Sample deliverables
See what a cyber-governance engagement can produce in concrete terms.
These outputs are not taken from a specific client. They are illustrative advisory examples designed to show format, decision quality, and evidence discipline.
Illustrative example: No real client data, names, findings, or confidential information are included. Adapt these to your context before using them as assurance evidence.
01 · Executive Risk Brief
Executive Cyber Risk Brief
Prioritizes material risk, delay, assurance, ownership, and leadership decisions instead of raw technical metrics.
| Topic | Status | Business impact | Owner | Leadership decision |
|---|---|---|---|---|
| Identity & privileged access | Developing | Inconsistent review across critical systems | CTO | Mandate quarterly owned review |
| Customer assurance | Controlled | Enterprise sales cycle | Security | Refresh evidence library monthly |
| AI governance | Fragmented | Shadow AI and data-processing risk | COO | Create AI inventory and approval gate |
02 · 30/60/90
90-Day Cybersecurity Roadmap
Every action should have an owner, business impact, and closure evidence.
| Window | Action | Owner | Expected evidence |
|---|---|---|---|
| 0–30 days | Unify critical risks and customer commitments in one register | Security / CTO | Approved risk register |
| 31–60 days | Assign control owners and evidence cadence | Functional owners | Control-owner-evidence matrix |
| 61–90 days | Operate executive reporting, exception, and revalidation cadence | CISO / Leadership | Executive brief + decision log |
03 · Assurance
ISO 27001 Evidence Matrix
Turns control language into a living evidence operating model.
| Control/activity | Owner | Frequency | Evidence | Gap |
|---|---|---|---|---|
| Risk assessment & treatment | Security | Annual + on change | Risk register / treatment plan | — |
| Access review | IT | Quarterly | Review export + approval | Two systems missing |
| Supplier security review | Procurement + Security | Onboarding + annual | Due diligence record | Tiering needs standardization |
04 · Vendor risk
Vendor Risk Register
| Vendor | Tier | Risk | Decision | Next review |
|---|---|---|---|---|
| Example Cloud Provider | Tier 1 | Customer data + prod access | Approved with controls | 12 months / event-driven |
| Example CRM | Tier 2 | Customer contact data | Approved | 12 months |
Download vendor-risk CSV template
05 · AI governance
AI Use-Case Inventory
| Use case | Data | Autonomy | Risk tier | Approval | Human oversight |
|---|---|---|---|---|---|
| Support-answer assistant | Internal | Low | Tier 2 | Conditional | Required |
| Hiring decision engine | Personal | High | Tier 4 | Formal review required | Required |
Download AI-inventory CSV template
06 · Customer trust
Security Questionnaire Response Library
| Question area | Approved-answer component | Evidence | Owner | Review |
|---|---|---|---|---|
| Access control | Describe RBAC, MFA, and periodic review scope | Policy + IdP configuration + review record | IT/Security | Quarterly |
| Incident response | Describe plan, roles, customer communications, and testing cadence | IR plan + tabletop record | Security | Annual |
07 · Governance calendar
Cyber Governance Calendar
| Cadence | Activity | Participants | Output |
|---|---|---|---|
| Monthly | Risk and overdue-action review | CISO, CTO, owners | Updated risk decisions |
| Quarterly | Board/leadership cyber brief | Leadership | KRI + material risk + decisions |
| Annual | Tabletop + program review | Cross-functional | Lessons + roadmap |
08 · Decision record
Risk Acceptance and Decision Log
| Decision | Rationale | Risk owner | Duration | Condition |
|---|---|---|---|---|
| Temporarily accept risk | Control improvement depends on Q4 release | CTO | 90 days | Compensating monitoring + re-review |