Skill 详情

business-strategy

Covers client acquisition, partnerships, positioning, and consultative selling.

匹配类型直接匹配已针对 业务拓展 审核
来源hack23/homepage外部来源
报告安装量39仅表示受欢迎程度

使用前先检查

自动化审核只检查相关性,不代表安全审查或推荐。使用前请阅读来源中的说明。

已保存的来源预览

SKILL.md

这段内容是审核时保存的快照。外部来源才是完整且最新的版本。

---
name: business-strategy
description: Strategic business growth, market positioning, client acquisition, partnership development, and revenue optimization for cybersecurity consulting services
license: Apache-2.0
---

# Business Strategy Skill

## Purpose

Guides strategic business development, market positioning, and revenue optimization for cybersecurity consulting services, with emphasis on consultative selling, transparency, and practical security expertise.

## Rules

### Market Positioning (MUST)

**MUST:**
- Position Hack23 as transparent security experts (not FUD-based vendors)
- Emphasize 30+ years of hands-on experience
- Highlight public ISMS as unique competitive advantage
- Showcase open-source contributions as proof of expertise
- Focus on developer-friendly DevSecOps approach

**MUST NOT:**
- Use fear, uncertainty, doubt (FUD) tactics
- Make unsubstantiated security claims
- Oversell or over-promise capabilities
- Compete on price alone without value differentiation

### Consultative Selling Approach

**MUST:**
```markdown
1. Discovery Phase
   - Understand client's business objectives
   - Identify security pain points and gaps
   - Map security needs to business outcomes
   - Assess current security maturity

2. Solution Design
   - Align security controls with business goals
   - Reference ISMS policies for credibility
   - Provide practical, implementable recommendations
   - Estimate realistic timelines and costs

3. Value Communication
   - Quantify risk reduction in business terms
   - Show ROI of security investments
   - Reference similar client successes (case studies)
   - Demonstrate expertise through technical depth

4. Partnership Approach
   - Position as security partner, not vendor
   - Offer ongoing support and guidance
   - Share knowledge through documentation
   - Build long-term relationships
```

### Target Markets & Personas

**Primary Markets:**
- Swedish organizations (GDPR, NIS2, ISO 27001 focus)
- Mid-market companies (50-500 employees)
- Tech startups needing security foundations
- Regulated industries (finance, healthcare, government)

**Key Decision Makers:**
- **CTO/CIO**: Technical depth, architecture alignment
- **CISO**: Compliance frameworks, risk management
- **CEO/CFO**: Business outcomes, ROI, efficiency
- **Engineering Leaders**: DevSecOps integration, tooling

### Service Portfolio

**Core Services:**
```markdown
1. ISMS Implementation
   - ISO 27001:2022 compliance
   - Gap analysis and remediation
   - Policy development and documentation
   - Internal audit preparation

2. Security Architecture Review
   - Threat modeling and risk assessment
   - Defense-in-depth design
   - Cloud security (AWS focus)
   - Application security review

3. DevSecOps Integration
   - CI/CD security automation
   - Infrastructure as Code security
   - Container security
   - Security testing integration

4. Compliance Support
   - GDPR compliance assessment
   - NIS2 readiness evaluation
   - CIS Controls implementation
   - NIST CSF alignment

5. Security Training
   - Secure development practices
   - Security awareness programs
   - Hands-on technical workshops
   - Executive security briefings
```

### Partnership Strategy

**Technology Partners:**
- **AWS**: Cloud infrastructure expertise
- **GitHub**: DevSecOps platform integration
- **Security Tool Vendors**: SAST, DAST, SCA tools

**Channel Partners:**
- Management consulting firms (security add-on services)
- IT service providers (security capabilities)
- System integrators (security architecture)

**Referral Network:**
- Legal firms (GDPR compliance clients)
- Accounting firms (audit preparation clients)
- Business consultants (growth-stage startups)

### Sales Enablement Materials

**MUST MAINTAIN:**
```markdown
1. Case Studies
   - Client industry and size
   - Initial challenge/pain point
   - Solution implemented
   - Measurable outcomes
   - Client testimonial

2. Service Descriptions
   - Clear scope and deliverables
   
在 GitHub 阅读完整来源 (打开外部页面)
相关上下文

相关工作