surable

Everything in the pack

Every document, section by section

Most template sets are prose you have to turn into evidence yourself. The thing that makes these different is the 21appendices, logs and registers: the inventories, the restore-test log, the offboarding checklist, the end-of-life register. Those are what an underwriter actually wants to see, and they're the part nobody advertises. So here's the whole table of contents.

20

Documents

107

Sections

21

Appendices & logs

15

Questions mapped

13 documents come in Core. All 20 come in Complete. Every one arrives as an editable Word-compatible file and as markdown, personalized to your business from a short intake. You can read a real one in full before deciding.

Guides & checklists

Read Me First — 30-Minute Orientation

Core & Complete

What you have · The 30-minute setup · The one rule that protects you · Suggested order · Keeping documents current

Application-Mapping Guide: Which Document Answers Which Question

Complete

Which document answers which cyber insurance application question · How to use this at application time

15 application questions, each with the answer standard, the document and section that evidences it, and the carrier wording notes that change the honest answer.

Pre-Signature Attestation Checklist

Complete

Part 1: Verify the load-bearing answers · Part 2: The five traps (read aloud, initial each) · Part 3: Ongoing warranty note

Evidence Index: where every answer's proof lives

Complete

The index · Before you submit · Where to keep it · If an answer changes mid-term

Policies

Acceptable Use Policy

Core & Complete

1. Purpose · 2. Scope · 3. The rules · 4. Privacy expectation · 5. Enforcement

Fill-in appendices

  • Acknowledgment

Answers on the application: What protects your computers and servers from malware?

Access Control & Account Management Policy

Core & Complete

1. Purpose · 2. Account lifecycle · 3. Least privilege · 4. Administrative access · 5. Access reviews · 6. Review

Fill-in appendices

  • Appendix A: Account and access inventory
  • Appendix B: Role-based access defaults
  • Appendix C: Offboarding checklist (run the same day)

Answers on the application: Is MFA required for remote access (VPN, remote desktop) and administrator accounts? When someone leaves the company, how quickly is their access removed?

Password & Multi-Factor Authentication Policy

Core & Complete

1. Purpose · 2. Scope · 3. Multi-factor authentication (MFA) · 4. Passwords · 5. Shared and service accounts · 6. Enforcement and exceptions · 7. Review

Fill-in appendices

  • Appendix A: Exceptions and shared/service account log

Answers on the application: Is multi-factor authentication (MFA) required on all business email accounts?

Patch & Vulnerability Management Policy

Core & Complete

1. Purpose · 2. Asset inventory first · 3. Patch timelines · 4. End-of-life (EOL) systems · 5. Vulnerability awareness · 6. Review

Fill-in appendices

  • Appendix A: Asset inventory
  • Appendix B: End-of-life register (with compensating controls)
  • Appendix C: Monthly patch check log

Answers on the application: How are security updates applied to your systems and software? Do you run any systems that no longer receive security updates (end-of-life)?

Backup & Recovery Policy

Core & Complete

1. Purpose · 2. What we back up · 3. How we back up (the 3-2-1 rule) · 4. Monitoring · 5. Restore testing · 6. Recovery priorities · 7. Review

Fill-in appendices

  • Appendix A: Backup inventory
  • Appendix B: Restore test log

Answers on the application: How is your critical business data backed up? When did you last successfully test restoring from a backup?

Email Security Policy

Core & Complete

1. Purpose · 2. Platform · 3. Technical protections (enabled and verified) · 4. Human procedures · 5. Compromise response · 6. Review

Answers on the application: What protections sit in front of your business email?

Data Protection & Classification Policy

Core & Complete

1. Purpose · 2. Classification: three tiers, plain English · 3. Handling rules by tier · 4. Retention and disposal · 5. Privacy obligations · 6. Review

Fill-in appendices

  • Appendix A: Data inventory
  • Appendix B: Disposal log

Remote Work Policy

Core & Complete

1. Purpose · 2. Approved remote access methods · 3. Working remotely: the rules · 4. Review

Answers on the application: Is MFA required for remote access (VPN, remote desktop) and administrator accounts?

Mobile Device & BYOD Policy

Core & Complete

1. Purpose · 2. Scope · 3. Requirements for any device touching company data · 4. BYOD: what's company, what's personal · 5. Lost or stolen devices · 6. Texting and payments · 7. Review

Fill-in appendices

  • Acknowledgment (BYOD participants)

Vendor & Third-Party Risk Policy

Core & Complete

1. Purpose · 2. The vendor inventory · 3. Before we sign: proportionate diligence · 4. While the relationship runs · 5. Annual review (fold it into a quarterly access review) · 6. Review

Fill-in appendices

  • Appendix A: Vendor inventory
  • Appendix B: Vendor security questions (email template)

Answers on the application: Do you review the security of vendors who access your systems or data?

Security Awareness Training Policy

Core & Complete

1. Purpose · 2. The program · 3. The culture rules · 4. Documentation (the part underwriters ask about) · 5. Review

Fill-in appendices

  • Appendix A: Training log

Answers on the application: How often do employees receive security awareness training?

Funds-Transfer & Payment Verification Procedure

Core & Complete

The rule · Triggers that require verification · The verification steps · If verification fails or something feels wrong · Bank-side controls (set once)

Fill-in appendices

  • Verification log
  • Acknowledgment

Answers on the application: Before changing bank details or sending an unusual payment, do you verify by phone using a known number?

Plans

Incident Response Plan (Fill-in-the-Blank)

Complete

THE EMERGENCY CARD (print this page) · 1. Purpose and scope · 2. Roles · 3. Severity ladder · 4. The first 24 hours · 5. Scenario runbooks · 6. Notification and legal · 7. After the incident · 8. Testing this plan

Fill-in appendices

  • Appendix A: System recovery priorities
  • Appendix B: Incident and exercise log
  • Appendix C: 60-minute tabletop script

Answers on the application: Do you have a written incident response plan? Do you have a written incident response plan? Have you tested your incident response plan in the last 12 months?

Training

Training One-Pager: Phishing & Social Engineering

Complete

The one-sentence version · The tells (any one of them is enough to slow down) · What to do · If you clicked (it happens, and speed beats shame) · Special cases

Training One-Pager: Passwords & MFA

Complete

The one-sentence version · The five rules · Do / don't · When something feels off

Training One-Pager: Payment & Wire Fraud

Complete

The one-sentence version · How the scam actually works · The procedure (the Funds-Transfer Verification Procedure is the full version, and it's policy) · The pressure test · If money already moved

Find out which of these you need

The free Readiness Check scores your answers and tells you which documents close your gaps, down to the section. Five minutes, no email needed for the score.