Included with your portal

The SMB cyber toolkit

Five things a small team actually needs, and usually keeps in a spreadsheet nobody maintains. Each one does something useful on its own, in an afternoon. They come with the portal, configured to the environment you describe in your profile, at no extra cost.

Policy Template Generator
Governance

A shelf of complete, generic security policies we wrote and keep current, ready to download and adapt, instead of starting from a blank page or inheriting someone else's PDF and hoping.

Reach for it when
  • A customer's procurement team has asked to see your information security policy, and you do not have one
  • You are starting ISO 27001 or SOC 2 and need the policy set that underpins it
  • Your policies exist, but were written years ago for a company you no longer are
Data-Breach Cost Estimator
Risk

What an incident would plausibly cost you, in money, modelled properly rather than guessed. Money is the only unit a budget conversation actually runs in.

Reach for it when
  • You are asking the board for security budget and need the number that justifies it
  • You want to know whether your cyber insurance cover is anywhere near your actual exposure
  • Someone senior has asked what would it actually cost us, and nobody has an answer
Vendor Questionnaire Generator
Third-party

Ask a supplier the right questions, scaled to how much damage they could do to you, and keep the answers somewhere you can find them again.

Reach for it when
  • You are onboarding a supplier who will hold your customer data
  • An auditor has asked how you assess third parties, and the honest answer is that you do not
  • You have thirty vendors and no idea which of them could hurt you most
Breach Exposure Check
Identity

Which of your corporate email addresses already appear in a known breach corpus. Takes seconds, needs nothing from you but your domain, and is usually the moment the conversation gets serious.

Reach for it when
  • You want to know, today, whether your staff's work accounts are already exposed
  • You are making the case internally that this is not a theoretical problem
  • You have just onboarded a team and want to know what they brought with them
Runs inside your workspace
Incident Response Plan Builder
Resilience

A plan written before the incident, naming who decides, who is called, and in what order. The alternative is deciding all three at three in the morning.

Reach for it when
  • An auditor or a customer has asked for your incident response plan
  • You have one, but nobody has read it and it names people who left
  • You want to run a tabletop exercise and need something to run it against
The toolkit comes with your portal. When a tool stops being enough, the product behind it is the next step, and we set that up with you.Create your company profile →