Strategic advisory · self-serve toolkit
A governance pack for businesses too small or too early for a full vCISO retainer. Templates you can actually operate — risk, policy, incident response, vendors, board reporting, and a POPIA-lite safeguards checklist. Not a finished compliance programme, and not a substitute for a qualified professional.
Scored register, worked SME examples (Microsoft 365, edge firewall, accounting system), and a treatment log you can take to exco.
Eight adopt-and-edit policies mapped to ISO 27001:2022 themes. Written for a business that already has an MSP or internal IT, not a greenfield ISMS project.
Severity matrix, contain-and-recover steps, POPIA s22 decision path, contacts sheet, and a tabletop (ransomware, mailbox compromise, lost laptop).
Third-party questionnaire, quarterly exco one-pager, and a safeguards checklist tied to POPIA s19 — not a binder nobody operates.
Sold by Impact Elements (Pty) Ltd, reg 2017/531020/07. Payments processed by PayFast; we never see or store card details. We are not a registered VAT vendor — no VAT is charged. Licence is for internal use by the purchasing organisation. Templates are a starting point, not legal advice, and do not constitute ISO 27001 certification.