security-comms

Translate technical cybersecurity findings into stakeholder-ready communication for non-security audiences.

345|47|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/briiirussell/cybersecurity-skills --skill security-comms
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-comms
Source: https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/security-comms
Command: npx skills add https://github.com/briiirussell/cybersecurity-skills --skill security-comms

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill turns technical security work into clear, audience-specific communication that non-security stakeholders can understand and act on, reducing the risk of misinterpretation, wasted time, and avoidable escalation.

Core Features & Use Cases

  • Audience-appropriate deliverables: Generates board updates, executive memos, engineering tickets, individual engineer instructions, sales/customer Q&A, and legal/procurement artifacts for questionnaires and evidence requests.
  • Incident and audit communication: Produces incident narratives, post-mortem storylines, and audit-finding translations that match the communication register of each stakeholder group.
  • Communication safety boundaries: Emphasizes legal review for customer breach disclosures, avoids misleading language, and prevents inappropriate disclosure of customer-identifying details.

Quick Start

Use the security-comms skill to draft a board update from your incident or audit findings by sharing the technical summary and the specific audience you need the message for.

Frequently Asked Questions about security-comms

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write an executive memo from technical audit findings?

To write an executive memo from audit findings, translate technical cybersecurity details into stakeholder-ready communication by selecting the appropriate audience register and reducing jargon. This generates decision-oriented artifacts that non-security executives can understand and act on.

What is the best way to communicate incident details to a board of directors?

Communicating incident details to a board requires translating technical summaries into stakeholder-ready board updates. This process matches the communication register of board members while avoiding misleading language and preventing inappropriate disclosure of customer-identifying details.

How do I translate security findings for a sales or customer Q&A?

To translate security findings for sales or customer Q&A, generate audience-specific deliverables that adjust the communication register for external stakeholders. This ensures accurate information sharing while emphasizing legal review for any customer breach disclosures.

Can I use this to draft engineering tickets from post-mortem findings?

Yes, you can draft engineering tickets from post-mortem findings by translating incident storylines into specific instructions for individual engineers. This aligns technical remediation tasks with the post-mortem outcomes without unnecessary executive hedging.

Does generating legal procurement artifacts require avoiding specific security jargon?

Generating legal procurement artifacts and evidence responses requires reducing security jargon and hedging to match the legal audience register. This translation ensures questionnaires and evidence requests are answered with decision-oriented clarity and no unauthorized disclosures.