Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- Step 1: Map the information you hold
- Step 2: Set access rules that fit real roles
- Step 3: Make device and remote work rules explicit
- Step 4: Align the policy with contracts and privacy documents
- Step 5: Create an incident response process
- Step 6: Train people and enforce the policy
- Common mistakes to avoid
- Key Takeaways
Many New Zealand businesses know they should take cyber risk seriously, but they still treat their information security policy like a generic IT document downloaded the night before a client asks for it. That usually leads to three common mistakes: copying a policy that does not match how the business actually works, focusing only on hackers while ignoring internal access and human error, and forgetting that privacy, contracts and day to day operations all need to line up with the policy.
A good information security policy is not just about satisfying a questionnaire. It helps you decide who can access what, how customer and staff information is handled, what happens when something goes wrong, and what your team is expected to do before you sign a contract or roll out a new system. For startups and SMEs, that clarity matters because one weak process can create legal, commercial and reputational problems very quickly.
This guide explains what an information security policy means in a New Zealand business context, when you are likely to need one, and the practical steps that make the policy usable rather than ornamental.
Overview
An information security policy sets the rules for protecting business information, customer data, staff records, systems and devices. For New Zealand businesses, it usually sits alongside privacy processes, employment documents, supplier agreements and incident response planning, rather than operating as a standalone IT paper.
The right policy should reflect how your business actually stores, shares and uses information, especially before you launch online, engage new staff, onboard software providers or sign contracts with enterprise customers.
- Identify what information your business holds, including personal information, commercial records, payment details and confidential know how.
- Decide who can access which systems, files and devices, and how access is approved, reviewed and removed.
- Set practical rules for passwords, multi factor authentication, remote work, device use, software updates and secure storage.
- Work out how the policy fits with your Privacy Act obligations, employment terms, contractor arrangements and client contracts.
- Prepare an incident response process for data loss, unauthorised access, ransomware, phishing and mistaken disclosure.
- Train staff so the policy becomes part of daily business practice, not just a document in a folder.
What Information Security Policy Means For New Zealand Businesses
An information security policy is a written set of rules that tells your business how to protect information and systems in practice. It should be clear enough that staff can follow it, detailed enough that management can enforce it, and realistic enough that it matches your actual tools and workflows.
For many founders, the phrase sounds technical, but the legal and business issues are broader than IT. If your team stores customer details in a CRM, uses cloud accounting software, handles employee records, sends invoices, uses shared drives or works remotely, you already have information security decisions to make.
What the policy usually covers
The exact content depends on your size, industry and systems, but most businesses need an information security policy that addresses the main operational risks. That often includes the following areas:
- classification of information, such as public, internal, confidential and sensitive material
- user access controls, including permissions, approval pathways and account removal
- password standards and multi factor authentication requirements
- acceptable use of company devices, email, messaging apps and cloud platforms
- remote work rules, including home networks, screen privacy and device security
- data retention and secure deletion practices
- physical security for offices, shared workspaces and paper records
- incident reporting and escalation procedures
- vendor and software assessment processes
- staff training and policy acknowledgement requirements
How it connects with New Zealand privacy law
If your business collects, stores or uses personal information, the Privacy Act 2020 is part of the picture. The Act does not simply require a business to say it cares about data security. It expects agencies to take reasonable safeguards against loss, unauthorised access, use, modification, disclosure and other misuse of personal information.
Your information security policy helps show what those safeguards look like inside the business. It can support your privacy compliance by setting internal standards for access, storage, sharing and incident handling. If your policy says one thing but your team does another, that gap becomes a real problem.
This matters most when a privacy issue arises and the business needs to explain what controls were in place, who had access, whether staff were trained, and how the incident was handled. A tailored policy will not guarantee compliance on its own, but it is often one of the first documents looked at when questions come up.
Why small businesses need one too
A lot of SMEs assume information security policies are only for banks, health providers or large tech companies. In reality, small businesses often face the same core risks with fewer internal controls and less room to absorb a mistake.
A design studio might hold client logins and confidential marketing plans. A retailer selling online may process customer names, delivery details and payment related information through third party platforms. A professional services firm may hold contracts, identity documents, payroll records and commercial secrets.
