Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Map the information your business handles
- 2. Decide the rules for access and authentication
- 3. Cover devices, remote work and physical security
- 4. Set rules for data handling and sharing
- 5. Include incident reporting and response steps
- 6. Align the policy with your contracts and other documents
- 7. Train people and review the policy regularly
- Common mistakes Australian businesses make
- Key Takeaways
Many Australian businesses know they need better cyber security, but get stuck on one basic question: what should an information security policy actually say? Founders often make the same mistakes. They download a generic overseas template that does not fit Australian privacy rules, treat the policy as an IT document instead of a business-wide set of rules, or write something so vague that staff cannot follow it in real situations. That leaves gaps when an employee loses a laptop, a contractor needs access to customer data, or a client asks about your security controls before you sign a contract.
A clear information security policy helps your business set internal rules, reduce avoidable risks, and show customers, suppliers and staff what standards apply. It also supports your privacy compliance, contracts, onboarding and incident response. This guide explains what an information security policy means for Australian businesses, when you are likely to need one, what to include, and the common mistakes that cause trouble later.
Overview
An information security policy is the written rulebook for how your business protects data, systems, devices and access. For Australian businesses, the right policy usually needs to cover both cyber security practices and the legal handling of personal information.
- Define what information and systems the policy covers
- Set clear access controls, password rules and device security requirements
- Address staff, contractors and third-party access
- Explain how sensitive and personal information must be collected, used, stored and shared
- Include incident reporting, breach escalation and response steps
- Assign responsibility for approvals, updates, training and enforcement
- Align the policy with your privacy documents, employment contracts and supplier contracts
- Review the policy regularly as your systems, team and risks change
What Information Security Policy Means For Australian Businesses
An information security policy tells your team what security standards apply in daily work, not just what your IT provider does behind the scenes. It should be practical enough for staff to follow and specific enough to support management decisions when something goes wrong.
For many businesses, this policy sits between high-level governance and day-to-day procedures. The policy states the rules and expectations. Separate procedures can then explain the exact steps for matters like onboarding users, approving software, handling phishing emails or restoring backups.
What the policy usually covers
Most Australian businesses should treat information security broadly. The issue is not limited to customer databases or cloud servers. It also includes email accounts, payment systems, employee records, mobile phones, laptops, messaging apps, paper files and any platform used to store or access business information.
A well-drafted information security policy often includes:
- The purpose of the policy and who must follow it
- Definitions of confidential information, personal information and sensitive information
- Rules for account access, permissions and user authentication
- Password, multi-factor authentication and device-lock requirements
- Approved systems, software and storage locations
- Remote work, bring your own device, and physical security rules
- Data classification and data retention expectations
- How information can be shared internally and externally
- Incident reporting processes and escalation pathways
- Training, monitoring, disciplinary consequences and review dates
Why this matters legally
The main legal issue is that information security does not sit in one law or one contract. Different obligations can apply at the same time, depending on your business model, industry, size and the information you hold.
For example, your obligations may be shaped by:
- The Privacy Act 1988 (Cth), including the Australian Privacy Principles, if your business is covered
- Notifiable data breach obligations where an eligible data breach occurs
- Confidentiality obligations in customer, supplier, funding or service contracts
- Employment law and workplace policies dealing with staff conduct and company property
- Industry-specific expectations, such as in health, finance, education or government supply chains
- General risk management and director duties to act with due care and diligence
Not every small business will be directly covered by the Privacy Act, but many still need a security policy because they handle client data, sign contracts with security clauses, process online orders, or work with larger organisations that ask for evidence of security controls. This is where founders often get caught. They assume security policies are only for large companies, then lose a deal because a customer due diligence form asks for one.
How it connects with privacy compliance
Your information security policy is not the same as a privacy policy. A privacy policy generally explains to the public how your business collects, uses and discloses personal information. An information security policy is usually an internal document that sets the rules for protecting that information and other business data.
The two still need to line up. If your privacy policy or collection notices say customer information is stored securely and access is limited, your internal policy should explain what that means in practice. If your contracts promise encryption, access restrictions or prompt incident notification, your policy should support those promises.
When This Issue Comes Up
Businesses usually need an information security policy before a problem happens, not after. The policy becomes important at the moments when you are about to trust someone with data, systems or access.
Before you hire staff or engage contractors
New team members create immediate security risk if expectations are unclear. Someone starts work, uses a personal device, saves files to an unapproved app, or keeps access after the relationship ends. A policy gives you a baseline for onboarding, acceptable use, confidentiality and offboarding.
