All Guides
Governance

IT Policies Every Australian Business Actually Needs

Most small and mid-sized businesses have no IT policies, or they downloaded templates years ago and filed them away. Neither approach protects you. This guide covers the policies that matter, what each one should contain, and the mistakes that make policies useless in practice.

Last updated October 20269 min read

Why most businesses skip policies, and why that is a mistake

Policies feel bureaucratic. They are not. They are the documented baseline that tells staff what is expected, gives IT the authority to enforce controls, and gives the business legal standing when things go wrong.

Without documented policies, a staff member who mishandles data cannot be held accountable. An insurer can deny a claim. A regulator can apply harsher penalties. Policies are protection, not paperwork.

Three tiers of policy priority

Essential

Every business regardless of size. Without these you have no documented security baseline.

Important

Businesses with more than 10 staff or handling sensitive client data.

Recommended

Best practice for growing businesses. Required for most compliance frameworks.

What each policy should cover

Acceptable Use Policy

Essential

Defines what staff can and cannot do with company-owned technology, networks and data. The foundation document. Without it you have no documented basis for enforcing any other security control or disciplinary action.

Key inclusions

  • Permitted and prohibited uses of company devices and internet access
  • Personal use boundaries on work systems
  • Social media conduct when representing the business
  • Consequences of policy violations

Information Security Policy

Essential

The overarching policy that defines how the business protects its information assets. The parent document all other security policies sit under. Required for most compliance frameworks including Essential Eight, ISO 27001 and SOC 2.

Key inclusions

  • Information classification and handling
  • Roles and responsibilities for information security
  • Risk management approach
  • Policy review and update schedule

Password and Credential Policy

Essential

Sets the minimum requirements for password length, complexity and storage. Must be paired with a deployed password manager and MFA enforcement to be effective. A policy without tooling to enforce it is meaningless.

Key inclusions

  • Minimum password length and complexity requirements
  • Prohibition on password sharing and reuse
  • Mandatory MFA on all business systems
  • Approved credential storage methods (no spreadsheets, no browsers)

Remote Work and BYOD Policy

Essential

Defines the security baseline for staff working outside the office and the rules around using personal devices for work. Increasingly important as hybrid work is now standard rather than an exception.

Key inclusions

  • Approved devices and operating system requirements
  • VPN and network access requirements when working remotely
  • BYOD enrolment in MDM and minimum security baseline
  • Physical security of devices outside the office

Incident Response Policy

Essential

Defines what constitutes a security incident, who is responsible for responding, and the steps to follow. Without this policy, staff do not know what to report, who to call, or how long they have before a notifiable data breach reporting obligation applies.

Key inclusions

  • Incident classification and severity definitions
  • Reporting chain and contact escalation
  • Containment, eradication and recovery steps
  • Notifiable data breach obligations under the Privacy Act

Data Backup and Recovery Policy

Important

Documents backup frequency, retention periods, storage locations and recovery testing schedules. Without a written policy, backups often exist in theory but have never been tested. Untested backups are not real backups.

Key inclusions

  • Backup frequency and retention schedule
  • Offsite and immutable backup requirements
  • RTO and RPO targets for each system category
  • Recovery testing frequency and documentation

Access Control and Privilege Policy

Important

Establishes the principle of least privilege across all business systems. Staff should only have access to the systems and data they need to do their job. Admin rights should be time-limited and justification-based.

Key inclusions

  • Onboarding and offboarding access provisioning
  • Prohibition on shared or generic user accounts
  • Admin privilege request and approval process
  • Periodic access reviews and recertification

Software and Patch Management Policy

Important

Defines how quickly security patches must be applied, who is responsible for patching, and what happens when a system cannot be patched. A direct Essential Eight control. Unpatched systems are the single most common entry point for attackers.

Key inclusions

  • Patch application timeframes by severity (critical within 48 hours)
  • Approved software list and prohibition on unapproved installs
  • Exception and risk acceptance process for systems that cannot be patched
  • Patch compliance reporting requirements

Third Party and Supplier Policy

Recommended

Governs how third parties, vendors and contractors access your systems and data. Supply chain attacks are increasingly common. Your security is only as strong as the controls you impose on organisations that have access to your environment.