In each case, the main risk is not only an external attack. Founders often get caught by simpler issues:
- a former employee still has access to systems after leaving
- staff use personal devices without clear security settings
- confidential files are shared through unsecured channels
- software subscriptions are purchased without any vendor review
- businesses promise security standards in customer contracts that they cannot actually meet
An information security policy gives structure to these decisions before they become expensive problems.
When This Issue Comes Up
Most businesses do not think seriously about an information security policy until a customer asks for one, a data scare happens, or a contract negotiation exposes a gap. The better approach is to sort it out before you spend money on setup, sign supplier agreements or make promises to customers about data handling.
When you are growing beyond founder only access
The moment more than one or two people can access customer data, financial records or internal systems, you need clear rules. Informal verbal instructions usually break down once you hire staff, engage contractors or use offshore support.
This is where founders often rely on trust instead of process. Trust matters, but it does not replace access logs, account management, confidentiality obligations or clear approval steps.
When enterprise customers or government clients ask questions
Larger customers commonly send security questionnaires during procurement. They may ask whether you have a documented information security policy, an incident response process, staff training, access controls, encryption practices or vendor management rules.
If your documents are vague or inconsistent, procurement can stall. Worse, you might feel pressure to overpromise in a contract. Before you sign, check that your policy, privacy practices and technical controls line up with any commitments on security, service levels, confidentiality and data breach notification.
When you are selling online or storing more personal information
Online trading creates more data touchpoints, especially where a business uses website forms, e-commerce tools, subscriptions, customer accounts, analytics tools and marketing platforms. The more systems involved, the easier it is for information to be mishandled.
Businesses expanding online should think about information security alongside privacy disclosures, website terms, cookie policies and internal access rules. A privacy policy tells people how their information is collected and used. An information security policy tells your team how to protect it internally.
When your industry has heightened expectations
Some sectors face stronger customer and commercial expectations, even where the legal rules are not identical for every business. That includes:
- health and wellness businesses handling sensitive client details
- professional services firms storing financial, legal or strategic information
- software businesses with hosted platforms and customer data environments
- education and training providers holding student records
- financial service related businesses managing identity and transaction information
If you operate in one of these areas, your contracts, privacy notices and staff policies should be more deliberate. A one page generic cyber statement usually will not be enough.
When a security incident has already happened
Many businesses only draft a proper information security policy after a phishing attack, lost laptop, mistaken email disclosure or suspicious login. That can still be worthwhile, but it is a harder position because you are fixing processes under pressure.
Where a privacy breach may have occurred, separate legal obligations can arise around assessing the incident and considering whether notification is required. A business in that situation should move quickly, preserve evidence and get advice on both the security response and any privacy implications.
Practical Steps And Common Mistakes
A useful information security policy starts with how your business actually operates, not with a template. The goal is to create rules your team can follow consistently and that support your legal and contractual obligations.
Step 1: Map the information you hold
You cannot protect information properly if you do not know what you have. Start by identifying the main categories of information your business handles.
That usually includes:
- customer contact details and account information
- employee and contractor records
- supplier information and commercial contracts
- financial records and invoices
- confidential business plans, pricing and intellectual property
- login credentials, API keys and system configuration information
Also note where that information sits. Many SMEs use a mix of email, cloud drives, phones, laptops, accounting platforms, CRMs and third party apps. If your data map lives only in your head, access and risk controls will be patchy.
Step 2: Set access rules that fit real roles
Access should be based on role, not convenience. Staff should only be able to view or change the information they need for their work.
Your policy should cover:
- who approves new user access
- how admin access is limited
- how often permissions are reviewed
- what happens when someone changes role or leaves
- whether shared accounts are banned or tightly controlled
One of the most common mistakes is forgetting offboarding. Former staff keeping access to email, shared drives or cloud systems is a basic but serious gap.
Step 3: Make device and remote work rules explicit
Hybrid work is normal for many New Zealand businesses, but remote access creates extra exposure. Your policy should tell people what is allowed on company devices and what is required if personal devices are used.
