A cyber incident rarely begins with a dramatic technical failure. More often, it starts with a convincing email, a reused password or a member of staff trying to get a job done quickly. That is why cyber security policies for small business need to be practical working rules, not a document that sits unread in a shared folder.
For a small business, the right policy set reduces uncertainty. Your staff know what to do, who to tell and which shortcuts are not worth the risk. It also gives directors confidence that customer information, business systems and day-to-day operations are being looked after sensibly.
What a cyber security policy should do
A policy is simply an agreed way of working. In cyber security, it sets expectations around the systems, information and devices your business relies on. It should make safe behaviour the easiest behaviour, rather than placing more admin on already busy people.
Good policies are short enough to be used and specific enough to guide decisions. A policy saying that staff must be careful with email is well meaning but not especially useful. A policy stating that staff must not enter passwords after following an unexpected email link, and must report suspicious messages immediately, gives people something clear to act on.
The detail will depend on your size, sector and risk. A charity holding sensitive supporter records has different considerations from a garage using diagnostic systems and booking software. Both, however, need controls that protect access, preserve reliable backups and keep the business running when something goes wrong.
The cyber security policies small businesses need first
You do not need to produce a large handbook on day one. Start with the areas most likely to cause a costly problem, then review them as your business changes. The following policies form a sensible baseline for most Sussex businesses.
Passwords and multi-factor authentication
Your password policy should require a unique, strong password for every account and prohibit password sharing. Password managers are often the most realistic way to achieve this, because they let staff use long, unique passwords without needing to remember every one.
Multi-factor authentication, often called MFA, should be required on email, cloud storage, finance systems, remote access and any administrator account. This extra check is not infallible, particularly if someone is persuaded to approve a fraudulent sign-in request. But it substantially reduces the damage a stolen password can cause.
The policy should also state who can access shared accounts, how access is removed when somebody leaves and what to do if a password is suspected to be exposed. Delays in removing former staff access are an avoidable risk.
Email, phishing and payment checks
Email is still the route into many small-business compromises. A clear policy should tell staff how to recognise and report suspicious messages, including emails that appear to come from a director, supplier or trusted customer.
It should make one rule non-negotiable: any request to change bank details, make an unusual payment, buy vouchers or share sensitive data must be independently verified. That means calling a known number or speaking to the person directly, not replying to the original email or using a number within it.
There is a trade-off here. Too many warnings can make staff tune out; too little guidance leaves them guessing. Short, regular awareness sessions using examples relevant to your business are usually more effective than annual training that people rush through once.
Device and remote-working rules
Laptops, mobiles and tablets carry business data far beyond the office. Your device policy should cover company-owned equipment and, if applicable, personal devices used for work.
At a minimum, require screen locks, automatic updates, approved security software and encrypted storage where available. Staff should know not to leave devices unattended in cars, lend them to others or connect unknown USB devices. Set out how lost equipment must be reported, including outside normal working hours if the device can access sensitive systems.
Remote working also needs a common-sense approach. Public Wi-Fi is not automatically forbidden, but staff should avoid accessing sensitive information on an unsecured network and use approved protection where it is provided. The aim is to support flexible work without treating every kitchen table or client site as a secure office.
Data handling and sharing
Your data policy should explain what information is confidential, where it may be stored and who is allowed to see it. This commonly includes customer details, staff records, financial information, contracts and commercially sensitive documents.
Set out approved places for storing and sharing files. Sending data to personal email addresses, saving it to an unapproved cloud account or sharing it through a consumer file-transfer service may feel convenient, but it creates blind spots. It can also make it difficult to meet your obligations under UK data protection law if information is lost or disclosed.
Retention matters too. Keeping every file forever increases the potential impact of an incident. Agree how long key information needs to be kept, then dispose of it securely when it no longer has a business purpose.
Access control and new starters
People should have the access they need to do their jobs, not unrestricted access simply because it is easier to set up. This principle is particularly important for finance software, customer databases and cloud administration.
Your access policy should cover starters, role changes, temporary access and leavers. Make a named manager responsible for confirming access requirements, and ensure accounts are disabled promptly when someone leaves. Review privileged accounts regularly, especially where an external supplier or former contractor has been given access.
Backups and recovery
A backup policy is not just a statement that backups happen. It should identify which systems and data are backed up, how frequently, where copies are held, who receives alerts and how restoration is tested.
The testing point is where many businesses get caught out. A backup that has never been restored is an assumption, not a recovery plan. Test whether you can recover a key file, a mailbox or a business system within a time that your operations can tolerate.
Keep at least one protected copy separate from the main network or cloud environment. Ransomware can affect connected backups as well as live systems. The exact setup depends on the systems you use, but the principle is consistent: a criminal or technical fault should not be able to destroy every copy at once.
Incident reporting and response
Staff should never worry that reporting a mistake will get them into trouble. The sooner a suspicious email, lost device or mistaken data disclosure is raised, the more options you have to contain it.
Your incident policy should say who to contact, what details to record and who can make decisions about customers, insurers, regulators or the police. It should also cover the first practical steps: disconnect an affected device if instructed, preserve evidence and do not attempt a quick fix that could make investigation harder.
For many small businesses, a short incident plan with names, phone numbers and priorities is more useful than a complex document. Keep a copy available if your main systems are unavailable.
Make policies part of normal work
Policies fail when they are handed to staff once and never mentioned again. Introduce each policy in plain English, explain the reason behind it and build the rules into everyday processes. A new starter should receive security guidance as part of induction, not weeks later when there is time.
Review policies at least annually, and after meaningful changes such as moving to a new cloud system, hiring more staff, opening a site or suffering an incident. Ask whether the rules reflect how people actually work. If staff constantly work around a control, investigate the reason rather than assuming they do not care about security.
It also helps to assign ownership. Someone in the business should be responsible for making sure policies are current, training is completed and exceptions are agreed rather than quietly ignored. That person does not need to be a cyber security specialist, but they do need access to the right advice.
When outside support makes sense
Writing a policy is only one part of protecting the business. The controls behind it matter just as much: properly configured MFA, monitored devices, secure backups, managed updates and reliable support when something looks wrong.
If you do not have an internal IT team, an experienced managed provider can translate your risks into straightforward policies and put the technical measures in place. My Tech Team works with small businesses across Sussex to make security manageable, without burying owners and office managers in jargon or unnecessary paperwork.
A useful first step is to take one real business process – approving supplier payments, sharing customer information or setting up a new starter – and check whether your current rules would help someone make the right decision under pressure. That is where a cyber security policy starts earning its place.