## Purpose of This Library

The Cybersecurity Playbook explains what a company should do. This library provides practical policies, forms, checklists, registers, and templates that can help put those recommendations into operation.

The templates in this library can be adapted to suit the company’s size, systems, industry, risks, contractual obligations, and regulatory requirements.

Where legal, regulatory, privacy, employment, or contractual requirements apply, the company should have the relevant documents reviewed by an appropriate qualified adviser.

## How to Use the Library

Start with the documents marked **Core**. These establish the minimum policies and procedures most companies should have.

Add **Recommended** documents where they match the company’s risks and operations.

Use **Additional** documents where the company has more complex systems, higher-risk activities, regulatory requirements, or a need for greater formalization.

Policies should be approved by an appropriate company owner and reviewed when significant changes occur or at least annually.

Templates and checklists should be incorporated into normal business processes rather than stored and forgotten.

## Policy and Template Directory

## 1. Governance and Cybersecurity Management

| Document                                        | Type     | Priority    | Purpose                                                                                                                  |
| ----------------------------------------------- | -------- | ----------- | ------------------------------------------------------------------------------------------------------------------------ |
| [Cybersecurity Policy](../policy-template-library/governance/cybersecurity-policy/)                        | Policy   | Core        | Establishes the company’s overall cybersecurity expectations, responsibilities, and management commitment.               |
| [Cybersecurity Roles and Responsibilities](../policy-template-library/governance/cybersecurity-roles-and-responsibilities/)    | Template | Core        | Defines who owns cybersecurity, IT, access, incidents, recovery, vendors, training, and leadership decisions.            |
| [Cybersecurity Risk Assessment Template](../policy-template-library/governance/cybersecurity-risk-assessment-template/)      | Template | Core        | Provides a consistent method for identifying, assessing, prioritizing, and treating cybersecurity risks.                 |
| [Cybersecurity Leadership Review Agenda](../policy-template-library/governance/cybersecurity-leadership-review-agenda/)      | Template | Recommended | Provides a standard agenda for periodic leadership reviews of risks, incidents, controls, actions, and priorities.       |
| [Security Exception and Risk Acceptance Form](../policy-template-library/governance/security-exception-and-risk-acceptance-form/) | Template | Recommended | Documents situations where a required security control cannot be implemented and records approval of the remaining risk. |

## 2. Acceptable Use, Accounts, and Access

| Document                             | Type     | Priority    | Purpose                                                                                                                 |
| ------------------------------------ | -------- | ----------- | ----------------------------------------------------------------------------------------------------------------------- |
| [Acceptable Use Policy](../policy-template-library/access/acceptable-use-policy/)            | Policy   | Core        | Defines acceptable use of company devices, systems, internet access, email, software, cloud services, and company data. |
| [Password and MFA Policy](../policy-template-library/access/password-and-mfa-policy/)          | Policy   | Core        | Establishes requirements for passwords, password managers, MFA, credential sharing, and account protection.             |
| [Access Control Policy](../policy-template-library/access/access-control-policy/)            | Policy   | Core        | Defines least privilege, account approval, privileged access, access reviews, and removal of unnecessary access.        |
| [Access Request and Approval Form](../policy-template-library/access/access-request-and-approval-form/) | Template | Core        | Records requests for new or changed access and the required business approval.                                          |
| [Privileged Access Register](../policy-template-library/access/privileged-access-register/)       | Template | Recommended | Records users and accounts with administrator or other high-risk access.                                                |
| [User Access Review Checklist](../policy-template-library/access/user-access-review-checklist/)     | Template | Recommended | Supports periodic confirmation that users still require the access they hold.                                           |

## 3. Employee Lifecycle and Insider Risk

| Document                                             | Type      | Priority    | Purpose                                                                                                                                          |
| ---------------------------------------------------- | --------- | ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| [Employee Cybersecurity Onboarding Checklist](../policy-template-library/employee/employee-cybersecurity-onboarding-checklist/)      | Checklist | Core        | Confirms security training, MFA, password manager setup, device requirements, access approval, and reporting instructions for new staff.         |
| [Employee Offboarding Checklist](../policy-template-library/employee/employee-offboarding-checklist/)                   | Checklist | Core        | Ensures accounts, devices, credentials, physical access, shared access, and vendor access are removed or transferred when someone leaves.        |
| [Role Change Access Review](../policy-template-library/employee/role-change-access-review/)                        | Template  | Recommended | Reviews and adjusts access when an employee changes role or department.                                                                          |
| [Insider Threat and Privileged Misuse Procedure](../policy-template-library/employee/insider-threat-and-privileged-misuse-procedure/)   | Procedure | Recommended | Defines how excessive access, suspicious activity, misuse, departing-user risk, and privileged account concerns should be managed and escalated. |
| [Contractor and Temporary Worker Access Checklist](../policy-template-library/employee/contractor-and-temporary-worker-access-checklist/) | Checklist | Recommended | Controls access granted to non-permanent workers and ensures timely removal.                                                                     |

