Skip to content

Guides

Cyber security policies for small businesses: what do you actually need?

Cyber security policies can quickly become more complicated than they need to be. For a smaller organisation, the objective isn't to build a large library of documents. It is to establish clear expectations that reflect how the business actually works and help people make the right decisions.

H ChangePublished 4 minute read

Government research published in 2026 found that 52% of small UK businesses had a formal policy covering cyber security risks, down from 59% the previous year.

That doesn't mean every small business needs a large library of security documents.

The better starting point is understanding what your organisation needs to protect, the requirements it needs to meet and where people need clear direction.

Start with why you need them

Before writing a policy, understand what it needs to achieve.

Sometimes the requirement comes from inside the organisation. The business may have grown to the point where informal ways of working are no longer enough.

Sometimes it comes from somewhere else. A customer may ask about your security arrangements. A contract may require particular controls. You may be responding to a security questionnaire or working towards a recognised standard.

Those situations can require different things.

Downloading a collection of policy templates may give you documents. It doesn't necessarily give you policies that reflect your business.

Start with the requirement, then decide what needs to be documented.

Focus on the policies that matter

There isn't a single policy set that every small business needs.

Some common areas are likely to need clear expectations. These might include how information and company systems are used, how access is controlled, how accounts are protected, what happens when somebody joins or leaves, how security incidents are reported and how people should work securely away from the workplace.

Suppliers and third parties may also need consideration where they can access your information, systems or services.

Other requirements will depend on the organisation.

The important point is that your policy set should follow your business needs rather than a generic checklist.

Keep policies usable

A policy can be comprehensive and still be ineffective.

If it is unnecessarily long, difficult to understand or disconnected from the way people actually work, it is less likely to be useful.

People should be able to understand what applies to them, what they are expected to do and where to go if they need help.

That doesn't mean every policy needs to fit on one page. Some subjects genuinely need more detail.

But complexity should come from the requirement, not from a belief that a longer document automatically provides better security.

Policy, standard or procedure?

These terms are often used interchangeably, but they have different purposes.

A policy sets out the organisation's position and expectations.

A standard defines specific requirements that need to be met.

A procedure explains how a particular activity should be carried out.

Keeping those purposes clear can prevent one document becoming a mixture of high-level expectations, detailed requirements and step-by-step instructions.

For a smaller organisation, this doesn't need to become bureaucratic. The aim is simply to make requirements and responsibilities clear.

Approval isn't the end

A policy only provides value if it remains relevant.

Policies should have an owner and should be reviewed when something significant changes. They should also be checked periodically to make sure they still reflect how the organisation operates.

People need to know about the requirements that affect them too.

That doesn't mean asking everybody to memorise a policy library. Important expectations should be reinforced through induction, training, management conversations and everyday processes.

If a policy says one thing while the organisation routinely works another way, the document isn't achieving very much.

What this means for your organisation

If you're reviewing your cyber security policies, start with five questions:

1. What security requirements do we actually need to document?

2. Are there customer, contractual, regulatory or certification requirements we need to consider?

3. Do our policies reflect how we genuinely work?

4. Can people understand what is expected of them?

5. Does each policy have an owner and a sensible review point?

You may find that you need some new policies.

You may equally find that existing documents need simplifying, combining or updating.

The objective isn't to build the largest policy library. It is to establish clear security expectations that support the organisation and can be put into practice.

Policies & Standards

Practical policies built around your business

H Change helps smaller organisations develop and improve cyber security policies and standards that reflect how they work and the requirements they need to meet.