← back to shop

// breach.cyber.essentials

Cybersecurity policies,
instant download, ready to
customize in minutes.

Your cyber insurance renewal asks for these. Generic templates fail underwriter review. Each policy is fully drafted and delivered as a fillable PDF and editable Word docx, reviewed and signed by Jeff O'Connor, Principal at Breach Security LLC.

Instant Download After Purchase NIST CSF 2.0 + CIS Controls v8 + ISO 27001:2022 Cyber-Insurance Ready Human-Reviewed, Jeff-Signed

// why.breach

Why This Exists

Cyber insurers are tightening underwriting. They're rejecting generic templates and asking for evidence that your policies reflect how your business actually operates. We built the system to answer that.

01

Instant download: customize in 5-10 minutes

Each policy is delivered as a fillable PDF and editable Word docx, fully drafted and ready for your company name, designated officer, and practice-specific fields. Jeff O'Connor personally reviewed and signed every policy in the library. You download the finished, signed document instantly after purchase.

02

Regulatory-citation-mapped

Every policy cites the specific controls it satisfies: NIST CSF 2.0, CIS Controls v8, and ISO 27001:2022. Each document maps content to primary-source citations so your auditor or underwriter can verify compliance without guesswork.

03

Cyber-insurance and vendor-questionnaire ready

Written to satisfy the questions your cyber insurer asks at renewal and the vendor questionnaires your enterprise clients send before onboarding you. Not written to sit in a drawer.

// how.to.buy

How to Buy

Three ways in. Pick the option that matches how many policies your business needs.

// choose.your.path

All three options deliver the same quality: fully drafted, regulatory-cited, Jeff-signed policies, delivered as fillable PDF and editable Word docx. Instant download after purchase. The difference is scope.

Single Policy
$299

Any one of the 12 policies. Use our policy picker to choose which one you need. Instant download: fillable PDF + editable Word docx. Customize in 5-10 minutes.

Buy Now →
Full 12-Policy Pack
$1,799 best value

All 12 policies, instant download. Complete cybersecurity policy library for any SMB, 24 files total (PDF + docx per policy). Covers every topic your cyber insurer and enterprise clients will ask about.

Get the Full Pack →

// what's.in.the.catalog

// what's in the catalog

12 modular security policies, each delivered as fillable PDF + editable Word docx. Browse the catalog below. Buy any one, pick a bundle of 5, or get the full pack. Use the purchasing options above.

01

Acceptable Use Policy

What employees may and may not do on company systems and networks. Monitoring, personal use limits, and sanctions.

NIST CSF PR.AT ISO 27001 A.5.10 CIS Control 14
02
// Available Now

BYOD Policy

Rules for employee-owned devices accessing company data. Eligible devices, required controls, wipe rights, and offboarding.

NIST SP 800-124 ISO 27001 A.6.2.1 CIS Control 4
03

Remote Work Policy

Security expectations for off-premises work. Home network requirements, VPN access, public WiFi rules, and physical workspace standards.

NIST CSF PR.AC ISO 27001 A.6.2.2 CISA Telework
04
// Available Now

Password & MFA Policy

Account credential and authentication standards. Password complexity, MFA scope, privileged-account rules, recovery flows, and shared-account ban.

NIST SP 800-63B ISO 27001 A.9.4 CIS Control 6
05

Data Retention & Destruction Policy

How long data lives and how it ends. Retention schedules, legal hold exceptions, NIST 800-88 destruction standards, and backup expiry.

NIST SP 800-88 ISO 27001 A.8.3
06

Vendor Risk Management Policy

Vetting and ongoing oversight of third-party software and service providers. Due diligence, required vendor controls, SOC 2/ISO requirements by tier, and annual review cadence.

NIST SP 800-161 ISO 27001 A.5.19 CIS Control 15
07
// Available Now

Incident Response Policy

What you do when something breaks or gets breached. Roles and call tree, severity tiers, containment steps, external notification procedures, and post-incident review.

NIST SP 800-61r2 ISO 27001 A.5.24 CIS Control 17
08

Backup & Disaster Recovery Policy

Keeping the business running through data loss and system failure. Backup scope, 3-2-1 rule, RPO/RTO targets, restore-test cadence, and DR process.

NIST SP 800-34 ISO 27001 A.8.13 CIS Control 11
09

Mobile Device Management Policy

Company-owned mobile device governance (distinct from BYOD). Issued-device inventory, MDM enrollment, OS update policy, lost/stolen reporting, and return at offboarding.

NIST SP 800-124 ISO 27001 A.8.1 CIS Control 4
10

Email & Communication Security Policy

Phishing defense and sensitive-data handling in email and messaging. Approved channels by data type, phishing reporting flow, encryption requirements, and auto-forwarding ban.

NIST CSF PR.DS ISO 27001 A.8.10 CIS Control 9
11

Physical Security Policy

Office, server room, and paper records. Access control, visitor policy, clean-desk standard, locked storage for sensitive paper, and camera policy.

ISO 27001 A.7 CIS Control 12 NIST SP 800-53 PE
12

Onboarding & Offboarding Policy

Provisioning and deprovisioning checklist. New-hire access grant, training acknowledgements, departure access revocation (same-day), asset return, and knowledge handoff.

NIST CSF PR.IP-11 ISO 27001 A.6.1 CIS Control 6

Not sure which policy fits your business? Email support@breachsecurity.io with your industry and team size; we'll send a recommendation within 1 business day.

// how.it.works

How It Works

Four steps from purchase to delivery.

