Small-Business Cybersecurity Kit
Small-Business Cybersecurity Kit — 5 editable policies, a fill-in incident response plan, a 26-slide staff training deck with speaker notes, and printable checklists — a phishing guide worked through line by line, an access inventory with no password column, and a ninety-day rollout a five-person business can actually finish.
A complete, plain-language security kit for a business of about five people with no IT department. It contains 6 editable Word documents — 5 starting-point policies covering acceptable use, passwords and accounts, data handling, remote and mobile working, and leavers, plus a fill-in Incident Response Plan with 6 roles, the first sixty minutes set out in order, a contact tree, evidence preservation, holding lines, recovery and the review afterwards. It contains a real editable PowerPoint deck of 26 slides with speaker notes on every single one, so somebody who has never run a training session can still run this one, ending in a 6-question quiz with an answer slide. And it contains a printable A4 guide holding everything that works better on paper: a 24-line password checklist, 3 worked phishing examples annotated tell by tell — including the supplier bank-detail change that actually takes money out of small businesses — a printable incident card and incident log, joiner and leaver checklists, an access inventory that records the service and whether two-factor is on but never the password, a backup page built around testing a restore, 10 questions to ask a supplier, and a ninety-day rollout in fortnights so that a busy business can actually finish it. It is general good practice, not a security audit, and the policies are starting-point templates rather than legal advice.
What's inside
- 5 EDITABLE POLICIES (DOCX): acceptable use, password and account security, data handling and confidentiality, remote and mobile working, and leavers and access removal — 71 plain numbered clauses in total, each policy with its purpose, who it applies to, what to do if something goes wrong, a review date and a sign-off block
- A FILL-IN INCIDENT RESPONSE PLAN (DOCX): 6 named roles, the first sixty minutes in 10 ordered steps, a contact tree of numbers you already hold, evidence preservation, holding lines for clients and staff, recovery, and the no-blame review afterwards
- A REAL 26-SLIDE STAFF TRAINING DECK (PPTX): editable slides with speaker notes on every one — why it matters, the password manager, two-factor in the right order, phishing recognition with all 3 worked examples, the payment rule, devices and data, what to do if you clicked, and a 6-question quiz with an answer slide
- A 24-LINE PASSWORD CHECKLIST: printable, manager-based, unique per service, two-factor on email and money first, no shared logins — and what to do instead when a shared login genuinely cannot be avoided
- 3 WORKED PHISHING EXAMPLES: shown as the messages themselves and annotated tell by tell — the mailbox that is about to be closed, the supplier whose bank details have changed, and the urgent favour from somebody senior. Recognition and response only
- INVOICE FRAUD AND PAYMENT REDIRECTION: the one that actually costs small businesses money, with the verification rule written out — phone a number you already hold, never one from the message, and a second person approves any change
- A PRINTABLE INCIDENT CARD AND INCIDENT LOG: one page for the wall with the first ten actions in order and a contact tree, plus a log to fill in as it happens
- JOINER AND LEAVER CHECKLISTS: 15 lines for the first day and 17 for the last, so access is granted properly and removed the same day
- AN ACCESS INVENTORY AND AN ASSET INVENTORY: one line per service and one per device, recording the login address, who has access, whether two-factor is on and whether recovery codes are saved — and deliberately no column anywhere for a password, PIN, one-time code or security answer
- A BACKUP PAGE BUILT AROUND THE RESTORE TEST: 12 lines, because nobody has ever had a backup problem — people have restore problems
- 10 QUESTIONS TO ASK A SUPPLIER before they are given access to anything of yours, with what each answer actually tells you
- A NINETY-DAY ROLLOUT IN FORTNIGHTS: 18 scheduled actions in the order that matters — email before everything, money second, inventories before the things that depend on them — plus a keep-it-alive routine from as-it-happens to annual
- WRITTEN TO BE ADOPTED, NOT ADMIRED: no statistics, no invented case studies, no claim to be an audit or a certification, no named regulation and no reporting deadline — the policies say plainly that they are starting points to be checked by a qualified adviser in your own jurisdiction
How it works
Open the DOCX files in Word, Google Docs or LibreOffice and replace the example text with your own details — the layout, spacing and structure are already done. The PDF guide walks you through step by step, with ready-to-use wording you can adapt. The slide decks open in PowerPoint, Google Slides, Keynote and LibreOffice Impress.
Specifications
- Format: DOCX (editable) + PPTX (editable slides) + PDF guide + read-me
- Works in: Word, Google Docs, LibreOffice
- License: full rights — use, edit, rebrand & resell
- Updates: free for life
Full rights
Sold with full rights: use it personally or with clients, edit anything, and even rebrand and resell it — keep 100% of the income, no attribution required. Customise before reselling (marketplaces reject identical duplicates).
Please note
Productivity and digital-organisation templates for personal and business use. Example entries are illustrations to adapt to your own setup. Never record passwords, PINs, one-time codes or full card numbers in these files — keep secrets in a dedicated password manager. Any security checklist here is general good practice, not a security audit or professional IT advice. Digital download — delivered instantly, so all sales are final; future updates are free.
Couldn't load pickup availability
Your payment information is processed securely. We do not store credit card details nor have access to your credit card information.

