75 templates — download and deploy in minutes.
No templates in this category yet.
The anchor volume: hardware sizing with an honest cost model, Proxmox and Ludus as the substrate, three-zone isolation, and the four-tier reset architecture that decides whether your range gets used daily or becomes a museum. Includes the Range Build Planner.
What to put in the range and how to curate what you maintain — the GOAD family for Active Directory, Vulhub for per-CVE containers, cloud and IaC targets, organised into five handling tiers by reset cost and risk, with the maintenance treadmill made explicit.
The flagship: from a KEV/NVD/EUVD identifier to a reproduced environment, a validated detection, and a remediation check — as a repeatable six-stage pipeline rather than a heroic weekend. Written for the post-2026 reality where four in five CVEs arrive un-enriched. Includes the CVE Repro Template.
Instrument the range so a detection test actually means something. Log fidelity first, then Wazuh or Elastic with Velociraptor, Suricata and Zeek, driven by Atomic Red Team and Caldera, with detections written as portable Sigma and validated in CI against the corpus.
The capstone: turn the validated stack into scored exercises. Time-to-detect and time-to-contain as the primary metrics, ATT&CK coverage mapping, evidence capture and after-action reporting — bridging the tabletop most teams already run into a live run against instrumented infrastructure.
The governance layer that lets the range ship — nine fill-and-sign documents so a security leader can stand up a defensible posture in an afternoon rather than discovering the need for it during an incident. Word to edit, PDF to sign.
The live calculator that catches the wrong hardware call before you buy it — seven working tabs and 86 formulas covering purpose weighting, VM inventory with linked-clone math, host fit analysis, a three-year on-prem-vs-cloud cost model with payback, VLAN plan and reset-time log.
Printable attack-and-defend scenario cards for running range exercises away from a screen — a ready deck of scenarios you can deal onto a table for a tabletop, a training session, or the warm-up before a live purple-team run.
All five volumes plus both build tools and the Range Runbook Library — the whole facility, from isolation architecture to scored purple-team exercises. 34% off buying separately.
The open-source SOC diagram everyone shares has two commercial products on it. This is the corrected version — six planes, 24 components with verified licenses and named replacements, an AI analyst plane with a defensible autonomy ceiling, and three sized builds with honest hour counts.
The RA-01 architecture landed on one machine you can hold — a coreboot NUC with the Management Engine disabled, Nitrokey as the root of trust, three disks mapped to three storage tiers, and a 14-test acceptance suite you run before pointing a single agent at it.
Everything you need to prepare, apply for, and manage cyber insurance — 8 tabs, 167 live formulas, built for security teams who need to hold their own with brokers and underwriters.
Discover, inventory, and score every unapproved AI tool in your environment — 10 tabs, 589 formulas, pre-seeded with 15 real-world shadow AI tools and a defensible 10-factor risk model.
27 tabs, 1,565 formulas — a complete client management system for solo vCISOs and small teams. NIST CSF 2.0 assessments, risk registers, roadmaps, and a portfolio dashboard for 20 clients. Includes the 584-paragraph Practitioner User Guide.
The active cyber diligence workbook for M&A deal teams — auto-generated deal recommendations, cost modeling, and deal-term mechanism mapping across a 10-day sprint framework.
Stage-aware VC diligence for Pre-Seed through Series B+ — founder assessment, investment thesis scoring, pipeline tracking, cap table analysis, and IC memo output. 16 tabs built around the question: what would have to go right for 10x?
10 research-calibrated IR scenarios, a 13-tab program management system, and a 687-paragraph facilitator guide — plus an ecosystem map that turns every buyer into a full IR practice.
Input five values on the Assumptions tab — revenue, IT budget, headcount, industry, maturity — and the entire workbook calculates itself. Three budget-sizing methods, 50+ line items, CRQ for boards, and board talking points with your actual numbers.
18 tabs of operational crisis preparedness — 80-control readiness assessment, 8 pre-built IR playbook cards with DO NOT lists, ransom decision framework with OFAC gate, and regulatory matrix covering all 2026 mandates.
20-tab SOC 2 program covering assessment through Type 2 audit — 100+ controls, 35 required policies, 7 pre-populated operational logs, and an executive dashboard with three auto-calculated readiness metrics.
23-tab HIPAA compliance workbook built for the 2026 Final Rule — covers all current safeguards plus the 12 new mandatory requirements, IoMT risk, BAA management, breach notification matrix, and a dedicated 2026 gap analysis tab.
14-tab operational efficiency toolkit for responding to security questionnaires — 400+ pre-written answers mapped to CAIQ v4, SIG, VSA, and HECVAT, AI governance supplements, deal pipeline tracking, and a trust portal content planner.
20-tab ISMS implementation workbook for ISO 27001:2022 — all 93 Annex A controls across 4 themes, 11 new 2022 controls, Clauses 4–10 ISMS framework, transition gap analysis from 2013, and policy library.
12-tab PCI DSS v4.0.1 workbook — all 12 requirement domains, SAQ type selector, 51 future-dated requirements tracker, e-commerce script security controls, and QSA-ready evidence register. Built for the March 2025 mandatory transition.
