The Founder’s Security Playbook
This playbook is a map of the cybersecurity topics every early company eventually hits—written for people who create businesses, not firewalls. Use it as a checklist when you launch, hire, pick tools, or recover from a scare.
1. Identity: passwords, MFA, and access
Most breaches start with a compromised login—not a Hollywood hack. Use a password manager, unique passwords everywhere, and multi-factor authentication (MFA) on email, banking, cloud, and code hosts. Review who has admin rights monthly.
2. Email and phishing
Your inbox is the front door. Train yourself to pause before clicking, verify unusual payment requests out-of-band, and treat attachments from unknown senders as hostile until proven otherwise.
3. Devices
Encrypt disks, enable automatic updates, use a screen lock, and separate personal chaos from work accounts when you can. A lost laptop without encryption is a data breach waiting to be discovered.
4. Cloud, SaaS, and collaboration
Google Workspace, Microsoft 365, Slack, Notion, GitHub, Stripe—each is a vault of company data. Turn on org-level MFA enforcement, limit public sharing, and disable dormant accounts.
5. Data and backups
Know where customer data lives. Keep automated backups you have tested at least once. If ransomware or accidental deletion hits, recovery time is your real metric—not how many security logos you own.
6. People: onboarding and offboarding
Access should follow the role, not friendships. When someone leaves—or a contractor finishes—revoke access the same day: email, cloud, code, payment tools, and shared passwords.
7. Vendors and freelancers
Every integration expands your attack surface. Ask where data is stored, who can access it, and how you’ll revoke it. Prefer least privilege over “full admin because it’s easier.”
8. Website and customer-facing apps
Keep CMS and plugins updated, use HTTPS everywhere, lock down admin panels, and don’t reuse production credentials in staging.
9. Privacy and customer trust
Collect only what you need, know why you store it, and be ready to answer “where is my data?” Basic privacy hygiene is part of security—and part of sales.
10. Incidents: when something goes wrong
Write a one-page plan before you need it: who to call, which accounts to freeze, how to communicate with customers, and how to preserve evidence. Calm checklists beat heroic improvisation.
How to use this site
Each section above maps to deeper guides on our blog. Start with identity and email, then devices and backups. Add process (people, vendors, incidents) as soon as you hire or outsource.
Questions about your setup? Tell us where you are in the journey—we’ll point you to the right next step.