Free resources
Cyber artefact templates
25 field-tested starting points for the documents security teams actually ship β incident plans, risk registers, policies, procedures, audit packs, board reports and more. Generated in your browser, nothing uploaded. Download, fill in the bracketed prompts, make them yours.
Start here β free
Incident Response Plan
Roles, severity matrix, NIST 800-61 lifecycle, contact tree, and comms templates β ready to fill in.
Stress-test your finished plan in the Design Review Workbench βRisk Register
Inherent + residual scoring, treatment, owner and review columns. Opens in Excel or Google Sheets.
The Risk Register tool fills this from your threat models automatically βThe full set
Threat Model Worksheet
STRIDE-per-element table with prompts, DFD guidance, and a risk-decision section.
Threat Model Studio drafts this from your architecture β or a URL βArchitecture Review Checklist + ADR
Secure-design checklist plus a MADR-format Architecture Decision Record with a security section.
Architecture Studio generates the ADRs and control map for you βISO 27001 Statement of Applicability
Annex A controls with applicability, justification, status, owner, and evidence columns.
Architecture Studio exports a populated SoA from your design βVendor Security Assessment
Weighted questionnaire across governance, data protection, isolation, and BCP with scoring.
BCP / DR Plan
RTO/RPO tiers, business impact analysis, recovery runbook, and a testing schedule.
Board Security Report
Printable one-pager: exec summary, KPI cards, top risks, program progress, and the ask.
The Board Report coach writes this with you, graded live βData Protection Impact Assessment
GDPR-style DPIA: processing description, data inventory, necessity test, and risk sign-off.
Vulnerability Management SOP
Risk-based prioritisation with KEV/EPSS, remediation SLAs, workflow, and metrics.
Acceptable Use Policy
The rules of the road in plain language β devices, credentials, AI tools, and a no-blame reporting clause.
Access Control Policy
Joinerβmoverβleaver, MFA, PAM, reviews and service accounts β with the metrics that prove it works.
The Org Designer maps who owns this policy in your structure βData Classification Policy
Four classes, a handling matrix, and ownership β the policy every other control hangs off.
Password & Authentication Policy
NIST-aligned: long passphrases, no forced rotation, phishing-resistant MFA, secrets in a manager.
Remote Work Security Policy
Assume hostile networks everywhere; managed devices, location rules, and the household-reality clause.
Incident Communications Policy
Who speaks, to whom, by when β regulator clocks, pre-approved skeletons, and a single voice rule.
Access Provisioning & Deprovisioning SOP
Joinerβmoverβleaver as numbered steps with SLAs, the orphan-account check, and leaver verification.
Patch Management SOP
Ring-based rollout, a 72-hour emergency path for KEV/exploited vulns, and scan-verified closure.
Backup & Restore Runbook
Tiered RPO/RTO, ransomware-assuming immutability rules, and a timed restore procedure with game-days.
Secure SDLC Gate Checklist
Four gates from design to post-release β owned by delivery, sampled by security, visible debt over silent debt.
The Design Review Workbench runs Gate 1 for you βSecurity Exception Process
One-page requests, a risk-tiered approval ladder, hard expiries, and the five-exceptions-means-broken-control rule.
Internal Audit Plan
Risk-based scope, phased schedule, honest ratings scale, and an escalation rule that protects independence.
Evidence Request (PBC) List
Ten pre-written evidence requests covering access, patching, backups, logging, IR, vendors and change.
Control Test Workpaper
Population β sample β procedure β exceptions β conclusion, with preparer/reviewer sign-off.
Management Response Tracker
Findings to closure: root cause, owner, due date, evidence of closure, and independent validation columns.
Want these filled in for you β grounded in real control catalogs and your own architecture?