Most small businesses have policies. They just aren’t written down. They’re stored in the owner’s head, buried in an old email, mentioned during somebody’s first week, or summed up with, “That’s just how we do things here.” And for a surprisingly long time, that can work just fine. Right up until it doesn’t.
When I talk about written policies with small businesses and nonprofits, I can almost see the eyes starting to glaze over. The word policy sounds corporate. It sounds like an employee handbook nobody reads, a compliance department you don’t have, or a 47-page document written by an attorney where every third sentence starts with “whereas.” If you’ve got six employees, or maybe it’s just you, that can feel like ridiculous overkill.
But a good policy doesn’t need to be complicated. At its simplest, a policy is just a decision you’ve already made and bothered to write down. That’s it. And that matters a lot more than most small businesses realize.
You’re Making These Decisions Anyway
Think about some of the technology decisions happening inside a business every day. Can employees use their work computer for personal stuff? Can they install software themselves? Can they use ChatGPT or another AI tool with company information? Who gets access to the accounting system? Does everyone have to use MFA? What happens to someone’s accounts when they leave? Who gets called if someone clicks on something they shouldn’t have?
If you haven’t answered those questions, it doesn’t mean your business doesn’t have a policy. It usually means each employee gets to make the policy for themselves. One employee might think putting company files in their personal Dropbox is perfectly reasonable. Another might paste customer information into an AI tool because nobody ever told them not to. Someone else might share a password with a coworker because it’s faster than asking for another account. None of them necessarily think they’re doing anything wrong. The business simply never drew the line.
That’s one of the biggest reasons I like written policies. They eliminate a lot of conversations that begin with “I thought...” I thought that was allowed. I thought somebody disabled his account. I thought OneDrive was our backup. I thought we could all use the same password. I thought IT was supposed to handle that.
“I thought” can become two very expensive words.
Make the Decision Before Something Is on Fire
There’s another reason written policies matter that has nothing to do with employees following rules. They force you to make decisions while you actually have time to think about them.
The worst possible time to decide how your business responds to ransomware is while you’re staring at the ransom note. That’s when people panic. Phones start ringing, someone starts unplugging things, somebody else starts trying to restore something, the owner calls IT, another employee calls the insurance company, and someone decides this would be an excellent time to post something on Facebook. Now you’ve got the original problem plus three or four new ones you’ve created for yourself.
Compare that with a business that has already made those decisions. If we have a cybersecurity incident, we know who gets called first. We know who is responsible for communicating with employees and customers. We know where our backups are and who is responsible for recovery. If we have cyber insurance, we know what the carrier requires us to do before anyone starts changing things.
You don’t have to invent the process during the emergency because you already did the thinking on a boring Tuesday afternoon when nothing was wrong. That’s really what a useful policy does. It lets Calm You leave instructions for Panicked You.
“But It’s Just Me”
This is usually where the solopreneurs get to feel smug for a minute. “I don’t have employees. Who am I writing a policy for? Myself?”
Yep.
In some ways, written policies can be even more valuable when you’re the entire company because there’s nobody else around forcing you to make these decisions. Do you require MFA on every important business account? Where are your business files stored? What actually gets backed up? What information will you never put into a public AI system? If your laptop disappears tomorrow, what happens next? If you’re unexpectedly unavailable for a week, can someone you trust get to the information necessary to keep the business running?
Maybe you know all those answers right now, but will you remember every detail six months from now when you’re dealing with an emergency? More importantly, does anybody else know them? Writing this stuff down isn’t bureaucracy. Sometimes it’s simply doing your future self a favor, because Future You is already going to be having a bad enough day.
We Decide. We Document. We Enforce.
I’ve started using a very simple framework when talking about technology policies: We decide → We document → We enforce.
First, we decide. Leadership decides what the rule actually is. Not IT, not the employee who happens to know the most about computers, and not whoever encounters the problem first. Technology can help implement and enforce a rule, but the business needs to decide what that rule should be.
Then, we document. Write it down somewhere people can actually find it, and please write it in English. If your employees need an attorney and a decoder ring to understand the acceptable use policy, they’re not going to follow it. A useful policy doesn’t have to be twenty pages long. Depending on the subject and the size of the business, it might only need to be a page or two.
Finally, we enforce. This is the part businesses sometimes forget. If your written policy says everyone uses MFA but the owner doesn’t because it’s inconvenient, that’s not really your policy. If the policy says employees can’t share passwords but everyone knows the accounting login is written on a Post-it note under Karen’s keyboard, that’s not your policy either. A policy you don’t enforce is just a document taking up space.
You Don’t Need Fifty Policies
The other mistake small businesses make is assuming that once they start down this road, they’re going to need a giant binder full of policies. You don’t. Start with the areas where a bad assumption could seriously hurt the business.
For most small organizations, I think there are four technology policies worth putting at the top of the list. An Acceptable Use Policy answers how company computers, accounts, internet access, email, and AI tools can be used. It establishes what is okay, what isn’t, and what information should never leave the company. A Password & Access Policy establishes how accounts are protected, where MFA is required, who gets access to what, and who approves that access.
An Incident Response Plan answers the big question nobody wants to think about: What do we do when something goes wrong? If you carry cyber insurance, that includes knowing what your policy requires you to do first. If you don’t, you still need to know who that first call is going to be and what happens next. Finally, an Employee Offboarding Checklist makes sure someone’s access to your company ends when their employment does. Not next week, not when somebody remembers, but as part of a defined process when they leave.
None of those need to start as enormous documents. They need to start as decisions.
The Policy Isn’t the Point
The goal isn’t to be able to brag that your company has written policies. The goal is consistency. You don’t want your cybersecurity strategy changing depending on which employee gets the suspicious email. You don’t want access removed from former employees only when somebody happens to remember. You don’t want to figure out your incident response process while an attacker is sitting inside your network, and you definitely don’t want your company’s rules to exist only inside one person’s head.
That’s why written policies matter whether you have one employee, ten employees, or a hundred. Decide what you’re going to do, write it down, and then actually do it. We decide. We document. We enforce.
It doesn’t need to be complicated. It just needs to stop being something everybody thought they knew.



