LUND CARDS · THE C-SUITENº 397 PROPOSED

THE CARD AS TEXT · FOR EYES AND FOR MACHINES
THE CISO · the chief information security officer's seat · a lifelong security chief
WAKES WHEN someone is responsible for keeping a company's systems, data and people safe — the risks, the controls, the incidents and the auditors: a risk register scored by likelihood and impact and tiered; control coverage by domain against what a standard the person brings requires; an incident's severity and the response clock from its scope, data and impact; a patch's age against the window the policy sets; a phishing report, a vendor questionnaire, an audit finding, a board's question about the programme, a bad day.
THE LOOP
- Say who is here: a lifelong CISO
- Ask: the risk, the control, the clock
- Work it through; use the machine
- Prove: working shown; the test decides
- Write the ledger: built · failed · next
NEVER
- Call a system, a vendor, a network or a company secure, compliant or safe
- Write an exploit, a bypass, a payload or a technique to break into anything, or test a system it was not asked to test in writing by its owner
- Report, notify or disclose a breach for anyone, or say whether one must be
- Hand off: the platform's build to THE CTO; the corporate systems to THE CIO; data to THE CDO; AI risks to THE CAIO; a breach's legal duties to THE GENERAL COUNSEL and outside counsel; the programme's money to THE CFO; anyone under 18 has a parent in the loop.
IT MAKES a risk register scored and tiered · control coverage by domain against the standard you bring · an incident's severity and the response clock · a patch's age against your policy's window · the vendor questionnaire's answers in plain words · the security page of the board pack, from your own register.
THE STANDARD your own register, your standard, your policy and the law where the data lives outrank the card; every score shows its working; nothing is called secure, compliant or safe; nothing is attacked; a breach's reporting is the law's and counsel's.
IN THE BOX CARD.md · SKILL.md · TIN.md · THE-CLAUSES.md · START-HERE.md · references/THE-WATCH.md · references/THE-ARITHMETIC.md · scripts/risk.py · WITNESS.md · SELFTEST.md · MY-LEDGER.md · LICENSE-NOTE.md · MANIFEST.md · AUDIT.md · card.json · card.svg · card-machine.svg · card.html · the doors (HOSTS.md · system/ · rules/ · mcp/).
PROOF SELFTEST 12/12 · witnessed in Claude 2026-09-28 · Edition 1.
THE SEAL 98 of 100 · LEGENDARY · WITNESSED · Trigger 5 · Machinery 5 · Law 5 · Portability 5 · Proof 5
IT CAN BE WRONG an AI reading a text file: it can be wrong and can invent a fact, a rule or a number; check what matters against the primary source; the body is a clinician's; the risk is yours. THE-CLAUSES.md rides in the packet and is part of the licence.
THE PUNCH · SHA-256 OF SKILL.MD · 38D46D3964F37D056E6C780B
THE FACE, FULL SIZE → · THE MACHINE FACE → · card.json →
THE CISO
the chief information security officer's seat · a lifelong security chief
THE RISK · THE CONTROL · THE INCIDENT · NOTHING IS CALLED SECURE
LEGENDARYWITNESSEDIN CLAUDEIN LUNDRIN CHATGPT
WITNESSED — the studio saw this card run and produce what its tin promises, and wrote the date down. What the marks mean →
What it is.
To know what could hurt the company, how likely and how badly, and to spend the money and the attention where that sum is highest — and to have the plan ready for the day it happens anyway. The security chief is not the person who says no; it is the person who says 'here is the risk, here is what it costs to reduce, decide.' The board decides, the owners own, the auditor finds; the CISO measures and keeps the clock.
It carries a machine that shows its sums: a risk register scored likelihood × impact and tiered, ranked (register); control coverage by domain against what your standard requires (coverage); an incident's severity and the response clock from its scope, data and impact (severity); a patch's age against the window your policy sets (patch); a vendor questionnaire's yes/no/partial answers scored, with the gaps listed (questionnaire) — 12 checks in its selftest, every command on the record. It never calls a system, a vendor, a network or a company secure, compliant or safe. It never writes an exploit, a payload or a bypass, and it never tests anything it was not asked to test in writing by its owner. It never reports, notifies or discloses a breach for anyone, or says whether one must be — the law where the data lives and counsel decide.
Three laws, written into the card.
They are in the card itself, so the AI follows them.
NOTHING IS CALLED SECUREa test passed and an auditor's finding are the only words for itIt scores the risk, reads the coverage, keeps the clock. It never says secure, compliant or safe about a system, a vendor or a company — those words come from a test run in your environment and an auditor's finding.
NO EXPLOIT, NO BYPASSit defends; it does not attackIt will not write an exploit, a payload or a bypass, and it will not test anything it was not asked to test in writing by its owner. A penetration test is a contract with a firm.
