User Reference Manual

Every menu in My CISO Partner, what it does, and when you would use it.

A practical guide to the public website, the Client Portal, and the consultant CRM. Not a technical document: it explains where things are and why you would go there.

This manual explains the navigation and purpose of every part of My CISO Partner. It is a practical guide, not a technical document. It covers the three places people work: the public website, the Client Portal, and the CRM used by the firm's staff.

Every top-level menu is documented the same way: Menu, Sub-menu, What it does, and When/why you would use it. Read the section for the surface you are using, or search the page for a menu name.

SectionWho it is forWhere it lives
1. Public WebsiteProspects, clients, and anyone researching the firmmycisopartner.com, no sign-in
2. Client Portal / Security PlatformClient executives, security leaders, IT, compliance, and board observersClient Portal link in the website header
3. CRM / Prospecting PlatformThe firm's admins, consultants, and viewersStaff sign-in only

Section 1 · Public Website

The public website is where prospects learn what My CISO Partner does, score themselves with a free assessment, and book a conversation. It needs no sign-in. Every page shares one header with six menus, a Client Portal link, and a primary call-to-action button.

1.1 Header at a glance

ElementWhat it doesWhen/why you would use it
LogoReturns to the home pageStart over from any page
AI CISOOpens the AI CISO showcase directly (no dropdown)Show someone what the AI CISO does before anything else
Platform, Solutions, Frameworks, Resources, AboutOpen dropdown menus (detailed below)Browse by capability, service, framework, learning, or company
Client PortalOpens the portal sign-in pageYou are an existing client going to your engagement
Primary buttonBook a Call, Get Started, or See AI CISO in Action, depending on the pageTake the next step the page is designed for
Mobile menuSame menus as an accordion, plus the Client Portal linkOn a phone or narrow window

1.2 AI CISO menu

MenuSub-menuWhat it doesWhen/why you would use it
AI CISO(direct link)Shows the AI CISO answering CISO-style questions from a program's own records, with grounding and confidence shownA prospect asks "what does the AI actually do?"

1.3 Platform menu

MenuSub-menuWhat it doesWhen/why you would use it
PlatformAI CISOSame showcase page as the AI CISO menuUnderstand the AI layer that sits over everything else
PlatformContinuous Exposure MonitoringExplains external attack-surface scanning, monitored assets, and scan reportsThe prospect wants ongoing monitoring, not a one-time review
PlatformRisk & RemediationJumps to the risk-to-remediation loop section of the AI CISO pageExplain how findings become risks, actions, and verified fixes
PlatformCompliance & FrameworksOpens the Frameworks page: one control library mapped to many frameworksThe prospect is framework-driven (SOC 2, ISO 27001, HIPAA, PCI, NIST, CMMC)
PlatformAI GovernanceDescribes ISO/IEC 42001 and NIST AI RMF aligned governanceThe prospect is deploying AI and needs policy, oversight, and evidence

1.4 Solutions menu

Solutions are the human services delivered through the platform. The menu is grouped by the kind of help a buyer is looking for.

