Cloud Security and Identity Management Are Critical for Startups
Most funded startups are technology companies themselves, so it can be surprising to see how often basic security gaps remain. This is particularly true among newer AI startups, where developers are moving quickly and the pressure to get a product to market can outweigh other considerations.
Cloud security is one of the biggest issues I encounter. A startup may put virtually everything into Amazon Web Services and assume that because the infrastructure is in the cloud, it is protected. But cloud security is a shared responsibility. The cloud provider secures the infrastructure it operates; customers still have the responsibility for how their environments, identities, data and workloads are configured and protected.
Identity and access management is another major gap. It can be a substantial undertaking to establish appropriate processes, but compromised credentials can give attackers an easy way into an environment.
DISCOVER: How small businesses can recover from ransomware.
And the potential damage goes beyond stolen data. An attacker who gains access to a startup’s cloud environment could use its resources to run unauthorized workloads, mine cryptocurrency or simply generate a massive cloud bill. And the same “we’re too small to be targeted” mentality can affect endpoint and email security. A distributed startup workforce may have employees traveling with laptops containing access to corporate systems, while phishing attacks can provide a straightforward path into an organization's email environment.
Investors and startup incubators increasingly recognize these risks too. There is no universal cybersecurity requirement across venture capital firms, but most expect their portfolio companies to have taken reasonable steps to secure themselves. Some may require active cybersecurity insurance, which itself requires companies to be following security frameworks recommended by organizations such as the National Institute of Standards and Technology. Other investors and incubators recommend specific security technologies or practices based on what has worked across their portfolio companies.
That means cybersecurity can become part of the conversation well before a startup reaches the size of a traditional enterprise.
How To Build Cybersecurity Into Your Startup Growth Strategy
Startup founders are understandably frugal: If they run out of money before demonstrating enough progress on their business goals, investors may balk at another funding round, and the company could fail. But startups don’t need to buy every security technology available on day one; they just need to identify their most important risks and put appropriate protections in place.
There are also ways to stretch limited budgets. Many security and data protection solution providers, including CrowdStrike, Mimecast and others, offer discount programs for venture-backed companies, although it can be difficult to know which companies are offering what level of discounts and on what terms. CDW’s High-Growth Startup discount program is available to help organizations find every discount they may be eligible for.
Services can be another important part of the equation. Many startups initially partner with managed service providers because they don’t have dedicated IT or security staff. That can make sense when the company has only a handful of employees. But as the organization grows, the economics and level of support can change. A service that worked for five employees may become prohibitively expensive for 40 or 50 employees, or the startup may find that it needs capabilities the provider doesn’t offer.
READ MORE: How to manage alerts to get real value.
That’s why it’s important to select a managed service provider that can offer the full gamut of services a startup will need as it grows at a cost it can manage. For many growing startups, endpoint and email security are good places to start. Cloud security and identity management should also be part of the conversation as the technology environment expands.
Managed endpoint protection can provide another layer without requiring a startup to build a security operation from scratch. CDW’s managed services for endpoint protection provide 24/7/365 alert monitoring, threat detection and analysis, and active remediation.
That last capability is particularly important. Knowing that something is wrong isn’t enough. A startup needs to know what happens next: Who investigates the incident? Who determines its scope? Who contains the threat and removes it from the environment?
For a lean organization, having access to those capabilities can be far more practical than trying to staff them internally.
Startups are built to move quickly. Cybersecurity shouldn’t prevent that. But it also shouldn’t be an afterthought. Building the right security foundation early can help a growing company protect its investment, satisfy increasingly security-conscious investors and customers, and keep a preventable security incident from derailing the growth it has worked so hard to achieve.