01

Buy

Select the policies your business needs and complete checkout via Stripe. Secure payment, no account required.

02

Instant Download

You receive a magic-link download email within minutes of purchase. One click downloads a ZIP of your policies. No forms to fill, no waiting period.

03

Open and Customize

Each policy ships fully drafted with placeholder fields for your company name, designated officer, and any practice-specific details. Click fields and type in any modern PDF viewer (Acrobat, Preview, Chrome) or use Find/Replace placeholders in Microsoft Word. Takes 5-10 minutes per policy.

04

Done: Insurance and Audit Ready

Your completed policies cite NIST CSF 2.0, CIS Controls v8, and ISO 27001:2022 by name. Present them to your cyber insurer, auditor, or enterprise client with confidence.

// pricing

Pricing

One-time per-policy purchase or bundle options. Annual refresh subscription available at $199/yr, covering all purchased policies.

Single Policy
$299 per policy

Any one of the 12 policies. Use our policy picker to choose which one you need. Instant download: fillable PDF + editable Word docx pair. Fill in your company name and designated officer in 5-10 minutes.

Buy Now →

7-day refund policy

Bundle of 5
$999 saves $496

Pick any 5 of the 12 policies. Use the bundle picker to choose your five, then check out. Instant download: 10 files total (fillable PDF + editable Word docx per policy). Customize each in 5-10 minutes.

Build Your Bundle →

7-day refund policy

Annual Refresh
$199/yr

Optional add-on. Annual policy updates as regulations and threat landscape change. Covers all purchased policies, once a year on your anniversary. Cancel anytime.

Add Annual Refresh →

Covers all purchased policies. Cancel anytime.

// not.sure.what.you.need

Not Sure Which Policies Fit Your Business?

Send us your situation. Response within one business day.

Email support@breachsecurity.io with a brief description of your business and what you are trying to accomplish. We will tell you honestly which policies apply to your situation, whether our Cyber Essentials service is the right fit, or whether a custom consulting engagement is the better answer. No pressure, no upsell. If consulting is the better fit, we will quote it upfront before you commit to anything.

support@breachsecurity.io

// faq

Frequently Asked Questions

Is this AI-generated?

No. Our compliance team drafts each policy using a regulatory documentation framework built from primary sources (NIST, ISO, CIS). Claude, our AI drafting assistant, is used to polish prose and flag missing required clauses after the human draft is complete. Jeff O'Connor reads every output and edits before signing. We don't ship AI output directly and we don't pretend to.

How do I customize each policy for my business?

Each policy ships fully drafted with clearly marked placeholder fields: your company name, your designated officer, and any practice-specific details. Click fields and type in any modern PDF viewer (Acrobat, Preview, Chrome) or use Find/Replace on the placeholders in Microsoft Word. Most buyers finish in 5-10 minutes per policy. Regulatory language (required sub-sections, mandatory control citations) is already written in; you are filling in your organization's specifics, not drafting policy text from scratch.

Can I edit the documents after purchase?

Yes. Every policy is delivered as an editable Word (.docx) and a fillable PDF, so you can revise them as many times as you like on your own systems, at no extra cost.

Will this satisfy my cyber insurance application?

We build to the specific controls and language that underwriters ask for. Every policy maps to named controls in NIST CSF 2.0, CIS Controls v8, and ISO 27001:2022 and includes the framework citations in the document body. Whether any given underwriter accepts any given policy is ultimately their call. We cannot guarantee insurer acceptance, but we build to what insurers ask for, and Jeff personally reviewed every policy against current underwriting expectations before signing off on it.

What if I'm in a regulated industry (HIPAA, PCI-DSS, SOC 2)?

Cyber Essentials policies are designed for any SMB and are not vertical-specific. For HIPAA-regulated healthcare practices, see our Healthcare Compliance product line. For businesses with significant PCI or SOC 2 obligations, email us at support@breachsecurity.io before purchasing. We will tell you if Cyber Essentials covers your needs or if a custom engagement is more appropriate.

Who is Jeff O'Connor?

Jeff O'Connor is the Principal of Breach Security LLC, a cybersecurity services company registered in Georgetown, Indiana. He has built and operated automated trading systems, compliance documentation frameworks, and security infrastructure across several business domains. He reviewed and signed every Cyber Essentials policy in this library and collaborated on writing each one. His signature means a human expert built it and stands behind it.

How does the annual refresh subscription work?

Add the Annual Refresh subscription at $199/yr; it covers all your purchased policies (not per-policy). Each year on your purchase anniversary, we update your policy templates against the latest NIST, CIS, and ISO standards, compare them to what we delivered originally, and re-deliver updated files if anything has materially changed. If no material changes are needed, we will notify you that your policies remain current. Your subscription renews either way. Cancel anytime.

What is your refund policy?

If the Cyber Essentials service is not what you needed, email support@breachsecurity.io within 7 days of purchase for a full refund. Include your order ID. Refunds are issued back to your original payment method within 5 business days. See the full refund policy.

// annual.refresh

Annual Refresh Subscription

// optional add-on

Annual Refresh Subscription: $199/yr

Optional add-on. Annual policy updates as regulations and threat landscape change. Cancel anytime. Covers all purchased policies, once a year on your anniversary. When NIST, CIS, or ISO standards materially change, you receive updated, Jeff-signed documents automatically, no additional purchase needed.

$199/yr
Add Annual Refresh →

Ready to Get Started?

Purchase the policies your business needs. You receive a download link by email within minutes: fillable PDF and editable Word docx, ready to customize in 5-10 minutes.