Having worked on SaaS products with high demands to security before, and having spent a serious chunk of people's hours on building security infrastructure around it, I'd say the biggest challenges were:<p>* Identifying threat model (assets we are protecting, what we are protecting them against), that connects to practical business values and risks, not abstract "security ideals". In our case it was understanding what kind of data we're afraid to lose / get tampered with to what extent - for some things we might've lost a license, for other things our CEO might've had a criminal case, so different measures applied.<p>* Orchestrating practical security with compliance (was relevant for that product, banking -> ISO, PCIDSS and local personal data protection regulation).<p>* Making hard decisions on whether doing it internally (we've had these competences) or outsourcing some of the implementation work to specialized outfit. Did it internally, was great experience, but would think twice to repeat.<p>* Making stakeholders understand how much the showstoppers, which emerge along the way, are important to be taken care of.