Skip to main content
Dig IT Solutions logo

Cyber Security

Why you need a cyber security policy (and what to put in it)

Why security software alone does not protect a small business, what a cyber security policy should contain, and a section-by-section template for UK SMEs.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

Security software blocks known threats, but it cannot decide how staff handle passwords, verify payment requests, use personal devices or respond when something looks wrong. A cyber security policy sets those rules in writing, gives everyone the same standard, provides the evidence UK GDPR and insurers expect, and turns Cyber Essentials into how the business actually operates.

Most small businesses that suffer a serious cyber incident had security software installed at the time. What they did not have was an agreed answer to questions like: who is allowed to approve a change to supplier bank details, and how? What happens to a leaver's accounts, and by when? Can staff use personal phones for email? Who do you tell when you click a link you should not have? Software cannot answer those questions. A policy can.

This article explains why the policy is the missing piece in many SMEs, then gives you an outline you can adapt.

Software blocks threats, policy shapes behaviour

Endpoint protection, email filtering, firewalls and MFA are necessary. We install them for every client. But every one of them has a gap that only people can close.

Email filtering removes most phishing, then a well-written invoice from a genuinely compromised supplier gets through and the accounts team needs a rule for what to do. MFA stops most account takeovers, then an attacker sends prompt after prompt and the user needs to know never to approve one they did not trigger. Encryption protects a lost laptop, then someone forwards the same files to personal Gmail. Antivirus blocks known malware, then a user with local admin rights installs a "free PDF converter".

The Cyber Security Breaches Survey has found for years that phishing is the most common attack on UK businesses, and phishing targets people. A policy is where you tell people what you expect, so that the secure choice is the normal one rather than an individual judgement made under pressure.

What a policy does that software cannot

It creates one standard. Without written rules, one person stores files in SharePoint and another in a personal Dropbox, one uses a password manager and another a spreadsheet. Consistency is what makes the technical controls effective.

It defines the verification steps that stop fraud. The single most valuable sentence in most SME policies is: "Changes to supplier or payroll bank details must be confirmed by telephone using a number already held on file before any payment is made." No software does that.

It covers hybrid working and personal devices. Where people may work, which devices may hold company data, what happens to that data when they leave. See our BYOD security guide.

It tells people what to do in an incident. Who to call, what not to touch, that reporting is expected and blame-free. Speed of reporting is the biggest factor in the cost of an incident.

It provides evidence. UK GDPR requires you to demonstrate appropriate security, and the ICO will ask for your policies after a breach. Cyber insurers ask for them before quoting. Larger customers ask for them in supplier questionnaires. Public-sector tenders often require Cyber Essentials, and a policy is how you answer its management questions consistently.

It makes enforcement fair. If someone repeatedly ignores security rules, HR needs a written standard that was communicated at induction. Without it, the business cannot act.

A policy template outline for a UK SME

Adapt this to your business. The goal is a document of four to eight pages, in plain English, that a new starter could read in twenty minutes.

1. Purpose and scope. One paragraph. What the policy protects, who it applies to (all staff, contractors, anyone with access), and which systems it covers.

2. Roles and responsibilities. Who owns the policy at director level. Who administers systems (internal or your IT partner). What every user is responsible for. Who leads an incident.

3. Acceptable use. Company systems are for business use. No installing unapproved software. No circumventing security controls. Personal use rules. Monitoring statement (what the business logs and why).

4. Accounts and passwords. Individual named accounts, no sharing. Password standard following NCSC guidance: long and unique, stored in the approved password manager, not changed on a schedule but changed immediately on suspicion of compromise. MFA mandatory on all systems that support it. Never approve an unexpected MFA prompt. Administrator rights only through separate admin accounts.

5. Joiners, movers and leavers. Access is requested by a manager and granted on least-privilege. Role changes trigger an access review. Leaver access is removed on the last working day (or earlier for sensitive roles), devices returned, work data wiped from personal devices, shared passwords they knew changed. Link to the offboarding checklist.

6. Devices. Company devices are encrypted, managed, patched and must not be left unattended in public. Screen lock within a set number of minutes. Personal devices may only access company data through managed apps under the BYOD section. Lost or stolen devices reported within a stated time.

