The security policies your organisation needs — written properly, downloaded today.
Editable policy and procedure packs for UK small businesses, charities and not-for-profits, written in plain English by a working UK security professional. Choose a pack, download it instantly, fill in the guided sections, and adopt it — no consultants, no subscriptions.
| Document | Status |
|---|---|
| Information Security Policy | ✓ Adopted |
| Password & Access Control Policy | ✓ Adopted |
| Acceptable Use Policy | ✓ Adopted |
| Incident Response Procedure | ✓ Adopted |
| Data Protection & UK GDPR Policy | ✓ Adopted |
| Backup & Recovery Procedure | ◌ In review |
- Written for UK GDPR & Cyber Essentials
- Instant download, fully editable
- One-off prices — yours to keep
- Personally written by Shofiqul "Si" Islam, UK security professional
Small businesses
Win contracts that ask for Cyber Essentials or "evidence of security policies" — without paying consultancy day rates.
Charities
Meet trustee, funder and Charity Commission expectations with policies sized for smaller, often volunteer-run organisations.
Not-for-profits
Protect member, donor and supporter data with practical policies written for how community organisations actually operate.
What the documents actually look like
Every template follows the same structure: a plain-English policy body, guided fill-in sections marked clearly, and sign-off boxes for whoever approves it — a director, trustee board or committee.
Three steps to adopted policies
Choose & download
Pay once by card through our secure checkout. Your pack arrives instantly as editable Word documents plus PDFs, with a receipt for your records.
Fill in the guided sections
Each template tells you exactly what to decide, what to fill in, and who should sign it off. No security knowledge required.
Adopt — or get it checked
Adopt the policies and record them in your document register. Want certainty? Book a Readiness Review and get a written findings report.
One-off prices. Yours to keep.
Every pack is a one-time purchase — editable templates you adapt, adopt and reuse. No subscriptions.
Core Pack
You need your first proper set of security policies — or to replace the ad-hoc ones you've outgrown.
- 9 essential policy & procedure templates
- Information security, passwords, acceptable use
- Incident response & backup procedures
- Document register & adoption guide
- Mapped to Cyber Essentials controls
Pro Pack
You hold donor, member or beneficiary data, have staff or volunteers to train, and answer to trustees or funders.
- Everything in the Core Pack
- Charity & not-for-profit policy set
- UK GDPR documents & privacy notices
- Staff & volunteer training materials
- Trustee briefing pack
Readiness Review
You've completed your pack and want a professional to check it before you rely on it — or before you go for Cyber Essentials.
- Personal review of your completed pack
- Written findings report with fixes
- Gap check against Cyber Essentials
- 30-minute follow-up call
- Stamped, dated document register
Not sure which pack? If you're a small business with no charity duties, the Core Pack covers you. If you're a charity or not-for-profit — or you hold donor or member data — go straight to the Pro Pack. The Readiness Review is for after you've completed either pack, when you want professional sign-off.
Written by a person, not a template mill
Safi InfoSec is run by Shofiqul "Si" Islam, a UK-based cybersecurity professional. Si works in information security by day and has spent years helping small organisations — including charities and community groups — get their security and data protection basics right without consultancy budgets.
Every template is written and maintained by Si personally, revised when Cyber Essentials or UK GDPR guidance changes, and every Readiness Review is done by him — not outsourced, not automated.
[CREDENTIALS LINE — e.g. certifications, years in industry] · LinkedIn profile
Start free. See the quality before you spend anything.
Enter your email and the Starter Pack arrives in minutes: a cyber hygiene checklist, a ready-to-adopt password policy, and a plain-English guide to Cyber Essentials.
One email with your downloads, occasional practical security tips after that. No sales calls. Unsubscribe any time.
Frequently asked questions
Are these templates specific to UK organisations?
Yes. Everything is written for UK law and UK schemes — UK GDPR, the Data Protection Act 2018, and the NCSC's Cyber Essentials scheme. Nothing is a rebadged US template.
What format do the documents come in?
Editable Microsoft Word (.docx) files that also open in Google Docs and LibreOffice, plus matching PDFs. You can add your logo, name and details throughout.
Will the Core Pack get us Cyber Essentials certified?
The packs get your documentation and processes ready; certification itself is assessed by a licensed certification body. The Core Pack maps each template to the Cyber Essentials controls so you can see exactly what's covered.
Do I need any technical knowledge to use the packs?
No. Each template comes with plain-English guidance on what to fill in, what to decide, and who should sign it off. If you can complete a form, you can adopt a policy.
What if the pack isn't right for us?
Tell us within 14 days of purchase and we'll refund you — no forms, no argument. We'd rather you trusted the next small organisation we serve.
Do the templates get updated?
Yes. Templates are revised when the Cyber Essentials scheme or UK GDPR guidance changes, and updates are free for 12 months from purchase.
Will I get a proper receipt or invoice?
Yes — a receipt is emailed automatically at purchase, suitable for your accounts and funder reporting.
What if we need more than templates?
For incidents, audits or larger engagements, Safi InfoSec offers direct help and can draw on a trusted professional network — see the Get help section below.
Need hands-on help?
Templates cover most of the journey. When something goes wrong — or the job is bigger than paperwork — you can get a person, not a portal.
Incident response
Suspected breach, ransomware, or a compromised account? Email with "INCIDENT" in the subject line and you'll get triage advice and a clear next-steps plan. Replies prioritised; typically within a few hours during UK working hours.
Report an incidentLarger engagements
Audits, supplier security questionnaires, or multi-site rollouts. Scoped and delivered directly, or through a trusted network of UK specialists. Replies within one working day.
Discuss a project