All sample legal documents

IT and Cybersecurity Policy

A completed IT and cybersecurity policy covering acceptable use, access controls, encryption, incident response and proportionate disciplinary consequences.

Jurisdiction: England and Wales - completed fictional worked example

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

# IT AND CYBERSECURITY POLICY

Date: 10 November 2031

Parties: Merewood Surveying Limited and all personnel with access to its systems

## 1. Purpose and parties

Merewood Surveying Limited, company number 08421639, issues this policy for employees, agency workers, contractors and third parties with logical or physical access to its systems. It takes effect on Monday 10 November 2031 and is owned by IT Director Marcus Green, with Data Protection Officer Sophie Patel responsible for privacy escalation. It applies to company laptops, phones, cloud accounts, networks, paper data and approved home working.

## 2. Facts, scope and terms

Business use is permitted and incidental personal use is allowed during breaks if it is lawful, reasonable and does not disrupt work. Users must not access illegal or abusive content, install unlicensed software, gamble excessively, use peer-to-peer file sharing, bypass security controls, share credentials, or process Merewood data on an unmanaged personal device. Bring-your-own-device access requires enrolment in Merewood's mobile-device management profile and consent to a security wipe of company data.

## 3. Process and responsibilities

Each user must have a unique password of at least 16 characters, use the approved password manager and never reuse a company password elsewhere. Multi-factor authentication is mandatory for email, remote access, administrator accounts and financial systems. Laptops must use full-disk encryption, removable media must be encrypted and pre-approved, and critical security patches must be applied within 24 hours, high-risk patches within seven days and other patches within 30 days.

## 4. Evidence, records and safeguards

Users must lock screens when unattended, verify unexpected payment or access requests through a second channel, and report suspected phishing, lost equipment, malware or unauthorised disclosure to security@merewood.example and the service desk within one hour of discovery. Marcus will preserve evidence, contain access, reset credentials where necessary, assess affected personal data and coordinate recovery. Sophie will decide whether the UK GDPR Article 33 72-hour supervisory-authority notification window is engaged; staff must not contact the regulator or affected customers without authorisation.

## 5. Review, escalation and outcome

Network traffic, access events, email headers and security metadata may be logged and reviewed for security, legal compliance and service management. Monitoring will be proportionate, communicated through this policy and limited to what is necessary; content inspection or covert monitoring requires Sophie to document the purpose, necessity and authorisation. Merewood retains security logs for twelve months unless a live incident or legal hold requires longer, and access is limited to authorised IT, security, HR and legal personnel.

## 6. Reservations and practical protections

A minor breach, such as a late patch or careless screen exposure, may lead to retraining or a written warning. A significant breach, such as sending personal data to the wrong recipient or losing an unencrypted device, may lead to investigation, disciplinary action and regulatory assessment. Deliberate theft, credential sharing, disabling controls or knowingly exfiltrating data may be gross misconduct and may lead to summary dismissal and a law-enforcement referral, subject to a fair process and the Employment Rights Act 1996.

## 7. England and Wales law and completion

This completed fictional policy requires annual review and an immediate review after a material incident, major technology change or legal guidance change. It supports, but does not replace, the UK GDPR, Data Protection Act 2018, contractual duties and Cyber Essentials controls; it does not guarantee that an attack will be prevented. It is governed by England and Wales law, and every user must complete acknowledgement and training by 17:00 on 24 November 2031. Acknowledgement records will be retained with HR records, and access rights will be disabled immediately when a person leaves or a contract ends.

Create a version for your situation

Create a tailored IT Security Policy