7. Email, phishing and payments. How to recognise and report phishing (report@phishing.gov.uk for the NCSC, plus internal reporting). No clicking links in unexpected messages. The bank-detail verification rule. No forwarding company email to personal accounts.

8. Data handling. Where data lives (SharePoint, the CRM, the accounts system) and where it must not (personal cloud, USB sticks, personal messaging). Sharing externally by link with expiry rather than attachment. Classification if needed (public, internal, confidential). Retention periods and secure disposal. Reference to the privacy policy and UK GDPR obligations, see UK GDPR IT controls for small businesses.

9. Remote and hybrid working. Approved connection methods (VPN, managed device). Home Wi-Fi expectations. Public Wi-Fi rules. Confidential calls and screens in shared spaces.

10. Software updates and security tools. Updates are applied automatically and must not be deferred beyond a stated period. Security software must not be disabled. Restart when prompted.

11. Suppliers and third parties. Who may grant external access, for how long, and the requirement for a processor contract where personal data is involved.

12. Incident reporting and response. What counts as an incident (including near misses). Who to contact, immediately, by phone. What not to do (do not switch off, do not try to fix it, do not pay a ransom). The 72-hour ICO reporting clock and who decides. Post-incident review.

13. Training. Induction training for all new starters, refresher training at least annually, simulated phishing with results shared.

14. Compliance and breaches of policy. Consequences under the disciplinary procedure. Review date, version and owner.

Most of the technical sections should match what is actually configured. If the policy says MFA is mandatory and the Microsoft 365 tenant has exceptions, the policy is fiction. That is why we draft policies alongside the technical work in a cyber security engagement, and check the two against each other.

Making it stick

A signed policy in a drawer changes nothing. Four things make it real: leadership follows it visibly (directors use MFA and the password manager too), it is part of induction and refreshed annually through security awareness training, technical controls enforce the important rules rather than trusting memory, and incidents are reviewed against it without blame so people keep reporting.

Keep it current. Review at least once a year, and whenever you adopt a new system, change how people work, or learn something from an incident. Businesses that hold Cyber Essentials find the annual renewal a natural point to do this.

What to do next

If your business has security software but no written policy, or a policy nobody has read since it was downloaded, we can draft one that matches your actual systems and walk your team through it. An IT health check is the starting point: it shows what is in place technically, so the policy describes reality rather than aspiration.

Frequently asked questions

What is a cyber security policy?
A cyber security policy is a short written document that sets out how your business protects its systems and data: who is responsible, what staff must and must not do, how access is granted and removed, how devices and data are handled, and what happens when an incident occurs. It is the rulebook that the technical controls enforce.
Is antivirus and a firewall enough without a policy?
No. Most incidents in small businesses start with a person: a reused password, an approved MFA prompt, a bank-detail change accepted by email, a file forwarded to a personal account. Software cannot prevent any of those. A policy sets the expected behaviour, and training plus technical controls such as MFA and conditional access make it stick.
How long should a small business security policy be?
Short enough to be read. For a business of up to 250 people, four to eight pages covering the sections in this article is plenty, with a one-page acceptable use summary that staff sign. A 40-page policy copied from a corporate template will not be read, followed or enforced, which is worse than no policy because it creates false assurance.
How often should the policy be reviewed?
At least annually, ideally alongside Cyber Essentials renewal, and whenever something significant changes: a new system, a move to hybrid working, a merger, a security incident or new guidance from the ICO or NCSC. Put the review date and the owner on the front page so it does not drift.
Do we need a policy for Cyber Essentials?
Cyber Essentials assesses technical controls rather than documents, but several questions ask how you manage things (leaver accounts, patching timescales, device standards) and a written policy is how you answer consistently. Cyber insurers and larger customers' supplier questionnaires almost always ask for one directly.
Can an IT provider write our policy for us?
A provider can draft it, and should, because the policy has to match the technical controls actually in place. But the business must own it: directors approve it, managers enforce it and HR includes it in onboarding. A policy that only the IT company has read protects nobody.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us