
Checklists
Our working checklists, handed over to you.
None of these sheets started life as marketing. They are working documents: web and API test cases, AD attack phases, OT questionnaires, a privacy crosswalk. The same checklists our consultants work through on paid engagements, exported as XLSX for your team to run without us
Featured Checklist

Web Application Security
Web Application and API Security Self-Assessment Checklist: OWASP-Mapped Test Cases
Over 200 web test cases mapped to the OWASP Top 10 2021, plus API checklists for the 2019 and 2023 OWASP API Security Top 10, so you test against a standard, not an ad-hoc list.
View Checklist


Oops! Something went wrong while submitting the form.
Web Application Security
Web Application and API Security Self-Assessment Checklist: OWASP-Mapped Test Cases
Over 200 web test cases mapped to the OWASP Top 10 2021, plus API checklists for the 2019 and 2023 OWASP API Security Top 10, so you test against a standard, not an ad-hoc list.



Web Application Security
DevSecOps Pipeline Integration Checklist: Controls Across the CI/CD Lifecycle
Security controls across the ten stages of a CI/CD pipeline, each with its objective, tools, and owner, plus a four-quarter rollout roadmap.



Critical Infrastructure
ICS/SCADA (OT) Cybersecurity Self-Assessment Checklist: 154 Questions Mapped to NIST 800-82
150+ self-assessment questions for ICS and SCADA environments, organized by the five NIST CSF functions and mapped to NIST 800-82, so an OT operator can baseline site security without waiting for a formal audit.



DevSecOps
Privacy Control Crosswalk: ISO 27701:2025 to GDPR and DPDP
All 82 ISO/IEC 27701:2025 subclauses mapped to the GDPR article and the DPDP Act section or 2025 Rule that covers them, so your team runs one control set against two regulators instead of two.
