GroupSub-menuWhat it doesWhen/why you would use it
Risk & Compliance AdvisoryCyber Risk AdvisoryRisk assessment, prioritisation, and treatment guidanceLeadership wants to know how much risk it carries and what to fix first
Risk & Compliance AdvisoryCompliance & Program LeadershipRunning the compliance program to a chosen frameworkAn audit, certification, or regulator deadline is coming
Risk & Compliance AdvisoryExecutive & Board AdvisoryBoard reporting, oversight, and executive coachingThe board needs cyber briefings it can act on
AI GovernanceAI GovernanceAI governance strategy and program leadershipThe organisation is adopting AI and has no oversight structure
Regulated IndustriesNuclear Cybersecurity & Regulatory ReadinessNRC-oriented readiness across cyber, physical protection, MC&A, FOCI, and personnel securityNuclear licensees and applicants
Regulated IndustriesFinancial Institution Cybersecurity Readiness ReviewReadiness against NCUA, FFIEC, and GLBA expectationsBanks and credit unions preparing for examiners
Regulated IndustriesGLBA Safeguards ComplianceSafeguards Rule program build-outAny financial institution subject to the FTC Safeguards Rule
Readiness ServicesPrivacy & Data Protection ReadinessCustomers, regulators and enterprise procurement now ask the same question in different words: what personal data do you hold, why, where does it go, and who can prove it? Most growing companies have a privacy policy and a cookie banner but no data inventory, no tested subject-request process and no way to say which of the state, GDPR or sector rules actually reach themCustomer DPA or privacy addendum
Readiness ServicesSecure SDLC & Product Security ReadinessEnterprise customers, federal buyers and now EU product regulation expect proof that the software you ship was built securely: threat models, code review, dependency control, secrets management, signed builds and a way to receive and fix vulnerability reportsCustomer security review asks for SDLC evidence
Readiness ServicesEnterprise Security Readiness & Questionnaire ResponseEnterprise deals stall in security reviewA large deal is waiting on a security review
Readiness ServicesCyber Insurance ReadinessRenewal arrives with a longer application, higher premium, a lower limit and exclusions nobody readRenewal within 180 days
Readiness ServicesSoftware Supply Chain Security & SBOM ReadinessA customer asks for an SBOM, a regulator asks how you would know if a component you ship carried a known exploited vulnerability, and the honest answer is a package manifest and hopeCustomer or federal SBOM request
Readiness ServicesDORA Readiness (Digital Operational Resilience)DORA has applied to EU financial entities since 17 January 2025, and it reaches the ICT providers that serve them through contractSupervisor questionnaire or inspection
Readiness ServicesEU Cybersecurity & NIS2 ReadinessNIS2 widened EU cybersecurity law to eighteen sectors and made management personally accountable, but whether it reaches a specific company depends on entity type, sector, size, jurisdiction and how each Member State transposed itNational authority registration deadline
Readiness ServicesEU AI Act ReadinessThe EU AI Act applies in phases: prohibited practices and AI literacy from 2 February 2025, general-purpose AI obligations from 2 August 2025, most high-risk system obligations from 2 August 2026, with some categories later, and a Commission proposal to adjust the high-risk timeline under reviewCustomer asks for AI Act role and risk classification
Readiness ServicesTrust Center ReadinessA trust page that lists an expired certificate, a claim nobody can evidence or a policy that legal never approved is worse than no trust pageBuyer asks for a trust page or portal
Readiness ServicesFraud, Identity & Account Takeover ReadinessAccount takeover shows up as support tickets, chargebacks and churn before anyone calls it an incident; identity, session, recovery and payout controls are one problemSpike in account takeover, chargebacks or partner pressure
Readiness ServicesEU Cyber Resilience Act ReadinessProducts with digital elements sold in the EU carry secure-by-design, vulnerability handling, SBOM, documentation and 24-hour reporting obligations phasing in from September 2026EU product sales, distributor or customer asks for a CRA position
Readiness ServicesOperational Resilience ProgramFive plans owned by four teams; the umbrella that sets tolerances per important business service and tests whether the plans hold togetherRegulator expectation, major outage or a board asking "would we keep running?"
Readiness ServicesAI Agent Security ReadinessAgents hold credentials, call tools and read content an attacker can write; identity, least-privilege tools, injection defence, approval gates and audit for agentsAgent with write access, agent reading external content, or an agent-caused incident
Readiness ServicesService CatalogEvery service grouped by category, with its problem, buyers, free check and statusFind the right door for the problem in front of you
Supply Chain & Frameworks ReadinessSupply Chain & Third-Party RiskVendor and supplier risk programCustomers or regulators are asking about third parties
Supply Chain & Frameworks ReadinessNIST & CMMC Compliance ReadinessNIST 800-171 and CMMC preparationDefence contractors and their suppliers
Fractional & Interim LeadershipFractional CISOPart-time, ongoing CISO leadershipYou need a CISO but not a full-time hire
Fractional & Interim LeadershipInterim CISOFull-time CISO cover for a fixed periodA CISO left, or a transformation needs temporary leadership

1.5 Frameworks menu

Every item here is a free, scored self-assessment or a public tracker. Results can flow into the CRM as a lead assessment.

