Cybersecurity
Skills
Compliance and Audit
Use when a project requires a compliance framework mapping, when risks need formal documentation, when audit evidence must be collected, or when prod…
Comply
Regulatory compliance and audit agent. Maps business regulatory requirements (SOC2/PCI-DSS/HIPAA/ISO 27001), checks control implementations, designs …
Comply
Regulatory compliance and audit agent. Maps business regulatory requirements (SOC2/PCI-DSS/HIPAA/ISO 27001), checks control implementations, designs …
Cybersecurity Breach Summary
Summarizes cybersecurity breach incidents into structured legal and compliance records. Trigger when synthesizing incident reports, forensics, logs, …
Cybersecurity Breach Summary
Produces structured cybersecurity breach summary documents for regulatory and compliance use. Use when drafting breach summaries, incident response r…
Enterprise Evidence Pack Generation
Use this skill when generating ISO 27001 or NIST SP 800-53 audit evidence packs, compliance reports, evidence narratives, reviewer-ready control matr…
Information Security Policy
Drafts a board-approvable Information Security Policy covering data classification, access controls, encryption, incident response, breach notificati…
Tabletop Exercise Script for Incident Response Plan
Drafts a tabletop exercise script to stress-test an organization's Incident Response Plan against cybersecurity threats and breach notification oblig…
Vendor Security Assessment Questionnaire
Drafts a Vendor Security Assessment Questionnaire evaluating third-party cybersecurity posture, data handling, and regulatory compliance. Vendor resp…
cybersecurity legal skills for GENERAL
Cross-border cybersecurity incidents rarely respect jurisdictional lines: a ransomware attack on a multinational's infrastructure may simultaneously trigger breach notification duties in the EU under the GDPR, sector-specific incident reporting obligations in the United States, and data localisation requirements in other markets — all within the same seventy-two-hour window. The cybersecurity legal skills for general and multi-jurisdiction matters in the ThomasMore catalog are built for exactly that pressure, covering incident response protocols, regulatory notification timelines, vendor contract risk allocation, and cross-border data breach assessment across the world's major frameworks. Each is agent-ready, callable over MCP or available as a direct download, so your team can run a notification-deadline analysis or draft a breach disclosure in the middle of an active incident without switching contexts.
Because no single domestic statute governs a truly global cyber event, these skills are deliberately jurisdiction-agnostic at the framework layer while remaining anchored to the specific rules — EU network and information security legislation, national cybersecurity agencies, sector regulators such as financial supervisors — that actually apply to a given matter. Authors in the ThomasMore catalog maintain them as threat-reporting obligations evolve and new national cyber laws come into force. The collection is especially useful for counsel advising clients on pre-incident preparedness: tabletop exercise checklists, third-party supplier due diligence templates, and cyber insurance coverage gap reviews sit alongside the response-phase tools. Filter by license or contributor to find the skill that fits the regulatory exposure your client is facing right now.