This often works best when the policy is supported by:
- Employment contracts with confidentiality and intellectual property clauses
- Contractor agreements covering data access, security obligations and return of materials
- Workplace policies on acceptable technology use and remote work
Before you sign a customer or supplier contract
Security questions now appear in many commercial contracts, even for smaller businesses. A client may ask whether you have documented access controls, data breach processes, encryption standards or staff training. If your answer is informal or inconsistent, negotiations can slow down quickly.
You are also likely to see this issue when:
- A supplier hosts or processes data for you
- A customer shares personal information or commercially sensitive documents with your business
- You work with enterprise clients, government-related bodies, schools, health providers or regulated industries
- You seek investment or due diligence before a sale or funding round
Before you launch online or adopt new systems
Founders often spend money on setup, websites, SaaS tools and payment platforms before deciding where data should live and who should access it. That creates messy workarounds later. An information security policy is useful before you launch online, before you roll out a CRM, and before you connect multiple apps that move customer data around automatically.
This matters whether you sell products online, run a service business, manage subscriptions or build software. The more digital your workflows become, the more your policy needs to cover user permissions, third-party platforms, account ownership and records retention.
After a near miss or internal confusion
Many businesses only create a policy after something goes wrong. A phishing email is opened, a shared password is reused, a founder cannot access a departing employee's accounts, or customer files are uploaded into a personal storage drive. Those events usually reveal that nobody agreed on the rules in the first place.
A policy is also useful if your team is asking practical questions such as:
- Can staff use their own phones and laptops for work?
- Who approves new software tools?
- Where should signed contracts and ID documents be stored?
- How long should records be kept?
- Who must be told if there is a suspected breach?
Practical Steps And Common Mistakes
The best information security policy is specific to how your business actually works. A short, usable policy that matches your systems and contracts is far more valuable than a long generic document nobody reads.
1. Map the information your business handles
Start with a practical inventory. You need to know what information you hold, where it sits, who can access it and why your business needs it. Without that, policy drafting turns into guesswork.
At a minimum, identify:
- Customer personal information
- Employee and contractor records
- Payment details and billing data
- Confidential business information, such as pricing, forecasts and product plans
- Login credentials, API keys and administrator accounts
- Paper records, hard drives, cloud storage and third-party software platforms
This step often exposes risk areas that should be reflected in your policy. For example, a business may discover that multiple staff share one admin login, or that a former contractor still has access to a project management account.
2. Decide the rules for access and authentication
Access control is one of the most important parts of an information security policy. Staff should only have access to the systems and information they need for their role. That principle sounds obvious, but many SMEs drift into broad access because it feels easier in the early stages.
Your policy should state clear expectations about:
- User account ownership and approval
- Role-based access levels
- Password standards
- Multi-factor authentication requirements
- Shared accounts and whether they are prohibited or restricted
- Prompt removal of access when roles change or someone leaves
A common mistake is leaving these points to verbal instructions from a founder or IT provider. That causes inconsistency and makes it harder to enforce standards later.
3. Cover devices, remote work and physical security
Many security incidents are basic operational problems, not sophisticated hacks. A lost laptop, unlocked screen, printed file left in a co-working space, or staff member using public Wi-Fi can create serious exposure.
Your policy should deal with practical matters such as:
- Company-issued versus personal devices
- Required screen locks, updates and antivirus settings
- Storage of files on local devices
- Use of removable media and external drives
- Secure disposal of paper records and old hardware
- Physical access to offices, storage rooms and filing cabinets
If you allow bring your own device arrangements, the policy should say what controls apply and what happens to company information when the person stops working with you.
4. Set rules for data handling and sharing
Information security is not only about preventing outsiders from getting in. It is also about controlling how your own business collects, stores, uses and discloses information. This is where privacy and confidentiality issues often overlap.
Your policy should address:
- Approved storage locations for different categories of information
- Restrictions on emailing, downloading or copying files
- Use of messaging apps and collaboration tools
- Sending information to external advisers, suppliers or customers
- Encryption or secure transfer expectations where appropriate
- Retention and deletion rules once information is no longer needed
One common mistake is assuming cloud software automatically solves the legal side. The platform may offer security features, but your business still needs internal rules about who may use it, how records are managed and whether the tool is suitable for the information involved.
