Free resources

Cyber artefact templates

25 field-tested starting points for the documents security teams actually ship — incident plans, risk registers, policies, procedures, audit packs, board reports and more. Generated in your browser, nothing uploaded. Download, fill in the bracketed prompts, make them yours.

Start here — free

OperationsFeatured · Free

Incident Response Plan

Roles, severity matrix, NIST 800-61 lifecycle, contact tree, and comms templates — ready to fill in.

Stress-test your finished plan in the Design Review Workbench
GovernanceFeatured · Free

Risk Register

Inherent + residual scoring, treatment, owner and review columns. Opens in Excel or Google Sheets.

The Risk Register tool fills this from your threat models automatically

The full set

Design

Threat Model Worksheet

STRIDE-per-element table with prompts, DFD guidance, and a risk-decision section.

Threat Model Studio drafts this from your architecture — or a URL
Design

Architecture Review Checklist + ADR

Secure-design checklist plus a MADR-format Architecture Decision Record with a security section.

Architecture Studio generates the ADRs and control map for you
Compliance

ISO 27001 Statement of Applicability

Annex A controls with applicability, justification, status, owner, and evidence columns.

Architecture Studio exports a populated SoA from your design
Third-party

Vendor Security Assessment

Weighted questionnaire across governance, data protection, isolation, and BCP with scoring.

Resilience

BCP / DR Plan

RTO/RPO tiers, business impact analysis, recovery runbook, and a testing schedule.

Governance

Board Security Report

Printable one-pager: exec summary, KPI cards, top risks, program progress, and the ask.

The Board Report coach writes this with you, graded live
Privacy

Data Protection Impact Assessment

GDPR-style DPIA: processing description, data inventory, necessity test, and risk sign-off.

Operations

Vulnerability Management SOP

Risk-based prioritisation with KEV/EPSS, remediation SLAs, workflow, and metrics.

People

Acceptable Use Policy

The rules of the road in plain language — devices, credentials, AI tools, and a no-blame reporting clause.

Identity

Access Control Policy

Joiner–mover–leaver, MFA, PAM, reviews and service accounts — with the metrics that prove it works.

The Org Designer maps who owns this policy in your structure
Data

Data Classification Policy

Four classes, a handling matrix, and ownership — the policy every other control hangs off.

Identity

Password & Authentication Policy

NIST-aligned: long passphrases, no forced rotation, phishing-resistant MFA, secrets in a manager.

People

Remote Work Security Policy

Assume hostile networks everywhere; managed devices, location rules, and the household-reality clause.

Operations

Incident Communications Policy

Who speaks, to whom, by when — regulator clocks, pre-approved skeletons, and a single voice rule.

Identity

Access Provisioning & Deprovisioning SOP

Joiner–mover–leaver as numbered steps with SLAs, the orphan-account check, and leaver verification.

Operations

Patch Management SOP

Ring-based rollout, a 72-hour emergency path for KEV/exploited vulns, and scan-verified closure.

Resilience

Backup & Restore Runbook

Tiered RPO/RTO, ransomware-assuming immutability rules, and a timed restore procedure with game-days.

Engineering

Secure SDLC Gate Checklist

Four gates from design to post-release — owned by delivery, sampled by security, visible debt over silent debt.

The Design Review Workbench runs Gate 1 for you
Governance

Security Exception Process

One-page requests, a risk-tiered approval ladder, hard expiries, and the five-exceptions-means-broken-control rule.

Assurance

Internal Audit Plan

Risk-based scope, phased schedule, honest ratings scale, and an escalation rule that protects independence.

Assurance

Evidence Request (PBC) List

Ten pre-written evidence requests covering access, patching, backups, logging, IR, vendors and change.

Assurance

Control Test Workpaper

Population → sample → procedure → exceptions → conclusion, with preparer/reviewer sign-off.

Assurance

Management Response Tracker

Findings to closure: root cause, owner, due date, evidence of closure, and independent validation columns.

Want these filled in for you — grounded in real control catalogs and your own architecture?

Free Cyber Artefact Templates · PlayCISO