How to Write Your One-Page Governance Sheet This Afternoon

Practical Advice

How to Write Your One-Page Governance Sheet This Afternoon

Forty-five minutes. One sheet of paper. Here’s exactly how to build it, step by step, with a time estimate for each section so you know when you’re done.

Step 1: Name the Owner (5 minutes)

Write one name at the top of the page under the heading “Who owns security.” Not a team, not a job title, a specific human being. If that’s you, write your own name and say it out loud to at least one other person in the business today. If you’re handing it to someone else, confirm they’ve actually accepted it before you write it down. An owner who hasn’t agreed to the job isn’t an owner, they’re a surprise waiting to happen.

If this step takes longer than five minutes, stop and think about why. Uncertainty here usually means the business has never actually had this conversation, which is exactly the gap this exercise exists to close.

Step 2: Set Spending and Software Decisions (10 minutes)

Answer three questions in writing:

  • Who can approve spending on security tools or software, and up to what amount before it needs a wider conversation?
  • Who’s allowed to install software on work devices?
  • What happens when someone leaves the business? Who removes their access, and on what day?

Write the answers as plain sentences. “Dave approves spending up to £500 without discussion, anything above that gets a proper conversation” is a complete, usable answer. Don’t overthink the exact figure, pick something sensible for your business and move on.

Step 3: Write the Crisis Contact List (10 minutes)

List who gets called when something goes wrong: your IT support provider, with their actual phone number and your account reference, not just a company name you’ll have to search for under pressure. If you have cyber insurance, add the claims line number here too. This section only works if it saves someone from hunting for information during an actual incident, so be specific.

Step 4: Record Where Passwords Actually Live (10 minutes)

Don’t write passwords on the page itself. Write down the system: which password manager you use, and who has emergency access if the primary account holder is unreachable. If you don’t currently use a proper password manager, note that as an action item rather than leaving the section blank. A blank section here is more dangerous than an honest “not yet.”

Step 5: Set the Quarterly Review Reminder (5 minutes)

Open your calendar now, while you’re already thinking about this, and create a recurring event every three months labelled “GRC review.” Ten minutes is enough for most quarters. The point of this step is that a task with no date attached never actually happens.

Step 6: Print It and Store It Properly (5 minutes)

Print the page and put it somewhere more than one person in the business can access, a physical folder in a shared location, or a shared digital drive with appropriate permissions. A governance sheet that only exists in the owner’s head or personal inbox has solved nothing.

How to Turn This Into a Competitive Advantage

A completed governance sheet, even an imperfect first draft, gives you a specific, confident answer the moment a client or insurer asks who’s accountable for security in your business. Most competitors your size have nothing to show at all.

How to Sell This to Your Board

  1. The time cost is fixed and small. Forty-five minutes, once, plus ten minutes every quarter afterwards.
  2. It directly addresses the factor UK enforcement data shows regulators weigh most heavily: documented decision-making versus none at all.
  3. It removes the single-person dependency risk that turns an ordinary staff absence into an operational crisis.

What This Means for Your Business

  1. Block out 45 uninterrupted minutes this week, ideally away from the phone and email.
  2. Work through the six steps in order, without skipping ahead, since each one builds on the last.
  3. Print and store it before you consider the job done. A file saved only on one laptop doesn’t count.
  4. Put the quarterly reminder in the calendar before you close this page, since this is the step people most often forget.
SourceArticle
NCSCCyber Security Board Toolkit
NCSCSmall Business Guide: Cyber Security
legislation.gov.ukCompanies Act 2006, Section 174

Filed under

  • smb-security
  • uk-business
  • executive-security
  • business-risk
  • compliance-failure