← Guides

Does a small business need an IT security policy?

Why insurers, clients and data protection law all expect small businesses to have written IT security policies, and which ones matter most.

Yes, and the reasons have changed. A few years ago a written IT security policy was something only larger companies had. Now three different pressures land on businesses of every size.

1. Data protection law expects it

If you hold personal data about customers, staff or suppliers, GDPR (and the UK GDPR) requires "appropriate technical and organisational measures" to protect it. Written policies are the organisational part. They are also your evidence: if something goes wrong, a regulator will ask what rules you had in place and whether staff knew about them.

The law also sets a clock. A personal data breach that poses a risk to people must be reported to the regulator within 72 hours of you becoming aware of it. Without a written incident plan, most small businesses lose the first day working out who should do what.

2. Cyber insurers ask for it

Cyber insurance proposal forms routinely ask whether you have a written information security policy, an incident response plan, multi-factor authentication and tested backups. Answering "no" can mean a higher premium, an exclusion, or no quote at all. Answering "yes" when it isn't true is worse: it can invalidate a claim.

3. Your clients ask for it

Larger organisations are now expected to manage the security of their suppliers. In practice that means a questionnaire arriving before a contract is signed or renewed, and the first question is usually "Please attach your information security policies."

Which policies matter most?

For a business of 5 to 50 people, these cover what insurers, clients and regulators ask about most:

  • An overarching Information Security Policy, signed by the owner or a director
  • Acceptable Use: how staff may use devices, email, internet and data
  • Password and Multi-Factor Authentication
  • Incident Response: who does what in the first 15 minutes and 24 hours
  • Data Protection and Handling
  • Backup and Recovery
  • Access Control: what happens when people join, change role and leave
  • Email and Phishing, including bank-detail fraud

What makes a good policy?

Short, specific and true. A policy that says "all data is encrypted with AES-256 and reviewed quarterly by the security team" is worse than useless for a 10-person firm with no security team. Good small-business policies name real people, match the systems you actually use, and set rules staff can follow without an IT degree.

The quickest way to get there

You can write them yourself from a generic template (allow a weekend), pay a consultant (typically €1,500 or more), or use PolicyPack: answer 18 questions and get 12 tailored policies in Word and PDF in about 10 minutes. If you'd like to see the quality first, the Password and MFA Policy is free.

Get your policies in place in 10 minutes

12 tailored IT and cybersecurity policies in Word and PDF, from €149.

See the policy pack