This manual explains the navigation and purpose of every part of My CISO Partner. It is a practical guide, not a technical document. It covers the three places people work: the public website, the Client Portal, and the CRM used by the firm's staff.
Every top-level menu is documented the same way: Menu, Sub-menu, What it does, and When/why you would use it. Read the section for the surface you are using, or search the page for a menu name.
| Section | Who it is for | Where it lives |
|---|---|---|
| 1. Public Website | Prospects, clients, and anyone researching the firm | mycisopartner.com, no sign-in |
| 2. Client Portal / Security Platform | Client executives, security leaders, IT, compliance, and board observers | Client Portal link in the website header |
| 3. CRM / Prospecting Platform | The firm's admins, consultants, and viewers | Staff sign-in only |
Section 1 · Public Website
The public website is where prospects learn what My CISO Partner does, score themselves with a free assessment, and book a conversation. It needs no sign-in. Every page shares one header with six menus, a Client Portal link, and a primary call-to-action button.
1.1 Header at a glance
| Element | What it does | When/why you would use it |
|---|---|---|
| Logo | Returns to the home page | Start over from any page |
| AI CISO | Opens the AI CISO showcase directly (no dropdown) | Show someone what the AI CISO does before anything else |
| Platform, Solutions, Frameworks, Resources, About | Open dropdown menus (detailed below) | Browse by capability, service, framework, learning, or company |
| Client Portal | Opens the portal sign-in page | You are an existing client going to your engagement |
| Primary button | Book a Call, Get Started, or See AI CISO in Action, depending on the page | Take the next step the page is designed for |
| Mobile menu | Same menus as an accordion, plus the Client Portal link | On a phone or narrow window |
1.2 AI CISO menu
| Menu | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| AI CISO | (direct link) | Shows the AI CISO answering CISO-style questions from a program's own records, with grounding and confidence shown | A prospect asks "what does the AI actually do?" |
1.3 Platform menu
| Menu | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| Platform | AI CISO | Same showcase page as the AI CISO menu | Understand the AI layer that sits over everything else |
| Platform | Continuous Exposure Monitoring | Explains external attack-surface scanning, monitored assets, and scan reports | The prospect wants ongoing monitoring, not a one-time review |
| Platform | Risk & Remediation | Jumps to the risk-to-remediation loop section of the AI CISO page | Explain how findings become risks, actions, and verified fixes |
| Platform | Compliance & Frameworks | Opens the Frameworks page: one control library mapped to many frameworks | The prospect is framework-driven (SOC 2, ISO 27001, HIPAA, PCI, NIST, CMMC) |
| Platform | AI Governance | Describes ISO/IEC 42001 and NIST AI RMF aligned governance | The prospect is deploying AI and needs policy, oversight, and evidence |
1.4 Solutions menu
Solutions are the human services delivered through the platform. The menu is grouped by the kind of help a buyer is looking for.
| Group | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| Risk & Compliance Advisory | Cyber Risk Advisory | Risk assessment, prioritisation, and treatment guidance | Leadership wants to know how much risk it carries and what to fix first |
| Risk & Compliance Advisory | Compliance & Program Leadership | Running the compliance program to a chosen framework | An audit, certification, or regulator deadline is coming |
| Risk & Compliance Advisory | Executive & Board Advisory | Board reporting, oversight, and executive coaching | The board needs cyber briefings it can act on |
| AI Governance | AI Governance | AI governance strategy and program leadership | The organisation is adopting AI and has no oversight structure |
| Regulated Industries | Nuclear Cybersecurity & Regulatory Readiness | NRC-oriented readiness across cyber, physical protection, MC&A, FOCI, and personnel security | Nuclear licensees and applicants |
| Regulated Industries | Financial Institution Cybersecurity Readiness Review | Readiness against NCUA, FFIEC, and GLBA expectations | Banks and credit unions preparing for examiners |
| Regulated Industries | GLBA Safeguards Compliance | Safeguards Rule program build-out | Any financial institution subject to the FTC Safeguards Rule |
