Policy and Template Library Directory

Purpose of This Library

The Cybersecurity Playbook explains what a company should do. This library provides practical policies, forms, checklists, registers, and templates that can help put those recommendations into operation.

The templates in this library can be adapted to suit the company’s size, systems, industry, risks, contractual obligations, and regulatory requirements.

Where legal, regulatory, privacy, employment, or contractual requirements apply, the company should have the relevant documents reviewed by an appropriate qualified adviser.

How to Use the Library

Start with the documents marked Core. These establish the minimum policies and procedures most companies should have.

Add Recommended documents where they match the company’s risks and operations.

Use Additional documents where the company has more complex systems, higher-risk activities, regulatory requirements, or a need for greater formalization.

Policies should be approved by an appropriate company owner and reviewed when significant changes occur or at least annually.

Templates and checklists should be incorporated into normal business processes rather than stored and forgotten.

Policy and Template Directory

1. Governance and Cybersecurity Management

Document Type Priority Purpose
Cybersecurity Policy Policy Core Establishes the company’s overall cybersecurity expectations, responsibilities, and management commitment.
Cybersecurity Roles and Responsibilities Template Core Defines who owns cybersecurity, IT, access, incidents, recovery, vendors, training, and leadership decisions.
Cybersecurity Risk Assessment Template Template Core Provides a consistent method for identifying, assessing, prioritizing, and treating cybersecurity risks.
Cybersecurity Leadership Review Agenda Template Recommended Provides a standard agenda for periodic leadership reviews of risks, incidents, controls, actions, and priorities.
Security Exception and Risk Acceptance Form Template Recommended Documents situations where a required security control cannot be implemented and records approval of the remaining risk.

2. Acceptable Use, Accounts, and Access

Document Type Priority Purpose
Acceptable Use Policy Policy Core Defines acceptable use of company devices, systems, internet access, email, software, cloud services, and company data.
Password and MFA Policy Policy Core Establishes requirements for passwords, password managers, MFA, credential sharing, and account protection.
Access Control Policy Policy Core Defines least privilege, account approval, privileged access, access reviews, and removal of unnecessary access.
Access Request and Approval Form Template Core Records requests for new or changed access and the required business approval.
Privileged Access Register Template Recommended Records users and accounts with administrator or other high-risk access.
User Access Review Checklist Template Recommended Supports periodic confirmation that users still require the access they hold.

3. Employee Lifecycle and Insider Risk

Document Type Priority Purpose
Employee Cybersecurity Onboarding Checklist Checklist Core Confirms security training, MFA, password manager setup, device requirements, access approval, and reporting instructions for new staff.
Employee Offboarding Checklist Checklist Core Ensures accounts, devices, credentials, physical access, shared access, and vendor access are removed or transferred when someone leaves.
Role Change Access Review Template Recommended Reviews and adjusts access when an employee changes role or department.
Insider Threat and Privileged Misuse Procedure Procedure Recommended Defines how excessive access, suspicious activity, misuse, departing-user risk, and privileged account concerns should be managed and escalated.
Contractor and Temporary Worker Access Checklist Checklist Recommended Controls access granted to non-permanent workers and ensures timely removal.

4. Data, Devices, and Technology Protection

Document Type Priority Purpose
Data Handling and Sharing Policy Policy Core Defines how sensitive company, customer, employee, and financial data should be stored, accessed, transferred, and shared.
Device Security Policy Policy Core Establishes security requirements for laptops, desktops, phones, tablets, and other company devices.
Remote Work and Remote Access Policy Policy Recommended Defines requirements for remote working, VPN or controlled access, devices, Wi-Fi, data handling, and remote administration.
Software and SaaS Approval Policy Policy Recommended Controls installation and use of software, cloud services, browser extensions, AI services, and other third-party applications.
Patch and Vulnerability Management Procedure Procedure Recommended Defines how vulnerabilities and security updates are identified, prioritized, assigned, and verified.
Secure Configuration Checklist Checklist Recommended Provides baseline checks for endpoints, servers, cloud services, network devices, and SaaS platforms.

5. Backup, Business Continuity, and Recovery

Document Type Priority Purpose
Backup and Recovery Policy Policy Core Defines what must be backed up, backup frequency, protection, retention, ownership, and restore testing.
Backup Test Record Template Core Records restore tests, results, problems, evidence, and corrective actions.
Recovery Priority Worksheet Template Core Identifies the systems, data, vendors, and business processes that should be restored first.
Business Continuity Workaround Template Template Recommended Documents temporary procedures used when normal systems are unavailable.
Recovery Validation Checklist Checklist Recommended Confirms restored systems, data, access, monitoring, backups, and business processes are safe before normal use resumes.

