Templates
Documents that have survived contact with real audits and real operations. Free, no email walls — each one comes with a short guide explaining why it's built the way it is, because the reasoning is the part that transfers.
Use them, adapt them, share them. If one saves you a bad afternoon, that's the point.
Risk Register
1–3 scoring with concrete anchors, separate Owner and Decision Maker columns, and ten realistic example risks — including the one where the single point of failure is you.
ExcelGap Assessment Workbook — CIS IG1
All 56 CIS Controls v8.1 IG1 safeguards in plain English, mapped to NIST CSF 2.0 and ISO 27001:2022, with SMB-realistic implementation notes, evidence guidance, and a self-calculating dashboard.
WordLeadership Risk Briefing
One page, quarterly, fifteen minutes. Decisions first, plain-language risks, one metric, and the risk-acceptance wording that actually gets signatures.
WordSMB Policy Starter Set
Acceptable Use, Access Control, and Incident Response — each under two pages, written to be read, enforceable as written, with executive approval built in.
Excel + WebRisk Library Workbook
37 realistic SMB risks in register-compatible columns, tagged for startups, US government work, India, and ISO — browse and filter on the Risk Library page, or download the workbook there.
A note on adaptation: every template carries the same warning — never let a document describe controls you don't run. A modest, true document beats an impressive fiction in every audit, claim, and incident that will ever test it.
License & safety: everything is free under CC BY 4.0 — use, adapt, and share with attribution. No file here contains macros, ever; if a copy of these templates asks you to enable anything, it didn't come from this site.