Written from your answers, not stamped with your name.
You answer questions about your environment. The document is written from those answers and downloads in your browser when you finish. The judgment in it comes from nine years of audit work at American Express, Deloitte, and Morgan Stanley.
Five documents. Each one finished when it downloads.
Each file is an editable Word document your firm can adopt: numbered sections, a contents page, and document control (reference number, version, revision history, distribution list, and an approval block). Appendices are filled from your intake. Controls are mapped to named NIST CSF 2.0 subcategories so a reviewer can trace a clause. Generation runs on your device. Your answers never leave it unless you choose to send them.
Incident Response Plan Starter Kit
$349
The plan a questionnaire, an insurer, or an examiner asks for, with the response team sized to a small firm's headcount.
An insurer, a client, or an examiner asks whether you have an incident response plan, and then asks who runs it. This is a working plan: severity definitions, an escalation path with named roles, a notification matrix giving the trigger and the requirement for each obligation you carry, and pre-drafted communication templates for the first four hours, when nobody is thinking clearly.
Structured against NIST SP 800-61. Written for the week an insurer or a client asks whether you have a plan, and for the people who will actually run it.
Includes
Full incident response plan, structured to NIST 800-61
Severity classification matrix with escalation thresholds
Role assignments mapped to a small-firm org chart
A notification matrix keyed to the obligations you select, giving the trigger and the requirement for each
Pre-drafted communication templates for the first four hours
A one-page version for the people who will not read the full plan
Best for
Any firm an insurer, a client, or an examiner has asked for an IR plan.
Examiner and carrier page
Appendix D, Insurer and Examiner Summary, one page inside the plan (about 45 pages). It answers who is called first, who decides whether anyone outside the firm is told, which cyber carrier is on the policy (or that none was named), who does forensics, and that the customer letter in Section 14 is a specimen, not a letter already sent. Hand an examiner this page and Appendix A, the contact directory.
First 60 Minutes, a separate card to print for the people named on it. It uses the consoles from the intake, and it is not pinned up until the incident lead’s mobile is written on Appendix A.
Tabletop exercise script, a separate file: two hours, four injects written for the systems named on the intake, and a findings template that feeds the plan’s revision history. That entry is what an insurer can see was tested.
Appendix B, the incident record, opened when an incident is declared, and Appendix C, the running log: one line per event, one time zone, decisions as well as actions. Months later, that log is the answer to what was decided and when.
Or take all five documents as the Documentation Set for $999. Bought individually the five come to $1,345, so the set saves $346.
Acceptable Use Policy Starter Kit
$199
The policy that decides what happens when an employee puts client data somewhere it should not be, written against the tools you actually run.
Acceptable use is the policy auditors check first, because it is the one that governs everyone rather than just IT. It defines what your people may do with firm devices, firm data, personal accounts, and increasingly, AI tools.
Most templates were written for a security operations center. This one is written for the firm that has to adopt it on Monday, against the tools you actually run.
Includes
Full acceptable use policy covering devices, data, accounts, and remote work
AI and generative tool provisions, which most policies still lack
BYOD and personal device sections
Employee acknowledgment form
Enforcement and exception language that a manager can actually apply
Best for
Firms preparing for SOC 2, an insurance renewal, or a client review.
Acknowledgment on file
The adopted policy (about 30 pages). An auditor or a client doing due diligence receives the PDF: firm devices, firm data, accounts, remote work, and the AI tools named on the intake, applying to every person who uses firm systems, including contractors.
The acknowledgment page. Human Resources keeps the signed page, or the electronic acknowledgment, in the personnel file. The policy owner can show a reviewer that it exists without producing the file.
Appendix A, the manager’s guide, for the person holding the conversation. The first hour is contain the file, do not delete anything, write down what was seen, then decide whether it is an incident. The consistency record stores the policy section and the action, not the person’s name. An exception is approved only by the policy owner, and twelve months is the longest it runs.
Or take all five documents as the Documentation Set for $999. Bought individually the five come to $1,345, so the set saves $346.
Vendor Questionnaire Response Pack
$399
Pre-written answers to the questions that keep stalling your deals, carrying SIG Lite and CAIQ identifiers a reviewer can trace.
A 200-question security questionnaire from an enterprise client is not really a security exercise. It is a writing exercise under deadline, and most firms lose a week to it or answer badly enough to trigger a follow-up review.
This is a library of answers to the questions that appear in nearly every questionnaire, written the way a reviewer wants to read them: direct, specific, and honest about compensating controls where a control does not exist. Includes guidance on how to answer "no" without losing the deal, which is the part nobody teaches.
Includes
Response library covering the most common questionnaire domains
Model answers for access control, encryption, backups, incident response, vendor management, and training
Guidance on answering honestly when a control is absent
A reusable evidence index so the second questionnaire takes an hour instead of a week
Best for
Firms in an active enterprise sales cycle with a questionnaire on the desk.
Paste into their sheet
Answer-bank spreadsheet. One row per question, with the SIG ID and the CAIQ ID in separate columns so the client’s sheet can be filtered on either. Where maturity changes the honest answer, three drafted responses sit side by side and the column matching the intake is shaded. A row that still has a blank is marked before anything is pasted into the form on the desk.
The Word pack (about 30 pages) is how those responses are chosen: a cover letter, the answers by domain, and Section 9 for a control that is not in place yet. That section states what is true today, what addresses the risk in the meantime, and that a control not held is not claimed as present.
Appendix A, the evidence index. For each artefact: where it lives, who owns it, whether an NDA is required, and whether it goes out as a PDF or only under NDA. The next questionnaire uses this index.
Evidence-pack folders, one directory per domain. Each README names the artefact, the likely owner, and where it usually sits, so the directory dropped into the document store matches the list the client asked for.
