The Security Policies Every Small Business Needs

By J. Mesa

An auditor, an insurance underwriter, and a new enterprise customer all open with the same request: send us your security policies. Many small businesses answer with silence or with a template downloaded the night before. Written policies are where a security program starts, because you can’t train people on rules that do not exist and you can’t enforce a rule nobody wrote down.

What is an information security policy?

An information security policy is a written statement of the rules your business follows to protect its information and systems. It says what must happen, who is responsible, and what the rule applies to. Leadership approves it, and every employee reads and acknowledges it.

What is the difference between a policy, a standard, and a procedure?

  • A policy states the rule. “All employees use multi-factor authentication to access company email.”
  • A standard sets the specific requirement. “Authenticator apps or security keys. No text message codes for administrators.”
  • A procedure gives the steps. “To enroll, open the security settings page, choose Add method, and scan the code.”

A small business can combine all three in a single document per topic. Keep the rule clear and the steps current.

Which security policies does a small business need first?

Start with these ten.

  1. Information security policy. The master document. It states leadership’s commitment, names the person responsible for security, defines the scope, and points to the other policies.
  2. Acceptable use policy. What employees may and may not do with company computers, email, internet access, and data. Cover personal use, software installation, and AI tools.
  3. Access control and password policy. Who gets access to what, how you approve it, password length, the password manager, multi-factor authentication, and how you remove access when someone leaves.
  4. Data classification and handling policy. The categories of data you hold, such as public, internal, and restricted, and the rules for storing, sending, and sharing each one.
  5. Incident response plan. Who to call and what to do when something goes wrong. See our guide to the first 24 hours.
  6. Backup and disaster recovery policy. What you back up, how often, where the copies live, how you test them, and how fast you need to recover. See the 3-2-1 rule.
  7. Remote work and mobile device policy. Requirements for home networks, personal devices, public Wi-Fi, and lost or stolen equipment.
  8. Vendor management policy. How you vet and monitor the companies that hold your data.
  9. Security awareness training policy. Who gets trained, how often, on what, and how you record it.
  10. Data retention and disposal policy. How long you keep each type of record and how you destroy paper, drives, and devices.

Add these as you grow: patch and vulnerability management, change management, physical security, encryption, logging and monitoring, and a payment verification procedure for wires and bank detail changes.

What should each policy contain?

Use the same structure for each one.

  • Purpose. One or two sentences on why the policy exists.
  • Scope. The people, systems, and data it covers.
  • Policy statements. The rules, in numbered sentences that use “must.”
  • Roles and responsibilities. Who does what.
  • Exceptions. How someone requests one and who approves it.
  • Enforcement. The consequences of a violation.
  • Review. The owner, the approval date, the version, and the next review date.

How long should a security policy be?

Short enough that your staff read it. Two to four pages per policy suits most small businesses. A 60-page manual that sits unread protects nobody and creates a liability, because it documents rules you do not follow.

Can I use a security policy template?

Yes, as a starting point. Good free sources include the SANS Institute policy templates, the Center for Internet Security, and, for tax professionals, the Written Information Security Plan template in IRS Publication 5708.

Then customize. Replace each generic statement with what your business does. Delete the sections that do not apply. A template that requires a “Change Advisory Board” at a six-person office tells an auditor that nobody read the document. Regulators and plaintiffs’ attorneys compare your written policy against your actual practice, and a gap between the two hurts more than a shorter, honest policy would.

What do compliance rules require in writing?

  • HIPAA requires written policies and procedures for the Security Rule, kept for six years.
  • PCI DSS requirement 12 calls for an information security policy that you publish, maintain, and review at least once a year, along with an acceptable use policy and an incident response plan.
  • The FTC Safeguards Rule requires a written information security program and, above the small-business threshold, a written risk assessment and incident response plan.
  • Cyber insurance applications ask whether you maintain written policies and an incident response plan.
  • Customer contracts and SOC 2 audits request the full set.

Who should write and approve the policies?

Assign one owner, usually the person responsible for security. Involve the people who know how the work happens: your IT provider, HR, the office manager, and the finance lead. Have an attorney review the policies that touch employment, privacy, and monitoring. The business owner or the board approves the final versions in writing. That approval carries weight with staff and with auditors.

How do I get employees to follow them?

  • Explain the reason behind each rule. People follow rules they understand.
  • Make the secure way the easy way. Provide the password manager, the approved file sharing tool, and the approved AI tool, so staff have no need for workarounds.
  • Cover the policies at hiring, and collect a signed acknowledgment.
  • Reinforce them in training with examples from your own business.
  • Have leaders follow the same rules. An owner who skips multi-factor authentication has cancelled the policy for everyone.
  • Respond to violations with consistency, and thank the people who report mistakes.

How often should I review the policies?

Once a year at minimum. Review a policy sooner after a security incident, a new law or contract requirement, a major technology change, or a change in how the business operates. Record the review date and what changed. A policy last touched four years ago, with a former employee listed as the owner, will draw a finding.

What are the most common policy mistakes?

  • Copying a template without changing it
  • Writing rules the business can’t or won’t follow
  • Publishing the policies and never training anyone on them
  • No named owner
  • No review dates
  • No process for exceptions, so staff invent their own
  • Storing the incident response plan only on the systems an attack would lock
  • Treating the documents as the goal and the practice as optional

How do I start?

  1. List the regulations and contracts that apply to you.
  2. Write the information security policy and the acceptable use policy first.
  3. Add the incident response plan.
  4. Work through the rest of the ten over 90 days.
  5. Have leadership approve each one.
  6. Train the staff and collect acknowledgments.
  7. Put the next review date on the calendar.

Your next step

Gather every security policy your business has today and check each one for an owner, an approval, and a date within the last year. The ones that fail the check are your starting list. Policy and documentation development is one of the three core services at Cerberus Cybersecurity. We write policies that match how your business runs and that hold up in front of auditors. See our services or contact us.