| Readiness Services | Privacy & Data Protection Readiness | Customers, regulators and enterprise procurement now ask the same question in different words: what personal data do you hold, why, where does it go, and who can prove it? Most growing companies have a privacy policy and a cookie banner but no data inventory, no tested subject-request process and no way to say which of the state, GDPR or sector rules actually reach them | Customer DPA or privacy addendum |
| Readiness Services | Secure SDLC & Product Security Readiness | Enterprise customers, federal buyers and now EU product regulation expect proof that the software you ship was built securely: threat models, code review, dependency control, secrets management, signed builds and a way to receive and fix vulnerability reports | Customer security review asks for SDLC evidence |
| Readiness Services | Enterprise Security Readiness & Questionnaire Response | Enterprise deals stall in security review | A large deal is waiting on a security review |
| Readiness Services | Cyber Insurance Readiness | Renewal arrives with a longer application, higher premium, a lower limit and exclusions nobody read | Renewal within 180 days |
| Readiness Services | Software Supply Chain Security & SBOM Readiness | A customer asks for an SBOM, a regulator asks how you would know if a component you ship carried a known exploited vulnerability, and the honest answer is a package manifest and hope | Customer or federal SBOM request |
| Readiness Services | DORA Readiness (Digital Operational Resilience) | DORA has applied to EU financial entities since 17 January 2025, and it reaches the ICT providers that serve them through contract | Supervisor questionnaire or inspection |
| Readiness Services | EU Cybersecurity & NIS2 Readiness | NIS2 widened EU cybersecurity law to eighteen sectors and made management personally accountable, but whether it reaches a specific company depends on entity type, sector, size, jurisdiction and how each Member State transposed it | National authority registration deadline |
| Readiness Services | EU AI Act Readiness | The EU AI Act applies in phases: prohibited practices and AI literacy from 2 February 2025, general-purpose AI obligations from 2 August 2025, most high-risk system obligations from 2 August 2026, with some categories later, and a Commission proposal to adjust the high-risk timeline under review | Customer asks for AI Act role and risk classification |
| Readiness Services | Trust Center Readiness | A trust page that lists an expired certificate, a claim nobody can evidence or a policy that legal never approved is worse than no trust page | Buyer asks for a trust page or portal |
| Readiness Services | Fraud, Identity & Account Takeover Readiness | Account takeover shows up as support tickets, chargebacks and churn before anyone calls it an incident; identity, session, recovery and payout controls are one problem | Spike in account takeover, chargebacks or partner pressure |
| Readiness Services | EU Cyber Resilience Act Readiness | Products with digital elements sold in the EU carry secure-by-design, vulnerability handling, SBOM, documentation and 24-hour reporting obligations phasing in from September 2026 | EU product sales, distributor or customer asks for a CRA position |
| Readiness Services | Operational Resilience Program | Five plans owned by four teams; the umbrella that sets tolerances per important business service and tests whether the plans hold together | Regulator expectation, major outage or a board asking "would we keep running?" |
| Readiness Services | AI Agent Security Readiness | Agents hold credentials, call tools and read content an attacker can write; identity, least-privilege tools, injection defence, approval gates and audit for agents | Agent with write access, agent reading external content, or an agent-caused incident |
| Readiness Services | Service Catalog | Every service grouped by category, with its problem, buyers, free check and status | Find the right door for the problem in front of you |
| Supply Chain & Frameworks Readiness | Supply Chain & Third-Party Risk | Vendor and supplier risk program | Customers or regulators are asking about third parties |
| Supply Chain & Frameworks Readiness | NIST & CMMC Compliance Readiness | NIST 800-171 and CMMC preparation | Defence contractors and their suppliers |
| Fractional & Interim Leadership | Fractional CISO | Part-time, ongoing CISO leadership | You need a CISO but not a full-time hire |
| Fractional & Interim Leadership | Interim CISO | Full-time CISO cover for a fixed period | A CISO left, or a transformation needs temporary leadership |
1.5 Frameworks menu
Every item here is a free, scored self-assessment or a public tracker. Results can flow into the CRM as a lead assessment.
