Bitweb
For companies with 1–100 staff

The paperwork your cyber-insurer and your biggest customer keep asking for.

Written security policies, an incident response plan you can run at 2 a.m., and an IT asset register with a red-flag dashboard. Editable Word and Excel files, ready in an afternoon — no consultant.

Get the complete kit · CA$39 Buy individually Instant download · Secure checkout by Stripe
Cyber Liability Application — Section CControls
C.4Does the applicant maintain written information-security policies that are acknowledged by employees?YesNo
C.7Does the applicant have a documented incident response plan that is tested at least annually?YesNo
C.9Does the applicant maintain an inventory of hardware, software and user accounts, with MFA enforced?YesNo
C.11Are user access rights reviewed at least every six months?YesNo

Representative wording. Each "Yes" above is backed by a specific document in the kit.

Mapped to CIS Controls v8 IG1NIST CSF 2.0 & SP 800-61Canadian privacy contacts pre-filled (PIPEDA)Single-organisation licence
Products

Three documents. One afternoon.

Cybersecurity Policy Bundle cover and sample pages
POL-01 … POL-08.docx · 20 pages

Small Business Cybersecurity Policy Bundle

  • 8 plain-English policies: Acceptable Use, Passwords & MFA, Access Control, Data & Backup, Remote/BYOD, Phishing, Incident Response, Vendors
  • Staff acknowledgement form and exceptions log
  • Every policy mapped to the CIS / NIST control it supports
CA$24Buy
Incident Response Plan cover and sample pages
IRP + LOG.docx 13 pages + .xlsx

Cyber Incident Response Plan & Ransomware Playbook

  • Roles, severity levels, and a 9-step first-hour checklist
  • Playbooks for ransomware, compromised email, and lost devices
  • Incident log, contact roster, post-incident review, tabletop scenarios
CA$19Buy
IT Asset and Access Register dashboard
REG · 5 tabs.xlsx · Google Sheets OK

IT Asset & Access Register

  • Hardware, SaaS, and user-access registers with dropdowns and formulas
  • Joiner / leaver checklist (19 tasks)
  • Dashboard that flags unencrypted devices, missing MFA, overdue reviews
CA$12Buy
Small Business Cyber Compliance Kit
Complete kit

Small Business Cyber Compliance Kit

All three products — 2 Word files and 2 Excel workbooks. Enough to answer every question in the sample application above with a document, not a promise.

CA$39CA$55SAVE 30%
Get the complete kit
What's inside

Which document answers which question

AskAnswered byControl reference
Written, acknowledged security policiesPolicy Bundle — 8 policies + Acknowledgement Form (Appendix C)CIS 14 · NIST PR.AT
Password and MFA standardPolicy Bundle — POL-02 (14+ char passphrases, password manager, MFA on email/admin/finance)CIS 5, 6 · PR.AA
Documented incident response planIR Plan — roles, severity matrix, first-hour checklist, three playbooksCIS 17 · NIST RS · SP 800-61
Plan is testedIR Plan §9 + workbook "Tabletop Scenarios" tab (4 ready-to-run scenarios)CIS 17.7
Backups and recoveryPolicy Bundle — POL-04 (3-2-1 rule, immutable copy, quarterly restore test) + IR Plan §5.5 recovery priorityCIS 11 · PR.DS
Asset inventoryRegister — "Assets" and "Software & SaaS" tabsCIS 1, 2
Access reviews / offboardingRegister — "Users & Access" (auto OVERDUE flag) and "Onboarding-Offboarding" tabsCIS 5, 6
Vendor / third-party riskPolicy Bundle — POL-08 + Register "Software & SaaS" as vendor registerCIS 15 · GV.SC
Breach notification dutiesIR Plan §5.3, §7.3 template, contact roster with privacy regulatorPIPEDA s.10.1
Who it's for

Built for the person who got handed the questionnaire

OWNERYou were asked for "your security policies" by an insurer, a bank, or a customer, and you have none written down.
OFFICE MGRYou look after the laptops, the logins and the leavers, and want one place to track it that proves you did.
IT LEAD / MSPYou need client-ready documents you can brand and hand over without writing from scratch.
G
Written by a working IT technician, not a content farm.

The author supports 400+ users across multiple sites in British Columbia, holds Security Pro, Client Pro, Hybrid Server Pro and PC Pro certifications, and is completing CompTIA Security+. These are the documents actually used in the field, trimmed to what a small business will read and follow.

Guides

Read before you buy

FAQ

Before you buy

How do I get the files?

Immediately after checkout, the confirmation page shows a download link and Stripe emails you a receipt. Save the link; it does not expire. Files are a ZIP of .docx / .xlsx that open in Word, Excel, Google Docs/Sheets, LibreOffice and Pages.

How much editing is needed?

Find & Replace [Company Name], fill in the bracketed fields (each document has a checklist of them), delete anything you don't actually do. Most businesses finish the policy bundle in an hour and the incident plan in another.

Will this pass a SOC 2 or ISO 27001 audit?

No — those need an audited program, not templates. This kit covers the foundational controls those frameworks build on (CIS v8 IG1), which is what cyber-insurers, enterprise procurement teams and readiness assessors look for first.

Is this legal advice?

No. The documents are general information written to common standards. Notification duties and insurance obligations vary by jurisdiction and policy; confirm specifics with your counsel and insurer.

Can I use it for more than one company?

The licence covers one organisation. MSPs and consultants who want to deploy it across clients: reply to your receipt email for multi-client pricing.

Refunds?

Because the files are delivered instantly, refunds aren't offered on downloads. If a file is broken or not as described, reply to your receipt and it will be fixed or refunded.