Previously a Customer-Exclusive Webinar

Governance is the system of frameworks, policies, and plans that makes a cybersecurity program produce consistent, measurable results. Without it, businesses spend 6 to 12 months building security tools and activity, then wonder why nothing is working. In this 49-minute webinar, Reg Harnish breaks it down for smaller businesses.

This guide is drawn from OrbitalFire’s Customer Learning Series webinar “Policies, Plans, and Frameworks: Effective Governance for Smaller Businesses,” featuring OrbitalFire CEO Reg Harnish. Watch the Recording, or read the full guide below.

Governance is the part of cybersecurity that gets skipped most often. Not security tools, not incident response, not even training: governance. The policies, frameworks, and plans that make every other part of a security program function.

Here’s the thing: the organizations that get hit hardest in a cyber incident are usually the ones with no written policies, no documented plan, and no framework for making security decisions. Not because they were technically vulnerable in some exotic way. Because they were making it up as they went, and “making it up” doesn’t hold up under pressure.

Good governance isn’t complexity for its own sake. It’s the difference between responding to an incident and scrambling through one.

What Cybersecurity Governance Actually Means

Think of it like operating a vehicle. Drivers need credentials — a license, training, some time behind the wheel. They need to know which side of the road to drive on, and that depends on which country, which industry, they’re operating in. And they need to know what to do when something goes wrong, before something goes wrong.

That’s governance. Three components:

Frameworks are the road system and its rules — the organized structures that define what good security looks like. Some are voluntary; you adopt them because they’re useful. Others are regulatory mandates; they apply to your industry whether or not you’ve chosen them.

Policies are how you operate your specific vehicle within those rules. They’re created from frameworks and tailored by your organization. As long as they don’t conflict with the framework underneath them, the specifics are yours to define and enforce.

Plans are what you do when something goes wrong. Incident response, business continuity, crisis management. Not administrative overhead — these documents are security controls in their own right.

Those three things, exactly. Not ten. Three.

Frameworks: What’s Voluntary and What Isn’t

Not all frameworks are optional, and knowing the difference matters.

The NIST Cybersecurity Framework (NIST CSF) is voluntary. If you’re not in a regulated industry and no specific framework is required of you, NIST CSF is a reasonable organizing structure for thinking about your program. It covers six functions — Govern, Identify, Protect, Detect, Respond, Recover — and it’s more useful as a planning tool than a compliance checklist. Where are your gaps? Which functions are getting no attention? That’s what NIST CSF helps you see.

HIPAA’s Security Rule is not voluntary. If you’re a covered entity or business associate, the framework applies. You don’t get to choose a different one. CMMC works the same way for organizations in the defense supply chain. NYSDFS Part 500 for financial services companies licensed in New York. When a framework is mandated by regulation, you comply or you face consequences — not because you agreed to the terms, but because the regulation says so.

Think of mandated frameworks like speed limits: you don’t control them, but you’re expected to comply. Voluntary frameworks are more like choosing your route.

For most smaller businesses not in regulated industries, NIST CSF is the right starting point. For organizations with specific regulatory obligations, the applicable framework takes precedence, and it’s worth understanding in detail with your cybersecurity advisor.

Why Written Policies Matter (Even for 20 People)

The most common objection: “We’re small enough that everyone just knows how we do things.”

The problem with that: people leave and take institutional knowledge with them. “How we do things” drifts over time without a reference point. And when an incident happens — a phishing click, a data breach, an accidental file share — everyone suddenly needs to know the same thing simultaneously, under pressure, with no time to figure it out together.

Policies are created from frameworks and tailored by the organization. The framework sets the requirements; the policy is how your organization meets them and, where the framework allows flexibility, makes the specific choices that fit your environment. As long as the policy doesn’t conflict with the framework underneath it, you have latitude to make it work for your business.

Written policies also matter for compliance and insurance. Cyber insurers ask whether you have documented policies. HIPAA, CMMC, NYSDFS, and most other regulatory frameworks require them. Auditors and business partners increasingly ask to see them. “We have a culture of doing the right thing” isn’t an answer that satisfies any of these parties.

The good news: policies don’t need to be long. A clearly written acceptable use policy, an access control policy, a data classification policy, and an incident response plan cover the baseline for most smaller businesses. Done well, none of these documents exceeds a few pages.

The Policies Every Smaller Business Should Have

Acceptable Use Policy (AUP). Defines what employees can and can’t do with company systems, accounts, and data. Covers personal use of company devices, approved software, remote work expectations, and what to do if something seems suspicious. This is the document most employees are most likely to encounter.

Access Control Policy. Defines how access to systems is granted, reviewed, and revoked. Covers MFA requirements, password standards, administrator account management, and the process for deprovisioning when someone leaves. This document drives the day-to-day discipline that prevents most credential-based incidents.

Data Classification Policy. Defines what categories of data your organization handles, how each should be protected, and who can access it. For organizations that handle regulated data (health information, financial records, CUI), this document maps to the specific handling requirements of the applicable framework.