| Group | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| (top) | One Control Library. Multiple Frameworks. | Explains the single control library behind every framework | Understand why one piece of evidence can satisfy several frameworks |
| Security | Ransomware Readiness Assessment | Scores readiness against the NIST IR 8374 ransomware profile | Leadership asks "would we survive ransomware?" |
| Security | Cyber Risk Assessment | Executive-level cyber risk score | A quick, board-friendly starting point |
| Business Resilience | Business Continuity Readiness Assessment | ISO 22301 aligned BCP readiness | Continuity planning is untested or missing |
| Business Resilience | Disaster Recovery Readiness Assessment | ISO/IEC 27031 aligned DR readiness | Recovery objectives and runbooks need checking |
| NIST | NIST & CMMC Readiness | Service page for 800-171 and CMMC | Defence supply chain obligations |
| NIST | NIST CSF 2.0 Tracker | Track current and target CSF 2.0 profile by function | Building or maturing a CSF-based program |
| ISO | ISO 27001 Readiness Assessment | Scores readiness for certification | Deciding whether to pursue ISO 27001 |
| ISO | ISO 27001 Tracker | Tracks Annex A control status | Working toward certification |
| ISO | ISO 42001 AI Governance Tracker | Tracks AI management system conformance | Building an AI governance program |
| Compliance | SOC 2 Readiness Assessment / SOC 2 Tracker | Score, then track, Trust Services Criteria readiness | SaaS companies asked for a SOC 2 report |
| Compliance | HIPAA Readiness Assessment / HIPAA Tracker | Score, then track, Security Rule readiness | Healthcare and business associates |
| Compliance | PCI DSS Readiness Assessment / PCI Tracker | Score, then track, PCI DSS readiness | Anyone handling card data |
| Compliance | GLBA Safeguards Assessment | Scores Safeguards Rule readiness | Financial institutions under the FTC rule |
| Financial Services | FFIEC Readiness Assessment | Scores against the FFIEC handbooks | Banks preparing for examination |
| Financial Services | NCUA Readiness Assessment | Scores against NCUA Part 748 and ISE expectations | Credit unions |
| Financial Services | Financial Institution Readiness Assessment | Combined institution readiness review | Not sure which regulator applies |
| Financial Services | Crypto & Digital Asset Regulatory Readiness | Which U.S. and EU crypto regulations may apply, and the highest-priority gaps; a readiness indicator, not legal advice | Exchanges, custodians, token issuers, stablecoin issuers, wallet and infrastructure providers |
| Enterprise Readiness & Product Security | Privacy Readiness Check | Which privacy obligations may reach you, and whether the inventory, subject-request process and breach workflow behind your policy actually exist; a readiness indicator mapped to the NIST Privacy Framework 1.0 | Customer DPA or privacy addendum |
| Enterprise Readiness & Product Security | Secure SDLC Quick Check | Fifteen questions across the NIST SSDF practice groups: prepare, protect, produce, respond. The gaps enterprise buyers and regulators test first; a readiness indicator mapped to the NIST SSDF v1.1 | Customer security review asks for SDLC evidence |
| Enterprise Readiness & Product Security | Enterprise Security Readiness Check | Fifteen questions on the controls enterprise procurement rejects vendors over, and whether your questionnaire answers are backed by evidence; a readiness indicator mapped to the SOC 2 Trust Services Criteria | A large deal is waiting on a security review |
| Enterprise Readiness & Product Security | AI Security Quick Check | Fourteen questions on the trust boundaries AI introduces: user to application, application to model, model to data, model to tools, tools to the outside world; a readiness indicator mapped to the OWASP Top 10 for LLM Applications 2025 | AI feature launch |
| Enterprise Readiness & Product Security | Trust Center Readiness Check | Eleven questions on whether your public security claims are evidenced, approved, current and withdrawable, before a buyer checks; a readiness indicator mapped to the SOC 2 Trust Services Criteria | Buyer asks for a trust page or portal |
| Enterprise Readiness & Product Security | Fraud & Account Takeover Readiness Check | Sixteen questions on onboarding, authentication, sessions, recovery through support, bots, fraud decisions and payouts; a readiness indicator mapped to the fraud and identity control set anchored to NIST SP 800-63-4 | Rising account takeover, chargebacks or a credential leak affecting customers |
| Enterprise Readiness & Product Security | Cyber Resilience Act Quick Check | Sixteen questions on secure-by-design, vulnerability handling, SBOM, support period, documentation and the 24-hour reporting clock; a readiness indicator mapped to Regulation (EU) 2024/2847 | Products with digital elements sold in the EU |
| Enterprise Readiness & Product Security | Operational Resilience Quick Check | Twelve questions on important business services, impact tolerances, dependencies, scenario testing and plan integration; a readiness indicator mapped to ISO 22301 with DORA crosswalks | Regulator, customer or board asks for a resilience picture |
| Enterprise Readiness & Product Security | AI Agent Security Quick Check | Fourteen questions on agent inventory, identity, tool permissions, injected instructions, approval gates, audit and kill switch; a readiness indicator mapped to the AI agent security control set | Agents with tool access in production |
| All Frameworks & Assessments | See all 36 free assessments | Catalogue of every assessment, including the nuclear series, AI governance, board, CISO, cyber insurance, and supply chain | Find an assessment not listed in the menu |
1.6 Resources menu
| Group | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| (top) | Guides | Library of plain-English guides (SOC 2 cost, ISO 27001 process, HIPAA checklist, NIST CSF, NRC rules, and more) | Research before a conversation |
