For small businesses in Ireland, the UK and the EU

Your IT and cybersecurity policies, written for your business, in 10 minutes.

Answer 18 quick questions. Get 12 tailored, editable policies that your insurer, your clients and your staff will actually understand.

From €149, one-offWord and PDFAligned with NCSC and CIS guidance14-day refund if not downloaded

Why now

Your insurer asked

“Do you have a written incident response plan?” It's on almost every cyber insurance proposal form.

A client asked

A 40-question security questionnaire arrived before a contract renewal, and it starts with “Please attach your policies.”

You know it's overdue

Your IT runs on good intentions. One fake invoice or lost laptop would expose it.

All three need the same thing: proper written policies. Consultants charge €1,500 or more. Generic templates take a weekend to adapt and still mention companies that aren't yours.

How it works

1

Choose your pack

Pay securely by card, Apple Pay or Google Pay. VAT invoices are issued automatically.

2

Answer 18 questions

Plain-English questions about your team, systems and data. About 5 minutes.

3

Download your pack

Tailored Word and PDF documents a few minutes later, ready to share with staff.

What's inside

Twelve policies covering what insurers, clients and regulators ask about most.

01

Acceptable Use

How staff may use company devices, email, internet, data and AI tools.

02

Password and MFA

Modern passphrase rules, password managers and multi-factor authentication for every account.

03

Incident Response

What to do in the first 15 minutes and 24 hours, including the 72-hour regulator deadline.

04

Data Protection and Handling

GDPR-aligned classification, handling, retention and individuals' rights.

05

Access Control

Joiners, movers and leavers, admin rights and an access register.

06

Backup and Recovery

The 3-2-1 rule, test restores and recovery priorities.

07

Remote Working

Safe home working, public Wi-Fi and travelling with devices.

08

Bring Your Own Device

Whether personal phones and laptops are allowed, and the rules if they are.

09

Email and Phishing

Spotting phishing, reporting it, and stopping bank-detail fraud.

10

Software and Patch Management

Update deadlines, approved software and anti-malware.

11

Supplier Security

Checking suppliers who handle your data, contracts and a supplier register.

12

Information Security Policy

The signed umbrella policy insurers and clients ask for first.

Plus the documents that make them work

Information Security Summary

A one-page overview to send to insurers and clients. It only states controls you actually have.

Staff Acknowledgement Form

A sign-off sheet so every employee confirms they have read the policies.

90-Day Rollout Checklist

Your biggest gaps first, based on your answers, then a clear order for everything else.

Supplier Questionnaire Answer Bank Pro

Suggested answers to the 40 questions clients ask most, matched to your policies.

Cyber Insurance Readiness Checklist Pro

The controls insurers ask about, your status on each, and the evidence to keep.

Framework Mapping Pro

Which ISO 27001, NIST CSF 2.0, CIS and Cyber Essentials controls each policy supports.

See what each document covers →

Practical policies, not generic templates

Every policy is written from hands-on experience running IT and security in real organisations, from small teams to global companies, including PCI DSS and ISO 27001 audits and data protection compliance.

Every clause is written and reviewed in advance. Your answers decide which clauses apply to you; nothing is made up on the fly.

About PolicyPack →

Tailored to your answers

  • Your company, your named contacts, your approval dates
  • The right regulator and law for Ireland, the UK or the EU
  • Microsoft 365 or Google Workspace specific steps
  • Clauses for health data, card payments or children's data
  • A rollout plan that starts with your biggest gaps
  • A security summary that never claims controls you don't have

Questions

Is this legal advice?

No. These are professionally written templates tailored to your answers. Read them, adjust anything that doesn't fit, and take legal advice for anything unusual.

Will my insurer accept these?

They're written to answer the policy questions cyber insurers commonly ask, and the Information Security Summary is designed to go straight to your broker. We can't guarantee any individual insurer's decision.

Can I edit the documents?

Yes. Every document comes as an editable Word file and a PDF.

How is it tailored?

Your answers decide which clauses are included, who is named as responsible, which regulator and laws are referenced, your platform-specific steps (Microsoft 365 or Google Workspace), and the order of your 90-day checklist. The wording itself is written and reviewed in advance, not generated on the fly.

We don't have an IT person. Is this still for us?

That's exactly who it's for. The policies name a responsible person, and the 90-day checklist tells you what to do first in plain English.

Which countries does it cover?

Ireland, the UK and the rest of the EU/EEA. Each pack references the right data protection law, regulator and reporting routes for your country.

What if my business changes?

Pro includes unlimited regeneration for 12 months. Annual Updates (€39/year) lets you regenerate any time and keeps your pack current.

What if I'm not happy?

If you haven't downloaded your pack, you can have a full refund within 14 days. If something is wrong with your documents, email us and we'll fix it.

Get your policies sorted this week

12 tailored policies, ready in minutes. From €149, one-off.

Get your policy pack