Cybersecurity
Skills
CMMC 2.0 Compliance Skill
Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DI…
Incident Response Plan and Playbook
Drafts incident response plans and playbooks for legal organizations, adapting NIST SP 800-61 to law firm contexts including privilege preservation, …
Incident Response Plan and Playbook
Drafts incident response plans and scenario playbooks for U.S. legal organizations, aligning NIST SP 800-61 Rev. 2 phases with ABA Model Rules 1.1/1.…
NYDFS Expert
NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including al…
NYDFS Information Security Program (23 NYCRR 500)
Drafts a comprehensive Information Security Program compliant with NYDFS Cybersecurity Regulation (23 NYCRR 500). Covers CISO designation, risk asses…
Written Information Security Program (WISP)
Drafts a Written Information Security Program compliant with Massachusetts 201 CMR 17.00 and supplementary frameworks (GDPR, CCPA, HIPAA, GLBA, PCI-D…
cybersecurity legal skills for United States
The United States has no single federal cybersecurity statute; instead, practitioners navigate a patchwork of sector-specific regimes — HIPAA for healthcare data, the Gramm-Leach-Bliley Act for financial institutions, CISA's incident-reporting rules, and the FTC's enforcement authority over unfair data-security practices — alongside state breach-notification laws that differ in trigger, timing, and scope across all fifty jurisdictions. That complexity is where the cybersecurity legal skills for the United States in the ThomasMore catalog do their heaviest work, covering incident-response documentation, breach-notification triage, regulatory filing timelines, and vendor contract review under applicable federal and state frameworks.
Each skill is agent-ready, callable over MCP or available as a download, so it slots directly into the workflow your team runs when a breach lands or a client needs a security program assessed against regulatory expectations. The ThomasMore catalog lets you filter by license or author to find capabilities tuned to specific sectors — healthcare, financial services, critical infrastructure — or to the state-law layer a matter requires. Authors maintain these skills as CISA guidance evolves, state legislatures update notification thresholds, and FTC rulemaking advances. If your practice touches SEC cybersecurity disclosure obligations for public companies or DOD supply-chain requirements, skills addressing those frameworks are catalogued here as well. Search by the regulatory body or statutory regime your matter turns on to reach the right starting point.