Sample document
This is what a pack document looks like.
One of the 20: the Password & MFA Policy, the written evidence behind the first question on nearly every cyber application. You're reading its opening sections exactly as they ship. The green highlights are the blanks a short intake fills in with your business.
Password & Multi-Factor Authentication Policy
Company: company name · Policy owner: policy owner · Effective: effective date · Version: 1.0 · Review: annually
Why this matters for insurance: MFA on email, remote access, and admin accounts is the first hard requirement on virtually every cyber application (see the Application-Mapping Guide, Q1 to Q3). This policy is the written evidence behind your "yes."
Reality check: (1) MFA is actually enforced, not merely available, for every mailbox in your email admin console. (2) Every remote access path (VPN, remote desktop, and the remote-support tool your IT provider uses) requires MFA. (3) You can name every exempted account, and each one has a documented reason, a compensating control, and an expiry date. Edit this policy until all three are true.
1. Purpose
Protect company name's accounts and data from credential theft, the most common way businesses like ours are breached, through strong authentication.
2. Scope
All workforce members (employees, contractors, temporary staff) and every account used for company business: email, line-of-business applications, cloud services, network equipment, and any system reachable from the internet.
3. Multi-factor authentication (MFA)
3.1. MFA is required and enforced on:
- All business email accounts, without exception;
- All remote access (VPN, remote desktop, and remote-support tools);
- All administrator or privileged accounts on any system;
- All financial systems (banking, payroll, accounting).
3.2. Approved second factors: an authenticator app (push with number matching, or a one-time code), a hardware security key, or a passkey. Administrator accounts use a phishing-resistant method (a security key or passkey) wherever the platform supports it, as CISA recommends. SMS codes are permitted only where no stronger option exists, and those cases are revisited at each policy review.
The preview stops here. The full policy continues with:
- 4. Passwords
- 5. Shared and service accounts
- 6. Enforcement and exceptions
- 7. Review
- Appendix A: Exceptions and shared/service account log
All of it ships in the pack, editable and filled in with your business, along with the exceptions log carriers expect you to keep.
The rest of this policy, and the other eighteen documents, are in the pack.
Twelve policies, the incident response plan, the training kit, and the application-mapping guide that ties each document to the question it answers. All of them written like what you just read, and personalized by the same short intake.
14-day no-questions refund · editable files · yours forever
Want to see the personalization itself? Preview the intake. It's the same few questions buyers answer before download.