| (top) | NIST IR 8374 Rev. 1 Ransomware Profile | Guide to the ransomware profile behind the assessment | Interpret a ransomware assessment result |
| (top) | Business Continuity Planning Guide | How to build and test a BCP | Starting continuity work |
| (top) | Disaster Recovery Guide | How to set recovery objectives and runbooks | Starting DR work |
| (top) | Free Executive Assessments | Same catalogue as "See all 36 free assessments" | Pick an assessment by topic |
| (top) | Platform Tutorials | Short narrated videos recorded from the live product | Learn a portal page before signing in, or share with a new user |
| (top) | User Reference Manual | This manual | Look up what a menu does and when to use it |
| (top) | Policies & Templates | Policy resources aligned to the supported frameworks | Need a starting document |
| (top) | Pricing | Essentials, Growth, and custom Interim or Enterprise tiers | Budgeting a fractional CISO engagement |
| Academy | CISO Academy | Executive and CISO leadership courses | New or aspiring security leaders |
| Academy | SMB Security Training | Security basics for small business owners | Small teams without security staff |
| Academy | Security Awareness | Employee awareness topics such as phishing and passwords | Staff training |
| Academy | AI Security & Governance | AI risk, policy, and shadow AI | Teams adopting AI tools |
| Academy | Vulnerability Management | Scanning, prioritisation, and remediation | IT teams running a vulnerability program |
| Academy | Compliance Training | SOC 2, ISO 27001, HIPAA, PCI, NIST, and CMMC courses | Preparing staff for an audit |
| Academy | Supply Chain Security | Vendor and supplier risk courses | Procurement and vendor managers |
| Academy | Browse the full Academy | Every course across all seven categories | Find a course not listed |
1.7 About menu
| Menu | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| About | About My CISO Partner | Founder background and firm story | Check credentials before engaging |
| About | Contact Us | Contact form for a no-obligation conversation | You have a question rather than a booking |
| About | Book a Consultation | Pick a 30-minute discovery call slot | You are ready to talk |
1.8 Footer and utility pages
| Footer group | Links | When/why you would use it |
|---|---|---|
| Platform | AI CISO, Continuous Exposure Monitoring, Frameworks, Free Assessments, Pricing, Client login | Quick access to the product pages and the portal |
| Services | Fractional CISO, Interim CISO, Cyber Risk Advisory, Board Advisory, Compliance Leadership, AI Governance, Nuclear Readiness, Financial Institution Readiness, Supply Chain Risk Management | Jump straight to a service page |
| Company | About, Guides, Contact, Trust & Security, Privacy Policy, Terms of Service | Due diligence and legal terms |
Pages reached from within other pages rather than a menu:
| Page | What it does | When/why you would use it |
|---|---|---|
| Individual assessment pages | Scored questionnaire with a results summary and recommended priorities | Complete one; results can be sent to you and appear in the CRM as a lead assessment |
| Trackers | Save control status in your browser and export it | Track progress between conversations |
| Nuclear readiness intake | Starts a nuclear readiness assessment with the firm | Nuclear licensee wants a guided review |
| Products (Monitoring & Assurance) | Subscription options for exposure monitoring and compliance-as-a-service | Buying monitoring rather than advisory hours |
| Tutorial viewer | Plays one tutorial with transcript and related tutorials | Opened from the tutorials library or a "Watch tutorial" link in the portal |
| Trust & Security | How the firm protects client data | Security review of the vendor |
| Success | Confirms a completed subscription | Shown after checkout |
| 404 | Not-found page with links back to the main sections | A broken or old link |
Section 2 · Client Portal / Security Platform
The Client Portal is the client's private view of their engagement: posture, risks, actions, decisions, compliance, reports, meetings, documents, and their CISO's guidance. It is read-mostly by design. Clients respond to decisions, add context, upload requested evidence, and ask questions; the consultant does the rest in the CRM.
2.1 Signing in
| Step | What happens | Notes |
|---|---|---|
| Open the Client Portal link on the website | The sign-in page asks for your work email | Only invited emails can sign in |
| Email me a sign-in code | A six-digit code arrives by email | No password exists to lose or reuse |
| Sign in | Enter the code and you land on your role's home page | Some pages, such as Academy, additionally require an authenticator app |
| First visit | A welcome banner explains the portal in three steps with links to the Platform Map, Academy, and Glossary | Dismiss it once; it stays hidden |
2.2 Header controls
| Control | What it does | When/why you would use it |
|---|---|---|
| Search box | Searches your risks, actions, decisions, policies, evidence, meetings, reports, and documents | You remember a name but not where it lives |
| ? (Help) | Opens How MyCISO Partner Works, Glossary, Academy, and this manual | Learn a term or the overall lifecycle |
| Bell | Opens your notifications and email preferences | See what changed since your last visit |
| Refresh | Reloads the current page's data | After your consultant tells you something was updated |
| Sign out | Ends the session | Shared or public computer |
| Watch tutorial | Appears on pages that have a recorded tutorial | First time on a page, or training a colleague |
2.3 Roles and what each one sees
Your consultant assigns a role when inviting you. The role decides your home page, your menu, and whether you can respond to decisions.
