Advisory & Innovation
No IT Policy for Employees? Fix It in 7 Steps
Affix Center · · 7 min read

An employee installs a free PDF tool that carries malware. Another forwards client files to a personal Gmail account "to work from home". A manager leaves and nobody knows which cloud accounts he still has access to. When something goes wrong, the first question is always the same: "Was this allowed?" In many Indian companies, nobody can answer, because there is no written IT policy for employees.
Without a policy, every IT decision becomes a personal judgement call. Staff do what is convenient, the IT team has no rule to point to, and management finds out about problems only after the damage is done. It also makes audits, client security questionnaires and data protection compliance much harder than they need to be.
The good news is that an IT policy does not have to be a 60-page legal document. Below we explain what goes wrong without one, what a practical policy should cover, and a seven-step plan to write and roll it out.
What Goes Wrong When There Is No IT Policy
Most companies do not decide against having an IT policy. It simply never gets written, because the business grew faster than its processes. The gaps show up in familiar ways.
1. Every device and app becomes a risk
If there is no rule on what software can be installed, staff will install whatever helps them finish work faster: free converters, browser extensions, remote access tools, personal cloud drives. Some of these are harmless. Some quietly collect data or open a door for attackers. The fix is a short list of approved software and a simple way to request new tools.
2. Company data leaves through personal accounts
Forwarding files to personal email or WhatsApp feels normal to many employees. Once data sits in a personal account, the company cannot protect it, recover it or delete it when the employee leaves. A clear rule on where company data may be stored and shared solves most of this.
3. Passwords and access are handled informally
Shared passwords on sticky notes, one admin login used by five people, and accounts that stay active months after someone resigns are common findings in any IT review. A policy sets the minimum standard: individual accounts, strong passwords, multi-factor authentication for email and remote access, and removal of access on the last working day.
4. Incidents are reported late, or not at all
When staff do not know what counts as a security incident or whom to tell, a suspicious email or a lost laptop can go unreported for days. For organisations covered by CERT-In's 2022 directions, certain cyber incidents must be reported within six hours of noticing them, which is impossible if the news never reaches IT.
5. Compliance becomes guesswork
The Digital Personal Data Protection Act, 2023 and the DPDP Rules notified in November 2025 expect organisations to protect personal data with reasonable security safeguards. Clients, banks and government departments increasingly send security questionnaires before they sign a contract. Without a written policy, you have nothing to show them and no standard to train staff on.
What a Practical IT Policy Should Cover
A good IT policy for employees is short enough to be read and specific enough to be followed. For most Indian SMEs and mid-size companies, these sections are enough to start:
- Acceptable use: what company laptops, email and internet may and may not be used for.
- Accounts and passwords: individual logins, password rules, multi-factor authentication and no sharing of credentials.
- Software and devices: approved software, who can install it, and rules for personal phones or laptops used for work.
- Data handling: where company and client data may be stored, how it may be shared, and what is not allowed, such as personal email or unapproved cloud drives.
- Email and messaging: how to spot phishing, and which channels are approved for business communication.
- Remote work: VPN use, home Wi-Fi, screen locking and working from public places.
- Incident reporting: what to report, whom to report it to and how quickly.
- Joining and leaving: how access is given on day one and removed on the last day.
- Consequences: what happens if the policy is broken, aligned with your HR rules.
Larger organisations, or those working towards ISO 27001, will add more detailed policies later, such as backup, access control and vendor management. But the employee-facing policy above is the foundation.
The Fix: Write and Roll Out Your IT Policy in 7 Steps
Here is a practical sequence that works for companies of 20 to 2,000 people.
- Take stock of what you have. List your devices, key software, cloud services, email system and who has admin access. You cannot write rules for systems you have not mapped.
- Talk to the people who will follow it. Spend an hour each with HR, finance, sales and operations. Ask how they share files, which tools they rely on and where rules would slow them down. A policy that blocks real work will be ignored.
- Write in plain language. Use short sentences and "you must" or "you must not". Avoid legal wording. Aim for 6 to 10 pages that an employee can read in 20 minutes.
- Back each rule with a tool or process. If the policy says "use multi-factor authentication", switch it on. If it says "only approved software", make sure users do not have admin rights on their laptops. Rules without enforcement become suggestions.
- Get management sign-off. The policy should be approved by a director or the CEO so it carries weight, and HR should link it to the code of conduct.
- Train, then collect acknowledgement. Run a short session, share the document, and have every employee confirm they have read it. Add it to the joining kit for new hires.
- Review it every year. New tools, new laws and new risks appear every year. Put an annual review date on the document and update it after any major incident.
Common Mistakes to Avoid
- Copying a template word for word. Templates are a useful start, but a policy that mentions systems you do not use tells employees it was not written for them.
- Making it too strict. Banning all personal phones or all USB drives may look secure on paper, but if work cannot happen, staff will find workarounds. Aim for rules people can actually follow.
- Treating it as an IT-only document. HR, legal and business heads need to own parts of it, especially data handling and consequences.
- Writing it once and forgetting it. A policy that still talks about software you retired three years ago loses credibility quickly.
How the Policy Supports Security and Compliance
A written IT policy is not a security tool by itself, but it makes every other control work better. Your firewall, endpoint protection and backups protect systems. The policy protects against the human side: weak passwords, careless sharing and late reporting. It also gives you a clear document to share when a client or auditor asks how you protect data, and it is one of the first documents an ISO 27001 auditor will ask for. If you are preparing for data protection obligations, it fits naturally with the steps in our DPDP Act compliance checklist.
Frequently Asked Questions
Is an IT policy mandatory for companies in India?
There is no single law that requires every private company to publish an IT policy. However, laws such as the DPDP Act expect reasonable security safeguards for personal data, and regulators, clients and certifications like ISO 27001 often expect documented policies. A written policy is the simplest way to show you take this seriously.
How long should an IT policy for employees be?
For most SMEs, 6 to 10 pages is enough. Detailed technical standards can sit in separate documents for the IT team, while the employee version stays short and readable.
Who should own the IT policy?
IT or the person responsible for technology usually drafts and maintains it, but management should approve it and HR should include it in onboarding and disciplinary processes.
Should the policy cover personal devices used for work?
Yes. If staff check email or use company apps on their own phones, the policy should state the minimum rules, such as a screen lock, updated software and permission to remove company data if the device is lost.
How Affix Center Helps
Affix Center helps Indian enterprises, SMEs and public sector organisations put practical IT governance in place. Our enterprise advisory team can review your current setup and draft an IT policy that fits how your teams really work. Our cybersecurity team then helps enforce it with the right controls, and our IT operations team can manage day-to-day compliance through onboarding, offboarding and monitoring.
Do not wait for an incident to find the gaps. Contact Affix Center to create a clear, workable IT policy for your employees.