Policy Pack Pro — add-on to your AUD 149 report

Cybersecurity & Privacy Policy Templates for Australian SMBs

20 editable cybersecurity and privacy policies, each mapped to the specific gaps found in your PostureCheck report. Ready to customise, sign and file — no policy writing required.

Price AUD 399 (add-on)
Policies included 20 editable documents
Requires PostureCheck report (AUD 149)
Format Word + PDF, mapped to your gaps

A cybersecurity consultant charges AUD 300–500/hr to write policies from scratch. At 2–3 hours per policy, 20 policies could cost AUD 12,000+. Policy Pack Pro delivers the same output pre-mapped to your specific gaps for AUD 399 — because the work is already done in your report.

How it works

Three steps from report to signed policies

1

Complete your assessment

Answer 33 guided questions about your current controls. Takes 12 minutes. No IT team needed.

2

Receive your report

Your AUD 149 executive report identifies gaps by severity and maps them to Essential Eight controls and Privacy Act obligations.

3

Unlock Policy Pack Pro

Add the pack after your report. Each policy arrives pre-mapped to your gaps — customise names, dates and ownership fields, then file.

What’s included

20 policies across every Essential Eight and Privacy Act domain

01 — Access Control

Access Control Policy

Governs who can access what systems, under what conditions, and how access is reviewed and revoked.

Critical Essential Eight — Admin privileges
02 — Access Control

Multi-Factor Authentication Policy

Defines MFA requirements across remote access, email, cloud services and privileged accounts.

Critical Essential Eight — MFA
03 — Endpoint Security

Application Control Policy

Specifies which applications may execute on workstations and servers, and the process for approvals.

Critical Essential Eight — App control
04 — Patch Management

Patch & Vulnerability Management Policy

Sets timelines for patching critical, high and medium vulnerabilities across operating systems and applications.

High Essential Eight — Patching
05 — Endpoint Security

Acceptable Use Policy

Defines permitted use of company devices, networks and data including personal use, social media and removable media.

Baseline Essential Eight — User behaviour
06 — Endpoint Security

BYOD (Bring Your Own Device) Policy

Covers conditions under which personal devices may access company systems, and the security controls required.

High Essential Eight — Device control
07 — Backup & Recovery

Backup & Recovery Policy

Defines backup frequency, retention, storage requirements, restoration testing and RTO/RPO targets.

Critical Essential Eight #8 — Backups
08 — Backup & Recovery

Business Continuity & Disaster Recovery Policy

Documents roles, communication protocols and recovery steps for system outages, ransomware and data loss events.

High Essential Eight #8 — Recovery
09 — Incident Response

Incident Response Policy

Establishes roles, escalation paths and response steps for security incidents from detection through to post-incident review.

Critical NDB Scheme — APP 11
10 — Incident Response

Data Breach Response Policy

Covers NDB Scheme notification obligations, OAIC reporting timelines and affected-individual communication requirements.

Critical NDB Scheme — Notification
11 — Privacy

Privacy Policy (Internal Governance)

Internal governance document covering data collection, use, disclosure, retention and destruction aligned to the APPs.

Compliance Privacy Act — APPs 1–5
12 — Privacy

Data Retention & Destruction Policy

Sets retention schedules by data type and governs secure destruction of physical and digital records.

High Privacy Act — APP 11
13 — Privacy

Vendor & Third-Party Data Processing Policy

Governs how vendors may access, process or store company data, including overseas disclosure controls and DPA requirements.

High Privacy Act — APP 8
14 — Privacy

Individual Rights & Subject Access Policy

Defines the process for handling access, correction and deletion requests from individuals within the 30-day APP requirement.

Compliance Privacy Act — APPs 12–13
15 — People & Awareness

Security Awareness & Training Policy

Defines minimum training requirements, frequency and content for all staff including privileged users and contractors.

Baseline Essential Eight — User education
16 — People & Awareness

Password & Credential Management Policy

Sets minimum password requirements, credential rotation schedules, shared account controls and password manager usage.

High Essential Eight — Credentials
17 — Network & Cloud

Network Security Policy

Covers firewall requirements, network segmentation, remote access controls and wireless security standards.

Baseline Essential Eight — Network hardening
18 — Network & Cloud

Cloud & SaaS Security Policy

Governs approved cloud services, shadow IT controls, data residency requirements and shared responsibility expectations.

Baseline Essential Eight — Cloud
19 — Governance

Information Security Policy (Master)

Top-level governance document that establishes the security framework, ownership, scope and compliance obligations across all other policies.

Governance All frameworks
20 — Governance

Risk Register & Acceptance Policy

Defines how risks are logged, rated, owned and accepted or escalated — with a template register pre-populated from your report findings.

Governance Board & leadership
Why it matters

Without policies vs. with Policy Pack Pro

Without policies

Gaps stay open — even after the report

  • Staff operate without documented rules — liability risk
  • Auditors, clients and insurers find no evidence of governance
  • Incident response is improvised, not structured
  • Privacy Act and NDB obligations remain undocumented
  • Policy writing from scratch takes weeks and costs AUD 5,000–15,000
With Policy Pack Pro

Governance layer in place the same day

  • 20 policies pre-mapped to your specific report gaps
  • Ready to customise and sign — no legal or consulting input needed to start
  • Evidence of governance for insurers, clients and board
  • Privacy Act and NDB obligations addressed in writing
  • AUD 399 vs. thousands in consulting fees
Policy Pack Pro — Add-on
AUD 399
Available immediately after your AUD 149 PostureCheck report — no new assessment required
20 editable policy documents
Mapped to your report gaps
Word + PDF format
Essential Eight aligned
Privacy Act APP aligned
NDB Scheme coverage
Immediate delivery
No subscription required
Get Policy Pack Pro — AUD 399
No report yet? Complete the free assessment first → unlock report for AUD 149 → add Policy Pack Pro for AUD 399