| Role | Home page | Menu | Can decide | Can contribute | Sees board material |
|---|---|---|---|---|---|
| Executive | Executive dashboard | Executive, Risk, Actions, Decisions, Compliance, Reports, Meetings, Documents, Ask Your CISO | Yes | Yes | Yes |
| Security leader | Security leader dashboard | Dashboard plus the standard menu | Yes | Yes | Yes |
| IT | Remediation dashboard | Dashboard plus the standard menu | No | Yes | No |
| Compliance | Compliance dashboard | Dashboard plus the standard menu | No | Yes | No |
| Board observer | Board dashboard | Board, Decisions, Reports, Meetings, Documents, Ask Your CISO | Yes | No | Yes |
| Contributor | Executive overview | Standard menu | No | Yes | No |
| Read only | Executive overview | Standard menu | No | No | No |
"Can decide" means you can approve, defer, or reject an open decision. "Can contribute" means you can add context to actions and upload requested evidence.
2.4 Main menu
| Menu | Sub-menu / tab | What it does | When/why you would use it |
|---|---|---|---|
| Overview | — | Where the organisation stands, what your CISO recommends, top priorities, decisions required, recent changes, upcoming items, and latest reports | Your weekly two-minute check |
| Executive (executive role) | — | The overview reframed for a leader: needs your direction, what your CISO ranks first, twelve-month trend, board and reporting | Before a leadership meeting |
| Dashboard (security leader) | — | Risk, findings, evidence, remediation, governance, what changed, and what is getting worse | Running the program day to day |
| Dashboard (IT) | — | Overdue material remediation, due dates, findings, evidence requests, affected assets and services | Planning the team's remediation work |
| Dashboard (compliance) | — | Framework readiness, control state, evidence coverage, findings, remediation, decisions required | Preparing for an audit or examiner |
| Board | — | Posture, agenda, priorities, oversight, accepted risk, strategic items, and trend, readable in under two minutes | Board and committee meetings |
| Risk | Risk register | Every open risk with score, owner, status, and treatment | Ask "what could hurt us most right now?" |
| Risk | Risk detail | One risk with its findings, actions, decisions, acceptance history, and trace | Understand why a risk is scored the way it is |
| Actions | Open / Verified / All tabs | The remediation plan: each action, its due date, owner, and verification status | Track whether fixes are done and proven |
| Actions | Action detail | One action with linked risk, evidence, and comments; contributors can add context | Give your consultant an update |
| Decisions | Open / Decided tabs | Decisions your CISO needs from you, and the record of past decisions | Something is blocked waiting on you |
| Decisions | Decision detail | Options, recommendation, rationale, and the response form for deciders | Approve, defer, or reject with a reason |
| Compliance | Frameworks | Readiness per adopted framework | See where certification or examination readiness stands |
| Compliance | Controls | Control implementation state | Answer "do we have this control?" |
| Compliance | Policies | Policy register with version and review dates; policy detail opens the document | Find the current approved policy |
| Compliance | Evidence | Evidence requested and supplied; contributors can upload | Respond to an evidence request |
| Reports | Reports | Every report shared with you, downloadable | Pull last quarter's report |
| Reports | Board | Board packs and board-visible items (board-eligible roles only) | Prepare the board pack |
| Reports | Assessments | Assessments run for you, with detail pages | Review a readiness assessment result |
| Meetings | — | Upcoming meetings and past notes with linked risks, decisions, and actions | Prepare for, or recall, a meeting with your CISO |
| Documents | — | Every document shared with or submitted by you, via short-lived download links | Fetch a deliverable |
| Ask Your CISO | — | Ask a question answered only from your engagement's data, with a certainty label on every statement | Get a grounded answer without waiting for a meeting |
2.5 More menu
| Menu | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| More | Engagement | Your service, cadence, objectives, deliverables, and onboarding milestones | Check what is included and what is coming |
| More | Academy | Role-based learning paths, courses, lessons, and badges | Learn the platform or a security topic; requires authenticator sign-in |
| More | Profile & notifications | Your account details, email preferences, and recent notifications | Change how often you are emailed |
| More | Security & trust | How the portal protects your account and data | Answer your own security team's questions |
| More | Regulatory readiness | Your regulatory readiness assessments (nuclear, crypto and digital assets, or another regime), if part of your engagement; the page is titled after your framework | Clients preparing for a regulator |
| More | NIST CSF 2.0 profile | Your current and target profile by function and outcome, using NIST's own labels | Discuss target state with your CISO |
| More | Exposure | Continuous Exposure Monitoring: monitored assets, scan history, findings by severity, scan reports, and compliance-as-a-service status | Subscribers to monitoring or assurance |
2.6 Guidance pages
| Page | Reached from | What it does |
|---|---|---|
| How MyCISO Partner Works | Help menu, welcome banner | The nine-stage lifecycle from control library to AI CISO, with where each stage lives |
| Glossary | Help menu, welcome banner | Plain-English definitions and how each term is used in your engagement |
| Trace | Links on risks and figures | Shows the source records and reasoning behind a number or recommendation |
| Search results | Header search box | Matches across every record type you can see |
Section 3 · CRM / Prospecting Platform
The CRM, titled Consultant Command Center inside the app, is the staff-only workspace where the firm runs every client engagement and its own sales pipeline. Everything a client sees in the portal is created or approved here. It is organised as ten menus across the top; each opens a dropdown grouped by sub-heading.