GroupSub-menuWhat it doesWhen/why you would use it
(top)One Control Library. Multiple Frameworks.Explains the single control library behind every frameworkUnderstand why one piece of evidence can satisfy several frameworks
SecurityRansomware Readiness AssessmentScores readiness against the NIST IR 8374 ransomware profileLeadership asks "would we survive ransomware?"
SecurityCyber Risk AssessmentExecutive-level cyber risk scoreA quick, board-friendly starting point
Business ResilienceBusiness Continuity Readiness AssessmentISO 22301 aligned BCP readinessContinuity planning is untested or missing
Business ResilienceDisaster Recovery Readiness AssessmentISO/IEC 27031 aligned DR readinessRecovery objectives and runbooks need checking
NISTNIST & CMMC ReadinessService page for 800-171 and CMMCDefence supply chain obligations
NISTNIST CSF 2.0 TrackerTrack current and target CSF 2.0 profile by functionBuilding or maturing a CSF-based program
ISOISO 27001 Readiness AssessmentScores readiness for certificationDeciding whether to pursue ISO 27001
ISOISO 27001 TrackerTracks Annex A control statusWorking toward certification
ISOISO 42001 AI Governance TrackerTracks AI management system conformanceBuilding an AI governance program
ComplianceSOC 2 Readiness Assessment / SOC 2 TrackerScore, then track, Trust Services Criteria readinessSaaS companies asked for a SOC 2 report
ComplianceHIPAA Readiness Assessment / HIPAA TrackerScore, then track, Security Rule readinessHealthcare and business associates
CompliancePCI DSS Readiness Assessment / PCI TrackerScore, then track, PCI DSS readinessAnyone handling card data
ComplianceGLBA Safeguards AssessmentScores Safeguards Rule readinessFinancial institutions under the FTC rule
Financial ServicesFFIEC Readiness AssessmentScores against the FFIEC handbooksBanks preparing for examination
Financial ServicesNCUA Readiness AssessmentScores against NCUA Part 748 and ISE expectationsCredit unions
Financial ServicesFinancial Institution Readiness AssessmentCombined institution readiness reviewNot sure which regulator applies
Financial ServicesCrypto & Digital Asset Regulatory ReadinessWhich U.S. and EU crypto regulations may apply, and the highest-priority gaps; a readiness indicator, not legal adviceExchanges, custodians, token issuers, stablecoin issuers, wallet and infrastructure providers
Enterprise Readiness & Product SecurityPrivacy Readiness CheckWhich privacy obligations may reach you, and whether the inventory, subject-request process and breach workflow behind your policy actually exist; a readiness indicator mapped to the NIST Privacy Framework 1.0Customer DPA or privacy addendum
Enterprise Readiness & Product SecuritySecure SDLC Quick CheckFifteen questions across the NIST SSDF practice groups: prepare, protect, produce, respond. The gaps enterprise buyers and regulators test first; a readiness indicator mapped to the NIST SSDF v1.1Customer security review asks for SDLC evidence
Enterprise Readiness & Product SecurityEnterprise Security Readiness CheckFifteen questions on the controls enterprise procurement rejects vendors over, and whether your questionnaire answers are backed by evidence; a readiness indicator mapped to the SOC 2 Trust Services CriteriaA large deal is waiting on a security review
Enterprise Readiness & Product SecurityAI Security Quick CheckFourteen questions on the trust boundaries AI introduces: user to application, application to model, model to data, model to tools, tools to the outside world; a readiness indicator mapped to the OWASP Top 10 for LLM Applications 2025AI feature launch
Enterprise Readiness & Product SecurityTrust Center Readiness CheckEleven questions on whether your public security claims are evidenced, approved, current and withdrawable, before a buyer checks; a readiness indicator mapped to the SOC 2 Trust Services CriteriaBuyer asks for a trust page or portal
Enterprise Readiness & Product SecurityFraud & Account Takeover Readiness CheckSixteen questions on onboarding, authentication, sessions, recovery through support, bots, fraud decisions and payouts; a readiness indicator mapped to the fraud and identity control set anchored to NIST SP 800-63-4Rising account takeover, chargebacks or a credential leak affecting customers
Enterprise Readiness & Product SecurityCyber Resilience Act Quick CheckSixteen questions on secure-by-design, vulnerability handling, SBOM, support period, documentation and the 24-hour reporting clock; a readiness indicator mapped to Regulation (EU) 2024/2847Products with digital elements sold in the EU
Enterprise Readiness & Product SecurityOperational Resilience Quick CheckTwelve questions on important business services, impact tolerances, dependencies, scenario testing and plan integration; a readiness indicator mapped to ISO 22301 with DORA crosswalksRegulator, customer or board asks for a resilience picture
Enterprise Readiness & Product SecurityAI Agent Security Quick CheckFourteen questions on agent inventory, identity, tool permissions, injected instructions, approval gates, audit and kill switch; a readiness indicator mapped to the AI agent security control setAgents with tool access in production
All Frameworks & AssessmentsSee all 36 free assessmentsCatalogue of every assessment, including the nuclear series, AI governance, board, CISO, cyber insurance, and supply chainFind an assessment not listed in the menu