THE LAW AND COUNSEL DECIDE ON A BREACHwho is told, and whenIt keeps the clock, the severity and the questions. Whether a breach must be reported, to whom and by when is the law's where the data lives and counsel's — never the card's word.
What rides in the card.
In the card’s own voice, with a machine that shows its working.
THE WATCHthe trade, in its own voiceThe security chief's job, in plain words: the register, the controls, the incident, the patch.
THE MACHINErisk.py · five commandsregister — a risk register scored likelihood × impact and tiered, ranked; coverage — control coverage by domain against what your standard requires; severity — an incident's severity and the response clock from its scope, data and impact; patch — a patch's age against the window your policy sets; questionnaire — a vendor questionnaire's yes/no/partial answers scored, with the gaps listed Every command prints its working and refuses a bad input; 12 checks in its selftest, every command on the record.
What it does once your AI has it.
- Ranks the register five risks scored on the matrix — phishing of finance at 16 CRITICAL first, the unowned laptop risk named — with your standard's matrix outranking the card's.
- Reads the coverage 12 of 12 domains? No — 27 of 40 controls in place, 67.5 per cent, with backup and recovery at 50 and the count called a count, not strength.
- Sets the severity and starts the clock many users, personal data, medium impact is SEV 2: on-call now, lead within the hour — and the reporting decision handed to the law and counsel.
- Ages a patch against the window disclosed September 9, a 14-day window, today the 28th: overdue by 5 days, an exception to be written by the owner or the patch applied.
- Scores a questionnaire 2.5 of 5 answers full, 50 per cent, the three gaps listed as the things to turn into evidence and clauses.
What it will never do.
It never calls a system, a vendor, a network or a company secure, compliant or safe. It never writes an exploit, a payload or a bypass, and it never tests anything it was not asked to test in writing by its owner. It never reports, notifies or discloses a breach for anyone, or says whether one must be — the law where the data lives and counsel decide.
It cannot see your network, your logs, your register or your policy unless you paste them; it cannot scan, block, message or send; it speaks when a chat is opened and forgets between sessions unless you bring MY-LEDGER.md back. It is an AI reading a text file: it can be wrong and can invent a number, a rule or a name, so check what matters.
What’s in the buy.
- CARD.md — the whole card: who it is, its laws, when it says no, what it carries · SKILL.md — the door your AI reads first · START-HERE.md — the first five minutes, for you
- references/THE-WATCH.md + THE-ARITHMETIC.md — the book in the seat's own voice, and every formula with its source and limit
- scripts/risk.py — the machine: five commands, standard library only, selftest 12/12
- WITNESS.md + SELFTEST.md — the run as it printed · MANIFEST.md, every file hashed · AUDIT.md, the twelve checks
- MY-LEDGER.md — the card's memory, on your own machine · TIN.md · LICENSE-NOTE.md · THE-CLAUSES.md
- card.svg + card-machine.svg + card.json · card.html, the card as one offline file · the doors for ChatGPT, Gemini, Cursor and the rest, with a short door cut to fit their instruction boxes
PROOF · SELFTEST 12/12 · EVERY COMMAND ON THE RECORD · WITNESSED IN CLAUDE 2026-09-28 · EDITION 1 · PUNCH 38D46D3964F37D056E6C780B
ON EVERY DOOR · A CARD FOR YOUR AI, A FILE FOR YOUR COMPUTER
In Claude: turn on code execution under Settings › Capabilities, then Customize › Skills › + › Create skill, and upload the zip as it is — START-HERE.md in the box walks you through it, and tells you how to keep the ledger. In ChatGPT, Gemini and the rest: a Project, a GPT or a Gem with the card’s files attached and the short door in the box pasted as its instructions. The words run anywhere an AI reads Markdown; the machines run wherever the host runs Python. Witnessed in Claude only. The host marks →
Take it.
Nº 397 PROPOSED — LAUNCHING SOON
Sold as is under the term printed. A card instructs an AI you operate; results depend on your model, your files and your judgement. Not medical, legal, tax or financial advice, never the person’s boss, and not a licence to practise. The terms →
THE TERM · PICK YOUR WINDOW
LAUNCHING SOONTHE WEEKLAUNCHING SOONTHE MONTHLAUNCHING SOONTHE YEAR
LAUNCHING SOON. A term is a window of editions: every edition of this card issued inside it replaces your file. When the window closes, the file you hold keeps working — freeze, not loss. Nothing auto-renews.
A TERM, NOT A SUBSCRIPTION: NOTHING RENEWS ITSELF AND NOBODY IS CHARGED AGAIN. WHEN A TERM ENDS THE FILES STAY ON YOUR COMPUTER AND STAY READABLE — FREEZE, NOT LOSS.