Compliance
Writing a security policy your small team will actually follow
Most small-business security policies are long, legalistic, and ignored. Here is a practical outline for a short one that a real team will read and follow — passwords, MFA, devices, data handling, incidents, and offboarding.
Most small-business security policies share the same fate. Someone downloads a template, fills in the company name, saves it to a shared drive, and never looks at it again. It runs to twenty pages of legal-sounding text nobody reads, so it protects nothing. A policy only works if the people it governs actually know what it says and can follow it without a lawyer.
The goal is not a document that would satisfy an auditor at a bank. It is a short, plain set of rules your team can read in ten minutes and apply every day. Here is what belongs in one and how to keep it usable.
Why short beats thorough
A security policy exists to change behaviour, not to sit in a folder. Every extra page lowers the odds anyone reads it, and a rule nobody knows is a rule nobody follows. A single page or two that your team has actually read protects you far better than a comprehensive manual they have not.
So the first principle is ruthless brevity. Write for the person on their first day, in language a new hire understands, covering the handful of things that genuinely reduce your risk. Leave out anything you cannot or will not enforce, because an unenforced rule teaches everyone that the rest are optional too.
What a usable policy covers
Six areas cover the risks that actually affect a small team. Each can be a few sentences, not a chapter.
Passwords. State that every account uses a strong, unique password and that the company provides a password manager so nobody has to remember them or reuse one. Say plainly that passwords are never shared over email or chat and never written on a note by the desk. That is the whole rule.
Multi-factor authentication. Require it on every business account that offers it, email first. This is the single highest-value line in the document, because a second factor stops most account takeovers even when a password leaks. Say which accounts it is mandatory on and that new accounts get it switched on from the start.
Devices. Cover the machines and phones that touch company data. Screens lock when unattended. Devices are kept updated. Company data stays on company-managed devices rather than drifting onto personal laptops and random USB sticks. If your business manages its devices centrally, this is where you say so, because consistent, managed devices are what makes the rest of these rules real rather than aspirational. Our device management page covers how that works in practice.
Data handling. In plain terms, say what counts as sensitive — customer records, financial data, anything personal — and the basic rules for it: where it is allowed to live, who can access it, and that it is not emailed to personal accounts or copied to unmanaged devices. Keep it concrete to the data your business actually holds rather than abstract categories.
Incident steps. Tell people exactly what to do when something goes wrong: a suspicious email, a lost laptop, a password that may have leaked, a click that felt wrong afterward. Name who to tell and how, and make it clear that reporting fast is rewarded, never punished. Most small-business damage comes from staff staying quiet about a mistake because they feared blame. A policy that makes reporting safe is worth more than one that sounds stern.
Offboarding. Write down what happens the day someone leaves: which accounts are disabled, what devices come back, which passwords change. Departures are a common security gap precisely because they happen in the middle of other disruption, and a short checklist written in advance means nothing is forgotten in the rush.
Keep it enforceable
The fastest way to kill a policy is to fill it with rules you do not actually apply. If the document says screens must lock after five minutes but nobody’s does, the whole thing loses authority. Every line should be something you can and will hold to.
That means matching the policy to how your business really operates. If people legitimately work from personal phones, write a rule that accounts for that safely rather than pretending they do not. If you cannot enforce a rule technically, consider whether it belongs in the document at all. A short policy that reflects reality beats a strict one that everybody quietly ignores.
It also helps to pair the policy with the tools that make following it easy. A password manager makes the password rule effortless. Managed devices make the device rules automatic. Rules that require constant willpower fail; rules the tools enforce for you hold.
Review it on a schedule
A security policy is not written once and finished. Businesses change: new tools, new staff, new kinds of data, new risks. A policy that fit last year may have quiet gaps now.
Put a recurring reminder to reread it, once or twice a year is plenty for a small team. Check that it still matches how you actually work, that the named contacts are still the right people, and that new tools you have adopted are covered. This is also a natural moment to look at the wider picture — the point at which a business needs a written policy is often the same point it has outgrown handling IT informally, which we cover in our post on the signs you have outgrown do-it-yourself IT.
A starting outline
If you want a structure to fill in, this is a workable one:
- Purpose — one sentence on why the policy exists.
- Who it applies to — everyone who touches company systems.
- Passwords and the password manager.
- Multi-factor authentication and where it is mandatory.
- Devices — locking, updates, and keeping company data on managed devices.
- Data handling — what is sensitive and the rules for it.
- Reporting an incident — who to tell, how, and the no-blame commitment.
- Offboarding — the leaving-day checklist.
- Review date — when this document gets reread.
That is a security policy a small team will actually follow. It is not legal boilerplate and it does not pretend to be. It is a short, honest set of rules that make your business meaningfully safer, and it fits on a page or two.
For the wider threat picture behind these rules, our guide to cybersecurity for Atlantic Canada small businesses sets out what small firms in the region are actually up against. And if you would like a hand turning this outline into a policy that fits your business, send us two paragraphs about your team and how you work through our contact page, and we will reply in writing within one business day.