Skip to main content

    Team Safety Snapshot now live, 10 founding partner spots at £39. Claim yours →

    CyberSafe Coach+
    Something happening right now?Digital 999
    Back to guides

    Cyber Security Policy Template (UK)

    A plain-English cyber security policy template for UK small businesses, charities and community organisations, aligned with UK GDPR and Cyber Essentials.

    10 min read3 sections
    01

    What's in the template

    • Passwords and accounts, length, password managers, two-factor authentication, removing old accounts.
    • Devices, screen locks, updates, encryption and reporting lost or stolen kit.
    • Remote and hybrid working, public Wi-Fi, screen locking, handling printouts.
    • Email and phishing, verifying urgent requests through a second channel, where to report suspicious emails.
    • UK GDPR essentials, data minimisation, access, rights requests, and the 72-hour breach reporting duty to the ICO.
    • Backups, frequency, off-site copies, annual restore tests.
    • Suppliers and third parties, basic due diligence and data processing agreements.
    • Training and incidents, annual refreshers and a simple, named incident process.
    02

    How to use it

    1. Download the template using the button above.
    2. Fill in the bracketed sections, organisation name, policy owner, named contacts, approved tools.
    3. Share it with your team, trustees or board for sign-off.
    4. Review it at least once a year, and after any significant change to your systems or services.
    03

    The template

    The full text below is what you will get in the downloaded file. You can also copy it straight from this page if that is easier.

    CYBER SECURITY POLICY TEMPLATE (UK)
    For small businesses, charities and community organisations
    Aligned with UK GDPR and Cyber Essentials
    
    ----------------------------------------------------------------
    ORGANISATION DETAILS
    ----------------------------------------------------------------
    Organisation name:    [Your organisation]
    Policy owner:         [Name / role]
    Approved by:          [Trustee / director / manager]
    Date approved:        [DD / MM / YYYY]
    Next review date:     [Annually, or after a significant change]
    
    ----------------------------------------------------------------
    1. PURPOSE
    ----------------------------------------------------------------
    This policy explains how we keep our systems, devices and information
    safe. It applies to everyone who works for or with us, including
    staff, volunteers, trustees, contractors and temporary helpers.
    
    The aim is plain: protect the people we serve, the information they
    trust us with, and the day-to-day running of the organisation.
    
    ----------------------------------------------------------------
    2. WHO THIS POLICY APPLIES TO
    ----------------------------------------------------------------
    - All staff, volunteers and trustees
    - Contractors and freelancers with access to our systems
    - Anyone using a device that connects to our accounts, email or data
    
    ----------------------------------------------------------------
    3. PASSWORDS AND ACCOUNTS
    ----------------------------------------------------------------
    - Every person has their own login. We do not share accounts.
    - Passwords must be at least 12 characters long, or use three random
      words (for example: "river-paper-lantern").
    - We use a password manager to store and generate strong passwords.
      Approved manager: [e.g. Bitwarden / 1Password / Dashlane]
    - Two-factor authentication (2FA) is turned on for email, finance,
      donor / supporter databases and any admin accounts.
    - Old accounts are removed within 5 working days of someone leaving
      or changing role.
    
    ----------------------------------------------------------------
    4. DEVICES (LAPTOPS, PHONES, TABLETS)
    ----------------------------------------------------------------
    - Devices used for work must have:
        * A screen lock (PIN, password or biometric)
        * Automatic updates turned on
        * Up-to-date antivirus / built-in security (Windows Security,
          macOS XProtect, etc.)
        * Disk encryption enabled (BitLocker on Windows, FileVault on
          Mac, default encryption on modern phones)
    - Lost or stolen devices are reported to [named contact] the same day.
    - Personal devices used for work must meet the same basic standards.
    
    ----------------------------------------------------------------
    5. REMOTE AND HYBRID WORKING
    ----------------------------------------------------------------
    - Work is only carried out on devices that meet section 4.
    - Public Wi-Fi (cafes, hotels, transport) is avoided for sensitive
      work. If it must be used, we use a trusted VPN or a mobile hotspot.
    - Screens are not left unlocked in public spaces.
    - Printed information is not left in shared or public areas.
    
    ----------------------------------------------------------------
    6. EMAIL, MESSAGING AND PHISHING
    ----------------------------------------------------------------
    - We pause before clicking links or opening attachments from
      unexpected messages.
    - Urgent requests for money, gift cards, login codes, password resets
      or changes to bank details are always verified through a second,
      trusted channel (a known phone number, a quick in-person check).
    - Suspected phishing is reported to [named contact] and forwarded to
      report@phishing.gov.uk (UK National Cyber Security Centre).
    
    ----------------------------------------------------------------
    7. DATA PROTECTION AND UK GDPR
    ----------------------------------------------------------------
    - We only collect personal data we genuinely need.
    - We store personal data only in approved systems: [list systems].
    - Access to personal data is limited to people whose role requires it.
    - We keep a simple record of what data we hold, why, and how long
      for. We delete data when it is no longer needed.
    - Subject access requests and other rights requests are passed to
      [named contact] and answered within one month.
    - Suspected personal data breaches are reported to [named contact]
      immediately. Notifiable breaches are reported to the Information
      Commissioner's Office (ICO) within 72 hours.
    
    ----------------------------------------------------------------
    8. BACKUPS
    ----------------------------------------------------------------
    - Important data is backed up at least weekly.
    - At least one backup copy is held separately from our main systems
      (for example, a different cloud account or offline copy).
    - Backups are tested at least once a year to confirm they restore.
    
    ----------------------------------------------------------------
    9. SUPPLIERS AND THIRD PARTIES
    ----------------------------------------------------------------
    - Before sharing personal or sensitive data with a supplier, we
      check they handle it responsibly and have a written data
      processing agreement where required.
    - We keep a short list of approved suppliers and review it annually.
    
    ----------------------------------------------------------------
    10. TRAINING AND AWARENESS
    ----------------------------------------------------------------
    - Everyone completes basic online safety awareness when they join
      and at least once a year afterwards.
    - New scam patterns and lessons learned are shared briefly in team
      meetings.
    
    ----------------------------------------------------------------
    11. INCIDENTS, WHAT TO DO
    ----------------------------------------------------------------
    If something goes wrong (lost device, suspicious activity, suspected
    breach, ransomware, fraudulent payment):
    
      1. Tell [named contact] straight away.
      2. Do not pay any ransom or transfer money based on the incident.
      3. Disconnect the affected device from the internet if safe to do.
      4. Change passwords for any accounts that may be affected.
      5. Report to the ICO within 72 hours if personal data is affected.
      6. Report fraud or cybercrime to Report Fraud (0300 123 2040 or
         reportfraud.police.uk).
      7. Keep a short written record of what happened and what we did.
    
    ----------------------------------------------------------------
    12. REVIEW
    ----------------------------------------------------------------
    This policy is reviewed at least once a year, and whenever there is
    a significant change to our systems, services or risks.
    
    Signed: ____________________________   Date: ____________________
    Name:   ____________________________   Role: ____________________
    

    A note on proportionality: a good policy for a small organisation is one that everyone actually reads and follows. Keep it short, name a real person for each responsibility, and revisit it once a year, that already puts you ahead of most.

    Find your own gaps in five minutes

    The free safety check turns this guide into a personal action list, with the three things worth fixing first.