assess.one – AI-powered business operations platform

Cybersecurity & Privacy

Cybersecurity and privacy workflows for security incidents, data breaches, privacy requests, access controls, vulnerability remediation, and privacy risk assessments.

Cybersecurity & Privacy Templates(14)

Privacy Enquiry Contact Form Workflow

Public website privacy enquiry contact form and lightweight intake workflow. Captures the enquiry, sends immediate confirmation, classifies it as a general privacy question or a formal rights request (routing rights requests to the existing DSAR workflow), prioritises urgent general enquiries, assigns them to the privacy owner for response, closes them once answered, sends a closure confirmation, and follows up with a short feedback request one day later.

privacy enquiry formprivacy contact formdata privacy enquiry

Security Awareness Training Workflow

Security team assigns a security awareness training campaign to a staff member, tracks whether they pass, fail, or fail to complete by the due date, automatically reassigns failed attempts for retake, escalates overdue/non-completions to the staff member's manager, and reports final completion status to the campaign owner once the campaign closes.

security awareness trainingcybersecurity trainingphishing training

Firewall Change Request Workflow

Captures firewall rule change requests, routes them through security risk assessment and appropriate approval (owner or, for higher-risk changes, security manager), implements and tests approved changes, sets a review-by date for temporary changes, notifies the requester on implementation, and returns rejected requests with a reason.

firewall change requestfirewall rule requestnetwork security change

Security Exception Workflow

Captures a security policy exception request, has the security team assess risk and route for approval based on severity, then on approval records the exception with expiry date and review conditions and notifies the requester; on rejection returns the reason to the requester.

security exceptionpolicy exceptionrisk acceptance

Phishing Report and Response Workflow

Captures phishing reports from employees, has a security analyst triage and assess maliciousness, and — if malicious — identifies affected users, contains the threat (reset credentials, block sender) and notifies affected users; if benign, notifies the reporter no action is needed. The report is closed in either case.

phishing reportsuspicious emailphishing response

Third-Party Security Assessment Workflow

Manages third-party vendor security assessments end-to-end: intake of vendor/service/data-access details, sends a security questionnaire to the vendor for completion, internal review of evidence with risk findings and remediation notes, approval routing on residual risk, and either recording final approval with a reassessment date or returning the assessment to the vendor for remediation and re-review.

third party security assessmentvendor security reviewsecurity questionnaire

Privileged Access Request Workflow

Manages requests for elevated/privileged system access. Captures the role, target system, justification and duration, routes for manager and system owner approval, adds a security review for high-risk access, provisions access with an expiry date on approval, and notifies the requester of the outcome or rejection reason.

privileged accessadmin access requestPAM

User Access Review Workflow

Security team runs a periodic user access review: owner defines scope and submits users/entitlements, each user's manager or system owner certifies or flags access against least-privilege, flagged access triggers a revocation/adjustment task, and the review is closed with a recorded outcome. A due date is set on certifications to enable follow-up on outstanding reviews.

user access reviewaccess recertificationaccess review

Vulnerability Remediation Workflow

Tracks a reported vulnerability from intake through validation, prioritisation, owner assignment, remediation planning or risk acceptance, fix verification, and closure. Applies a severity-based due date so overdue items can be escalated.

vulnerability remediationvulnerability managementsecurity finding

Privacy Impact Assessment Workflow

Enables a privacy team to intake initiatives involving personal information, screen them for privacy risk, conduct a full privacy impact assessment where required, obtain reviewer sign-off, record residual risk acceptance and treatment actions, close the assessment, and schedule a future reassessment.

privacy impact assessmentPIADPIA

Data Subject Access Request Workflow

Handles individuals' requests to access their personal information: captures identity details, request scope and contact preference; verifies identity; collects and redacts relevant records; routes the response through privacy review; delivers it securely; tracks the statutory deadline; and closes the request.

data subject access requestDSARsubject access request

Data Breach Response Workflow

Manages the end-to-end privacy incident response process: intake of a suspected data breach report, responder investigation and impact assessment, legal/privacy review with a notification decision, remediation and required communications, and formal incident closure with corrective actions recorded.

data breach responseprivacy breachdata breach workflow

Security Incident Response Workflow

Enables a security team to intake suspected cyber events, automatically classify severity, assign a responder to contain/investigate/eradicate the threat, escalate high-severity events, assess breach notification requirements, and record lessons learned before closing the incident.

security incident responsecyber incidentcybersecurity workflow

Software Access Request Workflow

Employees request access to applications by specifying the user, application, access level, business justification, and whether privileged access is needed. The request goes through manager approval, then system owner approval, with an additional security review for privileged access requests. On full approval, access is provisioned, verified, and the user is notified. If rejected at any stage, the request is returned to the requester with the reason.

software access requestapplication accessaccess approval
Cybersecurity & Privacy Workflow Templates | assess.one