Guides
Practical guidance, and most of it is not behind a form.
Three readiness checklists, described here item by item — and six pages on this site that already go further than any of them. The order to read them in depends on what is due: a renewal, a customer security review, a certification decision or a board meeting. So this page is organised that way rather than by topic.
Self-service signup opens shortly — we will set you up in the meantime
State of the library: the three checklists are in preparation and none is published. The six long-form pages further down are written, corrected when a standard changes, and have never been gated.
Underwriter questions
9 controls- YesMulti-factor authentication (email, remote/VPN, admin)
- YesEDR / next-gen AV deployed & monitored
- PartialBackups immutable/offline AND restore-testedBackups are immutable and off-site. The Q3 restore test has not been run yet; the Q2 report is the last dated proof.
- YesEmail filtering / advanced threat protection
- PartialPatch cadence with critical-vuln SLACorporate assets meet a 14-day critical SLA. The OT line-controller gateway is vendor-managed and currently excluded.
- YesDocumented & tested incident response plan
- YesSecurity awareness training + phishing sims
- PartialCritical vendor / third-party risk reviewsEight of ten suppliers assessed and approved. Two high-criticality suppliers have not provided assurance reports.
- YesEncryption at rest & in transit
The same nine questions the insurance checklist walks through — here in Sentinel, where each answer carries a note, an owner and a date, 96 days before the renewal. Example workspace; Northstar Manufacturing Ltd. is fictional.
Checklists
What will be in each one, listed rather than summarised.
None of these is published yet. Describing them in full anyway is the honest version of a coming-soon page: you can see whether the document would answer your question, and a request tells us which one to finish first.
checklist
In preparationCyber Insurance Readiness Checklist
The control questions underwriters ask most often, in roughly the order a submission asks them, with the evidence each answer needs sitting behind it.
Who it helps
Whoever owns the renewal — often a finance or operations lead with no security team behind them — working four to eight weeks ahead of the submission date.
What it will contain
- The questions that recur across almost every application: where multi-factor authentication actually reaches, how privileged accounts are handled, whether backups have been restored from rather than merely taken, endpoint and email controls, patching cadence, and training.
- What counts as evidence for each answer, and what an underwriter will read as an assertion with nothing behind it.
- Two columns rather than one: the answer you can support today, and the answer you want to be able to give at the next renewal.
- The questions that most often stall a submission because no single person owns the answer.
- A short section on gaps worth disclosing plainly, with the remediation date, instead of papering over them.
checklist
In preparationISO 27001 Readiness Checklist
A readiness pass over ISO/IEC 27001:2022 — the management system clauses first, then the Annex A themes, with the documented information each part expects.
Who it helps
A team that has been told to “get ISO 27001” and needs to size the work before committing to a certification body, a consultant or a budget line.
What it will contain
- Clauses 4 to 10 turned into questions: scope, leadership, risk assessment and treatment, objectives, competence, internal audit, management review, and how nonconformities are handled.
- The 93 Annex A controls grouped by their four themes, each with a line for the applicability decision and the reason for it.
- Which items an auditor expects to see as documented information, rather than as somebody describing what usually happens.
- The Statement of Applicability, and the two habits that make one unusable.
- A way to end up with an honest distance-to-go rather than a percentage that flatters you.
checklist
In preparationSecurity Questionnaire Checklist
The questions that appear in nearly every customer security review, and the answer set to build once so the next questionnaire is mostly a copy.
Who it helps
A founder, account executive or IT lead holding a sixty-question spreadsheet that is currently the only thing between them and a signed contract.
What it will contain
- The sections that recur: access control, encryption in transit and at rest, hosting and data residency, subprocessors, logging and retention, vulnerability management, incident response, personnel screening, and business continuity.
- Where an answer needs a document attached to it and where a sentence is genuinely enough.
- The questions where “not applicable” is the correct answer, and how to write it so it does not read as evasion.
- What to do with a question you have to answer “no” to while the deal is still live.
- A structure for recording each answer once, with its evidence, so the third questionnaire takes an afternoon instead of a week.
Asking goes through the contact page and reaches a person — there is no download handler on this site, and a button labelled “Download PDF” that opens a form is the kind of small lie a reader never forgives. Nothing is gated, and there is no marketing consent box to tick.
If the best thing we know sits behind a form, the form is the product.
The framework pages, the insurance readiness pages and the product pages are longer and more specific than any checklist here will be. Nobody has to ask for them, and there is no form in front of them.
Published, in the open
The most detailed material here is a page, not a document.
Six of them, in the order most readers need them. Each is corrected when the underlying standard or the product changes, which a PDF sitting in somebody’s downloads folder never is.
- 01
Insurance
Cyber insurance readiness
What underwriters actually ask about, why those particular controls, and what a submission looks like when the evidence behind each answer already exists. The closest thing here to a full guide, and it is a page.
- 02
Frameworks
Which framework you actually need
ISO 27001, SOC 2, NIST CSF 2.0 and CIS Controls v8.1 compared by who asks for them and what you end up holding. Read this before you commit a budget to the wrong token.
