-
The Plain-English Security Dictionary
Every security term you'll meet as a small-business owner — scams, backups, breaches, questionnaires — explained the way a person would actually say it.
-
Your First 5 High-Impact Security Fixes
Five plain-English actions for small businesses, in the order worth doing them. Most are free, and even the first one makes a real difference.
-
The First 5 Backup Mistakes Small Businesses Make
Almost every business believes it has backups; far fewer could recover tomorrow morning. The five quiet mistakes, and the fix for each.
Free guides that pair with every free assessment.
Each guide teaches the essentials, the matching free assessment shows where you stand, and the toolkit does the work when you're ready. Read, score, act — free to start, and every guide has a downloadable PDF.
Read a free guide
Plain-English essentials, in the order worth doing them. PDF included, no email required.
Take the free assessment
Score where you stand in your browser. Your answers never leave your device.
Get the toolkit
Templates, runbooks, and a prioritised plan when you want to go deeper.
The free guides, grouped by the product each one supports and listed alphabetically. Every guide is free to read, with a downloadable PDF and no email required.
-
The First 5 AI Security Fixes
Find your shadow AI, control access, handle prompt injection, vet your model supply chain, and set a simple AI use policy — the five gaps that catch teams adopting AI.
-
Your First 5 Cloud Security Fixes
Inventory and lock your accounts, audit access keys, close public exposure, turn on logging, and write a one-page incident card — the five cloud basics that prevent the most incidents.
-
Before Your Cyber Insurance Renewal
Read the supplemental without dread, triage the form green-amber-red in one sitting, make the broker and IT-provider calls with the right questions, and start the evidence habit that keeps every answer provable.
-
Before You Touch Anything — The First-Hour Incident Checklist
The do-not-touch list, the first three actions, who to call, and the clocks that may already be running.
-
The GDPR Breach Battle-Card — Your First 72 Hours
Anchor your awareness time, contain without destroying evidence, assess the risk, and make the Article 33 and Article 34 notification calls — the first three days in plain English.
-
The 5 Most Common GDPR Mistakes — and How to Avoid Them
Applicability, lawful basis, vendor agreements, retention, and breach readiness — the five misunderstandings that catch small businesses out, each with a simple fix.
-
5 Things to Have Ready Before Your First Vulnerability Report
An intake address, a one-page policy, a triage habit, a fix path, and a thank-you — ready before the email arrives.
-
Your First 5 SOC 2 Moves
Understand what SOC 2 is, scope it, turn on the controls auditors always check, write the core policies, and start collecting evidence early — before you spend on a platform and an audit.
-
A Customer Sent You a Security Questionnaire. Now What?
What a vendor security questionnaire actually asks, how to answer honestly without losing the deal, and what evidence reviewers expect.
-
Your First 5 Vulnerability Management Wins
Inventory your assets, scan what matters first, prioritise by real risk over raw scores, fix and verify, and make it a steady cadence — without buying anything new.
See where you stand
Every guide pairs with a free assessment that runs entirely in your browser. Your answers never leave your device.
Browse the free assessments →Ready to go deeper?
Each toolkit turns a guide's checklist into templates, runbooks, and a prioritised plan you own.
See the toolkits →These guides provide general guidance and recommended security practices drawn from widely recognised standards. They are not a professional security audit and not legal advice, and they do not guarantee security or prevent any particular breach. Responsibility for your business's security remains with you. © 2026 Sylvan Assurance, LLC.