Pack add-on · Priced on the pack
Your policies, standards and procedures rewritten against the systems you run and the obligations you carry, with every interval, threshold and owner set to a real number and a real name. One intake form. You own the files, and there is no assessment: that is a separate engagement and we say so on the documents.
What changes
This is the difference between a customized document and a template with your name dropped into it. Which of these apply depends on the tier.
Generic clauses rewritten to name your sector, its terminology and the way you actually operate. A policy that could describe any organization describes none.
Which obligations apply, decided from your industry, geography, data types and customer base. Controls that do not apply are marked so, with the reason recorded rather than left blank.
Each control marked in scope or out, with the justification written down. An assessor asks for this before anything else.
The register arrives with risks already entered for your industry and environment, each with a rated likelihood and impact, rather than as an empty grid.
Every interval, threshold and retention period set to a number appropriate to your size, in place of the bracketed field you would otherwise have to guess at.
Your systems named in the documents that govern them, so a reader can tell the policy was written for your estate.
Each requirement mapped to the framework a customer or an auditor is asking about, so one document answers more than one question.
Policy ownership mapped to your actual titles and reporting lines, including a fractional CISO or an MSP where that is who holds it, and the set arranged into your governance hierarchy so a policy, a standard and a procedure are not all called policy.
Remediation windows, access review cadence and retention periods set to what your team can actually sustain. A fourteen-day critical patch window you will miss every month is worse than a thirty-day one you meet, because the first is a documented breach of your own policy.
How an exception is logged, who accepts the risk and when it expires, calibrated before publication. Without it a policy set goes live already in breach of itself the first time somebody cannot meet a control.
Incident escalation paths, severities and notification lists carrying your legal counsel, your insurer's notification number, your retained responder and your executive tree, rather than bracketed placeholders nobody fills in.
How it works
Step 01
Choose a pack and a customization tier. Either can be bought on its own.
Step 02
One online form: company details, named owners, industry, technology, obligations, team size, approval chains, target framework. Thirty to forty-five minutes, once.
Step 03
Every action in your tier applied to every document in the pack.
Step 04
You receive editable files and read them at your pace. Revision notes back within ten business days.
Step 05
The final revision within five business days of your notes. The files are yours.
Tiers
| Foundation | Compliance | |
|---|---|---|
| Scope | One pack | One pack, aligned to a target framework |
| Industry context | Included | Included |
| Regulatory mapping | Included | Included |
| Control applicability | Included | Included |
| Risk pre-population | Included | Included, broader coverage |
| Parameter calibration | Included | Included |
| Technology references | Not included | Included |
| Framework cross-referencing | Not included | Included |
| Ownership and hierarchy | Titles and reporting lines | Titles, reporting lines and hierarchy |
| Threshold feasibility | Set to your size | Agreed with your team in a review session |
| Exceptions workflow | Not included | Included |
| Escalation grounding | Not included | Included |
| Intake | 30-minute form | 45-minute form, a technology questionnaire and one review session |
| Turnaround | 7 business days | 10 business days |
| Revisions | One round | One round |
| Fee | Quoted on the pack you choose | Quoted on the pack you choose |
Boundaries
Stated plainly so you can decide quickly rather than discovering it after the intake form.
Before you add this
Customized documents state what your organization intends to do, correctly and in your own terms. They do not establish that it is happening. If a customer, an insurer or your board is asking for proof rather than policy, the engagement you want is Cybersecurity Program Assessment, and we would rather tell you that now than after the intake form.