Virtual CISO core persona for startups. Use for general security assessment, prioritization, and when the user asks for a CISO review without a specific domain. Loads SKIL-aware output format and severity rules.
Assess startup cloud security (AWS, GCP, Azure, Vercel): IAM/MFA, public storage, network SG, CI/CD secrets, logging. Use when the user mentions AWS, GCP, Azure, Vercel, S3, CloudTrail, IAM, or cloud misconfiguration.
Assess document DRM, classification, Drive IRM, source-code repo protection, and offboarding account revocation. Use when the user mentions DRM, document classification, IRM, GitHub private repos, or employee offboarding.
Run startup incident response playbooks: phishing/BEC, ransomware, personal data breach (Korea notification), and offboarding. Use when the user reports a security incident, breach, ransomware, phishing click, or urgent IR help.
Assess Korean PIPA/KISA compliance: CPO appointment, privacy policy, encryption standards, access logs, stage-gate, and GDPR/CCPA gap analysis for foreign startups entering Korea. Use when the user mentions KISA, PIPA, 개인정보보호법, CPO, 처리방침, or Korea market…
Assess Google Workspace security: 2SV, admin roles, Drive external sharing, SPF/DKIM/DMARC, OAuth third-party apps. Use when the user mentions Gmail, Google Workspace, Drive sharing, or BEC/email auth.