Security and privacy templates
Vulnerability reports, security reviews, access audits, privacy requests and awareness messages. 35 free templates, 7 of them longer notes. Open one to fill in the blanks and copy it.
Vulnerability handling
From report to fix.
- Vulnerability report acknowledgement Snippet Thanks a researcher. Hi [Name], Thank you for reporting this. We have received your report ([Reference]) and our security team is…
- Vulnerability confirmed Snippet Confirms a finding. Hi [Name], We have confirmed the issue you reported and rated it critical. We plan to fix it by [Fix date].…
- Vulnerability fixed Snippet Tells the reporter. Hi [Name], The issue is fixed as of [today]. Thank you for helping keep our users safe.
- Not a vulnerability Snippet Declines a report. Hi [Name], Thanks for the report. After review, we do not consider this a security issue because [Reason].…
- Security advisory Snippet Public advisory. Security advisory [ID] Affected: [Affected] Severity: [Severity] Description: [Description] Fix: update to…
- Internal vuln ticket Snippet Hands to engineering. Vulnerability: [Title] Severity: Critical Asset: [Asset] Fix by: [SLA] Details: [Details]
- Patch reminder Snippet Nudge to patch. Hi [Owner], [System] is missing the [Patch] update, rated [Severity]. Please patch by [in 7 days] or let us…
Reviews and audits
Assess risk, check access.
- Security review Note Review a feature or system. System: [System] Reviewer: [Reviewer] Date: [today] Data handled Threats - Controls - Findings | # | Finding…
- Threat model Note STRIDE-style notes. System: [System] Assets Entry points Threats - Spoofing: - Tampering: - Repudiation: - Information…
- Access review Note Quarterly access audit. System: [System] Quarter: [Quarter] | User | Role | Still needed? | Action | | | | | | | | | | |
- Vendor security assessment Note Assess a supplier. Vendor: [Vendor] Data shared: [Data] Certifications Questions answered - Risks Decision Approve
- Security incident log Note Record an incident. Incident: [Incident] Detected: [today] What happened Containment Data involved Notifications - [ ] Lessons
- Pen test scope Note Plan a pen test. Target: [Target] Window: [Window] In scope - Out of scope - Rules of engagement Contacts
- Policy exception Note Record an exception. Policy: [Policy] Requested by: [Requester] Expires: [in 90 days] Reason Compensating controls Approved by
Privacy requests
GDPR-style data requests.
- Data access request received Snippet Acknowledges a subject access request. Dear [Name], We have received your request for a copy of your personal data. We will respond within 30 days.…
- Data export sent Snippet Provides the data. Dear [Name], Attached is a copy of the personal data we hold about you, in [Format]. It includes [Categories].
- Deletion request confirmed Snippet Confirms erasure. Dear [Name], We have deleted your personal data as requested, except [Retained], which we must keep for…
- Correction request Snippet Fixes personal data. Dear [Name], Thank you. We have updated your [Field] as requested.
- Objection to processing Snippet Stops marketing. Dear [Name], We have stopped using your data for [Purpose]. You will no longer receive [What] from us.
- Privacy policy update Snippet Notifies users. Hi [First name], We have updated our privacy policy, effective [today]. The main changes: [Changes]. Read it…
- Cookie notice Snippet Short cookie banner text. We use essential cookies to make this site work, and optional cookies to understand how it is used. You…
- Data breach notification Snippet Tells affected people. Dear [Name], We are writing to tell you about an incident affecting your data. On [today], [What happened].…
Awareness messages
Short, useful security tips.
- Phishing tip Snippet Spot fake emails. Security tip: be wary of emails that create urgency, ask for passwords or payment, or come from addresses…
- Password manager tip Snippet Encourages a manager. Security tip: a password manager lets you use a unique, strong password everywhere. Ours is [Tool]: [Link]
- MFA reminder Snippet Turn on MFA. Security tip: turn on multi-factor authentication for every account that offers it, especially email and…
- Suspicious call warning Snippet Voice phishing. Heads-up: we are seeing calls from people pretending to be [Who]. We will never ask for your password or…
- Clean desk reminder Snippet Physical security. Reminder: lock your screen, and do not leave printed confidential documents on your desk.
- Travel security tip Snippet When travelling. Travelling for work? Keep your laptop with you, use the VPN on public Wi-Fi, and turn on Find My for your…
- Report quickly Snippet Encourages reporting. Clicked something you should not have? Report it right away to [Security contact]. Speed matters more than…
Security questionnaires
Answer customer security reviews.
- Questionnaire cover email Snippet Sends answers. Hi [Name], Attached is our completed security questionnaire and supporting documents: [Documents]. Happy to…
- Encryption answer Snippet Standard answer. Data is encrypted in transit with TLS 1.2 or higher, and at rest with AES-256.
- Access control answer Snippet Standard answer. Access follows least privilege. Staff access to production requires SSO with MFA, is logged, and is reviewed…
- Incident response answer Snippet Standard answer. We maintain an incident response plan, tested annually. Affected customers are notified within 72 hours of a…
- Data location answer Snippet Where data lives. Customer data is stored in [Region] on [Provider]. Backups are kept in [Backup region] for [Retention].
- Subprocessors answer Snippet Who processes data. Our subprocessors are listed at [Link]. We notify customers 30 days before adding a new one.