Cyber risk scenario worksheet
Frame one plausible cyber-loss scenario, its assumptions, ownership, and next decision.
Best for: A risk has been raised, but the business impact, assumptions, or decision owner are still unclear.
Open checklistFree public control tools
Use these worksheets and checklists to organize one decision, one evidence set, or one governance conversation. They are public and require no email or account.
Template / checklist for operators. Not legal advice. Not a certification.
Frame one plausible cyber-loss scenario, its assumptions, ownership, and next decision.
Best for: A risk has been raised, but the business impact, assumptions, or decision owner are still unclear.
Open checklistIdentify whether control evidence is complete, attributable, current, and reviewable.
Best for: A team needs to organize proof for a control without claiming that the control has been independently validated.
Open checklistClassify supplier dependency so due diligence and ongoing oversight match operational exposure.
Best for: A vendor is new, materially changing, renewing, or supporting a business-critical service.
Open checklistA practical checklist for reviewing governance outcomes in the NIST Cybersecurity Framework 2.0 Govern Function.
Best for: Leadership needs a shared view of cybersecurity governance, accountability, and oversight before selecting detailed controls.
Open checklistCreate an accountable inventory of AI use cases, data, owners, risks, and human oversight.
Best for: A team is introducing, renewing, or materially changing an AI-assisted workflow, vendor, or model.
Open checklist