Free to use and share / No email required / Actually written by people who do this work

Free resources

Take these. No email required.

Six security templates we actually use, written in plain English for businesses without a security team. No gate, no signup, no drip campaign. Download them, use them, share them with your IT provider. If they help, you'll know where we are.

Start here

Security Checklist

27 items, ordered by what actually breaches you

Not alphabetical, not comprehensive-for-its-own-sake. Ordered so the first section eliminates most of your real risk. If you read one, read this.

Download PDF

Password Policy Template

Current NIST rules, not the outdated ones

Length over complexity, no pointless forced rotation, block breached passwords. Copy it, fill the blanks, adopt it.

Download PDF

Incident Response Plan

What to do in the first hour

Written for the panicked 2am version of you. Includes a printable first-60-minutes action card and fill-in emergency contacts.

Download PDF

Risk Assessment Worksheet

Find your real risks in an afternoon

Likelihood times impact, a worked example, and a blank worksheet. The same method a consultant uses, without the consultant.

Download PDF

NIST Gap Checklist

The famous framework, in plain questions

All six CSF 2.0 functions restated as yes/partly/no questions you can actually answer. Every gap becomes a to-do.

Download PDF

Vendor Security Questionnaire

Vet your vendors — and prep for your clients

Send it to suppliers, and use it to rehearse the questionnaire your biggest client will eventually send you. That deal stalls until you can answer it.

Download PDF

When the checklist isn't enough

A list tells you what should be true. A scan tells you what is.

When you're ready to know what's actually exposed on your systems, we'll scan your public-facing infrastructure and send you a real report in 48 hours. Free, nothing to install, no obligation.

Request your free scan