A startup security baseline for the first 90 days
KINNEX Team5 min read
Attackers do not care how small you are. They care what you hold: source code, customer data, cloud credentials and bank access. A baseline can be built quickly.
Identity
- Single sign-on for company apps.
- Multi-factor authentication for everyone, with phishing-resistant options for admins.
- A password manager for the team.
- Remove accounts of leavers on the day they leave.
Devices
- Managed laptops with disk encryption and automatic updates.
- Endpoint protection on every device.
- Separate admin and daily accounts.
Data and cloud
- Backups for cloud and SaaS data, with a test restore.
- Least-privilege access to code repositories and cloud consoles.
- Secrets in a vault, never in code or chat.
Email and web
- Email protection with SPF, DKIM and DMARC.
Response
- A one-page incident plan with names and phone numbers.
For investors and customers
Enterprise customers and investors ask security questions early. Keeping policies, evidence and a simple security overview ready shortens sales cycles.
Grow it
As the team grows, add logging and monitoring, vulnerability scanning, penetration testing and formal reviews. Each layer builds on this baseline.