1.6 Resources menu

GroupSub-menuWhat it doesWhen/why you would use it
(top)GuidesLibrary of plain-English guides (SOC 2 cost, ISO 27001 process, HIPAA checklist, NIST CSF, NRC rules, and more)Research before a conversation
(top)NIST IR 8374 Rev. 1 Ransomware ProfileGuide to the ransomware profile behind the assessmentInterpret a ransomware assessment result
(top)Business Continuity Planning GuideHow to build and test a BCPStarting continuity work
(top)Disaster Recovery GuideHow to set recovery objectives and runbooksStarting DR work
(top)Free Executive AssessmentsSame catalogue as "See all 36 free assessments"Pick an assessment by topic
(top)Platform TutorialsShort narrated videos recorded from the live productLearn a portal page before signing in, or share with a new user
(top)User Reference ManualThis manualLook up what a menu does and when to use it
(top)Policies & TemplatesPolicy resources aligned to the supported frameworksNeed a starting document
(top)PricingEssentials, Growth, and custom Interim or Enterprise tiersBudgeting a fractional CISO engagement
AcademyCISO AcademyExecutive and CISO leadership coursesNew or aspiring security leaders
AcademySMB Security TrainingSecurity basics for small business ownersSmall teams without security staff
AcademySecurity AwarenessEmployee awareness topics such as phishing and passwordsStaff training
AcademyAI Security & GovernanceAI risk, policy, and shadow AITeams adopting AI tools
AcademyVulnerability ManagementScanning, prioritisation, and remediationIT teams running a vulnerability program
AcademyCompliance TrainingSOC 2, ISO 27001, HIPAA, PCI, NIST, and CMMC coursesPreparing staff for an audit
AcademySupply Chain SecurityVendor and supplier risk coursesProcurement and vendor managers
AcademyBrowse the full AcademyEvery course across all seven categoriesFind a course not listed

1.7 About menu

MenuSub-menuWhat it doesWhen/why you would use it
AboutAbout My CISO PartnerFounder background and firm storyCheck credentials before engaging
AboutContact UsContact form for a no-obligation conversationYou have a question rather than a booking
AboutBook a ConsultationPick a 30-minute discovery call slotYou are ready to talk
Footer groupLinksWhen/why you would use it
PlatformAI CISO, Continuous Exposure Monitoring, Frameworks, Free Assessments, Pricing, Client loginQuick access to the product pages and the portal
ServicesFractional CISO, Interim CISO, Cyber Risk Advisory, Board Advisory, Compliance Leadership, AI Governance, Nuclear Readiness, Financial Institution Readiness, Supply Chain Risk ManagementJump straight to a service page
CompanyAbout, Guides, Contact, Trust & Security, Privacy Policy, Terms of ServiceDue diligence and legal terms

Pages reached from within other pages rather than a menu:

PageWhat it doesWhen/why you would use it
Individual assessment pagesScored questionnaire with a results summary and recommended prioritiesComplete one; results can be sent to you and appear in the CRM as a lead assessment
TrackersSave control status in your browser and export itTrack progress between conversations
Nuclear readiness intakeStarts a nuclear readiness assessment with the firmNuclear licensee wants a guided review
Products (Monitoring & Assurance)Subscription options for exposure monitoring and compliance-as-a-serviceBuying monitoring rather than advisory hours
Tutorial viewerPlays one tutorial with transcript and related tutorialsOpened from the tutorials library or a "Watch tutorial" link in the portal
Trust & SecurityHow the firm protects client dataSecurity review of the vendor
SuccessConfirms a completed subscriptionShown after checkout
404Not-found page with links back to the main sectionsA broken or old link

Section 2 · Client Portal / Security Platform

The Client Portal is the client's private view of their engagement: posture, risks, actions, decisions, compliance, reports, meetings, documents, and their CISO's guidance. It is read-mostly by design. Clients respond to decisions, add context, upload requested evidence, and ask questions; the consultant does the rest in the CRM.

2.1 Signing in

StepWhat happensNotes
Open the Client Portal link on the websiteThe sign-in page asks for your work emailOnly invited emails can sign in
Email me a sign-in codeA six-digit code arrives by emailNo password exists to lose or reuse
Sign inEnter the code and you land on your role's home pageSome pages, such as Academy, additionally require an authenticator app
First visitA welcome banner explains the portal in three steps with links to the Platform Map, Academy, and GlossaryDismiss it once; it stays hidden

2.2 Header controls

ControlWhat it doesWhen/why you would use it
Search boxSearches your risks, actions, decisions, policies, evidence, meetings, reports, and documentsYou remember a name but not where it lives
? (Help)Opens How MyCISO Partner Works, Glossary, Academy, and this manualLearn a term or the overall lifecycle
BellOpens your notifications and email preferencesSee what changed since your last visit
RefreshReloads the current page's dataAfter your consultant tells you something was updated
Sign outEnds the sessionShared or public computer
Watch tutorialAppears on pages that have a recorded tutorialFirst time on a page, or training a colleague

2.3 Roles and what each one sees

Your consultant assigns a role when inviting you. The role decides your home page, your menu, and whether you can respond to decisions.

