FREE RESOURCES

Policy templates for businesses without an IT department.

Your cyber insurance application asks whether you have written policies. Your customer’s security questionnaire asks the same thing. Most small businesses answer yes, and then go looking for the document. These are the documents.

WHAT THESE ARE

Written for a 10 to 50 person company with no IT department.

There are thousands of free policy templates and most of them are useless — either three paragraphs of nothing, or forty pages written for an enterprise with a compliance department. These are mapped to what cyber insurance applications and customer security questionnaires actually ask for, which is a shorter and more practical list than any framework will hand you.

Every one is readable in full on this site. Nothing is hidden behind a form, so you can decide whether they are any good before you give up an email address.

They are a starting point, not legal advice. They have not been reviewed against your contracts, your industry’s regulations, or your state’s law — have counsel review one before you adopt it. Using a template does not make you a Cybertitans client, and we are not attesting to anything on your behalf. We are not an assessor, an auditor or a C3PAO, and we do not certify anyone.

START HERE · THE COVER DOCUMENT

The WISP is the cover sheet. The ten below are the controls under it.

Written Information Security Plan

1,584 words · required of every paid tax preparer

The plan the IRS asks for and the FTC Safeguards Rule requires — who is responsible, where client data actually lives, and which controls are in place. It points at eight of the ten policies below, which is why it goes first.

PART 1 · THE INSURANCE FIVE

The five an insurance application makes you attest to.

Acceptable Use Policy

1,016 words

Where the line is on company equipment, accounts and networks — written so you can point at it when somebody crosses it.

Password and Authentication Policy

985 words

MFA everywhere, a password manager, and why a forced reset every 90 days is no longer the right answer.

Access Control Policy

904 words

Onboarding, role changes and departures. The one that answers what the last five leavers can still reach.

Incident Response Plan

893 words

Who to call, in what order, and what not to do. Includes the call list you keep printed.

Backup and Recovery Policy

887 words

RPO, RTO, the 3-2-1 rule, and the restore test record that turns a backup from an assumption into a fact.

PART 2 · THE OPERATIONS FIVE

The five you get asked for next.

Broader governance. These are the ones a customer questionnaire, a renewal or an auditor reaches for once the first five exist.

Business Continuity Plan

895 words

What the business has to keep doing, how long it can be down before it hurts, and who decides. Including the column people skip: how the work gets done with the system unavailable.

Vendor and Third-Party Management Policy

783 words

Your security is partly your suppliers' security. What to ask before you sign, what access a vendor gets, and how that access ends.

Data Retention and Disposal Policy

769 words

How long you keep things and how they are destroyed. Data you no longer hold cannot be stolen, demanded in litigation, or reported in a breach.

Remote Work and BYOD Policy

815 words

The minimum a device must meet to hold company data — and, said plainly, what the company can and cannot see on a device it does not own.

Security Awareness Training Policy

734 words

The payment verification callback rule, phishing simulations measured by reporting rate rather than click rate, and a no-blame reporting line.

THE WORD VERSIONS

Read them here. Take them with you.

The full text of every policy is on this site, free, with no form in the way. If you want the editable Word file — to drop your own company name into and hand to your team — that costs a name and an email. Tell us where to send it and the whole pack lands in your inbox.

Free. About 20 seconds.

We send the files you asked for and nothing else, unless you leave the mailing list box ticked. We do not sell or share your address, and every email carries a one-click unsubscribe.

IF YOU WOULD RATHER NOT OWN IT

A policy nobody operates is a document.

Writing it down is the easy half. The hard half is that somebody has to actually run offboarding the day a person quits, confirm the backup restored, and notice when MFA gets switched off on the finance mailbox.

That is what TiTAN is — someone owning the technology instead of it being everybody’s spare job. If that sounds like the part you are missing, book twenty minutes and we will work out which pieces you actually need.

Book 20 Minutes