cybersecurity
31 skills across 7 jurisdictions.
Skills
User Input
[COMMUNITY] Conduct an EBIOS Risk Manager risk analysis study following the ANSSI methodology — five workshops from study framing to risk treatment a…
User Input
[COMMUNITY] Generate an Information System Security Policy (PSSI) for French public or private organisations — security objectives, principles, organ…
User Input
[COMMUNITY] Assess SecNumCloud 3.2 qualification compliance for French sovereign cloud procurement and OIV/OSE obligations
User Input
[COMMUNITY] Assess Austrian NISG obligations (BGBl. I Nr. 94/2025) — AT transposition of NIS2, BKA (GovCERT) / BMI (SPOC) reporting, KSÖ coordination…
User Input
[COMMUNITY] Assess NIS2 Directive compliance obligations for EU member state operators of essential services and important entities
Vendor Security Assessment Questionnaire
Drafts a Vendor Security Assessment Questionnaire evaluating third-party cybersecurity posture, data handling, and regulatory compliance. Vendor resp…
Written Information Security Program (WISP)
Drafts a Written Information Security Program compliant with Massachusetts 201 CMR 17.00 and supplementary frameworks (GDPR, CCPA, HIPAA, GLBA, PCI-D…
cybersecurity legal skills by jurisdiction
Cybersecurity legal work sits at a pressure point where breach-response timelines are measured in hours, regulatory notification windows vary sharply by jurisdiction, and the same incident can simultaneously engage data protection authorities, securities regulators, and criminal enforcement bodies. Practitioners advising on this work — whether drafting incident response plans, negotiating vendor security obligations, or managing post-breach disclosure — need capabilities that reflect the actual regulatory environment rather than a generic checklist. The cybersecurity legal skills in the ThomasMore catalog are built for exactly that operational reality, covering breach notification analysis, security policy drafting, regulatory investigation support, and contractual risk allocation across multiple jurisdictions.
Each skill is agent-ready, meaning your AI agent can execute it directly — via MCP or as a download — without rebuilding the analysis from scratch every time a matter lands. Coverage spans frameworks including the EU's NIS2 Directive and GDPR notification rules, sector-specific regimes for financial services and critical infrastructure, and domestic cybersecurity statutes across multiple jurisdictions. Authors maintain these skills as regulators sharpen their expectations and enforcement activity rises. Filter by jurisdiction or license to reach the capability your current matter requires.