Or take all five documents as the Documentation Set for $999. Bought individually the five come to $1,345, so the set saves $346.
Phishing Simulation Templates
$149
Ten phishing emails written around the identity tooling you named, plus the part most programs get wrong.
Running a phishing simulation is easy. Running one that improves behavior rather than embarrassing people is harder, and the difference is almost entirely in what happens after someone clicks.
Ten templates modeled on the attacks actually used against professional services firms: business email compromise, credential harvesting, client impersonation, and vendor payment fraud. Each with difficulty rating, the specific tell employees should have caught, and the follow-up message to send someone who fell for it.
Includes
Ten phishing email templates with subject lines and body copy
Difficulty ratings and the intended teaching point for each
Post-click education message, written to instruct rather than shame
Program guidance: cadence, metrics worth tracking, and what to report to leadership
Baseline and follow-up measurement structure
Best for
Firms whose insurer or client asked whether they run security awareness training.
The page an underwriter is given
Appendix B, one page, for a managing partner, a board, or an underwriter, taken from a programme of about 34 pages. Before a wave is sent, the page states the method: who receives the emails, what will be measured, that anyone who clicked is taught the same day, and that no person is named. After a wave, the same page carries the numbers. A cyber insurer or a client doing due diligence is given this page.
Appendix A is where those numbers are kept, wave against wave: how many people received it, report rate against the baseline, click rate, credential rate at the stated difficulty, and median minutes to the first report.
The ten emails, the tell on each, and the same-day message stay in the programme. They are what the firm runs. Appendix B is what an underwriter or a client receives.
Or take all five documents as the Documentation Set for $999. Bought individually the five come to $1,345, so the set saves $346.
Data Classification & Handling Standards
$249
The document that answers “how do you know where client data lives?”, with six appendices you complete once.
Every examiner and every serious client asks some version of this question, and most firms answer it with a shrug. Classification is the foundation the rest of a security program sits on, because you cannot protect data appropriately without first deciding what tier it belongs to.
A four-tier scheme with concrete handling rules for storage, transmission, retention, and destruction, written with financial services and legal data in mind rather than generic corporate examples.
Includes
Four-tier classification scheme with real-world examples for advisory and legal work
Handling requirements per tier: storage, transmission, sharing, retention, destruction
Labeling conventions your team will actually follow
Data inventory worksheet
Retention schedule aligned to common regulatory obligations
Best for
Firms starting a compliance program, or answering a data governance question they cannot currently answer.
Returned with the question
Section 3 and Appendix A answer a client who asks how data is classified. Section 3 is the four tiers, Restricted, Confidential, Internal, and Public, with storage, transmission, sharing, retention, and destruction for each. Appendix A is the inventory, seeded with the systems named on the intake: system, what it holds, highest tier, owner, who has access, and retention. The standard around them is about 20 pages.
Sections 5 and 6, with that inventory, are what an examiner is shown when the question is whether the scheme is applied: the labelling rules, the retention schedule, and a list that can be produced.
Appendix B, one page to print where documents are labelled: the tier, what may carry it, and what must never.
Appendix C, the destruction log, filled in at disposal, with the date, what was destroyed, the tier, the method, and who approved. It is kept seven years, and it is the record that the schedule in Section 6 was followed.
Appendix E, the data flow map, one row per movement: where a record enters, where it rests, what copied it, and where it leaves. Appendix F, the record of processing activities, one row per activity: purpose, whose data, who receives it, how long it is kept, and what protects it. Appendix D is the exception register. A departure is requested, approved, and dated, and twelve months is the maximum.
Or take all five documents as the Documentation Set for $999. Bought individually the five come to $1,345, so the set saves $346.
Documentation Set
$999
All five documents, each generated from the same intake. Individually $1,345, so the set saves $346.
The five documents answer different questions, and a firm that is being asked one of them is usually about to be asked the others. A client questionnaire that asks how you classify data will also ask whether you have an incident response plan, whether staff are trained, and what your acceptable use policy says. Answering one of those well and the rest with a shrug is the position the set exists to avoid.
They are also written to sit together: the classification tiers referenced in the acceptable use policy are the tiers defined in the classification standard, and the incident record in the response plan expects the retention periods the classification standard sets. Bought separately they still work. Bought together they agree with each other.
Includes
Incident Response Plan Starter Kit · $349 separately
Data Classification & Handling Standards · $249 separately
Acceptable Use Policy Starter Kit · $199 separately
Phishing Simulation Templates · $149 separately
Best for
A firm putting a documented security program on paper for the first time, usually because a client, an insurer, or an examiner has asked for more than one of these at once.
Credited in full toward any TRM advisory engagement booked within 90 days, on the same terms as the individual documents.
How you receive it. Pay on Stripe, return to this site, complete the intake, and the Word document downloads in your browser.
30-day money-back guarantee. Not what you expected? Email info@trmsolutions.io within 30 days for a full refund.
Credited in full toward any TRM advisory engagement booked within 90 days. If this turns out to be the start of something larger, you have not spent twice.
What this is not. A professionally drafted starting point, not a finished compliance artifact. Requires review, customization to your environment, and legal validation before use in a regulatory or audit context. If you would rather not do that yourself, that is what the assessment is for.
Book a call
Not sure a document is the right answer?
A short call is the fastest way to figure out whether a document is enough or an engagement is the better use of your time.
TRM Solutions is an independent advisory practice not affiliated with, endorsed by, or sponsored by any current or former employer. Employer names describe professional experience only. Engagements are conducted in a personal capacity and do not involve employer systems, data, clients, vendors, or confidential information. Client engagements are covered by NDA. Assessments and templates provide directional guidance and are not a penetration test, audit, certification, or guarantee of security.