Detalle del Skill
business-strategy
Covers client acquisition, partnerships, positioning, and consultative selling.
Revisar antes de usar
La revisión automática comprueba relevancia, no seguridad ni respaldo. Lee las instrucciones de la fuente antes de usar este Skill.
SKILL.md
Este extracto es una copia guardada durante la revisión. La fuente externa contiene la versión completa y actual.
--- name: business-strategy description: Strategic business growth, market positioning, client acquisition, partnership development, and revenue optimization for cybersecurity consulting services license: Apache-2.0 --- # Business Strategy Skill ## Purpose Guides strategic business development, market positioning, and revenue optimization for cybersecurity consulting services, with emphasis on consultative selling, transparency, and practical security expertise. ## Rules ### Market Positioning (MUST) **MUST:** - Position Hack23 as transparent security experts (not FUD-based vendors) - Emphasize 30+ years of hands-on experience - Highlight public ISMS as unique competitive advantage - Showcase open-source contributions as proof of expertise - Focus on developer-friendly DevSecOps approach **MUST NOT:** - Use fear, uncertainty, doubt (FUD) tactics - Make unsubstantiated security claims - Oversell or over-promise capabilities - Compete on price alone without value differentiation ### Consultative Selling Approach **MUST:** ```markdown 1. Discovery Phase - Understand client's business objectives - Identify security pain points and gaps - Map security needs to business outcomes - Assess current security maturity 2. Solution Design - Align security controls with business goals - Reference ISMS policies for credibility - Provide practical, implementable recommendations - Estimate realistic timelines and costs 3. Value Communication - Quantify risk reduction in business terms - Show ROI of security investments - Reference similar client successes (case studies) - Demonstrate expertise through technical depth 4. Partnership Approach - Position as security partner, not vendor - Offer ongoing support and guidance - Share knowledge through documentation - Build long-term relationships ``` ### Target Markets & Personas **Primary Markets:** - Swedish organizations (GDPR, NIS2, ISO 27001 focus) - Mid-market companies (50-500 employees) - Tech startups needing security foundations - Regulated industries (finance, healthcare, government) **Key Decision Makers:** - **CTO/CIO**: Technical depth, architecture alignment - **CISO**: Compliance frameworks, risk management - **CEO/CFO**: Business outcomes, ROI, efficiency - **Engineering Leaders**: DevSecOps integration, tooling ### Service Portfolio **Core Services:** ```markdown 1. ISMS Implementation - ISO 27001:2022 compliance - Gap analysis and remediation - Policy development and documentation - Internal audit preparation 2. Security Architecture Review - Threat modeling and risk assessment - Defense-in-depth design - Cloud security (AWS focus) - Application security review 3. DevSecOps Integration - CI/CD security automation - Infrastructure as Code security - Container security - Security testing integration 4. Compliance Support - GDPR compliance assessment - NIS2 readiness evaluation - CIS Controls implementation - NIST CSF alignment 5. Security Training - Secure development practices - Security awareness programs - Hands-on technical workshops - Executive security briefings ``` ### Partnership Strategy **Technology Partners:** - **AWS**: Cloud infrastructure expertise - **GitHub**: DevSecOps platform integration - **Security Tool Vendors**: SAST, DAST, SCA tools **Channel Partners:** - Management consulting firms (security add-on services) - IT service providers (security capabilities) - System integrators (security architecture) **Referral Network:** - Legal firms (GDPR compliance clients) - Accounting firms (audit preparation clients) - Business consultants (growth-stage startups) ### Sales Enablement Materials **MUST MAINTAIN:** ```markdown 1. Case Studies - Client industry and size - Initial challenge/pain point - Solution implemented - Measurable outcomes - Client testimonial 2. Service Descriptions - Clear scope and deliverablesLeer la fuente completa en GitHub (abre una página externa)