Implementation kits built from this index's own framework: the problems worth naming, the fixes under each, and every action with an owner and a time-box.
These contain no third-party research. Every question, action and owner in a kit was written here. No publisher is named, quoted or cited anywhere in them — that material lives on the research side of this site, where it is free and links to the organization that published it. A kit that breaks that line is not published.
How a kit works
Every kit is the same five documents, used in the same order. Together they take a team from "we are probably fine" to a plan with names against it.
Run the diagnostic. One question per problem worth checking for, with the statement underneath so a room can agree what it is answering. This is one meeting, not a survey. Anything marked no or unsure is the only part of the rest you need — most teams find they own about a third of the list.
Cut the action plan down. Every fix, broken into discrete actions with a role and a window against each. Delete the fixes for the questions you answered yes, and what remains is your programme.
Hand out the owner map. The same actions regrouped by who holds them, so each person gets their column without reading anyone else's.
Work the sequence. The same actions again, ordered by horizon, so the first thirty days are a list rather than a judgement call.
What you get
Twelve files. Four sections plus a guide, each in Word and PDF — editable for the version you circulate, printable for the room.
Unbranded on purpose
The .docx files carry no logo and no watermark. Put your own name on them and issue them as your own work; that is what they are for.
They do not go stale
Kits are generated from the same framework the research side renders. When the underlying work is revised the kit is reissued with it, not a year later.
Try before you buy
The diagnostic is free, in full, for every kit. It is the section that tells you whether you need the rest.
The kits
Governance & oversight
$129
A working kit for governance & oversight: what to check, what to do about each gap, and who owns it by when.
32diagnostic questions
49fixes
138owned actions
12roles assigned
7areas covered
54pages
5 documents · 54 pages · Word and PDF · 12 files in the download
1-how-to-use
How to use this kit
3 pp
Word + PDF
2-diagnostic
Diagnostic
8 pp
Word + PDF
3-action-plan
Action plan
22 pp
Word + PDF
4-owner-map
Owner map
11 pp
Word + PDF
5-sequence
Sequence
10 pp
Word + PDF
README
Contents and order of use
—
Text
LICENCE
What you may do with it
—
Text
What is in it
A diagnostic — 32 questions, one per problem worth checking for, written so a yes/no answer tells you whether you have it.
An action plan — 49 fixes broken into 138 discrete actions, each with a named role and a time-box.
An owner map — work already assigned across 12 roles: Risk (31), CIO (25), Board Chair (15), CFO (13), Legal (10).
A sequence — actions grouped by horizon: 0-30 days (46), 30-90 days (57), 90-180 days (15), ongoing (20).
Editable source — the whole kit as a document you can put your own name on.
Owners are named as they exist in a company with a formal board.
12 files · 601 KB
Private company or scale-up
Board-level roles are remapped to the people who actually hold them in a company without a formal committee structure.
12 files · 601 KB
Advisory and consulting
The owner column names who at the CLIENT holds each action, and the guide is written as an engagement rather than an internal programme.
12 files · 597 KB
$79 one-off, updates included · store not live yet — the sample below is the full diagnostic.
Security & threat model
$79
A working kit for security & threat model: what to check, what to do about each gap, and who owns it by when.
16diagnostic questions
16fixes
46owned actions
11roles assigned
6areas covered
26pages
5 documents · 26 pages · Word and PDF · 12 files in the download
1-how-to-use
How to use this kit
3 pp
Word + PDF
2-diagnostic
Diagnostic
6 pp
Word + PDF
3-action-plan
Action plan
8 pp
Word + PDF
4-owner-map
Owner map
5 pp
Word + PDF
5-sequence
Sequence
4 pp
Word + PDF
README
Contents and order of use
—
Text
LICENCE
What you may do with it
—
Text
What is in it
A diagnostic — 16 questions, one per problem worth checking for, written so a yes/no answer tells you whether you have it.
An action plan — 16 fixes broken into 46 discrete actions, each with a named role and a time-box.
An owner map — work already assigned across 11 roles: Head of security engineering (12), CISO (11), Head of architecture (5), Head of identity (5), Head of security operations (4).
A sequence — actions grouped by horizon: 0-30 days (16), 30-90 days (17), 90-180 days (12), ongoing (1).
Editable source — the whole kit as a document you can put your own name on.
Owners are named as they exist in a company with a formal board.
12 files · 592 KB
Private company or scale-up
Board-level roles are remapped to the people who actually hold them in a company without a formal committee structure.
12 files · 591 KB
Advisory and consulting
The owner column names who at the CLIENT holds each action, and the guide is written as an engagement rather than an internal programme.
12 files · 587 KB
$59 one-off, updates included · store not live yet — the sample below is the full diagnostic.
Data readiness
$59
A working kit for data readiness: what to check, what to do about each gap, and who owns it by when.
12diagnostic questions
12fixes
33owned actions
8roles assigned
5areas covered
22pages
5 documents · 22 pages · Word and PDF · 12 files in the download
1-how-to-use
How to use this kit
3 pp
Word + PDF
2-diagnostic
Diagnostic
5 pp
Word + PDF
3-action-plan
Action plan
6 pp
Word + PDF
4-owner-map
Owner map
4 pp
Word + PDF
5-sequence
Sequence
4 pp
Word + PDF
README
Contents and order of use
—
Text
LICENCE
What you may do with it
—
Text
What is in it
A diagnostic — 12 questions, one per problem worth checking for, written so a yes/no answer tells you whether you have it.
An action plan — 12 fixes broken into 33 discrete actions, each with a named role and a time-box.
An owner map — work already assigned across 8 roles: Head of data engineering (13), Chief data officer (7), Head of architecture (5), CFO (2), COO (2).
A sequence — actions grouped by horizon: 0-30 days (12), 30-90 days (12), 90-180 days (8), ongoing (1).
Editable source — the whole kit as a document you can put your own name on.