TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

When should my startup prioritize infosec?

16 pointsby vikrumabout 4 years ago

6 comments

crazygringoabout 4 years ago
This blog post is just an ad for Gold Fig.<p>It doesn&#x27;t answer the question except in the last sentence &quot;Gold Fig can help with the basics, and beyond! Talk to us about getting an assessment of the next steps to take&quot;<p>Flagged
endymi0nabout 4 years ago
What&#x27;s way more important than being smart about security is consistently not being dumb about it.<p>Knowing about the most important dangers (OWASP Top 10) and avoiding them while picking up some best practices on the go yields much better results than being completely oblivious on the topic and then try to &quot;pay back&quot; half a decade of neglected security that has not been baked into the architecture by then.<p>In the end though, later is usually preferable to earlier. I know less companies being killed by absolute lack of security (heck, even Equifax is still around) than companies having failed to achieve product-market fit because they focused too much on something else than their core mission.<p>Opportunity cost is real.<p>For a pragmatic guide on striking a good balance, I&#x27;ve found this one helpful: <a href="https:&#x2F;&#x2F;www.sqreen.com&#x2F;checklists&#x2F;saas-cto-security-checklist" rel="nofollow">https:&#x2F;&#x2F;www.sqreen.com&#x2F;checklists&#x2F;saas-cto-security-checklis...</a>
xtractoabout 4 years ago
Ha! I&#x27;ve has the chance to be in charge of technology (including its security) in two different start ups.<p>The first one was B2C (60+ ppl post Series A). My CEO just did not care about security even though we (myself and our internal security expert) warned about it. No dev cycles had priority for security improvement. For me it was always an uphill battle to sell the need of security .<p>This all changed in the 2nd startup. This was a B2B. That was the blessing: as sales go upmarket, larger prospects questioned sales about our security, soc2, pci, gdpr, ccpa, etc .<p>As the tech head it is A PLEASURE that I dont have to fight for that. The Sales team fights for it because otherwise they lose deals.
评论 #26255473 未加载
评论 #26255356 未加载
Terrettaabout 4 years ago
Sec and Ops are twin NFRs for your technology. You cannot bolt on NFRs. You have to architect them in.
UI_at_80x24about 4 years ago
The same answer to, &quot;When is the best time to plant a tree.&quot;<p>Good security practices make for good programs. (See OpenBSD core).
mkoubaaabout 4 years ago
As late as possible
评论 #26255441 未加载