Cyber Plan · The Startup IT & Security Operating Kit

Build a credible 12-month security plan in two weeks — without a CISO or a consultant.

The complete operating kit for IT leaders at 50–500 person companies: guided workbook, self-calculating roadmap tracker, budget builder, and two completed example plans.

Get the kit — CA$245 See what's inside ↓
Instant download · .docx + .xlsx + .pdf · Works in Excel & Google Sheets · Licensed for your whole org

Not ready to buy? Download the executive pitch script free → The complete 30-minute CEO pitch and one-page summary template from inside the kit. Not a teaser — it's the real chapter.

Sound familiar?

Everyone's asking about security. Nobody gave you the playbook.

1

The questionnaires keep coming

Enterprise customers, cyber insurers, and your board want answers — and "we're working on it" is wearing thin.

2

Consultants quote $15k–$50k

For a deliverable you could build yourself — if someone handed you the structure, the sequencing, and the budget numbers.

3

Frameworks are overwhelming

NIST has 100+ subcategories. ISO wants a management system. You need the 12 controls that actually matter at your size.

What's inside

Six files. One operating model.

Everything is pre-researched for 50–500 person companies — real tool names, real price ranges, realistic timelines.

WORD · WORKBOOK

The 12-Month Planning Workbook

Guided baseline assessment, risk prioritization, 8 control planning worksheets, budget builder, and a one-page executive summary template — plus a 12-control library with plain-English explanations, tools, and budget ranges.

EXCEL / SHEETS · TRACKER

The Roadmap & Progress Tracker

Edit the yellow cells and it builds itself: 12-month visual roadmap, phased budget totals with contingency, live progress dashboard, and a quarterly review template. 200+ formulas, zero setup.

PDF · GUIDE

The Guide

The method behind the plan, honest budget rules of thumb ($400–$1,200/employee/year), when to buy vs. build detection, and a 30-minute script for presenting to your CEO and CFO.

PDF · EXAMPLE

Example: Series B Fintech

A completed plan for a 220-person payments company — $286k budget, MDR decision logic, bank due-diligence milestones. See exactly what "done" looks like.

PDF · EXAMPLE

Example: SaaS on the SOC 2 path

An 85-person B2B SaaS getting to SOC 2 Type II on a $148k budget — including how they saved ~$25k/yr by reusing licensing they already had.

PDF · START HERE

Start Here

Your two-week path from download to a presented, approved plan — which file to open first and how long each step takes.

How it works

Assess. Plan. Present.

About five focused hours of your time, spread over two weeks.

STEP 1

Assess

A 5-part baseline: security posture, compliance drivers, budget, data, and infrastructure. Honest inputs, tailored outputs.

≈ 1 hour
STEP 2

Plan

Choose from 12 pre-researched controls. The tracker phases them across 12 months and totals your budget automatically.

≈ 3 hours
STEP 3

Present

A one-page executive summary plus a meeting script that leads with business risk and asks for a decision — not feedback.

≈ 1 hour
Proof it works at your size

Two completed plans, included.

Most templates show you empty boxes. Cyber Plan shows you finished plans with real numbers, so you're never guessing what good looks like.

PayFlow Technologies
Series B fintech · 220 employees · remote-first
  • $286k year-one ask, phased and defended line by line
  • Why they chose MDR over building a SOC (and saved ~$450k)
  • Bank due-diligence milestones tied to a $2.4M pipeline
  • SOC 2 Type I audit-ready by month 12
Brightline Software
B2B SaaS · 85 employees · SOC 2 required by customers
  • $148k budget with zero new headcount
  • Reused Microsoft licensing they already paid for (~$25k/yr saved)
  • Secure SDLC moved up — because product risk was the business risk
  • SOC 2 Type II report in hand by month 15
Pricing

One price. Whole kit. Whole org.

CA$245 one-time ≈ US$179 · billed in Canadian dollars
  • All six files — workbook, tracker, guide, both examples, start-here
  • Instant download (.docx, .xlsx, .pdf)
  • Excel and Google Sheets compatible
  • Licensed for your entire organization
  • Free updates for 12 months

14-day refund, no questions asked. One email, no form, no exit survey — and you keep the files.

Get Cyber Plan →

A consultant builds this exact deliverable for $15,000–$50,000 in 6–8 weeks.

Questions before you buy? hello@mycyberplan.com

Free chapter

The 30-Minute Security Budget Pitch

The complete executive pitch script and one-page summary template from inside the kit — the same version buyers get, nothing held back. If it gets you through your next budget meeting on its own, that was the point.

Instant download, no waiting. Occasional updates when the kit changes — unsubscribe anytime, and we never sell or share your address.

FAQ

Fair questions.

How long until I have a plan I can present?

About five focused hours of work, typically spread over two weeks: read the Guide and one example (day 1–2), complete the Workbook (days 3–7), tune the Tracker and budget (days 8–10), then write the one-pager and book 30 minutes with your CEO/CFO (days 11–14).

What if it doesn't work for us?

14-day refund, no questions asked. Email hello@mycyberplan.com and we process it in full, usually same day. No form, no retention offer, and you keep the files. We'd rather refund you than have you feel stuck with something that didn't help. Full refund policy →

Who wrote this?

Someone who runs IT and security at a venture-backed fintech and would rather not attach their employer's name to a side project. The budget ranges in the control library are prices actually paid or quoted in the last two years. Full explanation on the About page →

Is this AI-generated filler?

Download the free pitch script above and judge for yourself — that's the fastest answer to this question, and the reason it's free. The tell: the budget ranges name actual vendors at actual quoted prices, and the sequencing logic explains why identity comes before detection. Filler does neither.

Why is the price in Canadian dollars?

The store is registered in Canada, so checkout bills in CAD. CA$245 is roughly US$179 depending on the day's rate; your card issuer handles the conversion. The price you see here is the price you'll see at checkout — no surprises.

Which framework is this based on?

A pragmatic hybrid: NIST CSF structure, CIS-style prioritization, and ISO-style governance discipline — without implementing any framework wholesale. Everything maps cleanly onto SOC 2 or ISO 27001 if you pursue certification later.

We're only 60 people. Is this overkill?

No — drop from 12 controls to 8 (the Guide tells you which). Set "Include? = No" in the tracker and the roadmap, budget, and dashboard update automatically.

We already have some controls in place.

Even better. Mark them Complete in the tracker and take credit for them in your executive summary. A plan that acknowledges existing strengths reads as more credible, not less.

Is this compliance (SOC 2 / ISO) preparation?

It's the foundation for it. Certifications come after controls exist — run this plan first, and a compliance automation platform becomes an accelerator instead of a checkbox factory. One of the two included examples walks the full SOC 2 Type II path.

What exactly do I get, in what formats?

Six files: the Workbook (.docx), the Roadmap Tracker (.xlsx — Excel and Google Sheets compatible), the Guide (.pdf), two completed example roadmaps (.pdf), and a Start Here orientation (.pdf). Instant download after purchase.

Can I share it with my team?

Yes — one purchase covers your whole organization. Please don't redistribute or resell outside it.

Can I expense this?

Yes, and it sits under the approval threshold at most companies this size. You'll get a receipt you can put your company name on — reply to your order email if you need it changed.

Your board meeting is coming either way.

Walk in with a phased plan, a defensible budget, and answers — for less than one hour of a consultant's time.

Get Cyber Plan — CA$245