What should a small business cyber security policy include?
A small business cyber security policy needs five sections: accounts and passwords (multi-factor authentication required, none shared), access (who may reach what, leavers removed same day), devices (managed, updated, lockable), data (where it lives, how it is backed up), and incidents (who to call, in what order). Short enough to be read beats thorough enough to be filed.
One concrete rule per section does most of the work. Accounts: multi-factor authentication on everything, no shared logins, and a manager approves every new account. Access: permissions follow roles, and departures are processed the same day, not at month end. Devices: only managed, updated devices touch business data, including the phone that reads email. Data: name where the important records live, and state the backup arrangement including how often restores are tested. Incidents: a phone tree with names, starting with your IT provider, and one non-negotiable habit that belongs in writing, any change to bank account details gets verified by a phone call to a known number before a cent moves.
Most policies fail the same way: downloaded as a template, filled with someone else's systems, filed unread, and contradicted by daily practice. Two design choices prevent that. Keep each section to a page or less, because the policy's first job is to be read. And wherever possible, back each written rule with a system that makes it true, the policy says multi-factor authentication and Entra ID enforces it, the policy says managed devices and Intune enforces it. A policy documents intent; controls deliver it; insurers and tenders increasingly ask to see both, and they compare them.
The honest caveat: a template is a fine skeleton, and the ACSC's small business guidance is a good starting frame, but a policy that claims controls you do not run is not neutral, it is evidence against you after an incident. Write down what is true, then improve what is true. If you want the gap between your policy and your reality measured, our Essential Eight Cyber Security Scorecard is free, or call 1800 456 567.
Check your policy against what is actually running.
A policy that claims controls you do not have is evidence against you. The free Scorecard measures your real controls, control by control, so the document can tell the truth.
Other questions we are asked about this, answered the same way.
- 5 min
What are the 7 types of cyber security, translated for business owners?
Network, endpoint, cloud, application, data, identity, operational: each type in plain English, sized for an Australian small business.
Read the article - 4 min
How should a general practice protect patient records?
The Essential Eight, the Privacy Act and tested backups: a plain-English map of what protecting patient records actually involves.
Read the article - 4 min
Does a small business really need cyber security services?
Attackers automate; size is not camouflage. What a ten-person Australian business actually needs, and what it can safely skip.
Read the article
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business