Security and data basics

Not a security programme. The handful of things that prevent the incidents that actually happen to small companies.

What is it?

The basics that prevent most real incidents at small companies:

Unique passwords in a password manager, everywhere Two-factor authentication on email, cloud, code and banking Least privilege — people have access to what they need Offboarding that revokes access the same day Backups you have actually restored from Encryption in transit and at rest for customer data Knowing what personal data you hold and why

Why does a founder care?

Because startups are targeted precisely because they are unlikely to have these in place, and because the most common incidents are unglamorous: a reused password, a departed employee with live access, a backup that never worked.

And because enterprise customers will ask. A security questionnaire is a normal part of B2B sales, and being unable to answer stalls deals for weeks.

Example

The incidents that actually happen to small companies:

A founder reuses a password that appears in a public breach. An attacker gets into email, then uses password resets to reach everything else. Prevented by: a password manager and 2FA.

A contractor leaves and keeps access to the code repository for eight months because nobody had a checklist. Prevented by: an offboarding SOP.

A database is restored after a failure and turns out to be six weeks stale, because nobody ever tested a restore. Prevented by: restoring from backup once, deliberately.

An enterprise deal stalls for three weeks over a security questionnaire nobody can answer. Prevented by: writing the answers down before you need them.

None of these require a security team. All four are afternoons of work, and each prevents a category of incident that regularly kills or badly damages small companies.

The common mistake

First-time founders often defer all of this as something for larger companies. The basics take a day in total and prevent the great majority of realistic incidents.

The second mistake: backups that have never been restored. An untested backup is a belief, not a backup, and people find out at the worst possible moment.

The third: collecting personal data with no idea what you hold or why. Most jurisdictions require you to know, and it is far easier to establish early than to reconstruct later.

How it works

Step 1: Put everyone on a password manager

Unique passwords everywhere. This single step removes the most common attack path.

Step 2: Turn on 2FA everywhere that matters

Email first — it is the reset path for everything else — then cloud, code and banking.

Step 3: Write an offboarding checklist

Every system to revoke, same day. Run it every time someone leaves, including contractors.

Step 4: Restore from a backup once, deliberately

Until you have done it, you do not have backups. Diarise a repeat annually.

Step 5: Write down what personal data you hold

What, where, why, how long. Required in most jurisdictions and needed for any privacy policy that is accurate.

Step 6: Prepare security answers before you need them

A one-page overview turns a three-week enterprise stall into a same-day reply.

When to use this

Now. The basics take about a day and do not need to wait for scale.

When not to use it

Do not pursue formal certification early unless a specific deal requires it. It is expensive and slow, and the basics prevent far more real risk.

Do this now

Apply this to your own startup in My Full Journey (free account).