Somewhere on the shared drive is a forty-page security policy, written years ago, that almost nobody has read. Meanwhile, the procedures people actually follow have grown up by habit: the receptionist’s own way of signing in visitors, the IT manager’s informal list of leavers, the shortcut everyone uses when the door entry system is slow. Security policies only protect an organisation when they reflect how people really work.
Short, clear and usable
We write and review security policies that people can understand and follow: short documents with clear expectations, written in plain English and proportionate to the real risks. Where detail is needed, it goes into simple procedures and checklists rather than long paragraphs.
Common areas
Visitor and contractor management. Device and information handling. Travel and lone working. Joiners, movers and leavers, including removing access promptly. Reporting incidents and concerns without fear of blame. Household staff policies for private clients.
Making them stick
A policy is only the start. We help introduce new procedures with short briefings, so staff understand why they matter, and we suggest simple ways to check they are being followed.
Supporting compliance
Clear policies support certifications such as Cyber Essentials, help with client and insurer questionnaires and show regulators that risks are being managed.
Policies work best alongside threat awareness training. Ask us to review yours.

