You are the first and only security hire at a company that has grown faster than its defences. The framework documents list hundreds of controls. The vendors want to sell you a dozen platforms. Everyone has an urgent request. And there is exactly one of you.
The instinct is to try to do a little of everything, which reliably produces a lot of activity and not much security. The better approach is ruthless prioritisation: spend your scarce attention on the controls that remove the most risk per hour. Here is the order we recommend, and why.
You are not there to personally perform every security task. You are there to reduce the biggest risks first and to make security part of how everyone else works. Judge every hour by that standard.
First: lock down identity
If you do one thing, do this. The overwhelming majority of real-world intrusions begin with a stolen or guessed credential. Strong identity controls stop more attacks per unit of effort than anything else you can do.
- Enforce multi-factor authentication everywhere, starting with email, your identity provider, and anything internet-facing. Prefer phishing-resistant methods - passkeys or hardware keys - for administrators.
- Centralise logins through a single identity provider so you have one place to enforce policy and one place to cut off a departing or compromised account.
- Kill shared accounts and remove admin rights from anyone who does not actively need them.
This is unglamorous and enormously effective. Done well, it makes a leaked password a non-event.
Second: know what you have
You cannot protect what you do not know exists, and growing companies always have more than anyone thinks - forgotten servers, personal cloud accounts, a database someone spun up for a project two years ago. A rough, current inventory beats a perfect control applied to the wrong things.
- List your internet-facing assets - an external scan will find things you forgot.
- Identify where your most sensitive data lives. You will protect it far better if you know which three systems actually matter.
- Keep it lightweight. A living spreadsheet that is 80% right and updated is worth more than a perfect inventory that is a year old.
The most dangerous system in any company is the one nobody remembers owning.
Third: get the security basics running
With identity locked and assets known, cover the fundamentals that block the common attacks:
- Patching. Make sure operating systems and internet-facing software update promptly. Unpatched, exposed systems are how a lot of breaches start.
- Backups you have tested. Verified, offline backups are your single best defence against ransomware. An untested backup is a hope, not a control.
- Endpoint protection on laptops and servers, with the alerts actually going somewhere you will see them.
- Email security, since that is where most attacks arrive.
Fourth: automate the repeatable, escalate the human
Your time is the bottleneck, so refuse to spend it on anything a machine can do. Automate the routine, recurring controls and reserve your judgement for the things that genuinely need a human.
- Automate vulnerability scanning, log collection, and alerting so they run without you.
- Use your provider's native security tooling before buying anything new - you are likely paying for capabilities you have not switched on.
- Spend your saved time on the human work: reviewing access, thinking about risk, and talking to the teams who are actually building things.
Buying tools to feel productive. Every platform you add is another thing to configure, monitor, and maintain - with one person, that maintenance debt comes straight out of your limited hours. Add tools only when they clearly remove more work than they create.
Fifth: make security everyone's job
A team of one does not scale by working harder; it scales by making the rest of the organisation part of the solution. This is the highest-leverage thing you will do, and it is mostly relationships, not technology.
- Give engineers secure defaults and paved paths, so the easy way to build is also the safe way.
- Run short, practical awareness sessions that respect people's time and focus on the threats they will actually meet.
- Build a relationship with leadership so security has a voice in decisions before they are made, not after.
- Know your limits: for deep, specialist work - a serious penetration test, incident response, a compliance programme - bringing in outside help is a force multiplier, not an admission of failure.
Do not try to build the whole framework at once. Lock down identity, learn what you have, cover the basics, automate the routine, and turn the wider organisation into your extended team. In that order, one person can meaningfully secure a growing company.
If you are that one person and want a second, experienced pair of hands - to set the priorities, do the specialist work, or just sanity-check the plan - that is exactly what our consultancy practice is for.