Cybersecurity & Privacy
Cybersecurity and privacy workflows for security incidents, data breaches, privacy requests, access controls, vulnerability remediation, and privacy risk assessments.
Cybersecurity & Privacy Templates(14)
Privacy Enquiry Contact Form Workflow
Public website privacy enquiry contact form and lightweight intake workflow. Captures the enquiry, sends immediate confirmation, classifies it as a general privacy question or a formal rights request (routing rights requests to the existing DSAR workflow), prioritises urgent general enquiries, assigns them to the privacy owner for response, closes them once answered, sends a closure confirmation, and follows up with a short feedback request one day later.
Security Awareness Training Workflow
Security team assigns a security awareness training campaign to a staff member, tracks whether they pass, fail, or fail to complete by the due date, automatically reassigns failed attempts for retake, escalates overdue/non-completions to the staff member's manager, and reports final completion status to the campaign owner once the campaign closes.
Firewall Change Request Workflow
Captures firewall rule change requests, routes them through security risk assessment and appropriate approval (owner or, for higher-risk changes, security manager), implements and tests approved changes, sets a review-by date for temporary changes, notifies the requester on implementation, and returns rejected requests with a reason.
Security Exception Workflow
Captures a security policy exception request, has the security team assess risk and route for approval based on severity, then on approval records the exception with expiry date and review conditions and notifies the requester; on rejection returns the reason to the requester.
Phishing Report and Response Workflow
Captures phishing reports from employees, has a security analyst triage and assess maliciousness, and — if malicious — identifies affected users, contains the threat (reset credentials, block sender) and notifies affected users; if benign, notifies the reporter no action is needed. The report is closed in either case.
Third-Party Security Assessment Workflow
Manages third-party vendor security assessments end-to-end: intake of vendor/service/data-access details, sends a security questionnaire to the vendor for completion, internal review of evidence with risk findings and remediation notes, approval routing on residual risk, and either recording final approval with a reassessment date or returning the assessment to the vendor for remediation and re-review.
Privileged Access Request Workflow
Manages requests for elevated/privileged system access. Captures the role, target system, justification and duration, routes for manager and system owner approval, adds a security review for high-risk access, provisions access with an expiry date on approval, and notifies the requester of the outcome or rejection reason.
User Access Review Workflow
Security team runs a periodic user access review: owner defines scope and submits users/entitlements, each user's manager or system owner certifies or flags access against least-privilege, flagged access triggers a revocation/adjustment task, and the review is closed with a recorded outcome. A due date is set on certifications to enable follow-up on outstanding reviews.
Vulnerability Remediation Workflow
Tracks a reported vulnerability from intake through validation, prioritisation, owner assignment, remediation planning or risk acceptance, fix verification, and closure. Applies a severity-based due date so overdue items can be escalated.
Privacy Impact Assessment Workflow
Enables a privacy team to intake initiatives involving personal information, screen them for privacy risk, conduct a full privacy impact assessment where required, obtain reviewer sign-off, record residual risk acceptance and treatment actions, close the assessment, and schedule a future reassessment.
Data Subject Access Request Workflow
Handles individuals' requests to access their personal information: captures identity details, request scope and contact preference; verifies identity; collects and redacts relevant records; routes the response through privacy review; delivers it securely; tracks the statutory deadline; and closes the request.
Data Breach Response Workflow
Manages the end-to-end privacy incident response process: intake of a suspected data breach report, responder investigation and impact assessment, legal/privacy review with a notification decision, remediation and required communications, and formal incident closure with corrective actions recorded.
Security Incident Response Workflow
Enables a security team to intake suspected cyber events, automatically classify severity, assign a responder to contain/investigate/eradicate the threat, escalate high-severity events, assess breach notification requirements, and record lessons learned before closing the incident.
Software Access Request Workflow
Employees request access to applications by specifying the user, application, access level, business justification, and whether privileged access is needed. The request goes through manager approval, then system owner approval, with an additional security review for privileged access requests. On full approval, access is provisioned, verified, and the user is notified. If rejected at any stage, the request is returned to the requester with the reason.
