Everything in the pack
Every document, section by section
Most template sets are prose you have to turn into evidence yourself. The thing that makes these different is the 21appendices, logs and registers: the inventories, the restore-test log, the offboarding checklist, the end-of-life register. Those are what an underwriter actually wants to see, and they're the part nobody advertises. So here's the whole table of contents.
20
Documents
107
Sections
21
Appendices & logs
15
Questions mapped
13 documents come in Core. All 20 come in Complete. Every one arrives as an editable Word-compatible file and as markdown, personalized to your business from a short intake. You can read a real one in full before deciding.
Guides & checklists
Read Me First — 30-Minute Orientation
Core & CompleteWhat you have · The 30-minute setup · The one rule that protects you · Suggested order · Keeping documents current
Application-Mapping Guide: Which Document Answers Which Question
CompleteWhich document answers which cyber insurance application question · How to use this at application time
15 application questions, each with the answer standard, the document and section that evidences it, and the carrier wording notes that change the honest answer.
Pre-Signature Attestation Checklist
CompletePart 1: Verify the load-bearing answers · Part 2: The five traps (read aloud, initial each) · Part 3: Ongoing warranty note
Evidence Index: where every answer's proof lives
CompleteThe index · Before you submit · Where to keep it · If an answer changes mid-term
Policies
Acceptable Use Policy
Core & Complete1. Purpose · 2. Scope · 3. The rules · 4. Privacy expectation · 5. Enforcement
Fill-in appendices
- Acknowledgment
Answers on the application: What protects your computers and servers from malware?
Access Control & Account Management Policy
Core & Complete1. Purpose · 2. Account lifecycle · 3. Least privilege · 4. Administrative access · 5. Access reviews · 6. Review
Fill-in appendices
- Appendix A: Account and access inventory
- Appendix B: Role-based access defaults
- Appendix C: Offboarding checklist (run the same day)
Answers on the application: Is MFA required for remote access (VPN, remote desktop) and administrator accounts? When someone leaves the company, how quickly is their access removed?
Password & Multi-Factor Authentication Policy
Core & Complete1. Purpose · 2. Scope · 3. Multi-factor authentication (MFA) · 4. Passwords · 5. Shared and service accounts · 6. Enforcement and exceptions · 7. Review
Fill-in appendices
- Appendix A: Exceptions and shared/service account log
Answers on the application: Is multi-factor authentication (MFA) required on all business email accounts?
Patch & Vulnerability Management Policy
Core & Complete1. Purpose · 2. Asset inventory first · 3. Patch timelines · 4. End-of-life (EOL) systems · 5. Vulnerability awareness · 6. Review
Fill-in appendices
- Appendix A: Asset inventory
- Appendix B: End-of-life register (with compensating controls)
- Appendix C: Monthly patch check log
Answers on the application: How are security updates applied to your systems and software? Do you run any systems that no longer receive security updates (end-of-life)?
Backup & Recovery Policy
Core & Complete1. Purpose · 2. What we back up · 3. How we back up (the 3-2-1 rule) · 4. Monitoring · 5. Restore testing · 6. Recovery priorities · 7. Review
Fill-in appendices
- Appendix A: Backup inventory
- Appendix B: Restore test log
Answers on the application: How is your critical business data backed up? When did you last successfully test restoring from a backup?
Email Security Policy
Core & Complete1. Purpose · 2. Platform · 3. Technical protections (enabled and verified) · 4. Human procedures · 5. Compromise response · 6. Review
Answers on the application: What protections sit in front of your business email?
Data Protection & Classification Policy
Core & Complete1. Purpose · 2. Classification: three tiers, plain English · 3. Handling rules by tier · 4. Retention and disposal · 5. Privacy obligations · 6. Review
Fill-in appendices
- Appendix A: Data inventory
- Appendix B: Disposal log
Remote Work Policy
Core & Complete1. Purpose · 2. Approved remote access methods · 3. Working remotely: the rules · 4. Review
Answers on the application: Is MFA required for remote access (VPN, remote desktop) and administrator accounts?
Mobile Device & BYOD Policy
Core & Complete1. Purpose · 2. Scope · 3. Requirements for any device touching company data · 4. BYOD: what's company, what's personal · 5. Lost or stolen devices · 6. Texting and payments · 7. Review
Fill-in appendices
- Acknowledgment (BYOD participants)
Vendor & Third-Party Risk Policy
Core & Complete1. Purpose · 2. The vendor inventory · 3. Before we sign: proportionate diligence · 4. While the relationship runs · 5. Annual review (fold it into a quarterly access review) · 6. Review
Fill-in appendices
- Appendix A: Vendor inventory
- Appendix B: Vendor security questions (email template)
Answers on the application: Do you review the security of vendors who access your systems or data?
Security Awareness Training Policy
Core & Complete1. Purpose · 2. The program · 3. The culture rules · 4. Documentation (the part underwriters ask about) · 5. Review
Fill-in appendices
- Appendix A: Training log
Answers on the application: How often do employees receive security awareness training?
Funds-Transfer & Payment Verification Procedure
Core & CompleteThe rule · Triggers that require verification · The verification steps · If verification fails or something feels wrong · Bank-side controls (set once)
Fill-in appendices
- Verification log
- Acknowledgment
Answers on the application: Before changing bank details or sending an unusual payment, do you verify by phone using a known number?
Plans
Incident Response Plan (Fill-in-the-Blank)
CompleteTHE EMERGENCY CARD (print this page) · 1. Purpose and scope · 2. Roles · 3. Severity ladder · 4. The first 24 hours · 5. Scenario runbooks · 6. Notification and legal · 7. After the incident · 8. Testing this plan
Fill-in appendices
- Appendix A: System recovery priorities
- Appendix B: Incident and exercise log
- Appendix C: 60-minute tabletop script
Answers on the application: Do you have a written incident response plan? Do you have a written incident response plan? Have you tested your incident response plan in the last 12 months?
Training
Training One-Pager: Phishing & Social Engineering
CompleteThe one-sentence version · The tells (any one of them is enough to slow down) · What to do · If you clicked (it happens, and speed beats shame) · Special cases
Training One-Pager: Passwords & MFA
CompleteThe one-sentence version · The five rules · Do / don't · When something feels off
Training One-Pager: Payment & Wire Fraud
CompleteThe one-sentence version · How the scam actually works · The procedure (the Funds-Transfer Verification Procedure is the full version, and it's policy) · The pressure test · If money already moved
Find out which of these you need
The free Readiness Check scores your answers and tells you which documents close your gaps, down to the section. Five minutes, no email needed for the score.