Guides

Practical guidance, and most of it is not behind a form.

Three readiness checklists, described here item by item — and six pages on this site that already go further than any of them. The order to read them in depends on what is due: a renewal, a customer security review, a certification decision or a board meeting. So this page is organised that way rather than by topic.

Self-service signup opens shortly — we will set you up in the meantime

State of the library: the three checklists are in preparation and none is published. The six long-form pages further down are written, corrected when a standard changes, and have never been gated.

Insurance readinessSentinel interface, reproduced

Underwriter questions

9 controls
  • Yes
    Multi-factor authentication (email, remote/VPN, admin)
  • Yes
    EDR / next-gen AV deployed & monitored
  • Partial
    Backups immutable/offline AND restore-tested
    Backups are immutable and off-site. The Q3 restore test has not been run yet; the Q2 report is the last dated proof.
  • Yes
    Email filtering / advanced threat protection
  • Partial
    Patch cadence with critical-vuln SLA
    Corporate assets meet a 14-day critical SLA. The OT line-controller gateway is vendor-managed and currently excluded.
  • Yes
    Documented & tested incident response plan
  • Yes
    Security awareness training + phishing sims
  • Partial
    Critical vendor / third-party risk reviews
    Eight of ten suppliers assessed and approved. Two high-criticality suppliers have not provided assurance reports.
  • Yes
    Encryption at rest & in transit
6
Evidenced
3
Partial
0
Not in place

The same nine questions the insurance checklist walks through — here in Sentinel, where each answer carries a note, an owner and a date, 96 days before the renewal. Example workspace; Northstar Manufacturing Ltd. is fictional.

Checklists

What will be in each one, listed rather than summarised.

None of these is published yet. Describing them in full anyway is the honest version of a coming-soon page: you can see whether the document would answer your question, and a request tells us which one to finish first.

  • checklist

    In preparation

    Cyber Insurance Readiness Checklist

    The control questions underwriters ask most often, in roughly the order a submission asks them, with the evidence each answer needs sitting behind it.

    Who it helps

    Whoever owns the renewal — often a finance or operations lead with no security team behind them — working four to eight weeks ahead of the submission date.

    What it will contain

    • The questions that recur across almost every application: where multi-factor authentication actually reaches, how privileged accounts are handled, whether backups have been restored from rather than merely taken, endpoint and email controls, patching cadence, and training.
    • What counts as evidence for each answer, and what an underwriter will read as an assertion with nothing behind it.
    • Two columns rather than one: the answer you can support today, and the answer you want to be able to give at the next renewal.
    • The questions that most often stall a submission because no single person owns the answer.
    • A short section on gaps worth disclosing plainly, with the remediation date, instead of papering over them.
  • checklist

    In preparation

    ISO 27001 Readiness Checklist

    A readiness pass over ISO/IEC 27001:2022 — the management system clauses first, then the Annex A themes, with the documented information each part expects.

    Who it helps

    A team that has been told to “get ISO 27001” and needs to size the work before committing to a certification body, a consultant or a budget line.

    What it will contain

    • Clauses 4 to 10 turned into questions: scope, leadership, risk assessment and treatment, objectives, competence, internal audit, management review, and how nonconformities are handled.
    • The 93 Annex A controls grouped by their four themes, each with a line for the applicability decision and the reason for it.
    • Which items an auditor expects to see as documented information, rather than as somebody describing what usually happens.
    • The Statement of Applicability, and the two habits that make one unusable.
    • A way to end up with an honest distance-to-go rather than a percentage that flatters you.
  • checklist

    In preparation

    Security Questionnaire Checklist

    The questions that appear in nearly every customer security review, and the answer set to build once so the next questionnaire is mostly a copy.

    Who it helps

    A founder, account executive or IT lead holding a sixty-question spreadsheet that is currently the only thing between them and a signed contract.

    What it will contain

    • The sections that recur: access control, encryption in transit and at rest, hosting and data residency, subprocessors, logging and retention, vulnerability management, incident response, personnel screening, and business continuity.
    • Where an answer needs a document attached to it and where a sentence is genuinely enough.
    • The questions where “not applicable” is the correct answer, and how to write it so it does not read as evasion.
    • What to do with a question you have to answer “no” to while the deal is still live.
    • A structure for recording each answer once, with its evidence, so the third questionnaire takes an afternoon instead of a week.

Asking goes through the contact page and reaches a person — there is no download handler on this site, and a button labelled “Download PDF” that opens a form is the kind of small lie a reader never forgives. Nothing is gated, and there is no marketing consent box to tick.

If the best thing we know sits behind a form, the form is the product.

The framework pages, the insurance readiness pages and the product pages are longer and more specific than any checklist here will be. Nobody has to ask for them, and there is no form in front of them.

Published, in the open

The most detailed material here is a page, not a document.

Six of them, in the order most readers need them. Each is corrected when the underlying standard or the product changes, which a PDF sitting in somebody’s downloads folder never is.

  1. 01

    What underwriters actually ask about, why those particular controls, and what a submission looks like when the evidence behind each answer already exists. The closest thing here to a full guide, and it is a page.

    Prepare for a renewal

  2. 02

    ISO 27001, SOC 2, NIST CSF 2.0 and CIS Controls v8.1 compared by who asks for them and what you end up holding. Read this before you commit a budget to the wrong token.

    Compare the frameworks

  3. 03

    Clauses 4 to 10, the 93 Annex A controls in their four themes, the Statement of Applicability, and where a first-time programme reliably underestimates the work.

