shield Role playbook · CISO

CISO

CISO and direct reports (head of SOC, head of GRC).

Audience: Security leadershipTime to first value: end of week 2

Why CyViation matters in your role

You already own enterprise IT risk. CyViation adds the airborne and ground-operations layer with the same governance language — risk register, KPIs, approval workflows, audit trail:

wb_sunnyDaily playbook

  1. Glance at the fleet risk score and any unacknowledged critical alerts — 60 seconds, mobile is fine.
    [SkyRay → Executive Dashboard]
  2. Review escalations from SOC and MRO; unblock anything waiting on you.
  3. Approve out-of-cycle patches or risk acceptances — one click + a reason, not a long ticket dance.

event_repeatWeekly playbook

  1. Review fleet-wide risk posture vs. last week — trend matters more than the absolute number.
    [SkyRay → Risk Posture]
  2. Sign off on the weekly threat brief before it reaches flight ops and the board readout.
  3. Review compliance / audit readiness — open findings, control evidence, anything aging.
  4. Sync with COO / Head of Ops on decisions where security and availability trade off.
  5. Sync with the CyViation TAM if anything is off-trend.

checklistFirst 30 days

insights
KPIs worth tracking from day one: time-to-acknowledge for critical alerts · patch SLA compliance (critical 7d / high 30d, adjust to contract) · open risk acceptances & aging · coverage (% tails with current SBOM & scan) · mean time-to-decide for escalations.

grid_viewKey screens

Use caseScreen
Daily glance[SkyRay → Executive Dashboard]
Fleet risk posture, trend, drilldownRegulation & Risk · [SkyRay → Risk Posture]
Strategic campaign / actor view[Overwatch → Campaign View]
User & customer scope management[Admin UI → Customer & User Management]
Approvals queue[SkyRay → Approvals]

priority_highEscalation flow

SituationDirectionHow
Risk score breached your thresholdSOC → CISOAutomatic; already on your dashboard
Patch backlog past SLAMRO → CISOWeekly review, plus immediate ping for critical breaches
Material event with disclosure implicationsCISO → board / regulatorPre-agreed template — don't draft under pressure
Customer-scope policy changeCustomer success → CISOApproval flow in Admin UI, never email-only

menu_bookGlossary

Full list on the Glossary page. Key terms here: risk acceptance, out-of-cycle patch, customer scope, EASA Part-IS, tabletop.