RoleHome pageMenuCan decideCan contributeSees board material
ExecutiveExecutive dashboardExecutive, Risk, Actions, Decisions, Compliance, Reports, Meetings, Documents, Ask Your CISOYesYesYes
Security leaderSecurity leader dashboardDashboard plus the standard menuYesYesYes
ITRemediation dashboardDashboard plus the standard menuNoYesNo
ComplianceCompliance dashboardDashboard plus the standard menuNoYesNo
Board observerBoard dashboardBoard, Decisions, Reports, Meetings, Documents, Ask Your CISOYesNoYes
ContributorExecutive overviewStandard menuNoYesNo
Read onlyExecutive overviewStandard menuNoNoNo

"Can decide" means you can approve, defer, or reject an open decision. "Can contribute" means you can add context to actions and upload requested evidence.

2.4 Main menu

MenuSub-menu / tabWhat it doesWhen/why you would use it
OverviewWhere the organisation stands, what your CISO recommends, top priorities, decisions required, recent changes, upcoming items, and latest reportsYour weekly two-minute check
Executive (executive role)The overview reframed for a leader: needs your direction, what your CISO ranks first, twelve-month trend, board and reportingBefore a leadership meeting
Dashboard (security leader)Risk, findings, evidence, remediation, governance, what changed, and what is getting worseRunning the program day to day
Dashboard (IT)Overdue material remediation, due dates, findings, evidence requests, affected assets and servicesPlanning the team's remediation work
Dashboard (compliance)Framework readiness, control state, evidence coverage, findings, remediation, decisions requiredPreparing for an audit or examiner
BoardPosture, agenda, priorities, oversight, accepted risk, strategic items, and trend, readable in under two minutesBoard and committee meetings
RiskRisk registerEvery open risk with score, owner, status, and treatmentAsk "what could hurt us most right now?"
RiskRisk detailOne risk with its findings, actions, decisions, acceptance history, and traceUnderstand why a risk is scored the way it is
ActionsOpen / Verified / All tabsThe remediation plan: each action, its due date, owner, and verification statusTrack whether fixes are done and proven
ActionsAction detailOne action with linked risk, evidence, and comments; contributors can add contextGive your consultant an update
DecisionsOpen / Decided tabsDecisions your CISO needs from you, and the record of past decisionsSomething is blocked waiting on you
DecisionsDecision detailOptions, recommendation, rationale, and the response form for decidersApprove, defer, or reject with a reason
ComplianceFrameworksReadiness per adopted frameworkSee where certification or examination readiness stands
ComplianceControlsControl implementation stateAnswer "do we have this control?"
CompliancePoliciesPolicy register with version and review dates; policy detail opens the documentFind the current approved policy
ComplianceEvidenceEvidence requested and supplied; contributors can uploadRespond to an evidence request
ReportsReportsEvery report shared with you, downloadablePull last quarter's report
ReportsBoardBoard packs and board-visible items (board-eligible roles only)Prepare the board pack
ReportsAssessmentsAssessments run for you, with detail pagesReview a readiness assessment result
MeetingsUpcoming meetings and past notes with linked risks, decisions, and actionsPrepare for, or recall, a meeting with your CISO
DocumentsEvery document shared with or submitted by you, via short-lived download linksFetch a deliverable
Ask Your CISOAsk a question answered only from your engagement's data, with a certainty label on every statementGet a grounded answer without waiting for a meeting

2.5 More menu

MenuSub-menuWhat it doesWhen/why you would use it
MoreEngagementYour service, cadence, objectives, deliverables, and onboarding milestonesCheck what is included and what is coming
MoreAcademyRole-based learning paths, courses, lessons, and badgesLearn the platform or a security topic; requires authenticator sign-in
MoreProfile & notificationsYour account details, email preferences, and recent notificationsChange how often you are emailed
MoreSecurity & trustHow the portal protects your account and dataAnswer your own security team's questions
MoreRegulatory readinessYour regulatory readiness assessments (nuclear, crypto and digital assets, or another regime), if part of your engagement; the page is titled after your frameworkClients preparing for a regulator
MoreNIST CSF 2.0 profileYour current and target profile by function and outcome, using NIST's own labelsDiscuss target state with your CISO
MoreExposureContinuous Exposure Monitoring: monitored assets, scan history, findings by severity, scan reports, and compliance-as-a-service statusSubscribers to monitoring or assurance

