Information security policy
The umbrella document approved by the board, setting out the assets at stake, the threats that matter and where accountability lies. Directors should be able to explain it, not just sign it.
What goes into the set depends on its purpose: NIS2 and the Polish KSC act, the National Interoperability Framework (KRI) for public bodies, requirements passed down by a bank covered by DORA, or plain internal order.
The umbrella document approved by the board, setting out the assets at stake, the threats that matter and where accountability lies. Directors should be able to explain it, not just sign it.
A clear register of threats and their impact, leading straight to the controls you need and to the ones you deliberately skip, each with a written justification.
How rights are granted, adjusted and withdrawn, linked to the HR steps for new starters and people leaving.
Remote work aligned with your remote work regulations, passwords and MFA, private devices, backup, supplier oversight and incident response, including the path for reporting to the appropriate CSIRT.
Short, readable sheets of one or two pages. A thirty-page password standard goes unread; two pages with real examples get remembered.
Templates for an incident register, periodic access reviews and training confirmations. Auditors often ask to see these rather than the policy itself.
Everything is measured against one question: can people actually follow this? A rule that fights the workflow will be broken by Friday.
Teams calls with management, your IT lead and HR about the current reality of onboarding, access requests, suppliers and outages.
We produce the texts and review the wording together, so each requirement is achievable in your setting.
The board signs off, employees attend a brief online session and acknowledgements are stored.
A yearly review is booked, and documents are revised whenever systems or the organisation change significantly.
NIS2 puts weight on the accountability of management for cybersecurity. In organisations it covers, directors should understand the risk measures they approve. A policy nobody at the top has read turns from a paperwork weakness into a governance issue, which is why we close every engagement with a short briefing for leadership.
Usually, as a starting point. We check what still reflects reality and what describes a server that no longer exists, then fill the gaps, typically supplier management and incident handling. Starting from scratch is rarely necessary.
Only an accredited certification body can issue that certificate, not us. We follow ISO 27001 principles, so the documents form a sound base should you choose a certification audit later, and we can help you prepare for it.
Yes. The KRI regulation obliges public bodies to operate an information security management system. We structure the documents to meet it. If your authority runs a project, for example under the “Cyberbezpieczny Samorząd” programme, we help prepare the technical part of the paperwork.
No. Staff confirm they have read the short instructions relevant to them, ideally electronically with a date and document version. The full policies are for the people applying them: management, IT and HR.
Say what the documents should cover, whether NIS2, KRI, a client demand or internal order. We will suggest a scope and schedule.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.