How to Create a Cybersecurity Policy for Your Small Business in South Africa

By Ubuntu Guard | 11 May 2026

"We're too small to need a cybersecurity policy."

We hear it from business owners constantly. It is the exact mindset attackers count on.

You do not need to be a corporate giant to have a cybersecurity policy. If your business has a website, uses email, stores customer data, or accepts electronic payments, you need one. And under POPIA, you are legally expected to have "reasonable measures" in place to protect personal information. A written policy is the foundation those reasonable measures sit on.

The good news. A cybersecurity policy for a small business does not need to be a 60-page legal document. Five to ten pages of clear, practical rules that your team actually understands and follows. Here is how to build it.

What a cybersecurity policy actually is

A cybersecurity policy is a written document that tells your team how to handle technology, data, and security in your business. What is allowed. What is not. What to do when something goes wrong. Who is responsible for what.

It is not a technical manual. It is a set of human-readable rules. If your team cannot understand it without a computer science degree, it is not a good policy.

A solid policy does three things. It reduces risk by giving people clear guidelines instead of letting them guess. It demonstrates POPIA compliance by showing you have implemented reasonable security measures. It gives you a framework for responding to incidents instead of scrambling when one hits.

The seven sections every SME policy should include

1. Acceptable use

This section defines what employees can and cannot do with company devices and systems. Keep it practical and specific to your business.

Cover whether personal use of company devices is permitted. Which websites and services are acceptable to access on company networks. Rules about connecting personal devices to the business Wi-Fi. Whether company email can be used for personal communication. Guidelines on downloading software or apps onto company devices.

The principle: company devices and accounts are company property. Treat them accordingly.

2. Password and authentication

This section sets the rules for how your team creates and manages passwords. Weak passwords remain a top entry point for attackers in South Africa.

Require passwords of at least 12 characters with a mix of letters, numbers, and symbols. Prohibit password reuse across accounts. Require two-factor authentication on all business email accounts, cloud platforms, and any system holding customer data. Recommend or provide a password manager so employees do not write passwords on sticky notes or store them in spreadsheets.

If you need help rolling this out, see our 2FA setup guide.

3. Data handling and POPIA compliance

This section covers how your business collects, stores, processes, and disposes of personal information. Under POPIA, you are required to handle personal data responsibly.

Define what types of personal data your business collects. Customer names. ID numbers. Email addresses. Financial information. Specify where this data is stored and who has access to it. Establish rules for sharing data with third parties, including that written consent or a contractual agreement must be in place. Define how long data is retained and how it is securely deleted when no longer needed. Name your Information Officer and document their responsibilities.

4. Device and network security

You do not need enterprise-level detail, but you do need clear expectations.

All devices must have up-to-date antivirus or endpoint protection software. Operating systems and applications must be updated promptly when updates are available. Company Wi-Fi must be secured with a strong password and WPA3 encryption where supported. Guest Wi-Fi should be separate from the business network. Employees working remotely must use a VPN or secure connection to access company systems. Lost or stolen devices must be reported immediately so they can be remotely wiped or locked.

5. Email and communication security

Email is the number one attack vector for South African businesses. Your policy needs specific guidance.

Employees never click links or open attachments in unexpected emails, even if the sender appears familiar. Any email requesting a change in banking details, an urgent payment, or sensitive information must be verified by phone call to a known number before any action is taken. Business email forwarding to personal accounts is prohibited. Suspicious emails should be reported to a designated person, not deleted.

If your business does not have SPF, DKIM, and DMARC set up on the email domain, fixing that should be a priority. Our domain security check guide walks through it.

6. Backup and recovery

This section ensures your business can recover from data loss, whether from a cyber attack, hardware failure, or human error.

Define your backup schedule. For most SMEs, daily automated backups of critical data is the minimum. Follow the 3-2-1 rule. Three copies of your data, on two different types of media, with one copy stored offsite or in the cloud. Test your backups quarterly. A backup that has never been tested is not a backup, it is a hope. Define who is responsible for managing and monitoring backups. Document your recovery process. If your systems went down tomorrow, what are the exact steps to get them back?

For more detail, see our business backup guide for SA SMEs.

7. Incident response

This section tells your team what to do when something goes wrong. Without it, people panic, make mistakes, and make the situation worse.

Define what counts as a security incident. Suspected malware infection. Unauthorised access to accounts. Lost or stolen devices. Ransomware messages. Suspicious emails that were clicked. Unusual system behaviour.

Establish a clear reporting chain. Who does the employee contact first? Provide a name, phone number, and email. Not a generic "IT department" that nobody knows how to reach.

Outline the immediate steps. Disconnect the affected device from the network. Do not turn it off. Document what you see. Contact the designated person.

If your business does not have internal security capability, name your external incident response partner in the policy.

How to make your policy stick

A policy that lives in a drawer is worthless. Here is how to make sure yours actually gets used.

Keep it short and readable. Five to ten pages. Plain language. No legal jargon. No acronyms without explanations. If your receptionist cannot understand it, rewrite it.

Have every employee sign it. When someone joins the business or when the policy is updated, they read and sign an acknowledgement. This creates accountability and protects you legally.

Train your team on it. Do not just hand them the document. Walk through the key points in a team meeting. Use real examples. Show them what a phishing email looks like. Demonstrate how 2FA works.

Review it annually. Cyber threats evolve. Your business changes. Your policy should change with them. Set a calendar reminder to review and update it at least once a year.

Lead by example. If the business owner uses "password123" and refuses to set up 2FA, the policy is dead on arrival. Security culture starts at the top.

Getting started today

You do not need to build a perfect policy on day one. Start with the most critical sections, passwords, email security, and incident response, and build from there. A basic policy that your team follows is infinitely better than a comprehensive one that nobody reads.

If you want professional help assessing your current security posture and building a policy tailored to your specific business, a cybersecurity assessment is the best place to start. We identify your gaps, prioritise the risks, and help you build practical protections that fit your people, tools, and budget.

Reach us at [email protected].

Sources


© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za

Need help building a policy that fits your business?

Ubuntu Guard's cybersecurity assessment identifies your gaps, prioritises the risks, and gives you a practical policy framework built around your people, your tools, and your budget.

Book a Cybersecurity Assessment

Questions? Reach us at [email protected]