2.6 Guidance pages

PageReached fromWhat it does
How MyCISO Partner WorksHelp menu, welcome bannerThe nine-stage lifecycle from control library to AI CISO, with where each stage lives
GlossaryHelp menu, welcome bannerPlain-English definitions and how each term is used in your engagement
TraceLinks on risks and figuresShows the source records and reasoning behind a number or recommendation
Search resultsHeader search boxMatches across every record type you can see

Section 3 · CRM / Prospecting Platform

The CRM, titled Consultant Command Center inside the app, is the staff-only workspace where the firm runs every client engagement and its own sales pipeline. Everything a client sees in the portal is created or approved here. It is organised as ten menus across the top; each opens a dropdown grouped by sub-heading.

3.1 Signing in and staff roles

StepWhat happensNotes
Consultant sign inEnter your staff email and the emailed codeAuthorised staff only
First sign-inSet up an authenticator app (Google Authenticator, 1Password, Authy, or similar)Required for admins and consultants
Later sign-insEnter the authenticator code after the email codeSessions expire after eight hours; all access is logged
RoleWhat it can doWhen it is used
AdminEverything, plus consultant management, AI model registry, pricing reference, and Academy analyticsFirm leadership
ConsultantFull read and write on the clients assigned to them, and the sales pipelineDelivery staff
ViewerRead-only across the CRM; every write is refused; signs in with the email code aloneAuditors, partners, or observers who need visibility without change rights

3.2 Header controls

ControlWhat it doesWhen/why you would use it
Search (Ctrl+K)Searches clients, risks, actions, decisions, policies, meetings, and reportsJump to any record by name
Name and role badgeShows who is signed in and as whatConfirm you are in the right account
HelpHow MyCISO Partner Works, Glossary, Academy, and this manualSame guidance set as the portal, from the consultant side
MenuOn narrow screens, opens the ten menus as an accordionWorking from a tablet or phone
Sign outEnds the sessionLeaving a shared machine
BreadcrumbShows the path from menu to recordStep back one level

3.3 Command Center menu

Sub-headingSub-menuWhat it doesWhen/why you would use it
OverviewDashboardPersonal greeting, average readiness, highest open risk band, and today's items across your clientsStart of day
OverviewCISO Command CenterPortfolio home base: attention items, posture, what is new, and the client listDecide which client needs you first
OverviewExecutive DashboardFirm-wide sales pipeline value, conversion, and funnel healthWeekly pipeline review
OverviewMy DayYour own due and overdue items across delivery and salesPlan the day
OverviewClientsClient list with health, attention items, risk counts, and overdue actions; opens the client recordEnter a client's world
WorkflowCISO Work QueueEvery task, POA&M action, and open attention item you can see, as one worklistWork the queue between meetings
WorkflowCISO TasksDiscrete delivery tasks filtered by client, type, priority, and statusAssign and close routine work
WorkflowSecurity ProjectsMulti-step initiatives with status, health, progress, and target dateTrack a migration or program build
WorkflowActivityChronological log of everything recorded across the portfolioReconstruct what happened and when
WorkflowMeetingsUpcoming and past client meetings, preparation needed, and follow-upsPrepare agendas and capture notes

3.4 AI CISO menu

MenuSub-menuWhat it doesWhen/why you would use it
AI CISOAI CISO Advisor (direct link)Review queue of every AI-drafted interaction: what needs review, volume by mode, recent activityApprove or correct AI drafts before clients see them

AI-assisted tools also appear inside each client record. They draft answers, priorities, and analysis from the client's real records and never act on their own.

