Add-on or standalone

Security Policy Writing

Custom, plain-language security policies written specifically for your business. Choose the policies you actually need — from a single focused document to a complete staff policy suite. No legal boilerplate, no generic templates.

Rules your team will actually read and follow.

Most small businesses don't have written security policies. That means staff make up the rules as they go — using personal email for work, sharing passwords, connecting to public Wi-Fi without protection, and countless other habits that create real risk.

A security policy doesn't need to be a 40-page legal document. It needs to be clear, specific to your business, and short enough that people will actually read it. That's what we write.

You choose what you need. Every business is different. A dental practice may need a data handling policy above all else. A law firm with remote staff needs a remote work policy. A growing business needs an onboarding and offboarding policy. You pick the policies that fit your situation — you don't have to buy a bundle of things you don't need.

When paired with a Security Assessment, policies are written to directly address the risks and gaps we found — turning findings into enforceable practice for your team.

Why written policies matter

Beyond reducing risk, written security policies are often required for cyber insurance, client contracts, and some regulatory frameworks. They also give you clear standing if a staff member violates security rules — you can't enforce a rule that was never written down.

Choose what fits your business.

Select any combination. Each policy is written from scratch for your business — not adapted from a generic template. If you've completed a Security Assessment with us, policies are built directly from your findings.

1Password & Authentication

Password requirements, two-factor authentication expectations, and password manager guidance.

2Acceptable Use

What staff can and can't do on company devices, networks, and email — personal use, prohibited software, and public Wi-Fi rules.

3Data Handling & Classification

How sensitive data should be stored, shared, and disposed of — including cloud storage, email, and physical documents.

4Remote Work & Mobile Devices

VPN requirements, personal device expectations, home network guidance, and rules for working from public locations.

5Onboarding & Offboarding

Account provisioning for new staff, access levels by role, and a step-by-step checklist to revoke access when someone leaves.

6Incident Reporting

What counts as a security incident, who to notify and when, what to do immediately, and how to preserve information for follow-up.

7Software & Update Management

Expectations for keeping devices and applications current, patch timelines, end-of-life software rules, and who is responsible.

Not sure which to choose? If you've done a Security Assessment with us, the findings will point to the most relevant policies. Starting fresh? The most universally useful starting point is the Password & Authentication policy paired with the Onboarding & Offboarding policy.

What you get with every policy.

Custom to your businessWritten from your intake information and assessment findings — not a generic template with your name on it.
Plain languageWritten for your staff to read and follow, not for a legal team to review. Clear rules, no jargon.
Word + PDF deliveryBoth formats included — Word for future editing, PDF for distribution and onboarding materials.
One revision roundWe incorporate your feedback before delivering the final version. Additional rounds available at hourly rate.
Acknowledgment formA simple sign-off form included with each policy so you have a record that staff received and read it.
5–7 business day deliveryFrom intake to first draft. Final delivery within 2 business days of receiving your revision feedback.

Scope boundaries.

From conversation to document.

01

Select your policies

Choose which policies you need from the menu above. If you're unsure, we'll help you decide based on your business type and any assessment findings.

02

Intake

We gather information about your business, staff size, tools you use, how you currently handle the areas each policy covers, and any specific requirements.

03

Draft

We write each policy tailored to your business — plain language, practical rules, specific enough to be enforceable.

04

Your review

You review the draft and provide feedback. We incorporate one round of revisions per policy.

05

Final delivery

You receive each policy in Word and PDF formats with the staff acknowledgment form included.

Often paired with.

Simple, transparent pricing.

Priced by the number of policies. All policies are the same price per unit. Add-on pricing applies when bundled with a Security Assessment.

Standalone
Any 2 policies
$200
one-time
  • Choose any 2 from the menu
  • Word + PDF delivery each
  • One revision round each
  • Acknowledgment form included
Any 4 policies
$325
one-time
  • Choose any 4 from the menu
  • Word + PDF delivery each
  • One revision round each
  • Acknowledgment forms included
When added to a Security Assessment
Any 2 policies
$100
add-on
  • Same deliverable as standalone
  • Built from assessment findings
Any 4 policies
$175
add-on
  • Same deliverable as standalone
  • Built from assessment findings

Additional revision rounds available at $75/hr. Annual policy updates available at 40% off original price.

Give your team clear rules to follow.

Written security policies are one of the most cost-effective protections a small business can have.

Get started →