NetOpsKit

IT Security Policy Generator

Generate Acceptable Use, Password & Authentication, Incident Response, Backup & Recovery and Remote Access policies from your answers.


How to use this tool

Choose a policy, fill in your company details and key parameters (password length, MFA scope, backup frequency, recovery objectives, incident contacts), and copy the generated Markdown text into your document system. Policies are built from templates in your browser. They are a starting point: adapt them to your environment, get management approval, publish them to staff and review them at least yearly.

Worked example

An Incident Response policy for "Acme Ltd" with a 24/7 contact and GDPR and NIS2 ticked includes the 72-hour authority notification and the 24-hour NIS2 early warning steps, plus roles and escalation.

Frequently asked questions

Are these policies legally sufficient?

No. They are practical templates. A policy only counts if it matches what you really do, is approved by management and is communicated to staff.

Which policies does NIS2 expect?

Article 21(2) requires, among others, policies on risk analysis and information system security, incident handling, business continuity and backup, access control, cryptography and authentication. These templates cover the common core.

What password rules do the templates use?

They favour length, a block-list of known-breached passwords and MFA over forced complexity and routine expiry, in line with NIST SP 800-63B guidance.

How often should policies be reviewed?

At least annually and after significant changes or incidents is common practice.

Stuck on something this page doesn't cover?

Tell us the problem in your own words. We use these reports (anonymously) to decide which guides to write. No account, name or email needed. Do not include passwords or customer data.