The security baseline cyber insurers ask about, without hiring a consultant.
A free 12-question self-assessment that runs entirely in your browser; your answers never reach us, by design. It shows you, in plain English, where you stand on access management, data classification, backup and recovery, and patching. With it comes a practical toolkit: policies, Word templates, Excel workbooks, training decks, and tabletop exercises.
Two free ways to see if the toolkit fits.
Two free ways in: take the assessment or read the guide. Both are the first pages of the full toolkit below: same plain-English standard, same privacy architecture.
1. Take the free assessment
12 questions across four security areas. About five minutes. Returns a category-by-category snapshot of where your business is exposed. Runs in your browser — no email required, no data transmitted.
Take the free assessment →2. Read the free 5-fixes guide
"Your First 5 High-Impact Security Fixes" walks through the actions that address the most common attacks on small businesses, in the right order, with time estimates. Three minutes to read.
Read the free 5-fixes guide →This is for a general small-business security baseline.
It covers the everyday controls (access, data, backup, and patching) that cyber insurers and customers ask about. If your real need is privacy compliance for European customers, see the GDPR Checklist; if you ship a product and receive vulnerability reports, that's PSIRT Response. And if the trigger is this year's insurance renewal form itself, the Cyber Insurance Readiness Assessment walks that exact form — this assessment builds the baseline behind it.
Three tiers: one for solo operators, one for small businesses, one for consultants.
The full toolkit behind the free assessment: 62 documents and more than 200 PDF pages across the three tiers, written to operator grade: the playbook a senior consultant would otherwise email you as a Word document. One-time purchase. Your files, yours forever.
- Personal multi-factor authentication setup guide
- Personal backup setup guide
- Account-compromise recovery playbook
- Solo Identity and Access Management playbook
- Phishing and scam recognition card
Enough if it’s just you and you want to be secure without an IT team.
Get the Solo kit — $49- 11 toolkit guides (~190 pages) including the four category toolkits
- 9 working Word templates: incident-response communications, insurance readiness, and an offboarding checklist
- 4 Excel workbooks: asset inventory, data inventory, risk register, and vendor risk scoring
- 6 Security Awareness training slide decks
- 3 facilitated tabletop exercises: ransomware, business email compromise, lost laptop
Choose this when you’re securing a small organisation: people, policies, and controls.
Get the Team toolkit — $99- Everything in Team
- Consultant pack: contract, statement-of-work, engagement-letter, and NDA templates
- Executive Findings Report template and Annual Risk Assessment template
- Branded findings deck and quarterly board-reporting deck
- Multi-client tracking dashboard
- Pricing & Packaging Guide and 1-Day Assessment playbook
- 3 advanced tabletop scenarios and 4 additional vertical case files
- White-label delivery licence note
Step up here only if you deliver this to clients: it includes white-label delivery rights under the standard Pro licence.
Get the consultant practice kit — $299Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.
How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.
The companion book: read the thinking behind the toolkit.
The book teaches the discipline; the toolkit does the work with you. The Small Business Security Playbook covers the same four-category framework in depth: the judgement behind every template in this toolkit.
If this is your situation, one of these usually is too
GDPR Checklist
If your business handles any European customer data, the GDPR Checklist covers the privacy-compliance side that the security assessment does not.
PSIRT Response
Do you ship a software product, not just run internal systems? PSIRT Response covers handling vulnerability reports from researchers.
The situation this toolkit is built for, written up.
The first security baseline for a small team — ~9 min read.