TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

When should my startup prioritize infosec?

16 点作者 vikrum超过 4 年前

6 条评论

crazygringo超过 4 年前
This blog post is just an ad for Gold Fig.<p>It doesn&#x27;t answer the question except in the last sentence &quot;Gold Fig can help with the basics, and beyond! Talk to us about getting an assessment of the next steps to take&quot;<p>Flagged
endymi0n超过 4 年前
What&#x27;s way more important than being smart about security is consistently not being dumb about it.<p>Knowing about the most important dangers (OWASP Top 10) and avoiding them while picking up some best practices on the go yields much better results than being completely oblivious on the topic and then try to &quot;pay back&quot; half a decade of neglected security that has not been baked into the architecture by then.<p>In the end though, later is usually preferable to earlier. I know less companies being killed by absolute lack of security (heck, even Equifax is still around) than companies having failed to achieve product-market fit because they focused too much on something else than their core mission.<p>Opportunity cost is real.<p>For a pragmatic guide on striking a good balance, I&#x27;ve found this one helpful: <a href="https:&#x2F;&#x2F;www.sqreen.com&#x2F;checklists&#x2F;saas-cto-security-checklist" rel="nofollow">https:&#x2F;&#x2F;www.sqreen.com&#x2F;checklists&#x2F;saas-cto-security-checklis...</a>
xtracto超过 4 年前
Ha! I&#x27;ve has the chance to be in charge of technology (including its security) in two different start ups.<p>The first one was B2C (60+ ppl post Series A). My CEO just did not care about security even though we (myself and our internal security expert) warned about it. No dev cycles had priority for security improvement. For me it was always an uphill battle to sell the need of security .<p>This all changed in the 2nd startup. This was a B2B. That was the blessing: as sales go upmarket, larger prospects questioned sales about our security, soc2, pci, gdpr, ccpa, etc .<p>As the tech head it is A PLEASURE that I dont have to fight for that. The Sales team fights for it because otherwise they lose deals.
评论 #26255473 未加载
评论 #26255356 未加载
Terretta超过 4 年前
Sec and Ops are twin NFRs for your technology. You cannot bolt on NFRs. You have to architect them in.
UI_at_80x24超过 4 年前
The same answer to, &quot;When is the best time to plant a tree.&quot;<p>Good security practices make for good programs. (See OpenBSD core).
mkoubaa超过 4 年前
As late as possible
评论 #26255441 未加载