Cybersecurity for Startups and SMBs
Startup Cybersecurity Checklist: 25 Essential Actions
The top 10 startup cybersecurity actions: 1) Enable MFA on all accounts, 2) Deploy a password manager company-wide, 3) Configure cloud IAM with least privilege, 4) Remove secrets from code repositories, 5) Enable disk encryption on all devices, 6) Configure DMARC/DKIM/SPF, 7) Enable cloud audit logging, 8) Set up automated dependency scanning, 9) Implement automated backups, 10) Create an offboarding checklist for access revocation.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
How to Use This Checklist
This checklist is prioritized by impact — the actions at the top prevent the most common attacks. Each item includes effort level and cost to help founders make informed decisions about where to invest.
Work through the checklist from top to bottom. The first 10 items prevent the majority of startup breaches and can be completed in a single week.
Identity & Access (Items 1-7)
- 1. Enable MFA on all accounts. ⏱ 2 hours | 💰 Free Enforce multi-factor authentication on email, cloud consoles, code repositories, CI/CD, and all SaaS tools. This single action blocks over 99.9% of account compromise attacks, according to Microsoft.
- 2. Deploy a company-wide password manager. ⏱ 1 hour | 💰 Per-user subscription Roll out 1Password Business or Bitwarden to all employees. Require unique passwords for every service. Eliminate shared credentials.
- 3. Configure SSO. ⏱ 2-4 hours | 💰 Free (with Google Workspace/M365) Centralize authentication through your identity provider. Connect all SaaS tools via SSO. This enables instant access revocation when someone leaves.
- 4. Apply least-privilege IAM. ⏱ 4 hours | 💰 Free Review cloud IAM roles and permissions. Remove admin access from non-admins. Create separate roles for different functions. Disable root account usage.
- 5. Create an offboarding checklist. ⏱ 1 hour | 💰 Free Document every system and tool with the account types and access levels. When someone leaves, revoke all access within 24 hours.
- 6. Audit service accounts. ⏱ 2 hours | 💰 Free Identify all service accounts, API keys, and machine credentials. Ensure each has minimum necessary permissions and is documented.
- 7. Implement session management. ⏱ 1 hour | 💰 Free Configure session timeouts for sensitive applications. Require re-authentication for critical operations.
Cloud & Infrastructure (Items 8-13)
- 8. Remove secrets from code. ⏱ 4 hours | 💰 Free Scan repositories for committed secrets (truffleHog, git-secrets). Migrate to environment variables or a secrets manager. Rotate any exposed credentials.
- 9. Enable cloud audit logging. ⏱ 1 hour | 💰 Free (basic tier) Enable CloudTrail (AWS), Activity Log (Azure), or Audit Logs (GCP). These logs are essential for detecting and investigating security incidents.
- 10. Review cloud network security. ⏱ 2 hours | 💰 Free Audit security groups, NACLs, and firewall rules. Remove overly permissive rules (0.0.0.0/0). Restrict database access to application servers only.
- 11. Scan for cloud misconfigurations. ⏱ 2 hours | 💰 Free Run Prowler (AWS), ScoutSuite (multi-cloud), or cloud-native security tools to identify misconfigurations. Fix critical findings immediately.
- 12. Enable encryption in transit and at rest. ⏱ 2 hours | 💰 Free Enforce HTTPS everywhere. Enable encryption at rest for databases and storage. Use TLS for all internal communications.
- 13. Configure alerting for critical events. ⏱ 2 hours | 💰 Free Set up alerts for: root account usage, new IAM users, security group changes, and failed authentication spikes.
Endpoints & Devices (Items 14-17)
- 14. Enable disk encryption. ⏱ 30 min/device | 💰 Free FileVault (Mac), BitLocker (Windows). Encrypt every company device so lost or stolen hardware doesn't expose data.
- 15. Enable automatic updates. ⏱ 30 min | 💰 Free Configure automatic OS and application updates on all devices. Unpatched systems are a top attack vector.
- 16. Deploy endpoint protection. ⏱ 1 hour | 💰 Per-device subscription Install EDR on all company devices. Microsoft Defender for Business, CrowdStrike Falcon Go, or SentinelOne.
- 17. Enforce screen lock. ⏱ 15 min | 💰 Free Require password/biometric to unlock after 5 minutes of inactivity.
Code & Application (Items 18-21)
- 18. Enable dependency scanning. ⏱ 30 min | 💰 Free Activate GitHub Dependabot or Snyk free tier. Automatically detect and fix vulnerable dependencies.
- 19. Enable secret scanning. ⏱ 30 min | 💰 Free Activate GitHub secret scanning and push protection. Catches secrets before they enter the repository.
- 20. Require code review. ⏱ Configuration only | 💰 Free Configure branch protection rules requiring at least one code review before merge. Catches security issues and improves code quality.
- 21. Implement HTTPS everywhere. ⏱ 1 hour | 💰 Free Force HTTPS on all web properties. Use HSTS headers. Obtain certificates via Let's Encrypt (free).
Data & Email (Items 22-24)
- 22. Configure DMARC/DKIM/SPF. ⏱ 1 hour | 💰 Free DNS configurations that prevent attackers from sending phishing emails that appear to come from your domain.
- 23. Implement automated backups. ⏱ 2 hours | 💰 Usage-based Automate database and critical data backups. Test restoration quarterly. Store backups in a separate location/account.
- 24. Classify sensitive data. ⏱ 2 hours | 💰 Free Identify where customer data, financial records, and credentials are stored. Apply appropriate access controls to sensitive data stores.
Governance (Item 25)
- 25. Document basic security policies. ⏱ 4 hours | 💰 Free Write simple, actionable policies for: acceptable use, password management, incident reporting, and data handling. Keep them short enough that everyone actually reads them.
Tracking Progress
Print this checklist and track completion. Most startups can complete all 25 items within 2-3 weeks using existing engineering resources. The first 10 items should take less than a week and prevent the majority of common attacks.
How SeqOps fits
SeqOps gives small teams one view of the security of their AWS, Azure or Google Cloud accounts and servers, with findings ranked by severity and a plan sized to their infrastructure. Start with a 14-day free trial.