agentsclimarketplace

Stakeholder management

Skill Liberty91LTD/cti-skills/skills/stakeholder-management

Cyber Threat Intelligence Skills for each stage of the CTI Lifecycle.

Install
npx -y skills add Liberty91LTD/cti-skills --skill stakeholder-management

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 8 stars8 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Use when the user asks "who are our customers?" / "how do we tailor for X stakeholder?" / "who should this report go to?", or wants to map / re-map stakeholder needs. Ensures intelligence reaches the right people in the right format.

SKILL.md

4.1 KB, as published. Nobody here has run it

Stakeholder Management

Intelligence that doesn't reach the right person in the right format might as well not exist. This skill ensures every product is tailored to its audience.

Stakeholder Identification

Common CTI Stakeholders

StakeholderNeedsFormatCadence
CISOStrategic risk, business impact, investment justificationExecutive summary, risk scores, trend analysisMonthly + ad-hoc
SOC ManagerOperational context, detection priorities, hunt leadsOperational briefs, IOC packages, hunt playbooksWeekly + real-time
SOC AnalystsTactical indicators, detection rules, response guidanceIOCs, SIGMA/YARA rules, enriched alertsDaily + real-time
IR TeamCampaign context, TTP detail, forensic indicatorsDetailed campaign reports, investigation leadsPer-incident
Security ArchitectureThreat landscape, emerging attack vectors, control gapsThreat assessments, ATT&CK mapping, control recommendationsQuarterly
Risk ManagementThreat trends, probability assessments, sector comparisonsRisk assessments, likelihood language, quantified impactQuarterly
Board / ExecutiveHigh-level risk posture, material incidents, peer benchmarks1-page dashboard, non-technical language, visual aidsQuarterly + material events
Legal / ComplianceRegulatory threat intelligence, breach notification triggersCompliance-focused briefs, attribution (when needed)Ad-hoc
IT OperationsVulnerability intelligence, patch priorities, asset exposureVulnerability assessments, prioritised patch listsWeekly

Stakeholder Register Template

Maintain in data/pirs/stakeholder-register.md:

| Stakeholder | Role | PIRs | Products | Format Preference | Cadence | Feedback Method |
|-------------|------|------|----------|-------------------|---------|-----------------|
| [Name/Title] | [Role] | PIR-001, PIR-003 | Threat assessments, weekly brief | Executive summary, max 1 page | Monthly | Email response |

Tailoring Intelligence Products

For Executives (CISO, Board)

  • Lead with business impact, not technical detail
  • Use risk language: "This threat could result in..."
  • Include peer comparisons: "Organisations in our sector have seen..."
  • Recommend actions in business terms: "Investment in X reduces risk by..."
  • Maximum 1-2 pages
  • Visual aids (charts, traffic lights, risk matrices)

For Security Operations (SOC, IR)

  • Lead with actionable indicators
  • Include detection rules and hunt queries
  • Provide full TTP chain with ATT&CK mapping
  • Technical detail is expected and valued
  • Response playbook pointers
  • Real-time delivery for active threats

For Risk / Compliance

  • Lead with likelihood and impact assessments
  • Use standardised likelihood language (probability yardstick)
  • Map to frameworks (NIST CSF, ISO 27001)
  • Quantify where possible
  • Regulatory implications highlighted

Dissemination Matrix

TLPDistribution ChannelNotes
REDDirect communication only (in-person, encrypted message)Named recipients only
AMBER+STRICTInternal secure channel (encrypted email, restricted SharePoint)Organisation only
AMBERSecure channel + need-to-know partnersMay share with clients/partners
GREENCommunity channels (ISAC portal, closed mailing lists)Not public
CLEARAny channel (blog, public advisories)Unrestricted

Feedback Collection

After every significant product delivery:

  1. Was the intelligence useful? (Yes/Partially/No)
  2. Was it timely? (Yes/Too late/Too early)
  3. Was the format appropriate? (Yes/Too technical/Too high-level)
  4. What should we cover next? (Free text)

Track feedback in stakeholder register. Feed into PIR refinement (see feedback-loops skill).

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.