The minimum viable security stack for small companies

by
Dawid Winiarski
Last update:
July 17, 2026

If you run a company of fewer than fifty people without a security specialist, almost everything written about cybersecurity is aimed at someone bigger than you. The product pitches, the frameworks, the analyst reports all quietly assume a budget and a team you do not have, and reading enough of it leaves you feeling either that you need to spend a fortune or that you are hopelessly exposed. Neither is true.

Here is the opposite. At your size the goal is not a sophisticated program, it is to shut the handful of doors attackers actually use: a stolen password, a phished employee, an unprotected device, a missing backup. Close those and you have handled the large majority of your real risk, usually with things you already pay for. This is the short version for a lean team that needs to do the few right things and get back to work.

  • At under fifty people the goal is not a sophisticated program. It is to shut the handful of doors attackers actually use: a stolen password, a phished employee, an unprotected device, a missing backup.
  • You have likely already bought most of the floor. Microsoft 365 or Google Workspace includes MFA, single sign-on, email security, and device management, much of it switched off.
  • The top three to do this week: MFA everywhere, a password manager, and tested backups. They are cheap and close a large share of real risk.
  • You do not yet need a PAM platform, an identity-governance suite, a DLP platform, an SSPM tool, a SIEM, a SOC, or a compliance platform. These are overkill and unrunnable for a lean team.
  • The one detection exception: you cannot staff round-the-clock monitoring, so if that becomes a real worry, a managed service beats tools you cannot operate, but prevention and backups come first.
  • The floor holds until something changes: a security questionnaire, investor diligence, a regulation, crossing ~50 people, or a scare.

the floor, in one table

  • MFA everywhere · What it takes: Usually free in your suite. The single biggest risk reduction you have. No exceptions for founders or admins.
  • Use the identity provider you already own · What it takes: Get apps signed in through it, turn on its rules, make it the one place you add and remove people.
  • A password manager · What it takes: Kills reused passwords and gives you somewhere safe for shared logins.
  • Endpoint protection on every device · What it takes: Often in your suite or cheap. A laptop with nothing on it is an open door.
  • Backups you have tested · What it takes: Your real defense against ransomware. Restore from one once, as a drill.
  • Email filtering · What it takes: On and configured in your suite, since phishing is how most attacks start.
  • SaaS behind single sign-on · What it takes: And an occasional look at the OAuth grants that pile up.
  • A one-page AI guideline · What it takes: What not to paste, and which tools are fine for which data.
  • Offboarding that removes access · What it takes: A simple checklist run from your identity provider.

you probably already own most of this

The thing nobody selling you security mentions is that you have likely already bought most of the floor. The Microsoft 365 or Google Workspace subscription you pay for includes multi-factor authentication, single sign-on, basic email security, device management, and more, much of it switched off or never configured. A lot of what passes for small-company security is really just turning on what you already have, which is also why it costs so little to get the basics right. Do MFA everywhere, get your apps and people running through your identity provider, and make sure backups and email filtering are actually on, and you are past the point where most small companies get breached.

what to skip, with a clear conscience

Knowing what to ignore matters as much as knowing what to do, because a small team's time is the scarcest thing it has. You do not yet need a dedicated privileged-access platform, an identity-governance suite, a data-loss platform, a SaaS posture tool, a SIEM, a security operations center, a full zero-trust networking bundle, or a compliance platform. All of these are real and useful at scale, and all of them are overkill and unrunnable for a lean team. Buying them early is how small companies end up with an expensive tool half-deployed and the basics still open. The one thing worth flagging is detection: you cannot staff people to watch for attacks around the clock, so if that becomes a real worry, a managed service is the sensible answer rather than tools you cannot operate, but prevention and backups come first.

If you happen to build software, add the application-security basics, because for you the code is the product. Otherwise the table above is genuinely most of it.

when to add more

The floor holds until something changes, and the signals are specific rather than vague. A customer sends you a security questionnaire, or a deal stalls on security. An investor opens diligence. A regulation comes into scope. You cross roughly fifty people, or your tool and account sprawl gets past what one person can hold in their head. Or you have a scare. Any of those is the cue to move from the floor toward the fuller stack.

where to start

Pick the top three, MFA everywhere, a password manager, and tested backups, and do them this week. They are cheap, they are mostly things you already own, and together they close a large share of your real risk. Then work down the rest of the table as you have time. A fifteen-person company can do most of this list itself, for little money, and does not need to hire anyone to map its stack. The honest path is to work through the floor, use what you own, and add more once you have grown into more sprawl than you can see.

Subscribe to unshadowed.

Subscribe to receive the latest blog posts to your inbox and stay up to date with

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

let's start with a conversation

Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.

Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.

We'll take it from there

Julian Machowski
Head of Technical Sales
+48 783 762 997
julian@unshadowit.com
Let's connect on LinkedIn
Message received. We'll be in touch soon.
Something failed. Try again or call us directly.