From ciso-toolkit
Translate technical security risk into business and financial terms — top risk scenarios, likelihood × impact, a risk register, and (where useful) quantified loss ranges (FAIR-aware) — to support executive decisions on treat/transfer/accept. Use to communicate or prioritize cyber risk for leadership.
How this skill is triggered — by the user, by Claude, or both
Slash command
/ciso-toolkit:cyber-risk-quantificationThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Cyber risk expressed the way executives make decisions: which scenarios matter, what
Cyber risk expressed the way executives make decisions: which scenarios matter, what they could cost the business, how that compares to risk appetite, and what to do (treat / transfer / accept).
threat-modeling, findings, and threat intel.A risk register + a heat map, plus quantified top risks (loss ranges) where relevant,
and treatment recommendations. Use security-reporting; visualize the heat map with
security-diagramming:infographic. Feeds security-strategy and board-deck.
Quantify in ranges, not false precision — "likely $2–8M annual loss exposure" beats a single fabricated number. Frame risks as business loss scenarios, not CVEs. Tie every significant risk to an explicit treatment decision and an accountable owner; accepted risk must be consciously accepted, not defaulted.
Provides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.
npx claudepluginhub jassics/awesome-claude-security --plugin ciso-toolkit