Most small businesses run on unwritten IT rules - "we don't really do that" or "ask the boss" - until a genuine dispute, incident, or new hire exposes exactly how unclear those rules actually were. A written policy doesn't need to be long or legalistic; it needs to exist, and be something staff have actually seen.
The Core Set
Acceptable Use Policy
Sets out what staff can and can't do with business devices, internet access, and accounts - covers personal use boundaries, prohibited activities, and the basics of what's expected. This is usually the first policy worth drafting since it covers the widest range of everyday situations.
Password Policy
Defines password strength expectations, MFA requirements, and password manager use. See our guide on password management for Perth businesses for what good practice actually looks like in detail.
BYOD Policy
Covers whether and how personal devices can access business data - most businesses have this happening informally whether it's been decided or not. See our guide on BYOD policy for Perth businesses.
Remote Work Policy
Sets expectations for working outside the office - what's required (VPN, approved devices) and what's not permitted (public Wi-Fi for sensitive work without protection, for instance). See our guide on remote work IT setup for the technical side this policy should reference.
Data Retention and Handling Policy
Sets out how long different types of data are kept and how sensitive information should be handled and shared. See our guide on secure file sharing for Perth businesses for the practical side of this.
AI Usage Policy
Increasingly essential given how widely staff already use tools like ChatGPT - see our guide on writing an AI usage policy for staff.
Onboarding and Offboarding Procedures
Not strictly a "policy" in the traditional sense, but a documented, consistent process for setting up and revoking access. See our guides on new employee IT onboarding and the Microsoft 365 offboarding checklist.
Policies Worth Adding as the Business Grows
- Privileged access policy - who's authorised to hold administrator rights, and under what conditions
- Right to disconnect policy - now a legal consideration for every Australian employer; see our guide on the right to disconnect and IT policy
- Change management policy - how significant IT changes get proposed, approved, and rolled back if needed, becoming more relevant as systems and headcount grow
How to Actually Write These Without It Becoming a Project
Keep each policy to one or two plain-language pages. Start with the policies covering your highest everyday risk (acceptable use, password, data handling) rather than trying to write everything at once. Review policies annually, or whenever a significant change in how the business operates makes an existing policy outdated.
Policy vs Technical Control
A policy states the expectation; a technical control enforces it. A password policy asking staff to use strong passwords relies on individual compliance, while MFA and a password manager enforce it regardless. Most businesses need both - policy sets the standard, technical controls make sure it actually happens.
Frequently Asked Questions
Do these policies need to be long, formal documents?
No - for a small business, a clear one-to-two-page document per policy, written in plain language, is far more useful than a lengthy formal policy nobody actually reads. The goal is that staff genuinely understand and follow it, not that it looks impressive in a folder.
Which policy should a small business write first if they have none at all?
An acceptable use policy and a password policy cover the most common everyday risk and are usually the fastest to draft, since they mostly codify practices that should already be happening informally.
Do staff need to formally sign off on these policies?
It's worth having staff acknowledge they've read and understood key policies, particularly acceptable use and data handling ones - this matters both for genuine understanding and as evidence of due diligence if an incident or dispute arises later.
How is a policy different from a technical control like MFA?
A policy sets expectations and rules; a technical control enforces them automatically. A password policy stating 'use strong, unique passwords' relies on staff compliance, while MFA and a password manager enforce good practice regardless of individual discipline. Most businesses need both, not one instead of the other.
We help Perth businesses draft and roll out practical IT policies staff will actually read and follow, not just sign and forget.
IT Consulting Services →Running on unwritten IT rules?
Call 0433 087 091 - we'll help you identify which policies matter most for your business first.
Get Free Policy GuidanceFor related reading, see our guides to the AI usage policy for staff and BYOD policy for Perth businesses.