    See the ISO 27001 mapping

  4. 04

    Type I against Type II, the Trust Services Criteria you actually need in scope, and the observation window that decides your timeline more than any control does.

    See the SOC 2 readiness profile

  5. 05

    The mechanics of an evidence library: status, expiry, ownership, and why the same artefact should answer an insurer, an auditor and a customer without being reassembled each time.

    See evidence workflows

  6. 06

    How a governance programme is put together when nobody on the team does this full time — ownership, cadence, and the reporting that comes out of the register rather than a deck.

    See the workflow

Method

Six steps, in this order, because each one needs the last.

Most readiness exercises fail in the same two places: they answer “yes” where the honest answer is “yes, but I could not prove it today”, and they finish without a single name against a single gap. The order below exists to stop both, and it works with any checklist — including one you write yourself.

  1. 01

    Pick the deadline, not the framework

    Whatever is actually due decides which checklist to open. A renewal in six weeks, a customer security review holding up a contract, a board meeting in the diary. Choosing by framework first is how a programme spends a quarter on scope and produces nothing anyone asked for.

  2. 02

    Answer it in one sitting, badly

    Go through the whole thing quickly and answer from what you know, including the answers you are not sure about. A rough pass over every question beats a perfect pass over the first third, because you are looking for the shape of the gap, not the wording.

  3. 03

    Mark the difference between “yes” and “yes, provably”

    This is the step everyone skips and the one that changes the outcome. For each yes, ask what you would hand over if somebody asked for proof this afternoon. If the answer is a description rather than an artefact, that is not a yes yet.

  4. 04

    Put one name against every gap

    Not a team, not a job title — a person. A gap with no name against it stays open indefinitely, and an auditor or an underwriter treats an unowned control as absent, because in practice it usually is.

  5. 05

    Date the ones that matter before the deadline

    Some gaps have to close before the submission goes in. Others can be disclosed with a date and a plan, which is a legitimate answer and reads far better than a silence somebody finds later. Decide which is which now, while there is still time to act on the first group.

  6. 06

    Put it somewhere it will be looked at again

    The last step decides whether any of this survives. A completed checklist in a downloads folder is worth almost nothing in three months. Whether that place is a shared register you maintain by hand or a workspace that raises the dates itself, it has to be somewhere with a reason to open it when nothing is due.

Afterwards

The completed checklist is the input, not the outcome.

What you have at the end of a good readiness pass is a list of gaps with names and dates against them. That list is worth keeping somewhere that will tell you when a date arrives — which is the job Sentinel does, and the only reason a software company publishes a library at all.

  • Gaps become tracked workbucketed by horizon — Critical Now, Next 30 Days, Next Quarter, Quick Wins, Strategic Projects
  • Answers become reusableattached to the control and the evidence behind it, so the next customer review starts mostly answered
  • Dates raise themselvesevidence carries an expiry, so a lapsed item reads as a gap without anybody remembering to check

See the workflow

Action centreSentinel interface, reproduced
Critical Now2Next 30 Days3Next Quarter3Quick Wins3Strategic Projects2
  • Run and document the Q3 backup restore test
    Module
    Audit
    Owner
    Jordan Blake
    Priority
    Critical
    Due
    30 Sep 2026
    Status
    Not started
  • Deploy privileged access management for shared admin accounts
    Module
    Risk
    Owner
    Priya Raman
    Priority
    Critical
    Due
    15 Oct 2026
    Status
    In progress
  • Obtain SOC 2 report from Great Lakes Logistics
    Module
    Vendors
    Owner
    Elena Kowalski
    Priority
    High
    Due
    05 Oct 2026
    Status
    In progress
  • + 2 more in the workspace

Straight answers

What a readiness guide cannot do.

Readiness material is exactly that. It tells you where you stand and what is missing. It does not confer a certificate, an opinion or a coverage decision, and any resource that implies otherwise is one to distrust.

Questions

Before you ask for one.

Six practical questions about the checklists themselves — when they exist, what format they take, and what happens to your email address.

Can I have one of these checklists today?
Not yet — none of the three is published, and this page says so rather than putting a download button in front of a contact form. Ask for the one you need and a person will tell you where it stands and which published page answers the same question in the meantime. For most deadlines the page is the better answer anyway.
What will they be, technically — a spreadsheet, a document?
Working documents rather than brochures: built to be filled in by more than one person, to survive being emailed around, and to work without any CyberWave software. There is no self-serve download handler on this site, so nothing here will ever be dressed up as one.
Are these specific to Canada?
The frameworks are international standards and the questions on a cyber application cover similar ground wherever it is written, so the substance travels. Where it matters — data residency in a customer questionnaire, for instance — the checklist asks you to state where your data is held rather than assuming an answer for you.
Can we use these with our own consultant or auditor?
Yes, and several are more useful that way. They are readiness material: they help you turn up to a scoping conversation knowing what you have, which is generally a cheaper way to buy professional time. Nothing in them is CyberWave-specific and nothing depends on our software.
Does asking put us in a sales sequence?
No. There is no lead score, no tiering and no drip sequence — and no mailing list to add you to, because commercial email is on hold until we can send it to the Canadian standard properly. There is no marketing consent box on any page either, because there is no programme to consent to.
Is there anything longer than a checklist?
Yes — the six pages listed above, all published. The framework pages and the insurance readiness page carry more detail than any of the checklists will, and there is no form in front of them. If you want the most substance for the least commitment, start there.

Work through one readiness pass. You will know what you are dealing with.

An afternoon on the right questions tells you more about your position than a quarter of meetings about it. Bring what you find and we will tell you honestly whether software is the answer.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required