Not a security programme. The handful of things that prevent the incidents that actually happen to small companies.
The basics that prevent most real incidents at small companies:
Unique passwords in a password manager, everywhere Two-factor authentication on email, cloud, code and banking Least privilege — people have access to what they need Offboarding that revokes access the same day Backups you have actually restored from Encryption in transit and at rest for customer data Knowing what personal data you hold and why
Because startups are targeted precisely because they are unlikely to have these in place, and because the most common incidents are unglamorous: a reused password, a departed employee with live access, a backup that never worked.
And because enterprise customers will ask. A security questionnaire is a normal part of B2B sales, and being unable to answer stalls deals for weeks.
The incidents that actually happen to small companies:
A founder reuses a password that appears in a public breach. An attacker gets into email, then uses password resets to reach everything else. Prevented by: a password manager and 2FA.
A contractor leaves and keeps access to the code repository for eight months because nobody had a checklist. Prevented by: an offboarding SOP.
A database is restored after a failure and turns out to be six weeks stale, because nobody ever tested a restore. Prevented by: restoring from backup once, deliberately.
An enterprise deal stalls for three weeks over a security questionnaire nobody can answer. Prevented by: writing the answers down before you need them.
None of these require a security team. All four are afternoons of work, and each prevents a category of incident that regularly kills or badly damages small companies.
First-time founders often defer all of this as something for larger companies. The basics take a day in total and prevent the great majority of realistic incidents.
The second mistake: backups that have never been restored. An untested backup is a belief, not a backup, and people find out at the worst possible moment.
The third: collecting personal data with no idea what you hold or why. Most jurisdictions require you to know, and it is far easier to establish early than to reconstruct later.
Unique passwords everywhere. This single step removes the most common attack path.
Email first — it is the reset path for everything else — then cloud, code and banking.
Every system to revoke, same day. Run it every time someone leaves, including contractors.
Until you have done it, you do not have backups. Diarise a repeat annually.
What, where, why, how long. Required in most jurisdictions and needed for any privacy policy that is accurate.
A one-page overview turns a three-week enterprise stall into a same-day reply.
Now. The basics take about a day and do not need to wait for scale.
Do not pursue formal certification early unless a specific deal requires it. It is expensive and slow, and the basics prevent far more real risk.
Apply this to your own startup in My Full Journey (free account).