Service · Cybersecurity

Security policies and documentation

A downloaded policy template looks respectable right up to the moment an auditor asks for the approval date, the last review and proof that employees have seen it. Documents written for a different company stop matching reality within days. We draft yours after talking to your people and looking at your systems, so the paperwork holds firm with a contracting authority, a demanding client and the realities of an ordinary Monday.

A set
fitted to your firm
Timeline
agreed at the start
ISO 27001
as our reference point
Annual
review scheduled in

Included in this service

What goes into the set depends on its purpose: NIS2 and the Polish KSC act, the National Interoperability Framework (KRI) for public bodies, requirements passed down by a bank covered by DORA, or plain internal order.

Talk the scope through with an engineer

Information security policy

The umbrella document approved by the board, setting out the assets at stake, the threats that matter and where accountability lies. Directors should be able to explain it, not just sign it.

Risk analysis

A clear register of threats and their impact, leading straight to the controls you need and to the ones you deliberately skip, each with a written justification.

Access governance

How rights are granted, adjusted and withdrawn, linked to the HR steps for new starters and people leaving.

Supporting procedures

Remote work aligned with your remote work regulations, passwords and MFA, private devices, backup, supplier oversight and incident response, including the path for reporting to the appropriate CSIRT.

Staff guidance

Short, readable sheets of one or two pages. A thirty-page password standard goes unread; two pages with real examples get remembered.

Registers and records

Templates for an incident register, periodic access reviews and training confirmations. Auditors often ask to see these rather than the policy itself.

How we work together

Everything is measured against one question: can people actually follow this? A rule that fights the workflow will be broken by Friday.

01

Interviews

Teams calls with management, your IT lead and HR about the current reality of onboarding, access requests, suppliers and outages.

02

Drafting

We produce the texts and review the wording together, so each requirement is achievable in your setting.

03

Launch

The board signs off, employees attend a brief online session and acknowledgements are stored.

04

Keeping current

A yearly review is booked, and documents are revised whenever systems or the organisation change significantly.

NIS2 puts weight on the accountability of management for cybersecurity. In organisations it covers, directors should understand the risk measures they approve. A policy nobody at the top has read turns from a paperwork weakness into a governance issue, which is why we close every engagement with a short briefing for leadership.

Questions and answers

Usually, as a starting point. We check what still reflects reality and what describes a server that no longer exists, then fill the gaps, typically supplier management and incident handling. Starting from scratch is rarely necessary.

Only an accredited certification body can issue that certificate, not us. We follow ISO 27001 principles, so the documents form a sound base should you choose a certification audit later, and we can help you prepare for it.

Yes. The KRI regulation obliges public bodies to operate an information security management system. We structure the documents to meet it. If your authority runs a project, for example under the “Cyberbezpieczny Samorząd” programme, we help prepare the technical part of the paperwork.

No. Staff confirm they have read the short instructions relevant to them, ideally electronically with a date and document version. The full policies are for the people applying them: management, IT and HR.

Get documentation that survives an audit

Say what the documents should cover, whether NIS2, KRI, a client demand or internal order. We will suggest a scope and schedule.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.