Building a Security Program from Scratch
A ninety-day sequence for a business with nothing written down yet — cheapest, highest-impact work first.
Published · v1.0.0 · 2026-08-01
Template
Proof that backups exist, run, and have actually been restored at least once.
Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team
An untested backup is an assumption. One recorded restore per year turns it into a control.
Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.
NIST · 2.0
Cybersecurity Framework (CSF) 2.0(opens in a new tab)Link last confirmed 2026-02-01
Version v1.0.0 · Document owner: ComplianceAnvil Content Team
This template is provided for readiness and educational purposes. Organizations should review and adapt it for their environment.
Matched on shared frameworks, topics, and program packs.
A ninety-day sequence for a business with nothing written down yet — cheapest, highest-impact work first.
Published · v1.0.0 · 2026-08-01
A fast, honest look at your current security posture across identity, devices, data, people, and response.
Published · v1.0.0 · 2026-08-01
The thirty-day baseline: the controls that stop the majority of small-business incidents, ordered by impact.
Published · v1.0.0 · 2026-08-01
Practice building an inventory from a realistic ten-person business, then apply the same pattern to your own.
Published · v1.0.0 · 2026-08-01
The recurring, expensive errors we see small businesses make — and the cheap correction for each.
Published · v1.0.0 · 2026-08-01
Score yourself honestly across six areas and turn the two lowest into a short plan.
Published · v1.0.0 · 2026-08-01
Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.