$ ls resources/

Free Security Resources

Practical tools built from 25+ years of real GRC work. No fluff, no vendor pitch — just the frameworks and checklists that actually get used in audits.

Checklist · PDF

SOC 2 Readiness Checklist

42-item checklist covering all Trust Services Criteria common criteria — access controls, change management, incident response, vendor risk, and more.

Download Free →
Policy Template · PDF

AI Governance Policy Template

Ready-to-use policy template governing employee AI tool usage, data classification rules, prohibited uses, and incident reporting. Pairs with BitDrip for enforcement.

Download Free →
Interactive · 5 min

SMB Security Scorecard

15-question assessment across 5 security domains. See your maturity score, identify your top gaps, and get a breakdown by category. Results emailed to you.

Take the Assessment →
Interactive · Crosswalk

Compliance Framework Crosswalk

Pick a control in NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, or CMMC Level 2 and see exactly what maps to it in the other five — official sources only, gaps labeled honestly. Search everything, export any control or full catalog as a PDF.

Explore the Crosswalk →
Awareness · 2 min

Think Before You Scan

QR codes hide their destination. Learn what a malicious QR code could do, how to spot a suspicious scan, and five checks to make before scanning anything.

See the Guide →
Guide · Reference

How to Report Phishing

Practical steps for recognizing phishing emails, what to do if you clicked, and exactly where to report — from your IT team to CISA and the FTC.

Read the Guide →
Field References · 17 cards

Security Field Reference Library

17 terminal-styled reference cards covering NIST CSF, ISO 27001, HIPAA, CMMC 2.0, incident response, cloud hardening, BEC prevention, STRIDE, OWASP ASVS, DLP patterns, and more. Built from primary sources. Free, no gate.

Browse the Library →

Need hands-on help?

Resources help you see the gaps. A consultation helps you fix them.

Schedule a Free Consultation