Skip to main content

Blog

An HR-style policy document on a small business desk alongside a printed staff handbook and laptop

Why Your Business Should Have a Written IT Acceptable Use Policy

Why Your Business Should Have a Written IT Acceptable Use Policy

An IT acceptable use policy (AUP) is a written document that tells staff how they are expected to use the business IT systems: what they can and cannot do with their work laptop, the internet connection, email, and company data.

Most small businesses do not have one. When I ask why, the answer is usually: "We only have twelve people, we know each other, everyone is sensible." That may be true. The problem is that "everyone is sensible" is not enforceable, and it does not protect you when someone does something they genuinely thought was acceptable.

What an AUP actually covers

A well-written AUP for a small business is typically a two to four page document covering:

  • What devices may be used for work, and the rules for personal devices
  • Internet and email use: what is and is not acceptable during working hours
  • Data handling: where files must be saved, what data can be taken offsite or sent externally
  • Passwords and accounts: not sharing credentials, not using personal accounts for work purposes
  • Social media: what is acceptable to post about the business or clients
  • Software installation: whether staff can install their own software on work machines
  • What to do if a device is lost, stolen, or compromised
  • The consequences of violating the policy

None of these rules are surprising. Most staff will read them and think "that all seems reasonable." The value is in having them written down, signed for, and therefore enforceable.

Why "everyone knows" is not a policy

Consider a scenario: a member of staff uses their work laptop to download a piece of personal software, which introduces malware. The subsequent clean-up costs the business a day of downtime and an IT support call-out bill.

Without a policy, you have very limited recourse. The staff member may genuinely not have known it was not allowed. Even if you try to pursue some form of disciplinary action, HR will ask for the written policy that was violated. Without it, your position is weak.

With a policy that the staff member signed on joining, you have a clear basis for a disciplinary conversation and you have demonstrated that you take IT security seriously.

The GDPR and cyber insurance angle

UK GDPR: demonstrating that staff have been informed of their responsibilities around data handling is part of what the ICO expects in terms of staff training and awareness. An AUP that covers data handling, signed by all staff, is evidence of that.

Cyber insurance: insurers are starting to ask about the controls you have in place. An AUP is one of the basic organisational controls that demonstrates you take security seriously. Combined with MFA and a backup policy, it helps your case at renewal time.

Making it proportionate

An AUP for a 10-person professional services firm does not need to be the same length as the IT policy for a 500-person organisation. It needs to be proportionate: covering the real risks your business faces, written in language your team will actually read, and reviewed once a year to keep it current.

The things it absolutely must cover for a small business in 2026:

  • No sharing of credentials or use of personal email for work data
  • MFA is required on all work accounts
  • Work files must be saved to the company cloud storage, not local drives
  • Any lost or stolen device must be reported immediately so it can be wiped remotely
  • Suspicious emails should be reported and not clicked

Talk to ClearPath IT about an acceptable use policy

ClearPath IT Services works with small businesses across Kent, Medway and South East London on IT policy, security, and managed support.

ClearPath IT Services

Personal, reliable IT support for small businesses across Kent, Medway and South East London.

Clear IT. Sorted.

Get in Touch

Based in Kent, serving businesses across Medway, Dartford, Gravesend, Sidcup, Bexley and South East London.

Call: 0333 360 8308

Visit: 1a Saddington Street, Gravesend, DA12 1ED

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

Contact me


© 2026 ClearPath IT Services Limited. All rights reserved. | Privacy Policy