Templates
Two documents, and the fields that keep them alive.
A board report structure for the ten minutes you get on the agenda, and a risk register with the columns that make it maintainable. Both work in a spreadsheet and neither needs our software. Both are in preparation rather than published — so they are described here field by field, and each one names the page that covers the same ground today.
Self-service signup opens shortly — we will set you up in the meantime
Readiness moved from 68 to 76 since July. One critical risk is open, and the cyber insurance renewal is 96 days out.
Needs a decision
- Critical risk — ransomware via phishing on plant-floor workstations: approve the treatment or formally accept it with conditions.
- Two contracts expire inside 90 days: the shipping and EDI portal (20 October) and OT line-controller support (28 November).
- Finalise the Statement of Applicability before the Stage 1 readiness review on 20 October.
The board summary the report template is a manual version of — generated from the register, with every figure traceable to a record. Example workspace; Northstar Manufacturing Ltd. is fictional.
The templates
What will be in each, listed rather than summarised.
Neither is published yet. Setting them out in full anyway is the honest form of a coming-soon page: you can tell whether the document would answer your question, and a request tells us which to finish first.
template
In preparationBoard Cybersecurity Report Template
A structure for reporting security to a board that has ten minutes: where we are, what moved since last time, what is overdue, and the decisions that need them.
Who it helps
Whoever presents security to a board or audit committee — frequently a CTO, COO or finance lead who is not a security specialist and gets one slot on the agenda.
What it will contain
- A first page that answers the only question the board asked: our readiness position, the movement since the last report, and the two or three items that need a decision from them.
- A risk section that reports treatment decisions, owners and dates rather than a colour matrix nobody can act on.
- Wording for reporting a gap to a board without either alarming them or burying it.
- An incidents and near-misses section, with a note on what belongs in the minutes and what belongs in the appendix.
- A page for what the programme has cost and what the next period needs, because that question follows every security update ever given.
- A list of what to leave out: raw vulnerability counts, tool logos, and any figure you cannot trace back to a record.
template
In preparationCyber Risk Register Template
A register with the fields that make it maintainable — owner, treatment decision, linked control, review date — and no column that exists only to look thorough.
Who it helps
A team that ran one risk workshop, produced a genuinely good document, and has not opened it since — and now needs it for a renewal, an audit or a board pack.
What it will contain
- The columns: risk description, the asset or process affected, current assessment, controls already in place, treatment decision, owner, target date and review date.
- Worked entries for the risks most growing organisations actually carry, written the way a register entry should read rather than as a category.
- The four treatment decisions, and how to record the one you chose — including accepting a risk deliberately, which is a decision and not an omission.
- Scoring guidance that does not pretend a five-by-five grid is a measurement.
- Why the review date is the field that decides whether this document is still alive in six months, and who has to see it when that date arrives.
Asking goes through the contact page and reaches a person. There is no download handler on this site and nothing here pretends to be one, and there is no marketing consent box to tick.
Why these fields
Most registers die of the same four omissions.
The difference between a register that is still true next quarter and one that is quietly fiction is not the scoring method, the colour scheme or the number of columns. It is these four — which is why both templates look sparser than the ones you may have seen.
A person, not a team
Owner has to be one name. “IT”, “Security” and “Management” are all ways of writing down that nobody is accountable. When a real name goes in the cell, somebody notices when the date passes — and both templates are built to make an empty owner visible rather than easy.
The decision, written down
A risk entry without a treatment decision is an observation. Reduce it, avoid it, share it or accept it — and if you accept it, record who accepted it and when. Deliberate acceptance is a perfectly respectable answer; an unrecorded one looks like an oversight a year later.
A review date, and a reason to honour it
This is the field that decides whether the document is alive in six months. A register with no review dates is a snapshot of one afternoon’s thinking. A register with review dates that nobody surfaces is the same thing with extra columns.
Figures you can trace
Every number in a board report should be openable. If the only source for “87% complete” is the person who typed it, one sceptical director costs you the whole meeting. The template prefers counts of specific things over a percentage nobody can audit.
If nobody would notice its absence for a quarter, it was never a register.
Every field in both templates exists to answer one question: will anybody open this when nothing is due? A document that fails that test was never a register — it was a record of having held a workshop.
Method
Five steps once it is in front of you.
In this order, because each step depends on the one before it: you cannot record a treatment decision for an entry nobody owns, and you cannot review a register that has no dates in it.
- 01
Fill it in for the risks you actually have
Not a generic list borrowed from a standard. Six to twelve entries that describe your own exposure — the supplier holding your customer data, the admin account three people share, the backup nobody has restored from — beats forty inherited categories.
- 02
Put one name in every owner cell
Do this before you refine any wording. An entry without an owner cannot progress, and finding out that four entries have no plausible owner is itself one of the more useful outputs of the exercise.
- 03
Record the treatment decision you have actually made
Including the uncomfortable ones. If you are living with something because closing it costs more than it is worth this year, write that down with the person who decided it. That is a defensible position; a blank cell is not.
- 04
Set review dates you can defend
Tie them to something real — the renewal, the quarter end, the contract review — rather than scattering dates evenly. A date that coincides with a meeting which already exists is a date that gets honoured.
- 05
Report from it rather than rewriting it
When the board pack is due, the report should be a view of the register, not a fresh document assembled from memory. The moment those two diverge you have two versions of the truth, and the board is reading the one nobody maintains.