12-tab CMMC 2.0 workbook — all 110 NIST 800-171 practices with DoD SPRS weights, auto-calculated SPRS score, Level determination decision tree, SSP builder, POA&M tracker, and C3PAO readiness checklist. Built for the November 2026 Phase 2 deadline.
14-tab EU regulatory compliance workbook covering all 5 DORA pillars, NIS2 Article 21 measures, dual framework applicability decision tree, penalty calculator (2% DORA / €10M NIS2), and cross-framework mapping across 17 control domains.
Everything you need to brief the board on cybersecurity — editable Excel metrics workbook, 25-slide PowerPoint deck template, and a user guide covering what boards actually want to hear and how to answer the questions you will get.
14-tab NIST CSF 2.0 workbook — all 106 Subcategories with verbatim NIST.CSWP.29 outcome statements, Current/Target tier dropdowns, Organizational Profile Generator, heatmap, gap analysis pre-seeded with 12 high-gap 2026 scenarios, and crosswalks to SP 800-53r5, SP 800-171r3, CIS Controls v8.1, and ISO 27001:2022.
20-tab GDPR compliance workbook — Controller ROPA, Processor ROPA, DSR log with 30-day SLA tracking, 72-hour breach deadline calculator, TIA template, DPF certification tracker, and DPIA template with WP29 9-factor trigger test. Updated for April 2026 research baseline.
17-tab US state privacy compliance workbook covering the 20-state wave — CCPA/CPRA, MODPA, VCDPA, CPA, and 16 more — with auto-generated obligation matrix, DSR tracker, consent management log, ADMT register, and enforcement reference.
The structured first-90-days playbook for new CISOs — stakeholder mapping, program gap assessment, quick-win tracker, board briefing builder, and 30/60/90-day milestone framework. For FTE CISOs, vCISOs starting new engagements, and interim security leaders.
18 runbooks × 3 formats (54 files) — complete IR runbook library covering every major 2026 threat scenario, from ransomware multi-extortion to vishing to Magecart. ZIP delivery with Word, PDF, and Markdown versions of every runbook.
A concise checklist covering the controls underwriters check before quoting — MFA, backups, endpoint, email security, and IR — with a quick self-scoring mechanism to spot coverage red flags before you talk to a broker.
The key controls, evidence items, and policy gaps auditors check at every SOC 2 engagement — organized by Trust Service Criteria with a pre-audit readiness rating.
Updated for the 2026 Security Rule Final Rule — covers all 12 new mandatory requirements plus the core Administrative, Physical, and Technical safeguards in a single actionable checklist.
The pre-incident checklist for ransomware preparedness — backup validation, identity hardening, IR contacts, communication templates, and the ransom decision questions to answer before an attack hits.
A practical privacy and security guide for college students — accounts, devices, campus Wi-Fi, social media, AI tools, and identity protection covered in plain language.
A simple online safety and privacy checklist for pre-teens (ages 9–12) and the parents reviewing it with them — covering apps, gaming, passwords, and what to share online.
A comprehensive digital privacy and online safety guide for teenagers — social media, gaming, AI tools, relationships, identity protection, and what your data is actually worth.
Device hardening and network segmentation checklist for smart home setups — routers, cameras, smart speakers, thermostats, and everything else on your home network.
Platform-by-platform privacy settings guide for major social networks plus an AI tool awareness section — what each platform does with your data and how to tighten it.
A step-by-step guide to evaluating, selecting, and migrating to a password manager — comparison framework, migration checklist, and post-migration hardening steps.
Document your digital accounts, assets, subscriptions, and access wishes for estate planning — so your family can act quickly and nothing is permanently lost.
25-slide editable PowerPoint security awareness training deck — phishing, passwords, social engineering, AI threats, and incident reporting. Compatible with Google Slides, Keynote, and LibreOffice.
2-page printable audit for your home Wi-Fi — router hardening, WPA3, network segmentation (Main / Guest / IoT), DNS filtering, IoT device inventory, and a 90-day re-audit cycle. The average home has 22+ connected devices; most routers ship insecure.
4-page printable workbook to inventory, prioritize, and migrate all your accounts to a password manager — 30+ account types pre-listed in 4 priority tiers, 2FA migration tracker, lockout prevention checklist. Works with Bitwarden, 1Password, Proton Pass, and more.
4-page two-way family internet agreement updated for 2026 — AI chatbots, deepfakes, sextortion, and gaming strangers addressed in age-appropriate language. Parents promise things too (the two-column design is why teens actually sign it). Ages 8-17.
2-page before-you-buy checklist for personal cyber insurance — 10 coverage questions, 8 fine-print red flags, and a side-by-side quote comparison worksheet. Includes the #1 most-excluded coverage type that most buyers never think to ask about.
Fillable 4-page playbook for when an account gets hacked — pre-fill family contacts and fraud hotlines now, then follow the First 60 Minutes / Next 24 Hours / Cleanup Week checklists when it happens. 24 fillable fields + 30 priority-ordered checkboxes.
