Ciso Advisor
Security leadership for growth-stage companies.
Before & after
Same prompt, same agent — the only difference is the skill.
Justifying a security budget to the board requires framing security in business terms rather than technical ones. Here's how to approach it: **Focus on risk, not tools.** Boards care about business risk, not firewalls. Frame your ask around what could go wrong and what it would cost. **Tie to compliance requirements.** If you need SOC 2 or ISO 27001 to close enterprise deals, that's a revenue argument, not a cost center argument. **Benchmark against peers.** Showing that similar companies spend a comparable percentage of revenue on security helps normalize the ask. **Show what you've already accomplished.** Demonstrate ROI on previous security investments. **Present options, not ultimatums.** Give the board a tiered set of choices rather than a single number. Would you like help structuring the presentation?
BOARD MEMO — FY SECURITY BUDGET, $800K
Boards don't fund fear. They fund quantified risk and unblocked revenue.
Both are below.
QUANTIFIED RISK — top 3, annualized
Ransomware
Likelihood 8%/yr (sector base rate, our controls)
Impact $4.2M (14-day outage $2.1M + recovery $800K + notification
$600K + regulatory $700K)
Annualized loss expectancy .................... $336K
Credential compromise → data exposure
Likelihood 15%/yr · Impact $1.8M
ALE ........................................... $270K
Insider/third-party data loss
Likelihood 5%/yr · Impact $2.4M
ALE ........................................... $120K
TOTAL ANNUALIZED EXPOSURE ..................... $726K
The $800K reduces this to a modeled $310K. Net risk reduction $416K
against $800K spend — which alone does not clear the bar. The revenue
argument below is what does.
REVENUE CURRENTLY BLOCKED
$2.1M in pipeline gated on SOC 2 Type II (4 deals, security review
stalled). $340K of the ask is the audit path. That line is a revenue
unlock, not a cost.
THE ASK, IN TIERS — pick one
Tier 1 $340K SOC 2 Type II + evidence automation
Unblocks $2.1M pipeline. Risk unchanged.
Tier 2 $800K Tier 1 + IR retainer + EDR + IAM consolidation
Exposure $726K → $310K. RECOMMENDED.
Tier 3 $1.4M Tier 2 + 24/7 SOC
→ $180K. Diminishing return at our stage.
BENCHMARK
Peers at our ARR spend 6–9% of engineering budget on security.
Tier 2 puts us at 7%. Tier 1 alone leaves us at 3% — below every
comparable, and that gap is itself a diligence finding in the next
raise.
WHAT HAPPENS AT $0
SOC 2 slips 12 months, the four deals go to a competitor who has it,
and we carry $726K of annualized exposure with no IR retainer — the
single largest driver of breach cost in every published dataset.About this skill
name: ciso-advisor description: Use when Security leadership for growth-stage companies.
Ciso Advisor
Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting. Use when building security programs, justifying security budget, selecting compliance frameworks, managing incidents, assessing vendor risk, or when user mentions CISO, security strategy, compliance roadmap, zero trust, or board security reporting.
What you get
- Public GitHub repo (alirezarezvani/claude-skills)
- the ciso-advisor skill folder with SKILL.md. Part of a 337-skill / 30-agent / 70-command install.
Customize your output
- Fork the repo and adapt the skill's instructions and references to your workflow.
Example output
Activates automatically when your request matches Ciso Advisor; chains with the other skills, agents, and commands in the collection.
Best for
Creators, builders, and teams using Claude Code.
SKILL.md preview
---
name: ciso-advisor
description: Use when building security programs, compliance roadmaps, or board-level security reporting for a growth-stage company, or when referencing CISO-level decisions.
version: 1.0.0
category: Business & Ops / Executive Advisory
author: AgentVolt
license: proprietary
tags:
- business-ops
- executive-advisory
---
# Ciso Advisor
Acts as a fractional CISO for growth-stage companies, covering risk quantification, compliance roadmaps, security architecture, and incident leadership.
## When to use
… (sign up to view the full skill)More business & ops skills
View all Business & Ops skills →Gc Review
/cs:gc-review <plan> — General Counsel interrogation of contracts, IP, regulatory, term sheets, and employment-law surface.
Caio Review
/cs:caio-review <plan> — Eval-demanding Chief AI Officer interrogation of any plan that involves AI: model selection, risk classification, cost economics, or AI hiring.
Boardroom
/cs:boardroom <brief> — 6-phase multi-role deliberation across the C-suite with Phase 2 isolation, critic pre-screen, and synthesis.
Context Engine
Loads and manages company context for all C-suite advisor skills.