What should a small business cyber security policy include?
A small business cyber security policy needs five sections: accounts and passwords (multi-factor authentication required, none shared), access (who may reach what, leavers removed same day), devices (managed, updated, lockable), data (where it lives, how it is backed up), and incidents (who to call, in what order). Short enough to be read beats thorough enough to be filed.
One concrete rule per section does most of the work. Accounts: multi-factor authentication on everything, no shared logins, and a manager approves every new account. Access: permissions follow roles, and departures are processed the same day, not at month end. Devices: only managed, updated devices touch business data, including the phone that reads email. Data: name where the important records live, and state the backup arrangement including how often restores are tested. Incidents: a phone tree with names, starting with your IT provider, and one non-negotiable habit that belongs in writing, any change to bank account details gets verified by a phone call to a known number before a cent moves.
Most policies fail the same way: downloaded as a template, filled with someone else's systems, filed unread, and contradicted by daily practice. Two design choices prevent that. Keep each section to a page or less, because the policy's first job is to be read. And wherever possible, back each written rule with a system that makes it true, the policy says multi-factor authentication and Entra ID enforces it, the policy says managed devices and Intune enforces it. A policy documents intent; controls deliver it; insurers and tenders increasingly ask to see both, and they compare them.
The honest caveat: a template is a fine skeleton, and the ACSC's small business guidance is a good starting frame, but a policy that claims controls you do not run is not neutral, it is evidence against you after an incident. Write down what is true, then improve what is true. If you want the gap between your policy and your reality measured, our Essential Eight Cyber Security Scorecard is free, or call 1800 456 567.
Check your policy against what is actually running.
A policy that claims controls you do not have is evidence against you. The free Scorecard measures your real controls, control by control, so the document can tell the truth.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business