Incident Response Plan. The most important document most smaller businesses don’t have. Defines what counts as an incident, how it gets escalated, who does what, and how you communicate internally and externally during a security event. More on this below.

Vendor/Third-Party Policy. Defines how vendors are evaluated, what security expectations they’re held to, and how access is managed. Increasingly required by cyber insurance underwriters. For more on Third-Party Risk, READ: Third-Party Risk: Why This Could Be Your Biggest Cybersecurity Threat

Plans Are Security Controls, Not Documents

An incident response plan isn’t paperwork. It’s a security control — listed explicitly in NIST 800-171, HIPAA’s Security Rule, and NYSDFS Part 500. When frameworks require an effective incident response plan with roles and responsibilities, they’re not being thorough for its own sake. The document exists because the alternatives in a real incident are worse.

What a basic IR plan covers: how incidents are detected and reported, who has authority to make decisions (including who can authorize a shutdown, engage legal counsel, or communicate with regulators), the sequence of response steps, how to communicate with customers and partners, and how to document the incident for regulatory and insurance purposes.

The most valuable thing about an IR plan isn’t the document itself. It’s having thought through the scenarios before they happen. Organizations that have done tabletop exercises — where they walk through simulated incident scenarios — respond significantly better to real ones.

Tabletop exercises also surface a finding that surprises most organizations: people named in the incident response plan who don’t know the plan exists. They certainly don’t have a copy. They’ve never been trained on it. This is one of the most common things OrbitalFire sees when running tabletops for customers. The exercise is how you find that gap before it becomes a problem during an actual incident.

Cyber insurers are increasingly asking about IR plans and tabletop exercises during underwriting. It’s not just best practice anymore.

Making Governance Real Instead of Just Documented

The failure mode for governance isn’t usually inadequate documentation. It’s documentation that gets written once, reviewed never, and ignored in practice.

Assign ownership. Someone needs to be responsible for maintaining each policy and reviewing it annually. In a smaller organization, this often falls to a senior leader or an outside cybersecurity partner. Documents with no owner don’t get maintained.

Review annually at minimum. Regulations change. The threat landscape changes. Your business changes. Annual policy reviews catch the places where documents have drifted out of alignment with reality.

Connect policies to training. Employees who sign an AUP they’ve never read provide no real protection. Brief, regular reinforcement of key policies builds the habits that make them effective.

Manage exceptions deliberately. Every policy will encounter situations it didn’t anticipate. The answer isn’t to quietly work around the gap — it’s to document the exception, note why it exists, and decide whether it creates risk that needs mitigation through other means. Undocumented exceptions are where audits and incidents tend to find the most trouble.

Let’s have a conversation about where your governance program stands: Contact Us Today.

For more on Compliance, Read: Compliance Isn’t the Goal. Resilience Is.

Frequently Asked Questions About Cybersecurity Governance

What is cybersecurity governance?
Cybersecurity governance is the combination of frameworks, policies, and plans that determines how an organization approaches security. Frameworks organize the requirements you’re working from. Policies are the specific rules your organization creates and enforces. Plans document what happens when things go wrong. For smaller businesses, governance doesn’t require a dedicated department — it requires written documents, defined accountability, and consistent review.

What cybersecurity policies does a small business need?
At a minimum: an acceptable use policy (what employees can do with company systems and data), an access control policy (how access is granted, reviewed, and revoked), a data classification policy (what data you have and how it’s protected), and an incident response plan (what happens when a security event occurs). Organizations handling regulated data will need additional policies aligned with the applicable framework (HIPAA, CMMC, NYSDFS, etc.).

What is a cybersecurity framework and which one should I use?
A cybersecurity framework is an organized structure for managing security. Some are voluntary — the NIST Cybersecurity Framework (NIST CSF) organizes security into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Others are regulatory mandates with no opt-out: HIPAA’s Security Rule, CMMC (for defense contractors), NYSDFS Part 500 (for financial services companies licensed in New York). If you’re in a regulated industry, the applicable framework takes precedence. If not, NIST CSF is a useful starting point.

What should an incident response plan include?
An incident response plan should cover: how security incidents are detected and reported, who has authority to make key decisions (shutdowns, external communications, regulatory notifications), the sequence of response steps, how to communicate with customers and partners during an incident, and how to document the incident for insurance and regulatory purposes. Organizations that conduct tabletop exercises to walk through simulated scenarios typically respond significantly better to real incidents — and the exercises frequently reveal that people named in the plan don’t know they’re in it.

Do I need cybersecurity policies if I’m a small business?
Yes, and for several reasons. Written policies are required by most regulatory frameworks (HIPAA, CMMC, NYSDFS) and increasingly required by cyber insurers as a condition of coverage. They also provide operational value: clear policies reduce confusion when people leave, when incidents occur, or when employees need to make a decision about what’s permitted. The absence of written policies isn’t a sign of an informal culture; it’s a gap that shows up at the worst possible moment.

Watch the Recording