The intake address, the runbook, and the reply — ready before the first vulnerability report lands.
A free 17-question readiness self-assessment, built for startups, founder-CISOs, and small product teams. With it comes a working toolkit: runbooks, message templates, regulatory decision trees, and worked sample incidents. (PSIRT stands for Product Security Incident Response Team.) The assessment runs in your browser. Your answers never leave your device.
Two paths into the toolkit.
1. Take the free assessment
17 questions across Governance, Technical, and Communication readiness. About five minutes. You get a scored snapshot of how ready you are to receive and handle a vulnerability report, before one arrives. Runs in your browser. No email required; nothing is sent anywhere.
Take the free assessment →2. Read the free readiness guide
"5 Things to Have Ready Before Your First Vulnerability Report": the intake address, a disclosure policy, a triage habit, a fix path, and a thank-you — in plain English, before that first email arrives.
Read the free guide →This is for product teams who'll receive vulnerability reports.
It builds the readiness to handle a researcher's report (the runbooks, templates, and decision trees) before the first one lands. If a report has already arrived and you need to act now, First 4 Hours carries the vendor-side triage; for a general small-business security baseline, see the SMB Security Assessment.
Three tiers: one for individuals, one for small product teams, one for enterprise PSIRT teams.
- Expert notes on every assessment question
- Solo Practitioner Toolkit (10 reference PDFs)
- PSIRT Five Commandments poster
- Startup First-Report sample incident
- Customer Trust Page templates
Enough if you’re a lone practitioner or maintainer standing up disclosure.
Buy Solo — $49- A full fix roadmap built on your assessment results
- PSIRT Response Playbook and First-72-Hours Runbook
- Stakeholder Communication Template Library
- Regulatory Notification Decision Tree
- Coordinated-disclosure in-depth playbook
- Three worked sample incidents (~200 pages total)
Choose this when a small product team needs coordination and process.
Buy Team — $99- Everything in Team
- Assessment views by role — analysts, leads, engineering, legal, and executives
- Tabletop scenario generator and sector overlays
- Multi-country regulatory reference, plus a playbook for cyber insurance and liability
- Forensics and saving evidence; a bug-bounty operations manual
- PSIRT for AI systems, plus AI-assisted PSIRT work
- Excel calculators for incident cost, review trends, and readiness tracking
- Quarterly board-briefing slide deck
- The standard Pro licence — covers your organisation, or your practice and every client you serve
Step up here for enterprise scale, high-liability depth, or client delivery.
Buy Enterprise — $299Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.
How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.
The companion books: the field guide and the workbook behind this toolkit.
The books teach the discipline; the toolkit does the work with you. The PSIRT Field Guide covers the judgement; the Operator's Workbook carries the templates.
If this is your situation, one of these usually is too
The situations this toolkit is built for, written up.
Receiving your first vulnerability report — ~9 min read.
What the Cyber Resilience Act asks of a small software company — ~8 min read.