3.1 Signing in and staff roles
| Step | What happens | Notes |
|---|---|---|
| Consultant sign in | Enter your staff email and the emailed code | Authorised staff only |
| First sign-in | Set up an authenticator app (Google Authenticator, 1Password, Authy, or similar) | Required for admins and consultants |
| Later sign-ins | Enter the authenticator code after the email code | Sessions expire after eight hours; all access is logged |
| Role | What it can do | When it is used |
|---|---|---|
| Admin | Everything, plus consultant management, AI model registry, pricing reference, and Academy analytics | Firm leadership |
| Consultant | Full read and write on the clients assigned to them, and the sales pipeline | Delivery staff |
| Viewer | Read-only across the CRM; every write is refused; signs in with the email code alone | Auditors, partners, or observers who need visibility without change rights |
3.2 Header controls
| Control | What it does | When/why you would use it |
|---|---|---|
| Search (Ctrl+K) | Searches clients, risks, actions, decisions, policies, meetings, and reports | Jump to any record by name |
| Name and role badge | Shows who is signed in and as what | Confirm you are in the right account |
| Help | How MyCISO Partner Works, Glossary, Academy, and this manual | Same guidance set as the portal, from the consultant side |
| Menu | On narrow screens, opens the ten menus as an accordion | Working from a tablet or phone |
| Sign out | Ends the session | Leaving a shared machine |
| Breadcrumb | Shows the path from menu to record | Step back one level |
3.3 Command Center menu
| Sub-heading | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| Overview | Dashboard | Personal greeting, average readiness, highest open risk band, and today's items across your clients | Start of day |
| Overview | CISO Command Center | Portfolio home base: attention items, posture, what is new, and the client list | Decide which client needs you first |
| Overview | Executive Dashboard | Firm-wide sales pipeline value, conversion, and funnel health | Weekly pipeline review |
| Overview | My Day | Your own due and overdue items across delivery and sales | Plan the day |
| Overview | Clients | Client list with health, attention items, risk counts, and overdue actions; opens the client record | Enter a client's world |
| Workflow | CISO Work Queue | Every task, POA&M action, and open attention item you can see, as one worklist | Work the queue between meetings |
| Workflow | CISO Tasks | Discrete delivery tasks filtered by client, type, priority, and status | Assign and close routine work |
| Workflow | Security Projects | Multi-step initiatives with status, health, progress, and target date | Track a migration or program build |
| Workflow | Activity | Chronological log of everything recorded across the portfolio | Reconstruct what happened and when |
| Workflow | Meetings | Upcoming and past client meetings, preparation needed, and follow-ups | Prepare agendas and capture notes |
3.4 AI CISO menu
| Menu | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| AI CISO | AI CISO Advisor (direct link) | Review queue of every AI-drafted interaction: what needs review, volume by mode, recent activity | Approve or correct AI drafts before clients see them |
AI-assisted tools also appear inside each client record. They draft answers, priorities, and analysis from the client's real records and never act on their own.
