Why most businesses skip policies, and why that is a mistake
Policies feel bureaucratic. They are not. They are the documented baseline that tells staff what is expected, gives IT the authority to enforce controls, and gives the business legal standing when things go wrong.
Without documented policies, a staff member who mishandles data cannot be held accountable. An insurer can deny a claim. A regulator can apply harsher penalties. Policies are protection, not paperwork.
Three tiers of policy priority
Essential
Every business regardless of size. Without these you have no documented security baseline.
Important
Businesses with more than 10 staff or handling sensitive client data.
Recommended
Best practice for growing businesses. Required for most compliance frameworks.
What each policy should cover
Acceptable Use Policy
Defines what staff can and cannot do with company-owned technology, networks and data. The foundation document. Without it you have no documented basis for enforcing any other security control or disciplinary action.
Key inclusions
- Permitted and prohibited uses of company devices and internet access
- Personal use boundaries on work systems
- Social media conduct when representing the business
- Consequences of policy violations
Information Security Policy
The overarching policy that defines how the business protects its information assets. The parent document all other security policies sit under. Required for most compliance frameworks including Essential Eight, ISO 27001 and SOC 2.
Key inclusions
- Information classification and handling
- Roles and responsibilities for information security
- Risk management approach
- Policy review and update schedule
Password and Credential Policy
Sets the minimum requirements for password length, complexity and storage. Must be paired with a deployed password manager and MFA enforcement to be effective. A policy without tooling to enforce it is meaningless.
Key inclusions
- Minimum password length and complexity requirements
- Prohibition on password sharing and reuse
- Mandatory MFA on all business systems
- Approved credential storage methods (no spreadsheets, no browsers)
Remote Work and BYOD Policy
Defines the security baseline for staff working outside the office and the rules around using personal devices for work. Increasingly important as hybrid work is now standard rather than an exception.
Key inclusions
- Approved devices and operating system requirements
- VPN and network access requirements when working remotely
- BYOD enrolment in MDM and minimum security baseline
- Physical security of devices outside the office
Incident Response Policy
Defines what constitutes a security incident, who is responsible for responding, and the steps to follow. Without this policy, staff do not know what to report, who to call, or how long they have before a notifiable data breach reporting obligation applies.
Key inclusions
- Incident classification and severity definitions
- Reporting chain and contact escalation
- Containment, eradication and recovery steps
- Notifiable data breach obligations under the Privacy Act
Data Backup and Recovery Policy
Documents backup frequency, retention periods, storage locations and recovery testing schedules. Without a written policy, backups often exist in theory but have never been tested. Untested backups are not real backups.
Key inclusions
- Backup frequency and retention schedule
- Offsite and immutable backup requirements
- RTO and RPO targets for each system category
- Recovery testing frequency and documentation
Access Control and Privilege Policy
Establishes the principle of least privilege across all business systems. Staff should only have access to the systems and data they need to do their job. Admin rights should be time-limited and justification-based.
Key inclusions
- Onboarding and offboarding access provisioning
- Prohibition on shared or generic user accounts
- Admin privilege request and approval process
- Periodic access reviews and recertification
Software and Patch Management Policy
Defines how quickly security patches must be applied, who is responsible for patching, and what happens when a system cannot be patched. A direct Essential Eight control. Unpatched systems are the single most common entry point for attackers.
Key inclusions
- Patch application timeframes by severity (critical within 48 hours)
- Approved software list and prohibition on unapproved installs
- Exception and risk acceptance process for systems that cannot be patched
- Patch compliance reporting requirements
Third Party and Supplier Policy
Governs how third parties, vendors and contractors access your systems and data. Supply chain attacks are increasingly common. Your security is only as strong as the controls you impose on organisations that have access to your environment.
Key inclusions
- Supplier security assessment requirements
- Contractual security obligations and data handling clauses
- Vendor access provisioning and time-limited credentials
- Periodic review of third party access
Email and Communication Policy
Sets expectations for how staff use email and other business communication platforms. Phishing is responsible for the large majority of cyber incidents. Clear policy combined with training and technical controls is the most effective prevention approach.
Key inclusions
- Prohibited content in business email
- Rules for sending sensitive data externally
- Reporting suspected phishing emails
- Personal use of business email accounts
Physical Security Policy
Often overlooked in smaller businesses, physical security policy covers workstation locking, clean desk requirements, visitor management and the secure disposal of hardware containing business data.
Key inclusions
- Screen lock requirements when leaving a workstation
- Clean desk policy for sensitive documents
- Visitor sign-in and escort requirements
- Secure disposal of hardware and removable media
What makes policies useless in practice
Downloading templates and filing them away without implementation
The policy exists on paper but nobody knows about it and nothing enforces it. Useless.
Writing policies that are too long and too technical for staff to read
Policies should be readable by a non-technical employee. One page per policy is a good target.
No acknowledgement or sign-off process
If staff have not read and acknowledged the policy, you have limited ability to enforce consequences for violations.
Policies that are never reviewed or updated
A policy written years ago does not account for remote work, cloud services or current threat patterns. Review annually at minimum.
Technical controls that contradict the policy
If the policy says MFA is mandatory but the system does not enforce it, the policy is fiction.
A realistic approach for small and mid-sized businesses
Start with the five essential policies. Do not try to produce all eleven in one sitting. Write policies that are short, clear and enforceable. A one-page acceptable use policy that staff actually read is worth more than a 40-page document nobody opens.
Every policy needs an owner, a review date and a sign-off process. Staff should acknowledge they have read each policy when they join and when the policy is significantly updated. Keep records of acknowledgements. This matters if you ever need to enforce consequences or demonstrate compliance to an insurer or regulator.
Real Bytes can generate a starter set of IT policies custom to your business size, industry and technology stack. We also align policies to the Essential Eight, SMB1001 and Privacy Act obligations. A policy review is included in our initial assessment for all managed service clients.
Related: Cyber Hygiene Guide, Essential Eight Guide, IT Risk Guide, Shadow AI Policy Generator.
Common questions
What IT policies does a small business actually need?
How often should IT policies be reviewed?
Do IT policies need to be signed by staff?
Are downloaded IT policy templates good enough?
Do IT policies help with cyber insurance claims?
How do IT policies align with the Essential Eight and SMB1001?
Need Help Building Your Policy Framework?
Real Bytes produces IT policy frameworks for Australian SMBs aligned to the Essential Eight, SMB1001 and the Privacy Act. We write policies that are actually implementable, not legal boilerplate nobody reads. A policy review is included in our initial assessment for all managed service clients.

Remote Support