## 4. Data, Devices, and Technology Protection

| Document                                         | Type      | Priority    | Purpose                                                                                                                         |
| ------------------------------------------------ | --------- | ----------- | ------------------------------------------------------------------------------------------------------------------------------- |
| [Data Handling and Sharing Policy](../policy-template-library/data/data-handling-and-sharing-policy/)             | Policy    | Core        | Defines how sensitive company, customer, employee, and financial data should be stored, accessed, transferred, and shared.      |
| [Device Security Policy](../policy-template-library/data/device-security-policy/)                       | Policy    | Core        | Establishes security requirements for laptops, desktops, phones, tablets, and other company devices.                            |
| [Remote Work and Remote Access Policy](../policy-template-library/data/remote-work-and-remote-access-policy/)         | Policy    | Recommended | Defines requirements for remote working, VPN or controlled access, devices, Wi-Fi, data handling, and remote administration.    |
| [Software and SaaS Approval Policy](../policy-template-library/data/software-and-saas-approval-policy/)            | Policy    | Recommended | Controls installation and use of software, cloud services, browser extensions, AI services, and other third-party applications. |
| [Patch and Vulnerability Management Procedure](../policy-template-library/data/patch-and-vulnerability-management-procedure/) | Procedure | Recommended | Defines how vulnerabilities and security updates are identified, prioritized, assigned, and verified.                           |
| [Secure Configuration Checklist](../policy-template-library/data/secure-configuration-checklist/)               | Checklist | Recommended | Provides baseline checks for endpoints, servers, cloud services, network devices, and SaaS platforms.                           |

## 5. Backup, Business Continuity, and Recovery

| Document                                    | Type      | Priority    | Purpose                                                                                                                  |
| ------------------------------------------- | --------- | ----------- | ------------------------------------------------------------------------------------------------------------------------ |
| [Backup and Recovery Policy](../policy-template-library/backup/backup-and-recovery-policy/)              | Policy    | Core        | Defines what must be backed up, backup frequency, protection, retention, ownership, and restore testing.                 |
| [Backup Test Record](../policy-template-library/backup/backup-test-record/)                      | Template  | Core        | Records restore tests, results, problems, evidence, and corrective actions.                                              |
| [Recovery Priority Worksheet](../policy-template-library/backup/recovery-priority-worksheet/)             | Template  | Core        | Identifies the systems, data, vendors, and business processes that should be restored first.                             |
| [Business Continuity Workaround Template](../policy-template-library/backup/business-continuity-workaround-template/) | Template  | Recommended | Documents temporary procedures used when normal systems are unavailable.                                                 |
| [Recovery Validation Checklist](../policy-template-library/backup/recovery-validation-checklist/)           | Checklist | Recommended | Confirms restored systems, data, access, monitoring, backups, and business processes are safe before normal use resumes. |

## 6. Vendors and Third Parties

| Document                                     | Type      | Priority    | Purpose                                                                                                                         |
| -------------------------------------------- | --------- | ----------- | ------------------------------------------------------------------------------------------------------------------------------- |
| [Vendor Cybersecurity Policy](../policy-template-library/vendors/vendor-cybersecurity-policy/)              | Policy    | Recommended | Establishes minimum cybersecurity expectations for vendors, contractors, MSPs, and other third parties.                         |
| [Vendor Security Assessment Questionnaire](../policy-template-library/vendors/vendor-security-assessment-questionnaire/) | Template  | Recommended | Helps evaluate a vendor’s access, MFA, data handling, backups, incident response, subcontractors, and security practices.       |
| [Vendor Access Approval Form](../policy-template-library/vendors/vendor-access-approval-form/)              | Template  | Recommended | Records why vendor access is required, what access is permitted, who approved it, and when it should expire.                    |
| [Vendor Offboarding Checklist](../policy-template-library/vendors/vendor-offboarding-checklist/)             | Checklist | Recommended | Confirms accounts, remote access, credentials, data, integrations, and permissions are removed when a vendor relationship ends. |
| [MSP Responsibility Matrix](../policy-template-library/vendors/msp-responsibility-matrix/)                | Template  | Recommended | Clarifies which cybersecurity responsibilities belong to the company and which belong to the MSP or outsourced IT provider.     |