3.5 Risk menu
| Sub-menu | What it does | When/why you would use it |
|---|---|---|
| Cyber Risk | Risk register rolled up one row per client | Compare clients at a glance |
| Risk Register | Every risk with score, owner, treatment, and acceptance; opens risk detail | Add, score, or re-score a risk |
| Framework Risk | Risks and controls rolled up per framework requirement | Show an auditor where risk concentrates |
| Asset Risk | Critical assets with mapped risk, findings, and control coverage | Asset-centred conversations with IT |
| Vendor Risk | Third parties with mapped risk, findings, and supplier assessment evidence | Vendor review meetings |
| Business Services | Named business services an engagement protects | Tie risks to what the business actually runs |
| Risk Acceptance Debt | Every accepted risk with its review-cycle status | Make sure accepted risks are re-reviewed on time |
| Risk Reduction | How far compensating controls have reduced each open risk, and the direction of travel | Evidence that treatment is working |
3.6 Compliance menu
| Sub-heading | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| Frameworks | Frameworks | Each client's scored assessment per framework; opens assessment and finding detail | Run or review a readiness assessment |
| Regulatory Readiness | Financial Institution | Institution type, regulator, and regulatory readiness signals per client | Bank and credit union clients |
| Regulatory Readiness | Crypto & Digital Assets | Six-gate profile, regulatory scope map (what may apply and why), current requirements separated from future changes, Legal Review Queue, findings, licences, calendar, cross-regulatory coverage and exports | Digital-asset clients under U.S. and EU regimes |
| Regulatory Readiness | Cross-Framework Mapping | Where a requirement in one framework already covers another | Avoid assessing the same control twice |
| Regulatory Readiness | Examiner Readiness | Log of AI-run examiner simulations across assessments | Rehearse before a real examination |
| Regulatory Readiness | Regulatory Changes | Rule changes classified by impact on each client's frameworks | Monthly regulatory update |
| Regulatory Readiness | NCUA · Cyber Incident | NCUA incident requirements awaiting a customer-information determination | An incident may be reportable |
| Regulatory Readiness | SOC 2 Readiness | SOC 2-mapped controls, gaps, tests, and reviews by Trust Services Criteria | SaaS clients heading for a SOC 2 report |
| Regulatory Readiness | Regulatory Intelligence | Versioned register of every law, regulation, standard and framework with dates, requirement counts and clients in scope; per-client "why does this apply?" with the rule, inputs, missing inputs and evidence; admins supersede versions without deleting the old one | A client asks why they are in scope, or a regulation changes |
| Enterprise Readiness | Security Questionnaires | Import a customer questionnaire or load one of the platform's own question banks (enterprise or cloud service baseline, whole or by section), auto-match questions to approved answers and adopted controls with current evidence, confirm final answers with an owner, grow the approved-answer library | An enterprise buyer sends a security review, or the client wants to rehearse one |
| Enterprise Readiness | Trust Center | Approved security statements tied to controls, evidence or certificates, moved draft → review → approved → published with guardrails against expired or unsupported claims; the *Public trust page* panel sets the client's public address (`/trust/<name>`) and switches the page on or off | The client wants a trust page it can defend |
| Product Security | Software Supply Chain | Software products, components from a CycloneDX or SPDX SBOM, recorded vulnerabilities and licences, alerts for known-exploited items and stale SBOMs | A customer or the EU Cyber Resilience Act asks what is in the software |
Quick filters inside Frameworks open the NCUA (Part 748, ISE, ACET), FFIEC domain, and GLBA views without leaving the page.
3.7 Operations menu
| Sub-menu | What it does | When/why you would use it |
|---|---|---|
| Controls | Control implementation status across every client | Answer "who has this control in place?" |
| Evidence | Evidence items supporting controls, with requests to clients | Chase or accept evidence |
| Findings | Recorded gaps and deficiencies from assessments and reviews | Convert findings into risks and actions |
| Remediation | POA&M queue, validation, and security debt tabs | Verify fixes and manage what is overdue |
| Incidents | Every recorded incident with severity, status, and regulatory triage state | Incident response and reporting |
| Policies | Policy register with version, status, owner, and review date | Policy review cycle |
| Third-Party Risk | Vendor register; add a vendor and record an assessment | Onboard or re-assess a supplier |
3.8 Intelligence menu
| Sub-menu | What it does | When/why you would use it |
|---|---|---|
| AI Security Command Center | The Command Center focused on AI security posture | Clients deploying AI systems |
| Evidence Intelligence | Evidence gaps, contradictions, quality, and freshness, one row per client | Spot weak evidence before an auditor does |
| Decision Register | Formal log of governance decisions: what, when, by whom, and why | Show a board or regulator the decision trail |
| Governance Workflows | Auditable review-and-approval workflows: risk reviews, exceptions, policy approvals, risk acceptances | Route something for formal approval |
3.9 Reports, Administration, and Academy menus