- 03
ISO/IEC 27001:2022
The management system, clause by clause
Clauses 4 to 10, the 93 Annex A controls in their four themes, the Statement of Applicability, and where a first-time programme reliably underestimates the work.
- 04
Type I against Type II, the Trust Services Criteria you actually need in scope, and the observation window that decides your timeline more than any control does.
- 05
The mechanics of an evidence library: status, expiry, ownership, and why the same artefact should answer an insurer, an auditor and a customer without being reassembled each time.
- 06
Governance
Requirements to evidence to report
How a governance programme is put together when nobody on the team does this full time — ownership, cadence, and the reporting that comes out of the register rather than a deck.
Method
Six steps, in this order, because each one needs the last.
Most readiness exercises fail in the same two places: they answer “yes” where the honest answer is “yes, but I could not prove it today”, and they finish without a single name against a single gap. The order below exists to stop both, and it works with any checklist — including one you write yourself.
- 01
Pick the deadline, not the framework
Whatever is actually due decides which checklist to open. A renewal in six weeks, a customer security review holding up a contract, a board meeting in the diary. Choosing by framework first is how a programme spends a quarter on scope and produces nothing anyone asked for.
- 02
Answer it in one sitting, badly
Go through the whole thing quickly and answer from what you know, including the answers you are not sure about. A rough pass over every question beats a perfect pass over the first third, because you are looking for the shape of the gap, not the wording.
- 03
Mark the difference between “yes” and “yes, provably”
This is the step everyone skips and the one that changes the outcome. For each yes, ask what you would hand over if somebody asked for proof this afternoon. If the answer is a description rather than an artefact, that is not a yes yet.
- 04
Put one name against every gap
Not a team, not a job title — a person. A gap with no name against it stays open indefinitely, and an auditor or an underwriter treats an unowned control as absent, because in practice it usually is.
- 05
Date the ones that matter before the deadline
Some gaps have to close before the submission goes in. Others can be disclosed with a date and a plan, which is a legitimate answer and reads far better than a silence somebody finds later. Decide which is which now, while there is still time to act on the first group.
- 06
Put it somewhere it will be looked at again
The last step decides whether any of this survives. A completed checklist in a downloads folder is worth almost nothing in three months. Whether that place is a shared register you maintain by hand or a workspace that raises the dates itself, it has to be somewhere with a reason to open it when nothing is due.
Afterwards
The completed checklist is the input, not the outcome.
What you have at the end of a good readiness pass is a list of gaps with names and dates against them. That list is worth keeping somewhere that will tell you when a date arrives — which is the job Sentinel does, and the only reason a software company publishes a library at all.
- Gaps become tracked work — bucketed by horizon — Critical Now, Next 30 Days, Next Quarter, Quick Wins, Strategic Projects
- Answers become reusable — attached to the control and the evidence behind it, so the next customer review starts mostly answered
- Dates raise themselves — evidence carries an expiry, so a lapsed item reads as a gap without anybody remembering to check
| Action | Module | Owner | Priority | Due | Status |
|---|---|---|---|---|---|
| Run and document the Q3 backup restore test | Audit | Jordan Blake | Critical | 30 Sep 2026 | Not started |
| Deploy privileged access management for shared admin accounts | Risk | Priya Raman | Critical | 15 Oct 2026 | In progress |
| Obtain SOC 2 report from Great Lakes Logistics | Vendors | Elena Kowalski | High | 05 Oct 2026 | In progress |
| Approve the Data Retention & Disposal Policy | Policies | Dana Whitfield | High | 10 Oct 2026 | Not started |
| Tabletop exercise with plant leadership — ransomware scenario | Risk | Dana Whitfield | Medium | 20 Nov 2026 | Not started |
- Run and document the Q3 backup restore test
- Module
- Audit
- Owner
- Jordan Blake
- Priority
- Critical
- Due
- 30 Sep 2026
- Status
- Not started
- Deploy privileged access management for shared admin accounts
- Module
- Risk
- Owner
- Priya Raman
- Priority
- Critical
- Due
- 15 Oct 2026
- Status
- In progress
- Obtain SOC 2 report from Great Lakes Logistics
- Module
- Vendors
- Owner
- Elena Kowalski
- Priority
- High
- Due
- 05 Oct 2026
- Status
- In progress
- + 2 more in the workspace
Straight answers
What a readiness guide cannot do.
Readiness material is exactly that. It tells you where you stand and what is missing. It does not confer a certificate, an opinion or a coverage decision, and any resource that implies otherwise is one to distrust.
Questions
Before you ask for one.
Six practical questions about the checklists themselves — when they exist, what format they take, and what happens to your email address.
Can I have one of these checklists today?
What will they be, technically — a spreadsheet, a document?
Are these specific to Canada?
Can we use these with our own consultant or auditor?
Does asking put us in a sales sequence?
Is there anything longer than a checklist?
Work through one readiness pass. You will know what you are dealing with.
An afternoon on the right questions tells you more about your position than a quarter of meetings about it. Bring what you find and we will tell you honestly whether software is the answer.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required