// breach.cyber.essentials
Your cyber insurance renewal asks for these. Generic templates fail underwriter review. Each policy is fully drafted and delivered as a fillable PDF and editable Word docx, reviewed and signed by Jeff O'Connor, Principal at Breach Security LLC.
// why.breach
Cyber insurers are tightening underwriting. They're rejecting generic templates and asking for evidence that your policies reflect how your business actually operates. We built the system to answer that.
Each policy is delivered as a fillable PDF and editable Word docx, fully drafted and ready for your company name, designated officer, and practice-specific fields. Jeff O'Connor personally reviewed and signed every policy in the library. You download the finished, signed document instantly after purchase.
Every policy cites the specific controls it satisfies: NIST CSF 2.0, CIS Controls v8, and ISO 27001:2022. Each document maps content to primary-source citations so your auditor or underwriter can verify compliance without guesswork.
Written to satisfy the questions your cyber insurer asks at renewal and the vendor questionnaires your enterprise clients send before onboarding you. Not written to sit in a drawer.
// how.to.buy
Three ways in. Pick the option that matches how many policies your business needs.
All three options deliver the same quality: fully drafted, regulatory-cited, Jeff-signed policies, delivered as fillable PDF and editable Word docx. Instant download after purchase. The difference is scope.
Any one of the 12 policies. Use our policy picker to choose which one you need. Instant download: fillable PDF + editable Word docx. Customize in 5-10 minutes.
Buy Now →Pick any 5 of the 12 policies. Use our bundle picker to select the five that fit your business, then check out. Instant download: 10 files (PDF + docx per policy).
Build Your Bundle →All 12 policies, instant download. Complete cybersecurity policy library for any SMB, 24 files total (PDF + docx per policy). Covers every topic your cyber insurer and enterprise clients will ask about.
Get the Full Pack →// what's.in.the.catalog
12 modular security policies, each delivered as fillable PDF + editable Word docx. Browse the catalog below. Buy any one, pick a bundle of 5, or get the full pack. Use the purchasing options above.
What employees may and may not do on company systems and networks. Monitoring, personal use limits, and sanctions.
Rules for employee-owned devices accessing company data. Eligible devices, required controls, wipe rights, and offboarding.
Security expectations for off-premises work. Home network requirements, VPN access, public WiFi rules, and physical workspace standards.
Account credential and authentication standards. Password complexity, MFA scope, privileged-account rules, recovery flows, and shared-account ban.
How long data lives and how it ends. Retention schedules, legal hold exceptions, NIST 800-88 destruction standards, and backup expiry.
Vetting and ongoing oversight of third-party software and service providers. Due diligence, required vendor controls, SOC 2/ISO requirements by tier, and annual review cadence.
What you do when something breaks or gets breached. Roles and call tree, severity tiers, containment steps, external notification procedures, and post-incident review.
Keeping the business running through data loss and system failure. Backup scope, 3-2-1 rule, RPO/RTO targets, restore-test cadence, and DR process.
Company-owned mobile device governance (distinct from BYOD). Issued-device inventory, MDM enrollment, OS update policy, lost/stolen reporting, and return at offboarding.
Phishing defense and sensitive-data handling in email and messaging. Approved channels by data type, phishing reporting flow, encryption requirements, and auto-forwarding ban.
Office, server room, and paper records. Access control, visitor policy, clean-desk standard, locked storage for sensitive paper, and camera policy.
Provisioning and deprovisioning checklist. New-hire access grant, training acknowledgements, departure access revocation (same-day), asset return, and knowledge handoff.
Not sure which policy fits your business? Email support@breachsecurity.io with your industry and team size; we'll send a recommendation within 1 business day.
// how.it.works
Four steps from purchase to delivery.
Select the policies your business needs and complete checkout via Stripe. Secure payment, no account required.
You receive a magic-link download email within minutes of purchase. One click downloads a ZIP of your policies. No forms to fill, no waiting period.
Each policy ships fully drafted with placeholder fields for your company name, designated officer, and any practice-specific details. Click fields and type in any modern PDF viewer (Acrobat, Preview, Chrome) or use Find/Replace placeholders in Microsoft Word. Takes 5-10 minutes per policy.
Your completed policies cite NIST CSF 2.0, CIS Controls v8, and ISO 27001:2022 by name. Present them to your cyber insurer, auditor, or enterprise client with confidence.
// pricing
One-time per-policy purchase or bundle options. Annual refresh subscription available at $199/yr, covering all purchased policies.