| Menu | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| Reports | Board Reporting (direct link) | Every client's board-relevant items as one agenda; publishes board packs to the portal | Quarterly board season |
| Administration | Capacity | Trailing seven-day hours, weekly capacity, and utilisation for you, or everyone if admin | Balance workload |
| Administration | Settings | Your account and session details; admin panels for consultants, AI model registry, and pricing reference | Add a consultant or check a model |
| Academy | Home | Learning paths, courses, and lessons for staff | Onboard a new consultant |
| Academy | Admin Dashboard | Adoption, learning, and content analytics (admin only) | Measure training uptake |
3.10 Growth menu (prospecting and sales)
| Sub-heading | Sub-menu | What it does | When/why you would use it |
|---|---|---|---|
| Pipeline | Leads | Inbound and outbound leads with source, trigger event, and status | Qualify new interest |
| Pipeline | Opportunities | Active deals with stage, value, score, owner, and next action | Forecast and move deals |
| Pipeline | Proposals | Issued proposals and versions with tier, price, status, and validation gaps | Send or revise a proposal |
| Pipeline | Lead Assessments | Website self-assessments completed by prospects, with score and priorities | Follow up with context the prospect gave you |
| Pipeline | Activities | Calls, emails, and meetings with notes | Log a touchpoint |
| Pipeline | Follow-ups | Scheduled and sent follow-ups plus nurture tracks | Keep warm leads moving |
| Pipeline | Booking | Upcoming discovery calls and your public booking availability | Manage the calendar behind Book a Call |
| Conversion | Financial Institution Readiness | Prospects who completed the financial institution assessment, and their conversion | Regulated-industry campaign results |
| Conversion | Service Catalog | Every service with its problem, buyers, tiers, discovery questions and objections; pick a lead for one primary and up to five secondary recommendations with rationale and unknowns | Preparing for a discovery call |
| Marketing | Prospecting | Outbound funnel by research and score tier | Where the outbound effort stands |
| Marketing | Prospects | Researched prospect list with score, status, and campaign; opens prospect detail | Pick the next accounts to work |
| Marketing | Signals | Buying signals across prospects, newest first, with decayed strength | Time outreach to a trigger |
| Marketing | Buyers | Buyer contacts by persona, role, relationship stage, and Sales Navigator status | Multi-thread an account |
| Marketing | Saved Searches | Catalogue of Sales Navigator searches by vertical, as plain links | Reuse a proven search |
| Marketing | ICP Profiles | Ideal customer profile definitions that drive prospect scoring | Refine who you target |
| Marketing | Outbound | Whether automated sending is on, daily cap, today's volume, blocks, and suppressions | Control the sending engine |
| Marketing | Campaigns | Outbound campaign performance and inbound content campaign outcomes | Compare what is working |
| Marketing | Partners | Referral partners with leads referred, deals closed, and commission | Partner reviews |
| Marketing | Market Engine | Marketing-to-pipeline funnel: sessions, assessments, forms, bookings, attribution | Monthly marketing review |
| Marketing | Analytics | Website traffic and consented event analytics | Which pages and sources perform |
| Marketing | Metrics | Firm-wide funnel, assessment conversion, financial, and delivery metrics | Board-level view of the firm |
3.11 The client record
Opening a client from Clients, search, or any dashboard shows one record with tabs. This is where most delivery work happens.
| Tab | What it does | When/why you would use it |
|---|---|---|
| Overview | Health, attention items, and engagement summary | First stop for any client question |
| Risk | The client's risks and acceptance history | Risk review meeting |
| Compliance / Assessments / Evidence / Policies | The client's frameworks, assessments, evidence, and policies | Audit preparation |
| Actions / Decisions / Meetings | What is being fixed, what needs deciding, and the meeting record | Weekly engagement rhythm |
| Security Projects / Suppliers | Initiatives and third parties for this client | Program and vendor tracking |
| Reports / Board / Executive | What has been shared with each audience | Publish to the portal |
| Client portal | Portal users, roles, and visibility settings | Invite a client user or change their role |
| AI / AI systems / Reasoning & memory | AI-assisted drafting, the client's AI system inventory, and the AI's stored context | Governance of AI on both sides |
| Commercial | Subscription and commercial terms | Renewal conversations |
| Activity | Everything recorded for this client | Hand-over or dispute |
Each shared item carries a visibility label: Internal only, Client, Executives, or Board. That label decides who sees it in the portal.
Pages reached from within a client record rather than a menu:
| Page | What it does | When/why you would use it |
|---|---|---|
| Client 360 | One-page synthesis of the whole engagement | Executive briefing preparation |
| Handoff draft | Draft handover pack when a consultant changes | Transition between consultants |
| Supply Chain Risk | The client's supplier assessment workspace | Third-party program delivery |
| Readiness assessment detail | One regulatory readiness assessment with findings | Nuclear and financial institution work |
| Governance Workflow detail | One approval workflow with its steps and sign-offs | Follow an approval to completion |