SteadyPoint Cyber Free Cyber Checkup →

Free templates · yours to adapt

The templates from the book — fillable, and yours.

Every policy, checklist, incident plan and register marked in Shit, I've Been Hacked! — as documents you can type into, sort, and drop your own business name into. Nothing held back, and none of it costs money.

27 templatesEditable & PDF — Word, Google Docs, Sheets, or print-ready PDFSMB1001-aligned

Unlock the template library

Subscribe to SteadyPoint Cyber emails to unlock immediate access to all 27 templates.

Subscription is required to access the library. We'll handle your email as described in our Privacy Policy.

Templates unlocked

Choose an individual template below, or download the complete pack as an optional ZIP.

The ZIP is optional. Every template is also available individually below.

Download safety: the pack contains standard PDF, Word and Excel files only — no macros, executables or password protection. Files are checked before publication.

The library

Twenty-seven templates, grouped by what they protect.

Open one, make it yours, and put it to work. Each is a starting point — not a finished document — so adjust it to how your business actually runs.

Incident response

Shit, We've Actually Been Hacked!

DOCXPDF

The 8-step Emergency Action Card. Print it, fill in your numbers, stick it on the wall.

Cyber Incident Response Policy

GOLDDOCXPDF

Who's responsible, who decides, and how you prepare and recover. Pairs with the Emergency Action Card.

Payments & fraud

Payment & Invoice Verification Policy

SILVERDOCXPDF

Makes verify-by-phone the required way you handle payments and bank-detail changes.

Bank Detail Change Protocol

SILVERDOCXPDF

The 7-step card for the single most-exploited action in any business. Laminate it.

Payment Authority Matrix

SILVERDOCXPDF

Who can initiate, who must approve, and what verification each payment needs.

Delegation Checklist

SILVERDOCXPDF

Ten questions to pin down and document your payment authority. Review it yearly.

Email Footer — Fraud Alert

DOCXPDF

A ready-to-paste fraud warning for your email signature — puts customers on alert too.

Policies — drop your business name in

Cybersecurity Policy

GOLDDOCXPDF

The one-page baseline policy — SMB1001 Control 21. Your house rules, in plain English.

Acceptable Use Policy

BRONZEDOCXPDF

How your devices, accounts and data may be used. The do's and don'ts, on a page.

Access & Identity Policy

SILVERDOCXPDF

Individual accounts, MFA, least privilege, and clean joiner/leaver handling.

Backup & Recovery Policy

BRONZEDOCXPDF

What you back up, the 3-2-1 rule, and how you know a restore actually works.

AI Usage Policy

GOLDDOCXPDF

The one-page rules from Chapter 10 — SMB1001 Control 27. What AI can and can't touch.

Onboarding & Offboarding Policy

SILVERDOCXPDF

Access right on day one, and gone on the last day. The two riskiest moments, handled.

Patch Management Policy

BRONZEDOCXPDF

Keep software current with the least effort — the cheapest high-impact control.

Mobile & Remote Working Policy

SILVERDOCXPDF

Simple rules for phones, laptops and working away from the office.

Governance & registers

Simple Risk Register

XLSXPDF

The sortable one — dropdowns for likelihood, impact and status, and five worked examples.

Asset & Vendor Registers

XLSXPDF

Two tabs: your digital assets, and every third party with access — tiered by risk.

Visitor Register

XLSXPDF

A simple sign-in sheet — SMB1001 Control 17.

Quarterly Cyber Review Agenda

DOCXPDF

Thirty minutes, six five-minute passes, the same every quarter. Treat it like a BAS date.

Self-Assessment Checklist

DOCXPDF

A five-minute Bronze / Silver / Gold sanity check. The gaps are next quarter's agenda.

Devices & cloud

Cloud Control Checklist

SILVERDOCXPDF

Lock your side of Microsoft 365 / Google Workspace — the 9-point Chapter 4 checklist.

People & culture

The 60-Minute Cyber Upgrade

DOCXPDF

If you only do five things, do these. Most people finish in under an hour.

I Clicked Something. Now What?

DOCXPDF

The no-blame poster for the moment after a wrong click. Print it near every desk.

12-Month Awareness Calendar

DOCXPDF

One 10-minute topic a month, tailored to your team.

Suppliers & buying help

Vendor Questions — MSP & SaaS

DOCXPDF

The 10 MSP questions and 5 SaaS questions, with what a good answer looks like.

Owner / Provider Responsibility Matrix

DOCXPDF

Agree who owns what with your IT provider, so nothing falls through the gap.

The Walk-Away Checklist

DOCXPDF

Five signals that should end a cyber sales conversation. Don't get fleeced.

How to make them yours

Adapt any template with your favourite AI assistant.

These are starting points. The fastest way to fit one to your business is to hand it to an AI assistant with a prompt like this — straight from the book:

"I run a [type of business] in [town], Australia, with [number] staff. Rewrite the policy below so it fits how my business actually works, in plain English my team will read. Keep it to one page. [paste the template]"

Two rules though: start a fresh chat, and never paste real customer names, bank details or staff records into a free AI tool. Chapter 10 of the book explains why, and what to use instead.

Where to next

Not sure which you need? Or want a hand?

Find your biggest gap first

Take the free 12-minute Cyber Check and we'll tell you which of these to reach for first, and in what order.

Take the free Cyber Check →

Do it (mostly) yourself — or don't

These templates are the do-it-yourself path. When a job's fiddly or the clock's against you, we can tailor, review and sign one off with you. That's the DI(m)Y™ promise.

See how it works →

Free Australian help worth bookmarking

The authorities the book leans on — all free, all worth knowing before you need them.