Templates & Checklists
Practical, actionable checklists to audit and harden your security program.

3-Step Checklist to Audit a Security Awareness Program
Static security awareness programs create a false sense of confidence. This checklist gives security leaders a practical way to audit whether their current program reflects modern social engineering risks, monitors actual employee behavior, and responds quickly when risk increases. Use it to benchmark your awareness strategy against the policies, training, simulations, and reinforcement needed to change behavior over time.

Whaling & CEO Fraud: Defending the C-Suite Against AI Impersonation
Executive impersonation has moved beyond a spoofed email from the CEO. Attackers can now combine highly personalized phishing, compromised vendor accounts, AI-generated voices, deepfake video, and real organizational context to make fraudulent requests increasingly difficult to distinguish from legitimate communication. This guide breaks down how modern whaling and CEO fraud attacks work, the warning signs employees should recognize, and the layered controls security teams can implement to protect executives and the employees who act on their requests.

Phishing, Spam, or Spoofing? The 2026 Threat Identification Guide
Phishing, spam, and spoofing are often discussed as separate threats, but real-world attacks rarely stay inside those boundaries. Attackers can use bulk spam as cover, spoof trusted identities to gain credibility, and deliver highly targeted phishing lures across email, SMS, voice, QR codes, and other channels. This guide breaks down how each threat works, where they overlap, and how AI is changing the scale and sophistication of social engineering. Use it to help your organization recognize modern attack patterns and build a more dynamic defense strategy.

Top 10 Human Risk Metrics Every Security Team Should Track
Since the launch of ChatGPT, phishing attacks have grown by 4,151%, and deepfake attacks in the U.S. have grown 17-fold in a single year. Most organizations track patch coverage rates, mean time to detection, and vulnerability counts with precision, but human risk goes under-quantified even as it becomes attackers' most reliable way in. This report gives security teams 10 metrics that measure the human side of the organization with the same rigor as the technical one, covering behavior, exposure, training, and improvement over time, so you can see where risk is concentrating and where your program is actually working.

2026 Email Security Best Practices: Defending Against AI and Human Error
AI has made phishing cleaner, more personal, and harder to catch before it reaches an employee. This guide breaks down the email security practices every security team should pressure-test in 2026, from domain authentication and inbox protection to high-risk request verification, phishing reporting, and human risk measurement. Use it to evaluate the controls and workflows that protect employees before attackers exploit familiar names, trusted vendors, or compromised accounts.

Don’t Click! Top 10 Signs You’re Reading a Phishing Email
Phishing emails used to be easier to recognize. Today, attackers can use AI, public company data, cloned login pages, hijacked conversations, and multi-channel pressure to make malicious requests feel routine. This guide gives employees a practical list of phishing signs to watch for before they click, download, approve, or respond.

The CISO’s Email Security Checklist: A Practical Audit for Inbox Defenses in the Age of AI-Powered Attacks
Attackers are using AI to write personalized phishing emails at scale, pulling public information on your employees and sending thousands of targeted messages within minutes. This checklist helps CISOs and security leaders by taking stock of where their email security program stands across five interconnected layers, each with specific steps your team should act on immediately.

The AI Governance Checklist for Security Leaders: 6 Steps to Full Visibility and Control
This checklist walks security leaders through the six steps to build a governance program that gives leadership the visibility they’re asking for, enforces policy at scale, and positions the security team as an enabler of safe AI adoption.

Corporate Generative Artificial Intelligence Governance Policy
Generative AI can accelerate work across the business, but without clear governance, it can also introduce serious security, privacy, compliance, and intellectual property risk. This policy template gives organizations a practical starting point for defining acceptable AI use, classifying approved tools, protecting sensitive data, and enforcing AI governance in real time. Use it to build a policy that helps employees adopt AI safely without exposing company data or creating unmanaged shadow AI risk.