vendor-cyber-risk-analyst

Automate vendor cyber risk assessments with intake, tiering, and evidence review.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill vendor-cyber-risk-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-cyber-risk-analyst
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/vendor-cyber-risk-analyst
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill vendor-cyber-risk-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Guides organizations in managing vendor cyber risk through structured intake, tiering, and evidence review, reducing cycle times and increasing assurance.

Core Features & Use Cases

  • Intake and tiering for new and renewing vendors with data sensitivity and exposure context
  • Questionnaire analysis and scoring against control themes (SOC 2, ISO 27001) to drive evidence asks
  • Evidence review and attestation tracking, including subprocessor lists and incident history
  • Continuous monitoring triggers and concentration risk assessments to keep risk posture current
  • Remediation tracking and executive/ procurement reporting for governance
  • Portfolio-level risk insights and renewal pipeline integration with enterprise risk

Quick Start

Collect vendor data, assign a tier, review SOC 2/ISO 27001 attestations, and open a remediation tracker.

Frequently Asked Questions about vendor-cyber-risk-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate vendor cyber risk assessments for SOC 2 and ISO 27001 compliance?

Automate vendor cyber risk assessments by orchestrating intake, tiering, and evidence review workflows. The process applies standardized questionnaires and scoring against SOC 2 and ISO 27001 control themes to validate attestations and track remediation.

What is the best way to manage vendor onboarding and track concentration risk?

Manage vendor onboarding by assigning tiers based on data sensitivity and exposure context. The workflow tracks subprocessor lists and performs concentration risk assessments to monitor fourth-party risk and maintain an updated risk posture.

How does continuous monitoring work for third-party risk management during renewals?

Continuous monitoring for third-party risk management triggers assessments during vendor renewals and scope changes. It evaluates incident history and concentration risk to keep your portfolio-level risk posture current and integrated with enterprise risk.

Can I use this workflow for fourth-party management and executive procurement reporting?

Yes, the workflow supports fourth-party management by tracking subprocessor lists and concentration risk. It generates executive and procurement reporting to provide governance teams with portfolio-level risk insights and remediation status.

What do I need to start scoring vendor attestations and remediation tracking?

To start scoring attestations, collect vendor data and assign a tier based on data sensitivity. Review SOC 2 or ISO 27001 attestations against control themes, then open a remediation tracker to manage any identified gaps.

Does vendor risk tiering work for scope changes and continuous monitoring triggers?

Vendor risk tiering works for scope changes by re-evaluating data sensitivity and exposure context. This triggers continuous monitoring and evidence review to ensure attestations remain valid and risk posture is accurately maintained.