Free resources
Cyber artefact templates
25 field-tested starting points for the documents security teams actually ship — incident plans, risk registers, policies, procedures, audit packs, board reports and more. Generated in your browser, nothing uploaded. Download, fill in the bracketed prompts, make them yours.
Start here — free
Incident Response Plan
Roles, severity matrix, NIST 800-61 lifecycle, contact tree, and comms templates — ready to fill in.
Stress-test your finished plan in the Design Review Workbench →Risk Register
Inherent + residual scoring, treatment, owner and review columns. Opens in Excel or Google Sheets.
The Risk Register tool fills this from your threat models automatically →The full set
Threat Model Worksheet
STRIDE-per-element table with prompts, DFD guidance, and a risk-decision section.
Threat Model Studio drafts this from your architecture — or a URL →Architecture Review Checklist + ADR
Secure-design checklist plus a MADR-format Architecture Decision Record with a security section.
Architecture Studio generates the ADRs and control map for you →ISO 27001 Statement of Applicability
Annex A controls with applicability, justification, status, owner, and evidence columns.
Architecture Studio exports a populated SoA from your design →Vendor Security Assessment
Weighted questionnaire across governance, data protection, isolation, and BCP with scoring.
BCP / DR Plan
RTO/RPO tiers, business impact analysis, recovery runbook, and a testing schedule.
Board Security Report
Printable one-pager: exec summary, KPI cards, top risks, program progress, and the ask.
The Board Report coach writes this with you, graded live →Data Protection Impact Assessment
GDPR-style DPIA: processing description, data inventory, necessity test, and risk sign-off.
Vulnerability Management SOP
Risk-based prioritisation with KEV/EPSS, remediation SLAs, workflow, and metrics.
Acceptable Use Policy
The rules of the road in plain language — devices, credentials, AI tools, and a no-blame reporting clause.
Access Control Policy
Joiner–mover–leaver, MFA, PAM, reviews and service accounts — with the metrics that prove it works.
The Org Designer maps who owns this policy in your structure →Data Classification Policy
Four classes, a handling matrix, and ownership — the policy every other control hangs off.
Password & Authentication Policy
NIST-aligned: long passphrases, no forced rotation, phishing-resistant MFA, secrets in a manager.
Remote Work Security Policy
Assume hostile networks everywhere; managed devices, location rules, and the household-reality clause.
Incident Communications Policy
Who speaks, to whom, by when — regulator clocks, pre-approved skeletons, and a single voice rule.
Access Provisioning & Deprovisioning SOP
Joiner–mover–leaver as numbered steps with SLAs, the orphan-account check, and leaver verification.
Patch Management SOP
Ring-based rollout, a 72-hour emergency path for KEV/exploited vulns, and scan-verified closure.
Backup & Restore Runbook
Tiered RPO/RTO, ransomware-assuming immutability rules, and a timed restore procedure with game-days.
Secure SDLC Gate Checklist
Four gates from design to post-release — owned by delivery, sampled by security, visible debt over silent debt.
The Design Review Workbench runs Gate 1 for you →Security Exception Process
One-page requests, a risk-tiered approval ladder, hard expiries, and the five-exceptions-means-broken-control rule.
Internal Audit Plan
Risk-based scope, phased schedule, honest ratings scale, and an escalation rule that protects independence.
Evidence Request (PBC) List
Ten pre-written evidence requests covering access, patching, backups, logging, IR, vendors and change.
Control Test Workpaper
Population → sample → procedure → exceptions → conclusion, with preparer/reviewer sign-off.
Management Response Tracker
Findings to closure: root cause, owner, due date, evidence of closure, and independent validation columns.
Want these filled in for you — grounded in real control catalogs and your own architecture?