USEFUL BEFORE THE SALES CALL.
Practical cybersecurity, defence and resilience guides that help teams frame the problem, ask better questions and prepare for the work ahead. Each guide links to a related tool or service for the next step.
SIX PRACTICAL GUIDES.
Organized by the decision you are trying to make. Each guide can be printed or saved as a workshop handout.
Board Cybersecurity Readiness Guide
Six things boards and executives should settle before an incident, with questions to ask for each.
Read guide →Ransomware Tabletop Exercise Guide
How to plan a ransomware exercise that tests decisions, communications and recovery, not just technical response.
Read guide →CMMC & CPCSC Readiness Guide
Six steps to defensible readiness for Canadian and U.S. defence suppliers.
Read guide →ITSG-33 / PBMM Readiness Guide
How to prepare a system for ITSG-33 assessment and Protected B, Medium Integrity, Medium Availability requirements.
Read guide →Digital Sovereignty Assessment Guide
Six questions that reveal who really controls your data, keys, identity, cloud, suppliers and AI.
Read guide →Penetration Testing Scoping Guide
What to define before commissioning a test: objectives, scope, rules of engagement, authorization, safety and retesting.
Read guide →FROM LEARNING TO EVIDENCE.
Readers use these guides to understand a problem before commissioning work. The progression is simple: learn from the guide, self-assess with a tool, then validate with C3SA.
Guides are reviewed periodically and show the date they were last reviewed. Requirements such as CMMC, CPCSC and ITSG-33 change, so confirm current details against the official source.
Are the guides free?
Yes, and no registration is required.
Can I use a guide in a workshop?
Yes. Print or save the page as a handout or pre-engagement checklist.
What if a guide does not cover my situation?
Use the Solution Finder or contact C3SA to describe the problem.
