Stop building from scratch.
Start from done.
Build guides, workbooks and reference architectures for CISOs, security engineers and compliance teams — including the six-pillar security programme, published so you can build it yourself.
The AI Security Department, DIY
Six pillars. Build them yourself — or have them run for you.
These are the same pillars CISO Marketplace runs as a managed programme, published as build guides with the real architecture in them. Each stands alone; together they are one programme, where every stream feeds a register a human owns.
Compliance
Map controls once, satisfy every framework — driven from your registry, not a platform’s integrations.
Get Pillar 01 →DevSecOps
Discovery, scanning and AI triage across 100+ apps, in one self-healing risk register.
Get Pillar 02 →PTaaS
An authorized, sandboxed lane that proves the bug and drafts the patch, under a human gate.
Get Pillar 03 →AI-SOC
A reducer over your existing stack: read every alert, resolve the routine, escalate the few.
Get Pillar 04 →Incident Response
An operating system for the worst day — one room, one clock, and 90% of the choices already made.
Get Pillar 05 →Fractional CISO
The capstone hub — every stream above feeds one register a human owns, conducted out to the board.
Get Pillar 06 →The Operator Seat — the command layer over all six
Six capabilities are only a department if one seat conducts them — intake, the gates, one register, and observability over every AI channel.
Take the whole programme
All 6 pillars, plus their companions, in one purchase at 20% off — with every future edition included.
Featured
Browse and search all 115 →The Operator's Manual — C2 Command Layer
The capstone above all six pillars: one seat that conducts the whole department. Intake from four employee doorways, visible approval gates, one living risk register, and observability into every AI channel — with the agent layer and MCP wiring that runs it.
Pillar 05 — The Incident Response Operating System
An operating system for the worst day — the right people in one room, on one clock, with 90% of the hardest choices already made. Built on NIST 800-61 Rev. 3, with the offline runbook, the notification clocks and a ready-to-run tabletop.
Pillar 04 — The AI-SOC Operating System
Read every alert, resolve the routine, escalate only what needs a human. A reducer that overlays your existing SIEM, EDR, identity and cloud — human-gated, auditable, and capped at an autonomy level you can defend.
Pillar 01 — The Compliance Operating System
Map controls once, satisfy every framework. A continuous, registry-driven compliance program across SOC 2, ISO 27001, HIPAA, PCI, CMMC, DORA and NIS2 — plus the ISO 42001 and EU AI Act layer most guides still omit.
Compliance Program Starter
The Pillar 01 operating system plus the two workbooks most first programs actually need — SOC 2 Readiness and the NIST CSF 2.0 Self-Assessment — with both PDF readiness checklists included. 30% off buying separately.
Pillar 06 — The Fractional CISO Operating System
The capstone hub: a human-owned register that aggregates every security stream into board-legible, quantified risk. The 2026 pricing ladder, the first 90 days, the five-page board deck, and the layer the AI vCISO platforms structurally cannot replace.
Browse by Category
Part of the CISO Marketplace
How it works
One CISO Marketplace account works across every site — sign in once, pay your way, and your purchases follow you in the member portal.
Sign in once
One CISO Marketplace login (email magic-link, password, or SSO) across ciso.diy and the whole ecosystem.
Pay your way
Checkout by card, or with your membership credits ($1 = 1 credit) — allowance + top-up.
Instant delivery
Download links are emailed immediately and saved to your account — no waiting, no re-purchasing.
Your central library
Every purchase shows in your member portal — Finance, licenses & saved reports.
Part of the CyberAdX ecosystem
More tools for security teams
Explore our other properties built to accelerate security work.