Key inclusions

  • Supplier security assessment requirements
  • Contractual security obligations and data handling clauses
  • Vendor access provisioning and time-limited credentials
  • Periodic review of third party access

Email and Communication Policy

Recommended

Sets expectations for how staff use email and other business communication platforms. Phishing is responsible for the large majority of cyber incidents. Clear policy combined with training and technical controls is the most effective prevention approach.

Key inclusions

  • Prohibited content in business email
  • Rules for sending sensitive data externally
  • Reporting suspected phishing emails
  • Personal use of business email accounts

Physical Security Policy

Recommended

Often overlooked in smaller businesses, physical security policy covers workstation locking, clean desk requirements, visitor management and the secure disposal of hardware containing business data.

Key inclusions

  • Screen lock requirements when leaving a workstation
  • Clean desk policy for sensitive documents
  • Visitor sign-in and escort requirements
  • Secure disposal of hardware and removable media

What makes policies useless in practice

Downloading templates and filing them away without implementation

The policy exists on paper but nobody knows about it and nothing enforces it. Useless.

Writing policies that are too long and too technical for staff to read

Policies should be readable by a non-technical employee. One page per policy is a good target.

No acknowledgement or sign-off process

If staff have not read and acknowledged the policy, you have limited ability to enforce consequences for violations.

Policies that are never reviewed or updated

A policy written years ago does not account for remote work, cloud services or current threat patterns. Review annually at minimum.

Technical controls that contradict the policy

If the policy says MFA is mandatory but the system does not enforce it, the policy is fiction.

A realistic approach for small and mid-sized businesses

Start with the five essential policies. Do not try to produce all eleven in one sitting. Write policies that are short, clear and enforceable. A one-page acceptable use policy that staff actually read is worth more than a 40-page document nobody opens.

Every policy needs an owner, a review date and a sign-off process. Staff should acknowledge they have read each policy when they join and when the policy is significantly updated. Keep records of acknowledgements. This matters if you ever need to enforce consequences or demonstrate compliance to an insurer or regulator.

Real Bytes can generate a starter set of IT policies custom to your business size, industry and technology stack. We also align policies to the Essential Eight, SMB1001 and Privacy Act obligations. A policy review is included in our initial assessment for all managed service clients.

Related: Cyber Hygiene Guide, Essential Eight Guide, IT Risk Guide, Shadow AI Policy Generator.

Common questions

What IT policies does a small business actually need?
Every business needs five essential policies as a baseline: acceptable use, information security, password and credential, remote work and BYOD, and incident response. Larger businesses or those handling sensitive client data should add backup, access control and patch management policies.
How often should IT policies be reviewed?
Annually at minimum, and whenever a major change occurs such as a shift to hybrid work, a new cloud platform, or new regulatory obligations. A policy that has not been reviewed in over a year is likely out of step with how the business actually operates.
Do IT policies need to be signed by staff?
Yes. Staff should acknowledge they have read each policy when they join and when a policy is significantly updated. Keep records of acknowledgement. This matters if you ever need to enforce consequences or demonstrate compliance to an insurer or regulator.
Are downloaded IT policy templates good enough?
No. A generic template filed away and never implemented protects nothing. Policies need to reflect how your business actually works, be short enough for staff to read, and be backed by technical controls that enforce them. A one-page acceptable use policy staff actually read beats a 40-page document nobody opens.
Do IT policies help with cyber insurance claims?
Yes. Insurers increasingly require documented policies as a condition of cover and assess whether they were actually enforced. A claim can be denied if the policy said MFA was mandatory but the system did not enforce it, or if no incident response plan existed when a breach occurred.
How do IT policies align with the Essential Eight and SMB1001?
The ACSC Essential Eight expects documented policies for access control, patching and backup. SMB1001 requires a full information security management system including policies. The Privacy Act requires clear practices for handling personal information. We align policies to all three so one framework satisfies multiple obligations.

Need Help Building Your Policy Framework?

Real Bytes produces IT policy frameworks for Australian SMBs aligned to the Essential Eight, SMB1001 and the Privacy Act. We write policies that are actually implementable, not legal boilerplate nobody reads. A policy review is included in our initial assessment for all managed service clients.