cybersecurity
31 skills across 7 jurisdictions.
Skills
APRA CPS 234 Expert
APRA CPS 234 expert for Australian prudential information security. Reference-depth framework plugin with scope determination, evidence checklist, an…
Australian Information Security Manual (ISM) Skill
Expert Australian Information Security Manual (ISM) advisor for government entities and their supply chains. Use for ISM control selection, gap analy…
CMMC 2.0 Compliance Skill
Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DI…
Compliance and Audit
Use when a project requires a compliance framework mapping, when risks need formal documentation, when audit evidence must be collected, or when prod…
Comply
Regulatory compliance and audit agent. Maps business regulatory requirements (SOC2/PCI-DSS/HIPAA/ISO 27001), checks control implementations, designs …
Comply
Regulatory compliance and audit agent. Maps business regulatory requirements (SOC2/PCI-DSS/HIPAA/ISO 27001), checks control implementations, designs …
Cyber-Incident-Response 72 Stunden
Sofortmassnahmen bei aktivem Cyber-Vorfall Ransomware Datenexfiltration oder Insider-Threat. Anwendungsfall Cyberangriff ist entdeckt und IT-rechtlic…
Cybersecurity Breach Summary
Summarizes cybersecurity breach incidents into structured legal and compliance records. Trigger when synthesizing incident reports, forensics, logs, …
Cybersecurity Breach Summary
Produces structured cybersecurity breach summary documents for regulatory and compliance use. Use when drafting breach summaries, incident response r…
DORA Expert
DORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident report…
DORA — Digital Operational Resilience Act Skill
Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a …
DORA-IKT-Vertragsprüfung
IKT-Drittanbietervertraege auf DORA-Konformität prüfen wenn Finanzunternehmen digitale Dienstleistungen einkaufen. Art. 28 30 DORA VO (EU) 2022/2554.…
Enterprise Evidence Pack Generation
Use this skill when generating ISO 27001 or NIST SP 800-53 audit evidence packs, compliance reports, evidence narratives, reviewer-ready control matr…
EU NIS2 Directive Expert
EU NIS2 Directive (Directive (EU) 2022/2555) expert. Reference-depth knowledge of essential vs important entity classification, Article 20 governance…
Incident Response Plan and Playbook
Drafts incident response plans and scenario playbooks for U.S. legal organizations, aligning NIST SP 800-61 Rev. 2 phases with ABA Model Rules 1.1/1.…
Incident Response Plan and Playbook
Drafts incident response plans and playbooks for legal organizations, adapting NIST SP 800-61 to law firm contexts including privilege preservation, …
Information Security Policy
Drafts a board-approvable Information Security Policy covering data classification, access controls, encryption, incident response, breach notificati…
NIS2 Directive Compliance Advisor
EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities — entity classification, Art. 21 risk management…
NYDFS Expert
NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including al…
NYDFS Information Security Program (23 NYCRR 500)
Drafts a comprehensive Information Security Program compliant with NYDFS Cybersecurity Regulation (23 NYCRR 500). Covers CISO designation, risk asses…
Tabletop Exercise Script for Incident Response Plan
Drafts a tabletop exercise script to stress-test an organization's Incident Response Plan against cybersecurity threats and breach notification oblig…
User Input
[COMMUNITY] Assess EU Cyber Resilience Act (CRA, Regulation 2024/2847) compliance obligations for products with digital elements placed on the EU market
User Input
[COMMUNITY] Assess DORA (Digital Operational Resilience Act, EU 2022/2554) compliance for financial sector entities operating in the EU
User Input
[COMMUNITY] Assess compliance with ANSSI security recommendations — Guide d'hygiène informatique (42 measures) and cloud security recommendations
cybersecurity legal skills by jurisdiction
Cybersecurity legal work sits at a pressure point where breach-response timelines are measured in hours, regulatory notification windows vary sharply by jurisdiction, and the same incident can simultaneously engage data protection authorities, securities regulators, and criminal enforcement bodies. Practitioners advising on this work — whether drafting incident response plans, negotiating vendor security obligations, or managing post-breach disclosure — need capabilities that reflect the actual regulatory environment rather than a generic checklist. The cybersecurity legal skills in the ThomasMore catalog are built for exactly that operational reality, covering breach notification analysis, security policy drafting, regulatory investigation support, and contractual risk allocation across multiple jurisdictions.
Each skill is agent-ready, meaning your AI agent can execute it directly — via MCP or as a download — without rebuilding the analysis from scratch every time a matter lands. Coverage spans frameworks including the EU's NIS2 Directive and GDPR notification rules, sector-specific regimes for financial services and critical infrastructure, and domestic cybersecurity statutes across multiple jurisdictions. Authors maintain these skills as regulators sharpen their expectations and enforcement activity rises. Filter by jurisdiction or license to reach the capability your current matter requires.