What's inside your pack
Twelve policies, three working documents, and in Pro three extras for insurers and clients. Every document comes as an editable Word file and a PDF.
Acceptable Use
How staff may use company devices, email, internet, data and AI tools.
Password and MFA
Modern passphrase rules, password managers and multi-factor authentication for every account.
Incident Response
What to do in the first 15 minutes and 24 hours, including the 72-hour regulator deadline.
Data Protection and Handling
GDPR-aligned classification, handling, retention and individuals' rights.
Access Control
Joiners, movers and leavers, admin rights and an access register.
Backup and Recovery
The 3-2-1 rule, test restores and recovery priorities.
Remote Working
Safe home working, public Wi-Fi and travelling with devices.
Bring Your Own Device
Whether personal phones and laptops are allowed, and the rules if they are.
Email and Phishing
Spotting phishing, reporting it, and stopping bank-detail fraud.
Software and Patch Management
Update deadlines, approved software and anti-malware.
Supplier Security
Checking suppliers who handle your data, contracts and a supplier register.
Information Security Policy
The signed umbrella policy insurers and clients ask for first.
Working documents and Pro extras
Information Security Summary
A one-page overview to send to insurers and clients. It only states controls you actually have.
Staff Acknowledgement Form
A sign-off sheet so every employee confirms they have read the policies.
90-Day Rollout Checklist
Your biggest gaps first, based on your answers, then a clear order for everything else.
Supplier Questionnaire Answer Bank Pro
Suggested answers to the 40 questions clients ask most, matched to your policies.
Cyber Insurance Readiness Checklist Pro
The controls insurers ask about, your status on each, and the evidence to keep.
Framework Mapping Pro
Which ISO 27001, NIST CSF 2.0, CIS and Cyber Essentials controls each policy supports.
How your answers change the documents
| Your answer about | What changes |
|---|---|
| Country | Names the right data protection law, regulator, police and cyber centre for Ireland, the UK or the EU. |
| Team size | Sets how often access is reviewed and how formal the procedures are. |
| Who runs IT | Names your IT contact throughout and adds IT provider clauses if you outsource. |
| Email platform | Adds Microsoft 365 or Google Workspace specific MFA, device and phishing-report steps. |
| Remote work and personal devices | Chooses between strict, light or 'not permitted' versions of the device and remote-working rules. |
| MFA, passwords and backups | States your real position and puts any gaps at the top of your 90-day checklist. |
| Sensitive data | Adds clauses for health data, card payments or children's information only if you handle them. |
| Insurance and clients | Adjusts incident steps for insurers and prepares Pro answers for client questionnaires. |
Get your policies sorted this week
12 tailored policies, ready in minutes. From €149, one-off.