3.5 Risk menu

Sub-menuWhat it doesWhen/why you would use it
Cyber RiskRisk register rolled up one row per clientCompare clients at a glance
Risk RegisterEvery risk with score, owner, treatment, and acceptance; opens risk detailAdd, score, or re-score a risk
Framework RiskRisks and controls rolled up per framework requirementShow an auditor where risk concentrates
Asset RiskCritical assets with mapped risk, findings, and control coverageAsset-centred conversations with IT
Vendor RiskThird parties with mapped risk, findings, and supplier assessment evidenceVendor review meetings
Business ServicesNamed business services an engagement protectsTie risks to what the business actually runs
Risk Acceptance DebtEvery accepted risk with its review-cycle statusMake sure accepted risks are re-reviewed on time
Risk ReductionHow far compensating controls have reduced each open risk, and the direction of travelEvidence that treatment is working

3.6 Compliance menu

Sub-headingSub-menuWhat it doesWhen/why you would use it
FrameworksFrameworksEach client's scored assessment per framework; opens assessment and finding detailRun or review a readiness assessment
Regulatory ReadinessFinancial InstitutionInstitution type, regulator, and regulatory readiness signals per clientBank and credit union clients
Regulatory ReadinessCrypto & Digital AssetsSix-gate profile, regulatory scope map (what may apply and why), current requirements separated from future changes, Legal Review Queue, findings, licences, calendar, cross-regulatory coverage and exportsDigital-asset clients under U.S. and EU regimes
Regulatory ReadinessCross-Framework MappingWhere a requirement in one framework already covers anotherAvoid assessing the same control twice
Regulatory ReadinessExaminer ReadinessLog of AI-run examiner simulations across assessmentsRehearse before a real examination
Regulatory ReadinessRegulatory ChangesRule changes classified by impact on each client's frameworksMonthly regulatory update
Regulatory ReadinessNCUA · Cyber IncidentNCUA incident requirements awaiting a customer-information determinationAn incident may be reportable
Regulatory ReadinessSOC 2 ReadinessSOC 2-mapped controls, gaps, tests, and reviews by Trust Services CriteriaSaaS clients heading for a SOC 2 report
Regulatory ReadinessRegulatory IntelligenceVersioned register of every law, regulation, standard and framework with dates, requirement counts and clients in scope; per-client "why does this apply?" with the rule, inputs, missing inputs and evidence; admins supersede versions without deleting the old oneA client asks why they are in scope, or a regulation changes
Enterprise ReadinessSecurity QuestionnairesImport a customer questionnaire or load one of the platform's own question banks (enterprise or cloud service baseline, whole or by section), auto-match questions to approved answers and adopted controls with current evidence, confirm final answers with an owner, grow the approved-answer libraryAn enterprise buyer sends a security review, or the client wants to rehearse one
Enterprise ReadinessTrust CenterApproved security statements tied to controls, evidence or certificates, moved draft → review → approved → published with guardrails against expired or unsupported claims; the *Public trust page* panel sets the client's public address (`/trust/<name>`) and switches the page on or offThe client wants a trust page it can defend
Product SecuritySoftware Supply ChainSoftware products, components from a CycloneDX or SPDX SBOM, recorded vulnerabilities and licences, alerts for known-exploited items and stale SBOMsA customer or the EU Cyber Resilience Act asks what is in the software

Quick filters inside Frameworks open the NCUA (Part 748, ISE, ACET), FFIEC domain, and GLBA views without leaving the page.

3.7 Operations menu

Sub-menuWhat it doesWhen/why you would use it
ControlsControl implementation status across every clientAnswer "who has this control in place?"
EvidenceEvidence items supporting controls, with requests to clientsChase or accept evidence
FindingsRecorded gaps and deficiencies from assessments and reviewsConvert findings into risks and actions
RemediationPOA&M queue, validation, and security debt tabsVerify fixes and manage what is overdue
IncidentsEvery recorded incident with severity, status, and regulatory triage stateIncident response and reporting
PoliciesPolicy register with version, status, owner, and review datePolicy review cycle
Third-Party RiskVendor register; add a vendor and record an assessmentOnboard or re-assess a supplier

3.8 Intelligence menu

Sub-menuWhat it doesWhen/why you would use it
AI Security Command CenterThe Command Center focused on AI security postureClients deploying AI systems
Evidence IntelligenceEvidence gaps, contradictions, quality, and freshness, one row per clientSpot weak evidence before an auditor does
Decision RegisterFormal log of governance decisions: what, when, by whom, and whyShow a board or regulator the decision trail
Governance WorkflowsAuditable review-and-approval workflows: risk reviews, exceptions, policy approvals, risk acceptancesRoute something for formal approval

3.9 Reports, Administration, and Academy menus

MenuSub-menuWhat it doesWhen/why you would use it
ReportsBoard Reporting (direct link)Every client's board-relevant items as one agenda; publishes board packs to the portalQuarterly board season
AdministrationCapacityTrailing seven-day hours, weekly capacity, and utilisation for you, or everyone if adminBalance workload
AdministrationSettingsYour account and session details; admin panels for consultants, AI model registry, and pricing referenceAdd a consultant or check a model
AcademyHomeLearning paths, courses, and lessons for staffOnboard a new consultant
AcademyAdmin DashboardAdoption, learning, and content analytics (admin only)Measure training uptake