## 7. Incident Response and Emergency Management

| Document                                              | Type      | Priority    | Purpose                                                                                                                                            |
| ----------------------------------------------------- | --------- | ----------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
| [Cyber Incident Response Plan](../policy-template-library/incident-response/cyber-incident-response-plan/)                      | Procedure | Core        | Defines how the company activates, coordinates, contains, investigates, communicates, and escalates a cybersecurity incident.                      |
| [Emergency Cybersecurity Contact List](../policy-template-library/incident-response/emergency-cybersecurity-contact-list/)              | Template  | Core        | Records leadership, IT/MSP, insurer, legal, bank, cloud, hosting, backup, and other emergency contacts.                                            |
| [Employee Security Incident Reporting Instructions](../policy-template-library/incident-response/employee-security-incident-reporting-instructions/) | Template  | Core        | Gives employees simple instructions for reporting suspicious emails, MFA prompts, data mistakes, lost devices, fraud attempts, and other concerns. |
| [Incident Triage Form](../policy-template-library/incident-response/incident-triage-form/)                              | Template  | Core        | Captures initial incident facts, severity, scope, affected systems, active risk, evidence, and immediate actions.                                  |
| [Incident Timeline and Action Log](../policy-template-library/incident-response/incident-timeline-and-action-log/)                  | Template  | Core        | Records what happened, when it happened, decisions made, actions taken, and results.                                                               |
| [Evidence Collection Log](../policy-template-library/incident-response/evidence-collection-log/)                           | Template  | Recommended | Records incident evidence, collection time, collector, source, storage location, and handling information.                                         |
| [Incident Communication Log](../policy-template-library/incident-response/incident-communication-log/)                        | Template  | Recommended | Records leadership, employee, vendor, customer, insurance, legal, and other incident communications.                                               |
| [Incident Decision Authority Matrix](../policy-template-library/incident-response/incident-decision-authority-matrix/)                | Template  | Recommended | Defines who can approve system shutdowns, account suspension, external notifications, emergency spending, recovery, and risk acceptance.           |
| [Customer or Vendor Incident Holding Statement](../policy-template-library/incident-response/customer-or-vendor-incident-holding-statement/)     | Template  | Recommended | Provides a controlled starting point for external communication while facts are still being established.                                           |

## 8. Finance and Fraud Prevention

| Document                                       | Type      | Priority    | Purpose                                                                                                                  |
| ---------------------------------------------- | --------- | ----------- | ------------------------------------------------------------------------------------------------------------------------ |
| [Payment Change Verification Procedure](../policy-template-library/finance/payment-change-verification-procedure/)      | Procedure | Core        | Requires independent verification of bank-detail changes, payment destination changes, and unusual payment requests.     |
| [High Risk Transaction Approval Checklist](../policy-template-library/finance/high-risk-transaction-approval-checklist/)   | Checklist | Recommended | Provides additional verification for unusual, urgent, or high-value transactions.                                        |
| [Suspected Payment Fraud Response Checklist](../policy-template-library/finance/suspected-payment-fraud-response-checklist/) | Checklist | Recommended | Defines immediate actions when invoice fraud, payroll diversion, executive impersonation, or payment fraud is suspected. |

## 9. Review and Continuous Improvement

| Document                                             | Type      | Priority    | Purpose                                                                                                             |
| ---------------------------------------------------- | --------- | ----------- | ------------------------------------------------------------------------------------------------------------------- |
| [Post Incident Review Template](../policy-template-library/review/post-incident-review-template/)                    | Template  | Core        | Records the incident timeline, business impact, response performance, lessons, and open questions.                  |
| [Root Cause and Control Failure Analysis Template](../policy-template-library/review/root-cause-and-control-failure-analysis-template/) | Template  | Recommended | Documents why the incident occurred and which preventive, detective, response, or recovery controls failed.         |
| [Cybersecurity Improvement Action Tracker](../policy-template-library/review/cybersecurity-improvement-action-tracker/)         | Template  | Core        | Assigns corrective actions, owners, priorities, due dates, verification methods, and evidence.                      |
| [Annual Cybersecurity Review Checklist](../policy-template-library/review/annual-cybersecurity-review-checklist/)            | Checklist | Recommended | Provides a structured annual review of risks, assets, access, controls, vendors, incidents, recovery, and training. |

