All insights

What should a small business cyber security policy include?

2 min readBy Brendon Whiting, Founder · 7 July 2026

A small business cyber security policy needs five sections: accounts and passwords (multi-factor authentication required, none shared), access (who may reach what, leavers removed same day), devices (managed, updated, lockable), data (where it lives, how it is backed up), and incidents (who to call, in what order). Short enough to be read beats thorough enough to be filed.

One concrete rule per section does most of the work. Accounts: multi-factor authentication on everything, no shared logins, and a manager approves every new account. Access: permissions follow roles, and departures are processed the same day, not at month end. Devices: only managed, updated devices touch business data, including the phone that reads email. Data: name where the important records live, and state the backup arrangement including how often restores are tested. Incidents: a phone tree with names, starting with your IT provider, and one non-negotiable habit that belongs in writing, any change to bank account details gets verified by a phone call to a known number before a cent moves.

Most policies fail the same way: downloaded as a template, filled with someone else's systems, filed unread, and contradicted by daily practice. Two design choices prevent that. Keep each section to a page or less, because the policy's first job is to be read. And wherever possible, back each written rule with a system that makes it true, the policy says multi-factor authentication and Entra ID enforces it, the policy says managed devices and Intune enforces it. A policy documents intent; controls deliver it; insurers and tenders increasingly ask to see both, and they compare them.

The honest caveat: a template is a fine skeleton, and the ACSC's small business guidance is a good starting frame, but a policy that claims controls you do not run is not neutral, it is evidence against you after an incident. Write down what is true, then improve what is true. If you want the gap between your policy and your reality measured, our Essential Eight Cyber Security Scorecard is free, or call 1800 456 567.

Check your policy against what is actually running.

A policy that claims controls you do not have is evidence against you. The free Scorecard measures your real controls, control by control, so the document can tell the truth.

Frequently asked questions

For most small businesses there is no statute saying you must have one, but the pressure arrives from every other direction: Privacy Act obligations assume documented practices, cyber insurers ask for the policy at application and at claim time, and larger customers request it in due diligence. Some regulated industries do carry specific requirements, so check yours.

At least annually, and immediately after any incident or significant system change, because a policy describing systems you no longer run is worse than none. Put a named owner and a review date on the front page. The review itself should be short if the policy is short, which is another argument for keeping it to a few pages.

Yes, and pair the signature with a short walkthrough rather than treating it as paperwork. A signed, unread policy is theatre; twenty minutes explaining why bank detail changes get verified by phone and what a phishing report looks like buys real behaviour. New starters should get both on day one, before their accounts do.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.