managing-cyber-risk-financial

Structures financial sector cyber risk assessment with scenario quantification and insurance evaluation. Use when assessing cyber risk, quantifying cyber exposure, or evaluating cyber insurance.

11 stars

Best use case

managing-cyber-risk-financial is best used when you need a repeatable AI agent workflow instead of a one-off prompt.

Structures financial sector cyber risk assessment with scenario quantification and insurance evaluation. Use when assessing cyber risk, quantifying cyber exposure, or evaluating cyber insurance.

Teams using managing-cyber-risk-financial should expect a more consistent output, faster repeated execution, less prompt rewriting.

When to use this skill

  • You want a reusable workflow that can be run more than once with consistent structure.

When not to use this skill

  • You only need a quick one-off answer and do not need a reusable workflow.
  • You cannot install or maintain the underlying files, dependencies, or repository context.

Installation

Claude Code / Cursor / Codex

$curl -o ~/.claude/skills/managing-cyber-risk-financial/SKILL.md --create-dirs "https://raw.githubusercontent.com/CaseMark/skills/main/skills/finance/managing-cyber-risk-financial/SKILL.md"

Manual Installation

  1. Download SKILL.md from GitHub
  2. Place it in .claude/skills/managing-cyber-risk-financial/SKILL.md inside your project
  3. Restart your AI agent — it will auto-discover the skill

How managing-cyber-risk-financial Compares

Feature / Agentmanaging-cyber-risk-financialStandard Approach
Platform SupportNot specifiedLimited / Varies
Context Awareness High Baseline
Installation ComplexityUnknownN/A

Frequently Asked Questions

What does this skill do?

Structures financial sector cyber risk assessment with scenario quantification and insurance evaluation. Use when assessing cyber risk, quantifying cyber exposure, or evaluating cyber insurance.

Where can I find the source code?

You can find the source code on GitHub using the link provided at the top of the page.

SKILL.md Source

# Managing Cyber Risk Financial

## When To Use

- Assessing a financial institution's cyber risk posture and quantifying exposure in dollar terms
- Building or reviewing cyber risk scenarios for stress testing, capital planning, or board reporting
- Evaluating cyber insurance coverage adequacy against modeled loss distributions
- Responding to regulatory inquiries on cyber risk management (e.g., NYDFS 500, SEC cyber disclosure rules, FFIEC CAT) [VERIFY regulatory applicability by jurisdiction and charter type]
- Integrating cyber risk into enterprise risk management or economic capital frameworks

## Inputs To Gather

- **Asset inventory**: Critical systems, data stores, and third-party connections — prioritized by business impact (revenue-generating systems, customer PII volume, payment processing infrastructure)
- **Threat intelligence**: Current threat landscape relevant to the institution's segment (retail banking, capital markets, insurance, asset management)
- **Incident history**: Internal incident logs, near-miss events, and industry breach benchmarks (Advisen, Verizon DBIR, FS-ISAC alerts)
- **Control maturity data**: Current control posture mapped to NIST CSF, CIS Controls, or ISO 27001 — include gap assessment results
- **Financial parameters**: Annual revenue, customer count, records held, transaction volumes, existing insurance policies (limits, retentions, sub-limits, exclusions)
- **Regulatory context**: Applicable frameworks and examination findings [VERIFY which regulatory bodies have jurisdiction — OCC, FDIC, Fed, state regulators, SEC, FINRA]

## Workflow

1. **Scope and categorize risk**
   - Define assessment boundaries: entity, business line, or enterprise-wide
   - Classify cyber risk into categories: data breach, business interruption, funds transfer fraud, destructive attack, third-party/supply-chain compromise, regulatory action
   - Identify key risk indicators (KRIs) for each category

2. **Model loss scenarios**
   - Build 3–5 representative scenarios per risk category using a structured format: threat actor, attack vector, affected assets, control failures, business impact chain
   - Quantify each scenario using a frequency-severity approach:
     - **Frequency**: Estimate annualized probability (use industry benchmarks calibrated to institution size and control maturity)
     - **Severity**: Model loss components — incident response costs, notification costs, regulatory fines, litigation, business interruption, reputational harm
   - Express loss distributions as expected loss, 95th percentile, and 99th percentile estimates
   - Use FAIR (Factor Analysis of Information Risk) or comparable quantitative methodology; document all assumptions

3. **Aggregate and stress-test**
   - Aggregate scenario losses into an overall cyber risk exposure profile
   - Run stress scenarios: coordinated multi-vector attack, systemic third-party failure, extended outage during peak transaction period
   - Compare aggregate exposure to risk appetite thresholds and capital reserves
   - Identify concentration risks (single cloud provider, critical vendor dependencies)

