While I'm generally a fan of the Sqreen checklist that this is built on, looking over it with fresh eyes I have quite a few quibbles:<p>"Require 2FA wherever possible" - Given the target audience, it would be nice if this was explicit about the reason to use hardware keys (including those builtin to TouchID + chromebooks).<p>"Accustom your team to locking their computers" - This is good advice, but I'd recommend configuring locking on inactivity a higher leverage effort<p>"Hire your first security engineer" - "do we have a security roadmap? do we manage to deliver on it?" is not a good heuristic for whether you need a security hire. I'd argue that most startups will lack a formal security roadmap when they don't have dedicated security staff. For example, the linked First Round article [1] has a more actionable recommendation, with justification: "Onboard your first, full-time security hire between 30-100 employees."<p>"Set up a bug bounty program (NEXT)" and "Monitor your user’s suspicious activities (NEXT)" being placed before "Have a security incident response plan (LATER)"<p>[1] <a href="https://review.firstround.com/how-early-stage-startups-can-enlist-the-right-amount-of-security-as-they-grow" rel="nofollow">https://review.firstround.com/how-early-stage-startups-can-e...</a>