For small businesses in Ireland, the UK and the EU
Your IT and cybersecurity policies, written for your business, in 10 minutes.
Answer 18 quick questions. Get 12 tailored, editable policies that your insurer, your clients and your staff will actually understand.
Why now
Your insurer asked
“Do you have a written incident response plan?” It's on almost every cyber insurance proposal form.
A client asked
A 40-question security questionnaire arrived before a contract renewal, and it starts with “Please attach your policies.”
You know it's overdue
Your IT runs on good intentions. One fake invoice or lost laptop would expose it.
All three need the same thing: proper written policies. Consultants charge €1,500 or more. Generic templates take a weekend to adapt and still mention companies that aren't yours.
How it works
Choose your pack
Pay securely by card, Apple Pay or Google Pay. VAT invoices are issued automatically.
Answer 18 questions
Plain-English questions about your team, systems and data. About 5 minutes.
Download your pack
Tailored Word and PDF documents a few minutes later, ready to share with staff.
What's inside
Twelve policies covering what insurers, clients and regulators ask about most.
Acceptable Use
How staff may use company devices, email, internet, data and AI tools.
Password and MFA
Modern passphrase rules, password managers and multi-factor authentication for every account.
Incident Response
What to do in the first 15 minutes and 24 hours, including the 72-hour regulator deadline.
Data Protection and Handling
GDPR-aligned classification, handling, retention and individuals' rights.
Access Control
Joiners, movers and leavers, admin rights and an access register.
Backup and Recovery
The 3-2-1 rule, test restores and recovery priorities.
Remote Working
Safe home working, public Wi-Fi and travelling with devices.
Bring Your Own Device
Whether personal phones and laptops are allowed, and the rules if they are.
Email and Phishing
Spotting phishing, reporting it, and stopping bank-detail fraud.
Software and Patch Management
Update deadlines, approved software and anti-malware.
Supplier Security
Checking suppliers who handle your data, contracts and a supplier register.
Information Security Policy
The signed umbrella policy insurers and clients ask for first.
Plus the documents that make them work
Information Security Summary
A one-page overview to send to insurers and clients. It only states controls you actually have.
Staff Acknowledgement Form
A sign-off sheet so every employee confirms they have read the policies.
90-Day Rollout Checklist
Your biggest gaps first, based on your answers, then a clear order for everything else.
Supplier Questionnaire Answer Bank Pro
Suggested answers to the 40 questions clients ask most, matched to your policies.
Cyber Insurance Readiness Checklist Pro
The controls insurers ask about, your status on each, and the evidence to keep.
Framework Mapping Pro
Which ISO 27001, NIST CSF 2.0, CIS and Cyber Essentials controls each policy supports.
Practical policies, not generic templates
Every policy is written from hands-on experience running IT and security in real organisations, from small teams to global companies, including PCI DSS and ISO 27001 audits and data protection compliance.
Every clause is written and reviewed in advance. Your answers decide which clauses apply to you; nothing is made up on the fly.
About PolicyPack →Tailored to your answers
- Your company, your named contacts, your approval dates
- The right regulator and law for Ireland, the UK or the EU
- Microsoft 365 or Google Workspace specific steps
- Clauses for health data, card payments or children's data
- A rollout plan that starts with your biggest gaps
- A security summary that never claims controls you don't have
Questions
Is this legal advice?
No. These are professionally written templates tailored to your answers. Read them, adjust anything that doesn't fit, and take legal advice for anything unusual.
Will my insurer accept these?
They're written to answer the policy questions cyber insurers commonly ask, and the Information Security Summary is designed to go straight to your broker. We can't guarantee any individual insurer's decision.
Can I edit the documents?
Yes. Every document comes as an editable Word file and a PDF.
How is it tailored?
Your answers decide which clauses are included, who is named as responsible, which regulator and laws are referenced, your platform-specific steps (Microsoft 365 or Google Workspace), and the order of your 90-day checklist. The wording itself is written and reviewed in advance, not generated on the fly.
We don't have an IT person. Is this still for us?
That's exactly who it's for. The policies name a responsible person, and the 90-day checklist tells you what to do first in plain English.
Which countries does it cover?
Ireland, the UK and the rest of the EU/EEA. Each pack references the right data protection law, regulator and reporting routes for your country.
What if my business changes?
Pro includes unlimited regeneration for 12 months. Annual Updates (€39/year) lets you regenerate any time and keeps your pack current.
What if I'm not happy?
If you haven't downloaded your pack, you can have a full refund within 14 days. If something is wrong with your documents, email us and we'll fix it.
Get your policies sorted this week
12 tailored policies, ready in minutes. From €149, one-off.