PassCyber
PassCyber / Guides

A cyber security policy template you can actually use

Free, plain-English, and deliberately aligned to the five Cyber Essentials control areas — so the policy you adopt today is the policy an assessor recognises tomorrow. Copy it straight from this page, replace the bracketed parts, and put it in front of whoever signs things.

Aligned to: Cyber Essentials (Danzell)Reading time 6 minutes

Before you copy it — two honest notes

First: a policy nobody follows is worse than no policy, because it documents what you claimed and didn't do. Keep it short enough to be true. Second: this template is a strong general-purpose starting point, not legal advice or a guarantee of certification — adapt it to how your organisation actually works, and review it annually or when anything material changes.

Get the Word version, free

The same template as a ready-to-edit .docx, sent to your inbox — plus one short follow-up asking about your setup, so we can point out the sections an assessor would query. No charge, no spam, unsubscribe with a word.

Done — the template's on its way to your inbox.

The template

[Organisation name] — Cyber Security Policy

Owner: [name, role] · Approved by: [board/owner] · Date: [date] · Next review: [date + 12 months]

1. Purpose and scope. This policy protects [Organisation]'s systems, data, and customers. It applies to every person who uses our systems — employees, contractors, and volunteers — and to every device that accesses our data or email, including personally-owned devices used for work.

2. Responsibilities. [Name/role] is responsible for this policy, for maintaining our list of devices and cloud services, and for approving exceptions. Every user is responsible for following it and for reporting anything suspicious without fear of blame — fast reporting matters more than fault.

3. Firewalls and internet connections. Every internet-connected device runs a firewall. Router and firewall administration passwords are changed from defaults. We do not expose services to the internet unless there is a documented business need approved by [role].

4. Secure configuration. Default passwords are always changed. Software and accounts we don't use are removed. Devices lock automatically when idle and require a PIN, password, or biometric to unlock. Auto-run of external media is disabled.

5. Passwords and access. Every user has their own account — no shared logins. Passwords are unique per service, at least [12] characters, and never reused from personal accounts; a password manager [is provided / is permitted]. Multi-factor authentication is switched on for every cloud service that offers it, starting with email. Administrator rights are separated from day-to-day accounts and used only for administration. Access is removed on the day a person leaves.

6. Security updates. Operating systems and applications are kept in vendor support and set to update automatically where possible. High-risk updates are applied within 14 days. Any system that can no longer be updated is replaced or isolated — [role] maintains the list.

7. Malware protection. Every computer runs supported anti-malware protection, kept current. We only install software from approved sources. Unexpected attachments and links are treated with suspicion and reported rather than opened.

8. Data and backups. Business data is stored in [approved services], not on personal accounts or local-only folders. [Critical data] is backed up [frequency]; restores are tested [frequency]. Personal data is handled in line with our privacy notice and UK GDPR obligations.

9. Incidents. Anything suspicious — a strange email, a lost device, an unexpected login — is reported to [name/contact] immediately. We would rather investigate ten false alarms than miss one real incident. Serious incidents are assessed for reporting obligations (including to the ICO where personal data is involved).

10. Review. This policy is reviewed annually, and after any significant incident or change to how we work. The current version is stored at [location] and forms part of induction for new starters.

Why it maps to Cyber Essentials on purpose

Sections 3–7 are the five Cyber Essentials control areas in policy form. Adopt this and you haven't just written a document — you've committed to the exact controls the certification assesses, which makes certifying a formality rather than a scramble.

PassCyber

Policy is the paperwork — the readiness check tests the reality

Five minutes, no sign-up to see your result: what would currently pass, and what would fail, against the actual certification requirements.

Take the free readiness check  ·  hello@passcyber.co.uk

PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd