Stakeholder management
Use when the user asks "who are our customers?" / "how do we tailor for X stakeholder?" / "who should this report go to?", or wants to map / re-map stakeholder needs. Ensures intelligence reaches the right people in the right format.From its SKILL.md
npx -y skills add Liberty91LTD/cti-skills --skill stakeholder-managementAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 16 stars16 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
4.1 KB, 843 tokens by cl100k_base, as published. Nobody here has run it
Stakeholder Management
Intelligence that doesn't reach the right person in the right format might as well not exist. This skill ensures every product is tailored to its audience.
Stakeholder Identification
Common CTI Stakeholders
| Stakeholder | Needs | Format | Cadence |
|---|---|---|---|
| CISO | Strategic risk, business impact, investment justification | Executive summary, risk scores, trend analysis | Monthly + ad-hoc |
| SOC Manager | Operational context, detection priorities, hunt leads | Operational briefs, IOC packages, hunt playbooks | Weekly + real-time |
| SOC Analysts | Tactical indicators, detection rules, response guidance | IOCs, SIGMA/YARA rules, enriched alerts | Daily + real-time |
| IR Team | Campaign context, TTP detail, forensic indicators | Detailed campaign reports, investigation leads | Per-incident |
| Security Architecture | Threat landscape, emerging attack vectors, control gaps | Threat assessments, ATT&CK mapping, control recommendations | Quarterly |
| Risk Management | Threat trends, probability assessments, sector comparisons | Risk assessments, likelihood language, quantified impact | Quarterly |
| Board / Executive | High-level risk posture, material incidents, peer benchmarks | 1-page dashboard, non-technical language, visual aids | Quarterly + material events |
| Legal / Compliance | Regulatory threat intelligence, breach notification triggers | Compliance-focused briefs, attribution (when needed) | Ad-hoc |
| IT Operations | Vulnerability intelligence, patch priorities, asset exposure | Vulnerability assessments, prioritised patch lists | Weekly |
Stakeholder Register Template
Maintain in data/pirs/stakeholder-register.md:
| Stakeholder | Role | PIRs | Products | Format Preference | Cadence | Feedback Method |
|-------------|------|------|----------|-------------------|---------|-----------------|
| [Name/Title] | [Role] | PIR-001, PIR-003 | Threat assessments, weekly brief | Executive summary, max 1 page | Monthly | Email response |
Tailoring Intelligence Products
For Executives (CISO, Board)
- Lead with business impact, not technical detail
- Use risk language: "This threat could result in..."
- Include peer comparisons: "Organisations in our sector have seen..."
- Recommend actions in business terms: "Investment in X reduces risk by..."
- Maximum 1-2 pages
- Visual aids (charts, traffic lights, risk matrices)
For Security Operations (SOC, IR)
- Lead with actionable indicators
- Include detection rules and hunt queries
- Provide full TTP chain with ATT&CK mapping
- Technical detail is expected and valued
- Response playbook pointers
- Real-time delivery for active threats
For Risk / Compliance
- Lead with likelihood and impact assessments
- Use standardised likelihood language (probability yardstick)
- Map to frameworks (NIST CSF, ISO 27001)
- Quantify where possible
- Regulatory implications highlighted
Dissemination Matrix
| TLP | Distribution Channel | Notes |
|---|---|---|
| RED | Direct communication only (in-person, encrypted message) | Named recipients only |
| AMBER+STRICT | Internal secure channel (encrypted email, restricted SharePoint) | Organisation only |
| AMBER | Secure channel + need-to-know partners | May share with clients/partners |
| GREEN | Community channels (ISAC portal, closed mailing lists) | Not public |
| CLEAR | Any channel (blog, public advisories) | Unrestricted |
Feedback Collection
After every significant product delivery:
- Was the intelligence useful? (Yes/Partially/No)
- Was it timely? (Yes/Too late/Too early)
- Was the format appropriate? (Yes/Too technical/Too high-level)
- What should we cover next? (Free text)
Track feedback in stakeholder register. Feed into PIR refinement (see feedback-loops skill).
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.
Gives 0 of the 12 instructions most operations skills give in 843 tokens
Counted across 483 of the 484 authors here whose files we hold, read 2026-08-07
- Collect monitoring data throughout the simulationin 14 of 483, across 6 files
- Set the random seed for reproducibilityin 14 of 483, across 6 files
- Validate simulations against analytical solutionsin 12 of 483, across 4 files
- Clarify goals, constraints, and inputsin 11 of 483, across 2 files
- Implement contract tests for integration pointsin 11 of 483, across 2 files
- Implement strangler fig infrastructure with API gatewayin 11 of 483, across 2 files
- Audit modernized components for security vulnerabilitiesin 11 of 483, across 2 files
- Avoid Python blocking calls in processesin 10 of 483, across 3 files
- Use resource context managers for automatic cleanupin 9 of 483, across 2 files
- Maintain consistent time unitsin 9 of 483, across 2 files
- Validate outcomes against success criteriain 8 of 483, across 1 file
- Analyze the legacy codebase for technical debtin 8 of 483, across 1 file
Said here and by no other author read
- tailor intelligence products to the audience
- keep executive products under two pages
- use non-technical language for executives
- lead with actionable indicators for operations
- include detection rules and hunt queries for operations
- provide full TTP chains with ATT&CK mapping
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.