Practical rules often include:
- screen locks and device passwords
- approved software and update requirements
- secure Wi-Fi expectations
- limits on downloading confidential files locally
- rules for using USB drives or external storage
- reporting lost or stolen devices immediately
If your team works from home, the policy does not need to be extreme. It just needs to be clear enough that people know the minimum standard.
Step 4: Align the policy with contracts and privacy documents
Your information security policy should not contradict what you say in other documents. This is where legal review often matters most.
Check for consistency across:
- privacy policies and collection notices
- employment agreements and workplace policies
- contractor agreements and confidentiality clauses
- customer contracts, especially security warranties and notification obligations
- software vendor terms and data processing commitments
For example, if your customer contract promises restricted access, encryption and rapid incident notification, your internal policy should support those promises. If it does not, the business may be exposed both operationally and contractually.
Step 5: Create an incident response process
People panic when a security issue hits and there is no clear owner or process. Your policy should say how incidents are reported, who investigates, who makes decisions, and how the business records what happened.
The process should usually address:
- immediate containment steps
- internal reporting lines
- preservation of logs and evidence
- assessment of affected systems and information
- privacy breach assessment where personal information is involved
- external communications and customer messaging approvals
This does not need to be long, but it needs to be usable. A two page response plan that your managers understand is often better than a dense manual nobody has read.
Step 6: Train people and enforce the policy
A policy that is never explained will not change behaviour. Staff should know the main rules, where to find the document, and what to do if something looks wrong.
Training can be simple and regular. For example:
- induction training for new starters
- annual refreshers for all staff
- extra guidance for managers and admin users
- phishing awareness reminders
- records of policy acknowledgement
Founders sometimes assume common sense is enough. It rarely is. Clear written expectations reduce mistakes and make enforcement fairer if someone ignores the rules.
Common mistakes to avoid
Several patterns come up repeatedly in small and growing businesses:
- using a policy copied from another business without tailoring it
- treating the policy as an IT document only, without involving operations, legal and management
- failing to define who owns the policy and keeps it updated
- ignoring third party app risks and shadow IT purchases
- forgetting paper files, printed reports and physical office security
- making security promises in tenders or contracts before checking internal capability
- not reviewing the policy after an incident, new product launch or major system change
If you are a startup, also think about growth. A policy written for a five person team may not suit you once you begin hiring quickly, expanding offshore or onboarding larger customers. Review points should be built in from the start.
FAQs
Does every New Zealand business need an information security policy?
Not every business is legally required to hold a formal document with that exact title, but most businesses that handle customer, staff or confidential business information should have one. In practice, it becomes increasingly necessary once you use cloud tools, hire staff, work remotely or contract with larger clients.
Is an information security policy the same as a privacy policy?
No. A privacy policy usually explains to customers or users how personal information is collected, used, stored and disclosed. An information security policy is mainly an internal document that sets rules for protecting information and systems inside the business.
Can I just use a free template?
You can use a template as a starting point, but it should be tailored carefully. A generic policy often misses the actual systems, access arrangements, contracts and data flows in your business, which means it may not help much when an incident or client review occurs.
Who should be responsible for the policy in a small business?
Someone in management should own it, even if external IT support helps with technical controls. The policy needs business oversight because it affects privacy, contracts, staff conduct and incident decisions, not just software settings.
How often should the policy be reviewed?
At least annually is a sensible baseline, and earlier if your systems, staffing, services or customer requirements change. Review it as well after any significant security incident, near miss or major procurement process.
Key Takeaways
- An information security policy sets practical rules for protecting business information, systems and devices.
- For New Zealand businesses, the policy often supports Privacy Act compliance, contractual commitments and day to day staff behaviour.
- The document should be tailored to your real operations, including access controls, remote work, vendor use, incident response and training.
- Common problem areas include copied templates, weak offboarding, inconsistent contract promises and lack of staff awareness.
- Review the policy before you sign major customer contracts, launch new systems, expand your team or increase online data collection.
- If your business is dealing with information security policy and wants help with privacy compliance, customer contract commitments, employment and contractor documentation, incident response planning, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.







