Retour au blog

A Practical Cybersecurity Checklist for Growing Companies

Kodenique Team4 min de lecture

Most breaches we hear about from smaller companies don't involve sophisticated attackers. They involve a reused password, a former employee's account that was never disabled, or a backup that turned out not to exist when ransomware hit. Security for a growing company is less about buying tools and more about closing the obvious doors — in the right order.

Here's the checklist we walk through with clients, split into three tiers. Do the first tier before you think about the second.

Tier 1: The baseline (do these this month)

These items cost little or nothing and eliminate the majority of realistic risk.

  1. Turn on multi-factor authentication everywhere. Email, cloud consoles, banking, code repositories. Phishing-resistant methods (authenticator apps or hardware keys) beat SMS, but any MFA beats none.
  2. Use a password manager, company-wide. Reused passwords are how one breached service becomes five.
  3. Patch on a schedule. Operating systems, browsers, frameworks, and dependencies. Enable automatic updates where you can; calendar the rest.
  4. Back up, and test the restore. A backup you've never restored from is a hope, not a backup. Keep at least one copy offsite or in a separate cloud account.
  5. Write an offboarding checklist. When someone leaves, their access to email, cloud services, repositories, and shared drives should be revoked the same day. This is the single most commonly missed item we find.
  6. Inventory what you have. You can't protect laptops, servers, domains, and SaaS accounts you don't know about. A spreadsheet is fine to start.
  7. Encrypt laptops. Full-disk encryption is built into every modern OS and turns a stolen laptop from a breach into an inconvenience.

Tier 2: Growth stage (as the team passes ~15–20 people)

  1. Move to single sign-on. Central identity means one place to enforce MFA and one switch to flip at offboarding.
  2. Apply least privilege. Most people don't need admin rights, and most services don't need access to everything. Review who can touch production quarterly.
  3. Separate production from everything else. Developers shouldn't test against live customer data, and staging shouldn't share credentials with production.
  4. Get secrets out of code. API keys and passwords belong in a secrets manager, not in repositories or chat threads.
  5. Turn on logging and alerts. You want to know about unusual logins and permission changes when they happen, not months later.
  6. Train the team on phishing. Short, regular, and blameless works better than an annual lecture. The goal is a culture where reporting a suspicious click is praised, not punished.
  7. Write an incident response one-pager. Who do you call, who talks to customers, where are the backups? Deciding this during an incident is the worst time.
  8. Vet your vendors. Every SaaS tool with access to your data is part of your attack surface. Keep a list, and ask the bigger ones for their security documentation.

Tier 3: Compliance-ready

At some point a large customer will send you a security questionnaire, and "we take security seriously" won't be an acceptable answer.

  1. Document your policies. Access control, data handling, acceptable use, incident response. Auditors and enterprise customers want to see written policies that match actual practice.
  2. Understand what SOC 2 actually requires. It's not a product you buy — it's an audit of whether your controls (most of tiers 1 and 2 above) exist and operate consistently over time. Companies that have done the fundamentals typically need a few months of evidence collection, not a rebuild.
  3. Understand what GDPR actually requires. If you handle EU personal data: know what you collect and why, have a lawful basis, honor deletion requests, and report qualifying breaches within 72 hours. Data minimization — collecting less in the first place — is the cheapest compliance strategy there is.
  4. Run vulnerability scans, then a penetration test. Automated scanning catches the known issues cheaply; a manual pen test once a year (or before a major launch) catches what scanners can't.
  5. Get an outside review. Internal teams stop seeing their own gaps. A structured external assessment — well before a formal audit — tells you where you'd fail and what to fix first.

When to bring in help

The honest answer: tier 1 needs no outside help at all — just a decision to do it. Tier 2 is where growing companies often benefit from a few days of expert setup (SSO, secrets management, logging) rather than months of trial and error. Tier 3 is where going alone gets expensive, because audit preparation rewards people who've done it before. Our cybersecurity services cover exactly this range, from baseline hardening to SOC 2 readiness.

One more thing worth flagging: if your team has started using AI tools — and it almost certainly has — that's a new category on this checklist. We've written separately about the AI security and privacy risks businesses actually need to manage.

Security isn't a project you finish; it's a set of habits you keep. But the gap between "we've done nothing" and "we've done tier 1" is enormous, and it's crossable in a month. If you'd like a structured review of where you stand — and a prioritized plan instead of a scare report — get in touch. A short assessment is usually enough to know exactly what to fix first.

Un projet en tête ?

Parlons de la façon dont nous pouvons vous aider à le concrétiser.

Contactez-nous