Skip to content

Jul 29, 2026

Policies and Procedures

I’ve been thinking a lot about security audits lately. Several of our clients have these annually, whether they’re self-prescribed or required by an insurance company or government entity. They vary in their questions, but one thing that always shows up is “Do you have a ______ policy?” I’ve always loathed this question because of the vagueness of it. Every company must have some policies to run. Early on at Nordic, the policy was if you’re not sure, ask Nate. We didn’t have to write it down, nor did we even really have to talk about it, it just was. And while that works great for a small team, eventually there are too many questions for Nate to answer. That’s where documented policies and procedures come in.

We recently had a security issue with a client. The individual got an email from one of their colleagues that appeared to be an invitation to an event.  A totally normal and expected thing for this person to get. So, they opened it up, downloaded a ScreenConnect executable, and then gave an attacker complete access to their machine. To their credit, they realized something was off, but instead of calling their IT vendor (us), they called their office manager. The office manager, a very security conscious person, quickly turned off the computer to ensure that the attacker couldn’t do anything else. But this was midday, there was still work to be done. The unfortunate user came back to their computer, turned it on, and completed their day, leaving it open for the attacker all night.

I’ve been working on a security policy for one of our government clients, and in it, we clearly define what should have been done. The phases are prepare, detect / report, triage, contain, eradicate, recover, and review. While we may have verbally told our client to call us, they were not adequately prepared for this scenario. This is where the policies and fire drills would have been most helpful. Sure, “call Nordic” should have been the first thing because we say it to our clients all the time, but it wasn’t documented or trained on. Also, how to “call Nordic” needs to be defined. It’s not a text message to your account manager. It’s this phone number, this option, and here’s what to say.

Once Nordic has been alerted, we need our own set of policies to run through. How do we internally deal with the detect / report, triage, contain, eradicate, recover, and review steps? How often are we drilling this internally so that when Nate isn’t here, we can still provide the needed services to the client? If our go to policy of “call Nate” doesn’t work, what do we do?

These are all questions that are answered with a good security policy. It’s why every audit asks, “Do you have a ______ policy?” And it’s why business owners should be thinking about this stuff more. I recently was talking with some business owners, and when considering phishing training and advanced security options, their only view was whether spending money on it would help with prevention. While prevention is a very important thing, having a policy in place just in case can be the difference between a mostly harmless accident and a major security breach.

-Nate

Read More

Related Posts