6. Vendors and Third Parties

Document Type Priority Purpose
Vendor Cybersecurity Policy Policy Recommended Establishes minimum cybersecurity expectations for vendors, contractors, MSPs, and other third parties.
Vendor Security Assessment Questionnaire Template Recommended Helps evaluate a vendor’s access, MFA, data handling, backups, incident response, subcontractors, and security practices.
Vendor Access Approval Form Template Recommended Records why vendor access is required, what access is permitted, who approved it, and when it should expire.
Vendor Offboarding Checklist Checklist Recommended Confirms accounts, remote access, credentials, data, integrations, and permissions are removed when a vendor relationship ends.
MSP Responsibility Matrix Template Recommended Clarifies which cybersecurity responsibilities belong to the company and which belong to the MSP or outsourced IT provider.

7. Incident Response and Emergency Management

Document Type Priority Purpose
Cyber Incident Response Plan Procedure Core Defines how the company activates, coordinates, contains, investigates, communicates, and escalates a cybersecurity incident.
Emergency Cybersecurity Contact List Template Core Records leadership, IT/MSP, insurer, legal, bank, cloud, hosting, backup, and other emergency contacts.
Employee Security Incident Reporting Instructions Template Core Gives employees simple instructions for reporting suspicious emails, MFA prompts, data mistakes, lost devices, fraud attempts, and other concerns.
Incident Triage Form Template Core Captures initial incident facts, severity, scope, affected systems, active risk, evidence, and immediate actions.
Incident Timeline and Action Log Template Core Records what happened, when it happened, decisions made, actions taken, and results.
Evidence Collection Log Template Recommended Records incident evidence, collection time, collector, source, storage location, and handling information.
Incident Communication Log Template Recommended Records leadership, employee, vendor, customer, insurance, legal, and other incident communications.
Incident Decision Authority Matrix Template Recommended Defines who can approve system shutdowns, account suspension, external notifications, emergency spending, recovery, and risk acceptance.
Customer or Vendor Incident Holding Statement Template Recommended Provides a controlled starting point for external communication while facts are still being established.

8. Finance and Fraud Prevention

Document Type Priority Purpose
Payment Change Verification Procedure Procedure Core Requires independent verification of bank-detail changes, payment destination changes, and unusual payment requests.
High Risk Transaction Approval Checklist Checklist Recommended Provides additional verification for unusual, urgent, or high-value transactions.
Suspected Payment Fraud Response Checklist Checklist Recommended Defines immediate actions when invoice fraud, payroll diversion, executive impersonation, or payment fraud is suspected.

9. Review and Continuous Improvement

Document Type Priority Purpose
Post Incident Review Template Template Core Records the incident timeline, business impact, response performance, lessons, and open questions.
Root Cause and Control Failure Analysis Template Template Recommended Documents why the incident occurred and which preventive, detective, response, or recovery controls failed.
Cybersecurity Improvement Action Tracker Template Core Assigns corrective actions, owners, priorities, due dates, verification methods, and evidence.
Annual Cybersecurity Review Checklist Checklist Recommended Provides a structured annual review of risks, assets, access, controls, vendors, incidents, recovery, and training.

10. Training and Awareness

Document Type Priority Purpose
Security Awareness and Training Policy Policy Recommended Defines training responsibilities, frequency, audiences, evidence, and review requirements.
New Employee Cybersecurity Briefing Template Core Provides the minimum cybersecurity guidance every new employee should receive.
Employee Cybersecurity Quick Rules Template Core Provides a short reference covering phishing, MFA, passwords, data sharing, devices, payment fraud, and reporting.
Role Based Training Matrix Template Recommended Maps higher-risk roles to additional cybersecurity training requirements.
Phishing Simulation Record Template Additional Records simulation results, reporting rates, lessons, and follow-up actions.
Tabletop Exercise Template Template Recommended Provides a structured format for practicing ransomware, email compromise, data exposure, fraud, and other incident scenarios.

Suggested Minimum Policy Pack

For an SME starting from limited documentation, begin with these core documents:

  1. Cybersecurity Policy

  2. Acceptable Use Policy

  3. Password and MFA Policy

  4. Access Control Policy

  5. Data Handling and Sharing Policy

  6. Backup and Recovery Policy

  7. Employee Cybersecurity Onboarding Checklist

  8. Employee Offboarding Checklist

  9. Payment Change Verification Procedure

  10. Cyber Incident Response Plan

  11. Emergency Cybersecurity Contact List

  12. Employee Security Incident Reporting Instructions

  13. Incident Triage Form

  14. Incident Timeline and Action Log

  15. Recovery Priority Worksheet

  16. Post Incident Review Template

  17. Cybersecurity Improvement Action Tracker

  18. New Employee Cybersecurity Briefing

This provides a manageable starting library without requiring an SME to create dozens of policies before meaningful cybersecurity work can begin.

Objectives

Keep cybersecurity documentation short enough to use and specific enough to matter.

  • A useful policy tells people what is required.

  • A useful procedure tells them what to do.

  • A useful checklist helps them remember.

  • A useful template records that it happened.