Writing a One-Page Security Policy
A security policy only works if people read it. A one-page template with seven clear rules for small businesses, and how to introduce it without eye-rolling.

Many security policies are long, legalistic and ignored. A one-page policy with a few clear rules gets read, remembered and followed.
A seven-rule template
2. Use the company password manager; never reuse or share passwords.
3. Keep devices locked and updated; report lost devices immediately.
4. Never change payment details or make urgent payments without a call-back check.
5. Only install approved software and use approved apps for work data.
6. Report anything suspicious to [name] straight away. Nobody is blamed for reporting.
7. Handle customer and staff data only as needed for your job.
Rolling it out
- Explain the "why" behind each rule in a short team meeting.
- Make sure the tools exist first: password manager, two-step verification, reporting contact.
- Include it in onboarding. See security onboarding.
- Revisit it after incidents and once a year.
Rules need support. A payment rule only works if managers praise staff who check. See no-blame culture.
Related: AI tools at work and bring your own device rules. For more, see our complete guide to small business cybersecurity.
Frequently asked questions
Is one page really enough?
For most small businesses, yes. A short policy people follow beats a long one nobody reads. Add detail only where needed.
Do customers or insurers ask for policies?
Sometimes. A clear one-page policy, plus evidence you follow it, is often a good starting point.
How often should we update it?
Review it once a year and after incidents or big changes.
Sources
- Small organisations guide to cyber security, UK National Cyber Security Centre
- Cyber Essentials, US Cybersecurity and Infrastructure Security Agency
- Cybersecurity for Small Business, US Federal Trade Commission