Any one of the 12 policies. Use our policy picker to choose which one you need. Instant download: fillable PDF + editable Word docx pair. Fill in your company name and designated officer in 5-10 minutes.
Buy Now →Pick any 5 of the 12 policies. Use the bundle picker to choose your five, then check out. Instant download: 10 files total (fillable PDF + editable Word docx per policy). Customize each in 5-10 minutes.
Build Your Bundle →All 12 policies, instant download. Complete cybersecurity policy library for any SMB, 24 files total (fillable PDF + editable Word docx per policy). Covers every topic your cyber insurer and enterprise clients will ask about.
Get the Full Pack →Optional add-on. Annual policy updates as regulations and threat landscape change. Covers all purchased policies, once a year on your anniversary. Cancel anytime.
Add Annual Refresh →Covers all purchased policies. Cancel anytime.
// not.sure.what.you.need
Email support@breachsecurity.io with a brief description of your business and what you are trying to accomplish. We will tell you honestly which policies apply to your situation, whether our Cyber Essentials service is the right fit, or whether a custom consulting engagement is the better answer. No pressure, no upsell. If consulting is the better fit, we will quote it upfront before you commit to anything.
support@breachsecurity.io// faq
Is this AI-generated?
No. Our compliance team drafts each policy using a regulatory documentation framework built from primary sources (NIST, ISO, CIS). Claude, our AI drafting assistant, is used to polish prose and flag missing required clauses after the human draft is complete. Jeff O'Connor reads every output and edits before signing. We don't ship AI output directly and we don't pretend to.
How do I customize each policy for my business?
Each policy ships fully drafted with clearly marked placeholder fields: your company name, your designated officer, and any practice-specific details. Click fields and type in any modern PDF viewer (Acrobat, Preview, Chrome) or use Find/Replace on the placeholders in Microsoft Word. Most buyers finish in 5-10 minutes per policy. Regulatory language (required sub-sections, mandatory control citations) is already written in; you are filling in your organization's specifics, not drafting policy text from scratch.
Can I edit the documents after purchase?
Yes. Every policy is delivered as an editable Word (.docx) and a fillable PDF, so you can revise them as many times as you like on your own systems, at no extra cost.
Will this satisfy my cyber insurance application?
We build to the specific controls and language that underwriters ask for. Every policy maps to named controls in NIST CSF 2.0, CIS Controls v8, and ISO 27001:2022 and includes the framework citations in the document body. Whether any given underwriter accepts any given policy is ultimately their call. We cannot guarantee insurer acceptance, but we build to what insurers ask for, and Jeff personally reviewed every policy against current underwriting expectations before signing off on it.
What if I'm in a regulated industry (HIPAA, PCI-DSS, SOC 2)?
Cyber Essentials policies are designed for any SMB and are not vertical-specific. For HIPAA-regulated healthcare practices, see our Healthcare Compliance product line. For businesses with significant PCI or SOC 2 obligations, email us at support@breachsecurity.io before purchasing. We will tell you if Cyber Essentials covers your needs or if a custom engagement is more appropriate.
Who is Jeff O'Connor?
Jeff O'Connor is the Principal of Breach Security LLC, a cybersecurity services company registered in Georgetown, Indiana. He has built and operated automated trading systems, compliance documentation frameworks, and security infrastructure across several business domains. He reviewed and signed every Cyber Essentials policy in this library and collaborated on writing each one. His signature means a human expert built it and stands behind it.
How does the annual refresh subscription work?
Add the Annual Refresh subscription at $199/yr; it covers all your purchased policies (not per-policy). Each year on your purchase anniversary, we update your policy templates against the latest NIST, CIS, and ISO standards, compare them to what we delivered originally, and re-deliver updated files if anything has materially changed. If no material changes are needed, we will notify you that your policies remain current. Your subscription renews either way. Cancel anytime.
What is your refund policy?
If the Cyber Essentials service is not what you needed, email support@breachsecurity.io within 7 days of purchase for a full refund. Include your order ID. Refunds are issued back to your original payment method within 5 business days. See the full refund policy.
// annual.refresh
// optional add-on
Optional add-on. Annual policy updates as regulations and threat landscape change. Cancel anytime. Covers all purchased policies, once a year on your anniversary. When NIST, CIS, or ISO standards materially change, you receive updated, Jeff-signed documents automatically, no additional purchase needed.
Purchase the policies your business needs. You receive a download link by email within minutes: fillable PDF and editable Word docx, ready to customize in 5-10 minutes.