The eight security policies a small business needs, and why not twenty
The goal of a policy is that staff read it and an insurer accepts it. Both are easier with eight one-page policies than with a 60-page framework. Here is the minimum defensible set, mapped to the controls behind it.
A policy nobody has read is worse than no policy, because after an incident it becomes evidence that you knew what to do and didn't. So the design constraint for a small business isn't completeness; it's that every policy fits on a page or two, says what people must actually do, and has a signature under it.
Eight policies cover the controls that cyber-insurers, enterprise customers and the CIS Controls v8 Implementation Group 1 all agree on for a company under 100 people.
1. Acceptable Use
How staff may use company systems, internet and email; what's prohibited (personal cloud storage, unapproved software, entering company data into unapproved AI tools); that the company may monitor its own systems; and how to report a lost device or a mistake. This is the policy that gets quoted in an HR meeting, so it needs to be unambiguous. CIS 14 · NIST CSF PR.AT
2. Password and MFA
Fourteen-character passphrases, unique per account, stored in the approved password manager; no scheduled expiry, immediate change on suspicion; MFA mandatory on email, remote access, admin consoles, banking and anything holding customer data, with authenticator apps preferred over SMS; never approve a prompt you didn't trigger. Separate admin accounts. Default passwords changed before a device touches the network. CIS 5, 6 · PR.AA
3. Access Control
Least privilege; named accounts, no shared logins; joiner/mover/leaver process with the leaver's access disabled on the last day; no local admin for standard users; access reviewed every quarter or half-year and documented; inactive accounts disabled after 45 days. This is the policy behind two separate insurance questions. CIS 5, 6 · PR.AA
4. Data Protection and Backup
A four-level classification table (public, internal, confidential, regulated) with handling rules for each; approved storage locations; full-disk encryption on every laptop; the 3-2-1 backup rule with one immutable or offline copy; a quarterly restore test; retention periods and secure disposal. Privacy law references belong here (PIPEDA and provincial equivalents in Canada). CIS 3, 11 · PR.DS
5. Remote Work and Mobile Devices (BYOD)
Device requirements for working from home (encryption, screen lock, updates, EDR); what personal devices may access and on what conditions (management enrolment or app-level protection, and a clear statement that the company only ever wipes company data); public Wi-Fi rules; travel and border considerations; physical security at home. CIS 4, 10 · PR.PS
6. Email, Phishing and Social Engineering
How to recognise a suspicious message, how to report it, and the rule that matters most: any request to change bank details or make an unusual payment is verified by phone to a number already on file, even when it appears to come from the owner. Dual approval for new payees above a threshold. This single paragraph is the control against business email compromise, the most common small-business loss. CIS 9, 14 · PR.AT
7. Incident Response
What counts as an incident, who to report it to and how fast ("immediately" means minutes), what not to do (don't investigate, don't power off, disconnect instead), the five response phases with an owner each, and the external contacts. The policy is the short version; the plan is the long one. CIS 17 · RS
8. Vendor and Third-Party Security
New tools that hold confidential data are approved before use (this is the shadow-IT rule); a vendor register recording what data each holds and where; minimum requirements (MFA support, encryption, breach notification within 72 hours); contract clauses; and annual review with off-boarding of unused vendors. CIS 15 · GV.SC
Plus two forms
An acknowledgement form each employee signs, re-issued when a policy materially changes, and an exceptions log so that when the owner insists on keeping local admin, it's written down with a compensating control rather than quietly ignored.
What you can leave out under 100 people
A standalone change-management policy, a physical-security policy (fold it into remote work and acceptable use), a separate email policy (it's in acceptable use and phishing), and anything with the word "framework" in the title. If you later pursue SOC 2 or ISO 27001, you'll add those on top of this set, not replace it.
Free excerpt: the Acceptable Use "prohibited activities" list
- Attempt to bypass, disable or test security controls (antivirus, firewalls, web filters, MFA) on any company system.
- Install software, browser extensions or "free" utilities not approved by the IT Lead.
- Connect unauthorised USB drives or network equipment to company computers or networks.
- Copy company data to personal cloud storage, personal email, or unapproved AI tools.
- Enter customer data, financial data, credentials or confidential business information into any AI chatbot or online tool that has not been approved by the IT Lead.
Write the other seven to the same standard: short, imperative, specific. Or start from the finished bundle, which has all eight with the control mappings and forms included.