Cybersecurity isn’t just about firewalls, endpoint protection, MFA, and strong passwords. One of the most overlooked parts of protecting a business is having written security policies that explain how your organization expects employees, managers, and IT providers to handle technology and sensitive information.
You don’t need a 200-page security manual to get started. Every business should have a basic set of practical policies that establish clear expectations and provide a roadmap when something goes wrong.
Check http://mcservices.com/cyber for a survey to see how your organization’s security rates.
Here are the first policies we recommend every business have in place.
1. Information Security Policy
This is the foundation for your security program. It should explain your organization’s overall approach to protecting company systems, data, and information.
It should address:
- Who is responsible for cybersecurity
- What systems and information need to be protected
- Employee security responsibilities
- Acceptable use of company technology
- How security incidents are reported
- How policies are reviewed and updated
Think of this as the overall framework that ties your other security policies together.
2. Password and Authentication Policy
Passwords remain one of the most common ways attackers gain access to businesses.
Your policy should establish requirements for:
- Strong, unique passwords
- Password managers
- Multi-factor authentication (MFA)
- Prohibiting password sharing
- Protecting administrative accounts
- Changing compromised passwords
- Use of company versus personal accounts
Whenever possible, businesses should also consider phishing-resistant authentication, such as passkeys or security keys, for important accounts.
3. Access Control Policy
Employees should have access to the information and systems they need to do their jobs—but nothing more.
An access control policy should define:
- How access is requested and approved
- Who can approve access
- What administrative access is permitted
- How access is reviewed
- Requirements for remote access
- Access for contractors and vendors
A good rule is least privilege: users should receive only the access necessary to perform their job.
4. Employee Onboarding Policy
Security starts on an employee’s first day.
Your onboarding policy should provide a consistent process for setting up new employees, including:
- Creating the employee’s account
- Assigning appropriate permissions
- Providing a company computer and other equipment
- Enabling MFA
- Installing required security software
- Providing security awareness training
- Reviewing acceptable-use requirements
- Documenting the equipment assigned to the employee
A standardized onboarding checklist helps ensure that important security steps aren’t missed.
5. Employee Offboarding Policy
Offboarding is just as important—and potentially more dangerous—than onboarding.
When someone leaves the company, their access should be removed promptly.
Your offboarding process should include:
- Disabling accounts
- Removing MFA devices and sessions
- Revoking VPN and remote access
- Removing access to cloud applications
- Recovering company equipment
- Changing shared passwords when necessary
- Transferring ownership of files and accounts
- Removing access to third-party services
- Documenting completion of the process
For involuntary terminations or employees with elevated access, the process should be coordinated with management and IT so access can be removed at the appropriate time.
6. Acceptable Use Policy
Employees should know what is—and isn’t—appropriate when using company technology.
An acceptable-use policy can cover:
- Company computers and mobile devices
- Internet and email use
- Personal software
- Cloud services
- USB drives and external storage
- Personal devices
- Social media
- Downloading files and applications
- Prohibited activities
The goal isn’t to restrict employees unnecessarily. It’s to establish reasonable rules that reduce security and legal risks.
7. Incident Response Policy
Eventually, something may go wrong.
An employee may click on a phishing email. A laptop may be stolen. An account may be compromised. Or the company could experience ransomware.
An Incident Response Policy explains what happens when a security incident occurs.
It should define:
- Identify — Determine what happened.
- Contain — Limit the damage and prevent the incident from spreading.
- Investigate — Determine what systems and information were affected.
- Eradicate — Remove the threat.
- Recover — Restore systems and return to normal operations.
- Learn — Document what happened and improve security.
The policy should also identify who needs to be contacted, including management, IT, cybersecurity providers, insurance companies, legal counsel, and potentially law enforcement or regulators.
The worst time to figure out who is responsible for handling a ransomware attack is during the ransomware attack.
8. Business Continuity and Disaster Recovery Policy
Incident response focuses on dealing with an incident. Business continuity focuses on keeping the business operating.
Your Business Continuity and Disaster Recovery (BC/DR) policy should address what happens if critical systems become unavailable because of:
- Ransomware
- Hardware failure
- Fire
- Flood
- Severe weather
- Power failure
- Internet outage
- Cloud service outage
- Loss of a critical employee
The policy should identify critical business systems, recovery priorities, backup requirements, acceptable downtime, and who is responsible for restoring operations.
Most importantly, backups should be tested. Having a backup is not the same thing as knowing that you can successfully restore from it.
9. Backup Policy
Backups deserve their own policy because they are often the last line of defense against ransomware and other disasters.
A backup policy should establish:
- What data is backed up
- How frequently backups occur
- Where backups are stored
- How long backups are retained
- Encryption requirements
- Off-site or cloud backups
- How often restores are tested
Businesses should consider maintaining backups that cannot simply be deleted or encrypted by an attacker who compromises an administrative account.
10. Security Awareness Training Policy
Technology can’t protect a business from every mistake.
Employees need to know how to recognize and report threats such as:
- Phishing
- Business email compromise
- Social engineering
- Malicious attachments
- Fake login pages
- Suspicious phone calls
- Password theft
- Fraudulent payment requests
Security awareness training should occur regularly—not just when an employee starts.
A simple policy can establish annual training requirements along with additional training when significant threats or security issues arise.