All articles
Consultancy March 2026 8 min read

Building a Security Programme When You're the Whole Security Team

One person cannot do everything - but they can do the right things in the right order. A pragmatic priority list for the solo security lead at a growing company, built around impact per hour rather than an idealised framework.

JR Jacob RiggsChief Executive Officer, Cyse
Key takeaways
  • As a team of one, your scarcest resource is attention - spend it on controls that reduce the most risk per hour.
  • Identity and multi-factor authentication come first; they stop the largest share of real-world attacks for the least effort.
  • You cannot protect what you cannot see - a rough asset and data inventory beats a perfect control on an unknown system.
  • Automate the boring, repeatable controls so your limited time goes to judgement, not toil.
  • Your job is not to do all the security work - it is to make security everyone's job and to buy down the biggest risks first.

You are the first and only security hire at a company that has grown faster than its defences. The framework documents list hundreds of controls. The vendors want to sell you a dozen platforms. Everyone has an urgent request. And there is exactly one of you.

The instinct is to try to do a little of everything, which reliably produces a lot of activity and not much security. The better approach is ruthless prioritisation: spend your scarce attention on the controls that remove the most risk per hour. Here is the order we recommend, and why.

The one principle underneath all of this

You are not there to personally perform every security task. You are there to reduce the biggest risks first and to make security part of how everyone else works. Judge every hour by that standard.

First: lock down identity

If you do one thing, do this. The overwhelming majority of real-world intrusions begin with a stolen or guessed credential. Strong identity controls stop more attacks per unit of effort than anything else you can do.

  • Enforce multi-factor authentication everywhere, starting with email, your identity provider, and anything internet-facing. Prefer phishing-resistant methods - passkeys or hardware keys - for administrators.
  • Centralise logins through a single identity provider so you have one place to enforce policy and one place to cut off a departing or compromised account.
  • Kill shared accounts and remove admin rights from anyone who does not actively need them.

This is unglamorous and enormously effective. Done well, it makes a leaked password a non-event.

Second: know what you have

You cannot protect what you do not know exists, and growing companies always have more than anyone thinks - forgotten servers, personal cloud accounts, a database someone spun up for a project two years ago. A rough, current inventory beats a perfect control applied to the wrong things.

  • List your internet-facing assets - an external scan will find things you forgot.
  • Identify where your most sensitive data lives. You will protect it far better if you know which three systems actually matter.
  • Keep it lightweight. A living spreadsheet that is 80% right and updated is worth more than a perfect inventory that is a year old.
The most dangerous system in any company is the one nobody remembers owning.

Third: get the security basics running

With identity locked and assets known, cover the fundamentals that block the common attacks:

  • Patching. Make sure operating systems and internet-facing software update promptly. Unpatched, exposed systems are how a lot of breaches start.
  • Backups you have tested. Verified, offline backups are your single best defence against ransomware. An untested backup is a hope, not a control.
  • Endpoint protection on laptops and servers, with the alerts actually going somewhere you will see them.
  • Email security, since that is where most attacks arrive.

Fourth: automate the repeatable, escalate the human

Your time is the bottleneck, so refuse to spend it on anything a machine can do. Automate the routine, recurring controls and reserve your judgement for the things that genuinely need a human.

  • Automate vulnerability scanning, log collection, and alerting so they run without you.
  • Use your provider's native security tooling before buying anything new - you are likely paying for capabilities you have not switched on.
  • Spend your saved time on the human work: reviewing access, thinking about risk, and talking to the teams who are actually building things.
A trap for the solo lead

Buying tools to feel productive. Every platform you add is another thing to configure, monitor, and maintain - with one person, that maintenance debt comes straight out of your limited hours. Add tools only when they clearly remove more work than they create.

Fifth: make security everyone's job

A team of one does not scale by working harder; it scales by making the rest of the organisation part of the solution. This is the highest-leverage thing you will do, and it is mostly relationships, not technology.

  • Give engineers secure defaults and paved paths, so the easy way to build is also the safe way.
  • Run short, practical awareness sessions that respect people's time and focus on the threats they will actually meet.
  • Build a relationship with leadership so security has a voice in decisions before they are made, not after.
  • Know your limits: for deep, specialist work - a serious penetration test, incident response, a compliance programme - bringing in outside help is a force multiplier, not an admission of failure.
The bottom line

Do not try to build the whole framework at once. Lock down identity, learn what you have, cover the basics, automate the routine, and turn the wider organisation into your extended team. In that order, one person can meaningfully secure a growing company.

If you are that one person and want a second, experienced pair of hands - to set the priorities, do the specialist work, or just sanity-check the plan - that is exactly what our consultancy practice is for.

Need help putting this into practice?

Our practitioners deal with exactly these problems every week. A short conversation costs nothing and usually saves a lot.