8-page fillable career planner covering 16 certifications — Cert Decision Framework (8 scenarios), 2026 cost reference (Sec+ $404, CISSP $749, OSCP $1,649+), Domain Mastery Tracker, Practice Exam Score Log with "Am I Ready?" rubric, and weekly study tracker. Updated for SY0-701 and April 2026 CISSP CBK.
8-page printable with 3 dinner-table scenarios (smishing, AI voice cloning, gaming scam) plus a fillable Family Safe Word Card — the #1 defense against AI voice clone scams. Each scenario is 20 minutes with discussion questions tuned for ages 8-17.
7-page printable for your executor — accounts, passwords (via manager succession), crypto wallet guidance, platform legacy settings (Apple Legacy Contact, Google Inactive Account Manager, Facebook Memorialization), and RUFADAA authorization language. Passwords never go in a will; this is what goes instead.
Fillable 8-page binder built around FCRA §605B — the 4-business-day bureau block most identity theft kits skip. Includes a §605B dispute letter, §609(e) creditor records demand, phone scripts for banks/bureaus/debt collectors, Master Dispute Tracker, and 2026-verified bureau addresses. 21 fillable fields.
13-page fillable kit for solo founders and 2-25 person businesses — 2026 cyber insurance pre-fill worksheet (19 carrier questions), 7 starter policies (AUP, Password, Data Handling, Privacy Notice, IR Plan, Onboarding/Offboarding, Vendor Risk), and a 90-day implementation roadmap. 67 text fields + 66 checkboxes.
The dignified, 2026-current guide to elder cyber fraud — romance scam 4-phase playbook, AI voice cloning defense, government impersonation field guide, and fillable Family Safe Word card. For adult children buying for aging parents.
Four-page fillable PDF for remote employees and freelancers — home office audit, 2026 VPN comparison, AI tool risk policy, signed BYOD mini-policy, and monthly self-audit grid. Updated for post-quantum VPNs and co-working space security.
Everything your family needs to be cyber-safe in 2026 — Home Network Audit, Family Online Safety Contract (AI/deepfake-aware), 3-scenario Cyber Drill with fillable Safe Word card, and IR Runbook for account compromise. 26% off individual.
Lock down your accounts, protect your money, recover from identity theft, and pass your cyber insurance application — Password Manager Workbook, Cyber Insurance Checklist, Identity Theft Recovery Binder (FCRA §605B), and SMB Starter Kit. 24% off individual.
Built for the worst week — Senior Cyber Safety Workbook, Identity Theft Recovery Binder (FCRA §605B), and Family IR Runbook, plus a 2-page triage guide that tells you which workbook to open first based on what you discovered. 36% off individual.
The entire consumer catalog — 10 products covering family safety, financial protection, career planning, and small business documentation. 54 pages, scenario-based bundle index showing what to open first for any situation. 33% off individual.
SOC 2 + HIPAA + ISO 27001:2022 readiness in one bundle — the three certifications every enterprise buyer asks for. 17% off list.
SOC 2 + HIPAA + ISO 27001 + PCI DSS + CMMC 2.0 — every major compliance framework an auditor or regulator will ask about. 22% off list.
CMMC 2.0 + NIST CSF 2.0 + PCI DSS for defense and federal contractors — built for DoD, GSA, and agency RFP responses. 18% off list.
HIPAA + SOC 2 + Ransomware Readiness for healthcare SaaS and digital health. Healthcare ransomware is 31% of all attacks. 17% off list.
SOC 2 + ISO 27001 + GDPR/DPIA for B2B SaaS going international — US enterprise + EU data subjects in one bundle. 17% off list.
2026 US state privacy program + EU GDPR/DPIA — every SaaS selling to US and EU customers needs both. 15% off list.
CISO 90-Day Onboarding + NIST CSF 2.0 Assessment + CISO Budget Workbook + Board Reporting Pack — your Day-90 board meeting in a bundle. 20% off list.
CISO Budget Workbook + CISO Board Reporting Pack + NIST CSF 2.0 — everything a CISO needs for the quarterly board cycle. 17% off list.
CISO 90-Day Onboarding + Budget + Board Pack + NIST CSF 2.0 + Tabletop Exercise Pack — the most complete CISO toolkit in the catalog. 22% off list.
vCISO Client-in-a-Box + NIST CSF 2.0 Assessment + CISO Board Reporting Pack — drop-in kit for fractional CISOs running concurrent clients. 20% off list.
vCISO Client-in-a-Box + CISO 90-Day Onboarding + NIST CSF 2.0 + Budget + SOC 2 + Board Pack — complete vCISO practice toolkit. 25% off list.
Ransomware Readiness + Tabletop Exercise Pack + Cyber Insurance Workbook + Shadow AI Inventory — show underwriters and your CEO your program maturity. 20% off list.
M&A Cyber Diligence + VC Startup Due Diligence + Enterprise Questionnaire Response Kit — for deal advisors, corp dev, and VCs running cyber DD. 17% off list.
Ransomware Readiness Workbook + Tabletop Exercise Pack — prepare, practice, and survive a ransomware incident. 25% off individual pricing.
vCISO Client-in-a-Box + Shadow AI Inventory + CISO Budget Workbook — the three tools every vCISO needs to run a full program. 18% off individual pricing.