## 10. Training and Awareness

| Document                                   | Type     | Priority    | Purpose                                                                                                                       |
| ------------------------------------------ | -------- | ----------- | ----------------------------------------------------------------------------------------------------------------------------- |
| [Security Awareness and Training Policy](../policy-template-library/training/security-awareness-and-training-policy/) | Policy   | Recommended | Defines training responsibilities, frequency, audiences, evidence, and review requirements.                                   |
| [New Employee Cybersecurity Briefing](../policy-template-library/training/new-employee-cybersecurity-briefing/)    | Template | Core        | Provides the minimum cybersecurity guidance every new employee should receive.                                                |
| [Employee Cybersecurity Quick Rules](../policy-template-library/training/employee-cybersecurity-quick-rules/)     | Template | Core        | Provides a short reference covering phishing, MFA, passwords, data sharing, devices, payment fraud, and reporting.            |
| [Role Based Training Matrix](../policy-template-library/training/role-based-training-matrix/)             | Template | Recommended | Maps higher-risk roles to additional cybersecurity training requirements.                                                     |
| [Phishing Simulation Record](../policy-template-library/training/phishing-simulation-record/)             | Template | Additional  | Records simulation results, reporting rates, lessons, and follow-up actions.                                                  |
| [Tabletop Exercise Template](../policy-template-library/training/tabletop-exercise-template/)             | Template | Recommended | Provides a structured format for practicing ransomware, email compromise, data exposure, fraud, and other incident scenarios. |

## Suggested Minimum Policy Pack

For an SME starting from limited documentation, begin with these core documents:

1. [Cybersecurity Policy](../policy-template-library/governance/cybersecurity-policy/)
    
2. [Acceptable Use Policy](../policy-template-library/access/acceptable-use-policy/)
    
3. [Password and MFA Policy](../policy-template-library/access/password-and-mfa-policy/)
    
4. [Access Control Policy](../policy-template-library/access/access-control-policy/)
    
5. [Data Handling and Sharing Policy](../policy-template-library/data/data-handling-and-sharing-policy/)
    
6. [Backup and Recovery Policy](../policy-template-library/backup/backup-and-recovery-policy/)
    
7. [Employee Cybersecurity Onboarding Checklist](../policy-template-library/employee/employee-cybersecurity-onboarding-checklist/)
    
8. [Employee Offboarding Checklist](../policy-template-library/employee/employee-offboarding-checklist/)
    
9. [Payment Change Verification Procedure](../policy-template-library/finance/payment-change-verification-procedure/)
    
10. [Cyber Incident Response Plan](../policy-template-library/incident-response/cyber-incident-response-plan/)
    
11. [Emergency Cybersecurity Contact List](../policy-template-library/incident-response/emergency-cybersecurity-contact-list/)
    
12. [Employee Security Incident Reporting Instructions](../policy-template-library/incident-response/employee-security-incident-reporting-instructions/)
    
13. [Incident Triage Form](../policy-template-library/incident-response/incident-triage-form/)
    
14. [Incident Timeline and Action Log](../policy-template-library/incident-response/incident-timeline-and-action-log/)
    
15. [Recovery Priority Worksheet](../policy-template-library/backup/recovery-priority-worksheet/)
    
16. [Post Incident Review Template](../policy-template-library/review/post-incident-review-template/)
    
17. [Cybersecurity Improvement Action Tracker](../policy-template-library/review/cybersecurity-improvement-action-tracker/)
    
18. [New Employee Cybersecurity Briefing](../policy-template-library/training/new-employee-cybersecurity-briefing/)
    
This provides a manageable starting library without requiring an SME to create dozens of policies before meaningful cybersecurity work can begin.

## Objectives

Keep cybersecurity documentation short enough to use and specific enough to matter.

- A useful policy tells people what is required.

- A useful procedure tells them what to do.

- A useful checklist helps them remember.

- A useful template records that it happened.
