Cybersecurity tools

Tools

Security tools I build in conversation with Claude. Each one is a single HTML file that runs entirely in your browser — no accounts, no server, nothing leaves your machine.

A

Argus Watch

Cyber risk management, every eye open.

A cyber risk register that thinks like a CISO's office: describe the organization, build the register against sector-specific impact and likelihood drivers, see the exposure on 5×5 heat maps, and generate what leadership actually asks for — a board pack, and a draft of the Form 10-K Item 1C cybersecurity disclosure.

Open Argus Watch ↗ v2 · Sep 2026 · single HTML file
Organization profileRisk registerHeat mapControls & regulationsReports
  • Sector-aware scoringSector, revenue, headcount, and footprint set the impact dimensions, likelihood drivers, and regulatory obligations before you score a single risk.
  • Register, heat maps, treatmentInherent vs residual on 5×5 heat maps, risk templates per sector, owners, treatment plans, due dates, and overdue tracking.
  • Controls & regulationsMap risks to controls and to the regulations that apply to your footprint; see coverage and gaps.
  • Board pack exportOne click to PowerPoint, Word, or PDF: KPIs, both heat maps, top-ten residual risks, open risks by category, and obligations — built from the live register.
  • §
    SEC Item 1C draftDrafts the Form 10-K cybersecurity disclosure (governance, risk management and strategy) and downloads it as Inline XBRL.
  • Private by designEverything stays in your browser's local storage. Export and import as CSV to move or back up.

Argus Atlas

Every eye on the world.

A world map for the questions a security leader gets asked in the first week: which cybersecurity regulations apply where we operate, what has been breached in our sector lately, and which supply-chain shocks — wars, oil, disease, export controls — are heading our way. Pick your sector and countries; the map, the counts and the lists follow.

Open Argus Atlas ↗ v1 · Sep 2026 · single HTML file
SectorCountries of operationMapHover a dotObligations & exposure
  • Regulations in blueNinety-plus instruments across sixty-six countries — GDPR, NIS2, DORA, CRA, HIPAA, SEC, NYDFS, CIRCIA, China's CSL/PIPL, India's DPDP, SOCI and more — each with authority, effective date, reporting deadline and key obligations.
  • Breaches in redA live feed of the last 60 days, refreshed every six hours from SEC 8-K Item 1.05 filings, the HHS OCR breach portal and ransomware leak-site listings. The newer the breach, the redder the dot; older ones fade to grey. Leak-site entries are flagged as unverified claims.
  • Supply chain in orangeStructural risks by driver — conflict, energy, disease, trade, materials, logistics, climate, cyber — sized by severity, with impacts and mitigations.
  • Hover to expandEvery dot opens a tooltip and a detail pane; click to pin it. Click a country on the map to add it to your filter.
  • Table view tooEverything in scope is also listed — regulations by country, breaches by recency, supply risks by severity — so nothing depends on colour alone.
  • Private by designNo accounts and no tracking. The page reads one JSON file that a scheduled GitHub Action rebuilds from public sources; nothing you filter or click leaves your browser.

How these are built

Each tool starts as a problem I keep running into with clients. I work through the design with Claude — what the tool should and shouldn't do, what the data model is, how it should feel to use — and it produces a self-contained page. I test it against real scenarios, push back on the rough edges, and publish it here when it's genuinely useful.

Because they're single files with no backend, you can save any tool to your own machine and run it offline. If you find a bug or want a feature, get in touch.