4. **Evaluate cyber insurance**
   - Map modeled loss scenarios to existing policy coverage
   - Identify coverage gaps: war/terrorism exclusions, systemic event exclusions, sub-limits on regulatory fines, waiting periods for business interruption [VERIFY exclusion language against specific policy wording]
   - Calculate residual risk after insurance (retention + coverage gaps + policy limits)
   - Benchmark premium against expected loss transfer to assess cost-effectiveness
   - Recommend coverage adjustments: limit increases, sub-limit negotiations, excess layers, or alternative risk transfer (captive, parametric triggers)

5. **Produce management report**
   - Executive summary with top-line exposure figures and risk appetite comparison
   - Scenario detail tables with quantified loss ranges
   - Insurance gap analysis with recommended actions
   - Control improvement roadmap prioritized by risk reduction per dollar invested
   - KRI dashboard for ongoing monitoring

## Output

A cyber risk management report containing:

- **Risk heat map**: Scenarios plotted by frequency and severity with current vs. target positions
- **Loss quantification table**: Per-scenario and aggregate expected loss, VaR-95, VaR-99
- **Insurance coverage matrix**: Scenario-by-coverage mapping showing insured, partially insured, and uninsured exposures
- **Action register**: Prioritized list of control improvements and insurance adjustments with estimated cost and risk reduction impact
- **KRI monitoring framework**: Metrics, thresholds, and escalation triggers for ongoing tracking

## Quality Checks

- All loss estimates cite their source methodology (FAIR, actuarial data, industry benchmarks) — no unsourced figures
- Scenarios are specific to the institution's business model, not generic templates
- Insurance analysis references actual policy terms, not assumed standard coverage
- Regulatory framework mapping is confirmed for the institution's jurisdiction and charter type [VERIFY]
- Assumptions are explicitly listed with sensitivity analysis on key variables (breach probability, average cost per record, downtime duration)
- Report distinguishes between inherent risk (before controls), residual risk (after controls), and transferred risk (after insurance)
- Aggregation accounts for correlation between scenarios — do not assume independence of cyber events

Related Skills

managing-wound-care

11
from CaseMark/skills

Guides wound assessment, classification, and treatment selection with documentation requirements. Use when managing surgical wounds, classifying wound types, or selecting wound care protocols.

managing-wound-assessment-nursing

11
from CaseMark/skills

Structures wound assessment with measurement, staging, and treatment plan documentation. Use when assessing wounds, staging pressure injuries, or documenting wound care.

managing-workplace-safety-healthcare

11
from CaseMark/skills

Tracks OSHA healthcare requirements including bloodborne pathogen, TB, and violence prevention programs. Use when managing OSHA compliance, implementing safety programs, or documenting exposure incidents.

managing-workers-compensation-rehabilitation

11
from CaseMark/skills

Structures workers comp rehab documentation with functional capacity evaluation and return-to-work planning. Use when managing work injury rehab, performing FCEs, or documenting return-to-work status.

managing-vestibular-rehabilitation

11
from CaseMark/skills

Structures vestibular assessment with positional testing and customized exercise programs. Use when evaluating vestibular disorders, performing Dix-Hallpike testing, or designing vestibular exercise programs.

managing-venous-thromboembolism-prophylaxis

11
from CaseMark/skills

Applies VTE risk assessment (Padua, Caprini) with appropriate prophylaxis selection. Use when assessing VTE risk, selecting prophylaxis regimens, or documenting DVT prevention.

managing-valvular-heart-disease

11
from CaseMark/skills

Guides valve disease severity assessment with intervention criteria and surveillance schedules. Use when evaluating valve disease, assessing surgical/interventional timing, or monitoring valve function.

managing-vaccine-schedules

11
from CaseMark/skills

Applies CDC immunization schedules with catch-up protocols and contraindication screening. Use when managing vaccinations, creating catch-up schedules, or documenting immunization decisions.

managing-vaccination-campaigns

11
from CaseMark/skills

Plans mass vaccination campaigns with logistics, cold chain management, and adverse event monitoring. Use when planning vaccination drives, managing immunization logistics, or monitoring VAERS.

managing-traumatic-brain-injury-rehabilitation

11
from CaseMark/skills

Structures TBI rehab with Rancho Los Amigos scoring and cognitive rehabilitation protocols. Use when managing TBI rehab, tracking Rancho levels, or implementing cognitive therapy.

managing-trauma-assessments

11
from CaseMark/skills

Conducts structured primary and secondary trauma surveys following ATLS methodology. Use when assessing trauma patients, documenting trauma workups, or coordinating trauma team activations.

managing-transplant-evaluations

11
from CaseMark/skills

Guides transplant candidacy evaluation with organ-specific criteria and listing documentation. Use when evaluating transplant candidates, documenting listing criteria, or coordinating transplant workups.