5. Include incident reporting and response steps
A policy should tell people what to do the moment something feels wrong. Speed matters when accounts are compromised or information is misdirected. Staff should not be left guessing whether an issue is serious enough to raise.
Your incident section should generally cover:
- What counts as a suspected incident
- Who must be notified internally
- Immediate containment actions
- How to preserve evidence and records
- Who assesses legal or contractual notification obligations
- How the business reviews and fixes the issue afterwards
If your business is covered by the Privacy Act, an eligible data breach may trigger notification obligations. Even where the law does not require notice, your customer or supplier contracts might.
6. Align the policy with your contracts and other documents
Your information security policy should not contradict your other documents. If your employment agreements are silent on confidentiality, if your contractor terms do not require secure handling of data, or if your website statements promise things your business cannot actually do, the policy alone will not solve the problem.
Documents commonly needing alignment include:
- Privacy policies and collection notices
- Employment contracts and staff handbooks
- Contractor agreements
- Client service agreements and supplier terms
- Software and data processing arrangements
- Incident response plans and business continuity procedures
This is particularly important before you sign a major contract. If a customer asks you to meet specific security standards, those obligations should be checked against your internal policy and operational capability before you agree.
7. Train people and review the policy regularly
A policy only works if people know it exists and understand how to apply it. Staff training does not need to be complicated, but it should be regular and role-appropriate. Founders, managers, customer-facing staff and technical teams often face different security risks.
Review the policy whenever your business changes in a meaningful way, such as:
- You adopt new software or move systems to a different provider
- You expand offshore or engage overseas contractors
- You begin handling more sensitive customer information
- You move to remote or hybrid work
- You enter an industry with stricter compliance expectations
- You experience a security incident or near miss
Common mistakes Australian businesses make
Most policy problems are avoidable. The issue is usually not that a business has no interest in security. It is that the policy does not match the business, has no owner, or is treated as a one-off admin task.
Watch for these common mistakes:
- Using a foreign template that refers to overseas laws or unrealistic standards
- Copying enterprise-level security promises that the business cannot actually meet
- Writing a policy that only deals with IT systems and ignores people, contractors and paper records
- Failing to define who is responsible for approvals, updates and incident escalation
- Leaving staff to sign the policy without any training or explanation
- Ignoring offboarding, especially removal of access and return of devices
- Forgetting that third-party vendors and apps create security and privacy risk too
- Letting the policy sit unchanged for years while the business grows and changes tools
If your business is early stage, keep the document practical. You do not need a 40-page manual before you spend money on setup. You do need clear rules that fit your real systems, team size and legal obligations.
FAQs
Does every Australian business need an information security policy?
Not every business is legally required to have a formal standalone policy, but many should. If you handle customer or employee information, use cloud systems, engage staff or contractors, or sign contracts with security clauses, a written policy is usually sensible and often expected.
Is an information security policy the same as a privacy policy?
No. A privacy policy explains externally how your business handles personal information. An information security policy is usually internal and sets the rules for protecting systems, devices and data across the business.
What is the difference between a policy and a procedure?
A policy sets the rule or standard. A procedure explains the step-by-step process for carrying it out. For example, the policy may require prompt offboarding, while a separate procedure lists exactly how accounts are disabled and devices returned.
Should small businesses include contractors in the policy?
Yes, if contractors can access your systems, customer data or confidential information. The policy should apply to them where relevant, and your contractor agreements should back that up with clear security and confidentiality obligations.
How often should the policy be reviewed?
At least periodically, and sooner if your business changes systems, grows quickly, starts handling more sensitive data, moves into a regulated sector, or experiences a security incident. Annual review is common, but some businesses need more frequent updates.
Key Takeaways
- An information security policy sets the internal rules for protecting your business data, systems, devices and access.
- For Australian businesses, the policy should reflect privacy obligations, confidentiality commitments and any relevant contractual or industry requirements.
- A useful policy usually covers scope, access controls, device security, data handling, third-party access, incident response, training and review responsibilities.
- The policy should match how your business actually operates, including remote work, contractors, cloud platforms and customer data flows.
- Common mistakes include using generic templates, failing to align contracts and privacy documents, and not training staff on what the policy means in practice.
- It is best to put the policy in place before you hire, launch online, sign contracts, or roll out new systems, not after a security incident.
If your business is dealing with information security policy and wants help with privacy compliance, contractor and employment documents, customer and supplier contracts, data breach obligations, you can reach us on 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.






