back

by _tk_·4y ago·view on hn ↗
Giving security advice in a format like this is always a bit weird. You will never catch all interesting bits much less all the edge cases. On top of that Thomas Ptacek is watching your every move.

As already noted, a tailored list for startups doesn't really exist. IMO, there are two approaches when it comes to establishing security in a Startup. You can either go the standard route or the checklist route.

1. Standard route: You hire a consultant, decide on a standard (preferably ISO27k) and go implementing. Costs a lot of money, takes a lot of time/energy, you will be happy about it in the future, if your company is not broke by then.

The German Federal Office for Information Security has adapted the ISO27001 standard in the past and created the so called Core Protection methodology. You can find the details here: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundsch...

It's a nice compromise between adherence to the standard and pragmatism.

As a Startup you basically want to protect two things: your IP and availability of your product. The core protection method allows you to specify a very narrow scope that you want to protect and helps you to develop protection requirements.

2. The checklist route: If standards are not your thing, I would advise you to take a look at CISA's "Cyber Essentials" checklist for Small and Midsize Businesses.

If you have 90% of these things implemented - which should be very easy for a startup - you will have a better security posture than 90% of all other companies out there (if not more).

https://www.cisa.gov/cyber-essentials

1 comments
> As a Startup you basically want to protect two things: your IP and availability of your product.

On what basis do you make this claim? I’m working in cyber and see the damage side in large companies. IP is never a thing. It’s mostly service / production availability and, with companies doing business in the US, data breaches (loss of PII).

Hello colleague,

I agree, IP is very hard to measure. Especially for large corporations it is impossible to monitor if competitors gained access to IP due to an incident. I don't think the measurement portion is too interesting though. If a startup develops one product, or one solution, then that's the one thing your business revolves around. If your competitors can copy your product easily, because your S3 buckets are wide open you may go bankrupt. Cybersecurity is a means to an end. Not all things may lead to you going out of business. Focus on those that could.

If I understand your last point correctly, we seem to agree on the Availability piece.

Also missing, from the top of my head: your customers' data, company reputation, trade secrets,...
Customer data is basically what I referred to as PII.

Reputation is really hard to measure and has not been observed in cyber to my knowledge. People say they care, but most don’t.

Trade secrets is IP what OP mentioned. It’s not a big thing in the incidents I have seen.