The honest limit
A template has no way to tell you a date has passed.
Everything above is achievable in a spreadsheet, and plenty of organisations run a respectable register that way for a year or two. What a file cannot do is notice — that the control owner left in March, that the evidence behind entry seven expired, or that a figure in last quarter’s board report no longer matches anything.
- The same columns — owner, treatment, rating as likelihood × severity, target date — the fields the template is built around
- 7 open, 5 mitigated — in the example workspace, counted rather than described
- One register, several audiences — a board, an underwriter, an auditor and a customer questionnaire — in files that becomes four documents that disagree
| Title | Category | Rating | Status | Owner | Treatment | Target |
|---|---|---|---|---|---|---|
| Ransomware via phishing on plant-floor engineering workstations | Cyber | Critical4×5 | Open | Priya Raman | Mitigate | 30 Nov 2026 |
| Privileged accounts without PAM / shared local admin credentials | Cyber | High3×4 | Open | Priya Raman | Mitigate | 31 Oct 2026 |
| Unpatched OT/SCADA vendor appliance (vendor-managed) | Third-party | High3×4 | Open | Marc Lévesque | Transfer | 15 Dec 2026 |
| Third-party logistics portal — no SOC 2 report available | Third-party | Medium3×3 | Open | Elena Kowalski | Mitigate | 05 Oct 2026 |
| MFA not enforced for all Microsoft 365 users | Cyber | Critical4×5 | Mitigated | Priya Raman | Mitigate | Closed 08 May 2026 |
- Ransomware via phishing on plant-floor engineering workstations
- Category
- Cyber
- Rating
- Critical4×5
- Status
- Open
- Owner
- Priya Raman
- Treatment
- Mitigate
- Target
- 30 Nov 2026
- Privileged accounts without PAM / shared local admin credentials
- Category
- Cyber
- Rating
- High3×4
- Status
- Open
- Owner
- Priya Raman
- Treatment
- Mitigate
- Target
- 31 Oct 2026
- Unpatched OT/SCADA vendor appliance (vendor-managed)
- Category
- Third-party
- Rating
- High3×4
- Status
- Open
- Owner
- Marc Lévesque
- Treatment
- Transfer
- Target
- 15 Dec 2026
- + 2 more in the workspace
Two ways to run it
Where the spreadsheet stops being the right tool.
Not a reason to buy anything this week. Run the template by hand for a quarter and this table will tell you which row you have started to resent.
| A spreadsheet register | Sentinel | |
|---|---|---|
| Getting started | Immediate, free, and nobody has to approve it. This is a real advantage and the reason to start here. | Same day, on a published price, with the register and the report already connected. |
| Ownership | A name typed in a cell. Nothing tells that person the date arrived. | A named owner on the control and the action, with the due date attached to them. |
| Review dates | Present, and dependent on somebody remembering the file exists. | Flagged in the evidence list — each item carries an expiry, so a lapsed one stands out. |
| Evidence | A folder somewhere else, linked by convention at best. | Attached to the control, with status and expiry on every item. |
| Board reporting | Rewritten each quarter from the register, from memory, the night before. | A view of the register, so every figure can be opened in front of the person asking. |
| Answering an insurer or a customer | Answered from scratch each time, because neither exercise knows what the other proved. | Answered once and reused, from the same controls and the same evidence. |
- Getting started
- Same day, on a published price, with the register and the report already connected.
- Ownership
- A named owner on the control and the action, with the due date attached to them.
- Review dates
- Flagged in the evidence list — each item carries an expiry, so a lapsed one stands out.
- Evidence
- Attached to the control, with status and expiry on every item.
- Board reporting
- A view of the register, so every figure can be opened in front of the person asking.
- Answering an insurer or a customer
- Answered once and reused, from the same controls and the same evidence.
- Getting started
- Immediate, free, and nobody has to approve it. This is a real advantage and the reason to start here.
- Ownership
- A name typed in a cell. Nothing tells that person the date arrived.
- Review dates
- Present, and dependent on somebody remembering the file exists.
- Evidence
- A folder somewhere else, linked by convention at best.
- Board reporting
- Rewritten each quarter from the register, from memory, the night before.
- Answering an insurer or a customer
- Answered from scratch each time, because neither exercise knows what the other proved.
The checklists tell you what to put in these
A register is easier to fill in after a readiness pass, because the gaps a checklist finds are the first entries worth recording. All three are described item by item on the guides page: Cyber Insurance Readiness Checklist, ISO 27001 Readiness Checklist, Security Questionnaire Checklist.
Straight answers
What a template does not settle.
A well-kept register and a clear board report make the conversations with your auditor, your broker and your directors much shorter. They do not decide the outcome of any of them, and it matters that the page says so.
Questions
Before you ask for one.
Six questions about the templates themselves — when they exist, what you may change, and what they will and will not stand up to.
Can I have one of these today?
What will they be — a spreadsheet, a document?
Can we change them, or put our own logo on them?
Is the board report template appropriate for an audit committee?
Will a completed risk register satisfy an auditor or an insurer?
Do we have to agree to marketing to get one?
Run the register by hand first.
Fill one in, work it for a quarter, and you will know exactly which parts you are tired of maintaining yourself. That is a far better reason to look at software than a feature list.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required