from context. Look for explicit statements ("As a CISO...") or infer from the nature of their request:
If unclear, ask: "What's your role or perspective? This helps me tailor the depth and format."
Load the corresponding playbook from roles/<role>.md to guide tone, depth, and output format.
Determine which mode to operate in:
Provide expert analysis on security or architecture topics. Use role playbook to set depth and perspective.
Includes: Threat modelling, risk assessment, architecture review, security posture analysis, technology evaluation, attack surface analysis.
Generate a structured deliverable using a template from templates/.
Available templates:
templates/threat-model.md — STRIDE/PASTA threat modeltemplates/security-policy.md — Security policy documenttemplates/risk-assessment.md — Risk register / assessmentRead the template file, then fill each section with context from the user's request.
Walk through a framework-based assessment interactively.
Available frameworks:
frameworks/nist-800-53.md — NIST SP 800-53 control familiesframeworks/iso-27001.md — ISO 27001:2022 Annex A controlsProcess:
Map existing infrastructure, policies, or controls to specific framework requirements.
Process:
frameworks/Follow the role playbook for tone, depth, and output format:
Format output appropriate to the audience:
Executive audience (CISO, CTO):
Technical audience (Security Architect):
For architecture visualisation, reference the cloud-diagram skill:
| Problem | Fix |
|---|---|
| Role not detected | Ask the user directly: "What's your role or perspective?" |
| Framework not available | Use the closest available framework and note limitations |
| User wants visual output | Reference the cloud-diagram skill for architecture diagrams |
| Assessment too broad | Narrow scope to a specific domain or control family first |
| Need more roles/frameworks | Upgrade to CyberSorted Skills Pro |