3.10 Growth menu (prospecting and sales)

Sub-headingSub-menuWhat it doesWhen/why you would use it
PipelineLeadsInbound and outbound leads with source, trigger event, and statusQualify new interest
PipelineOpportunitiesActive deals with stage, value, score, owner, and next actionForecast and move deals
PipelineProposalsIssued proposals and versions with tier, price, status, and validation gapsSend or revise a proposal
PipelineLead AssessmentsWebsite self-assessments completed by prospects, with score and prioritiesFollow up with context the prospect gave you
PipelineActivitiesCalls, emails, and meetings with notesLog a touchpoint
PipelineFollow-upsScheduled and sent follow-ups plus nurture tracksKeep warm leads moving
PipelineBookingUpcoming discovery calls and your public booking availabilityManage the calendar behind Book a Call
ConversionFinancial Institution ReadinessProspects who completed the financial institution assessment, and their conversionRegulated-industry campaign results
ConversionService CatalogEvery service with its problem, buyers, tiers, discovery questions and objections; pick a lead for one primary and up to five secondary recommendations with rationale and unknownsPreparing for a discovery call
MarketingProspectingOutbound funnel by research and score tierWhere the outbound effort stands
MarketingProspectsResearched prospect list with score, status, and campaign; opens prospect detailPick the next accounts to work
MarketingSignalsBuying signals across prospects, newest first, with decayed strengthTime outreach to a trigger
MarketingBuyersBuyer contacts by persona, role, relationship stage, and Sales Navigator statusMulti-thread an account
MarketingSaved SearchesCatalogue of Sales Navigator searches by vertical, as plain linksReuse a proven search
MarketingICP ProfilesIdeal customer profile definitions that drive prospect scoringRefine who you target
MarketingOutboundWhether automated sending is on, daily cap, today's volume, blocks, and suppressionsControl the sending engine
MarketingCampaignsOutbound campaign performance and inbound content campaign outcomesCompare what is working
MarketingPartnersReferral partners with leads referred, deals closed, and commissionPartner reviews
MarketingMarket EngineMarketing-to-pipeline funnel: sessions, assessments, forms, bookings, attributionMonthly marketing review
MarketingAnalyticsWebsite traffic and consented event analyticsWhich pages and sources perform
MarketingMetricsFirm-wide funnel, assessment conversion, financial, and delivery metricsBoard-level view of the firm

3.11 The client record

Opening a client from Clients, search, or any dashboard shows one record with tabs. This is where most delivery work happens.

TabWhat it doesWhen/why you would use it
OverviewHealth, attention items, and engagement summaryFirst stop for any client question
RiskThe client's risks and acceptance historyRisk review meeting
Compliance / Assessments / Evidence / PoliciesThe client's frameworks, assessments, evidence, and policiesAudit preparation
Actions / Decisions / MeetingsWhat is being fixed, what needs deciding, and the meeting recordWeekly engagement rhythm
Security Projects / SuppliersInitiatives and third parties for this clientProgram and vendor tracking
Reports / Board / ExecutiveWhat has been shared with each audiencePublish to the portal
Client portalPortal users, roles, and visibility settingsInvite a client user or change their role
AI / AI systems / Reasoning & memoryAI-assisted drafting, the client's AI system inventory, and the AI's stored contextGovernance of AI on both sides
CommercialSubscription and commercial termsRenewal conversations
ActivityEverything recorded for this clientHand-over or dispute

Each shared item carries a visibility label: Internal only, Client, Executives, or Board. That label decides who sees it in the portal.

Pages reached from within a client record rather than a menu:

PageWhat it doesWhen/why you would use it
Client 360One-page synthesis of the whole engagementExecutive briefing preparation
Handoff draftDraft handover pack when a consultant changesTransition between consultants
Supply Chain RiskThe client's supplier assessment workspaceThird-party program delivery
Readiness assessment detailOne regulatory readiness assessment with findingsNuclear and financial institution work
Governance Workflow detailOne approval workflow with its steps and sign-offsFollow an approval to completion

Prefer to watch? The Platform Tutorials show the portal pages described in Section 2. Clients can also open How MyCISO Partner Works and the Glossary from the Help menu inside the portal.