Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

How to Build a Security Budget When You Have No Security Team

A founder asked us recently: "How much should we spend on security?" The honest answer is: it depends on your stage, your data, and your customers. But that is not helpful. So here is a framework with actual numbers.

Pre-seed to seed (1-15 employees, pre-revenue to $1M ARR)

Budget: $500-$2,000/month.

At this stage, security is about hygiene, not infrastructure. Spend money on:

  • Password manager: 1Password or Bitwarden for the team. $5-$8/user/month. This eliminates password reuse, which is the single most common attack vector for startups.
  • MFA everywhere: Free with most tools. Enforce it on email, cloud provider, GitHub, and any system with access to customer data.
  • Endpoint protection: CrowdStrike Falcon Go or SentinelOne. $5-$10/endpoint/month. Covers laptop security for the team.
  • SSL/TLS: Free with Let is Encrypt or included with your CDN. No excuse for not having HTTPS everywhere.
  • Automated vulnerability scanning: Snyk free tier for code dependencies. AWS Inspector free tier for infrastructure.

Total: $500-$1,500/month. This covers the basics and prevents the most common attacks.

Post-seed to Series A (15-50 employees, $1M-$10M ARR)

Budget: $3,000-$10,000/month.

At this stage, enterprise customers start asking for SOC 2, and your attack surface has grown. Add:

  • Compliance automation: Vanta, Drata, or Secureframe. $10,000-$20,000/year. This is your SOC 2 engine.
  • Virtual CISO: $3,000-$8,000/month. They set security strategy, manage compliance, and handle security questionnaires.
  • SSO: Okta or Google Workspace with SSO. $5-$15/user/month. Centralizes access management.
  • Penetration testing: Annual pentest by a reputable firm. $10,000-$25,000/engagement. Required for SOC 2 and most enterprise security reviews.
  • Security awareness training: KnowBe4 or similar. $2-$5/user/month. Covers phishing simulations and compliance training.
Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire. Fractional CISO

Series A to Series B (50-200 employees, $10M-$50M ARR)

Budget: $15,000-$40,000/month.

At this scale, you are either building an in-house security team or deeply investing in outsourced security services. Add:

  • First security hire: $150,000-$220,000/year. This person implements security controls, runs the vulnerability management program, and handles day-to-day security operations.
  • SIEM/log management: Datadog Security, Elastic Security, or Panther. $1,000-$5,000/month. Centralized security event monitoring.
  • Bug bounty program: HackerOne or Bugcrowd managed program. $2,000-$5,000/month platform fee plus bounty payouts.
  • DLP (Data Loss Prevention): Prevent sensitive data from leaking through email, cloud storage, or code repositories.

The rule of thumb

Spend 5-10% of your engineering budget on security. If your engineering team costs $1M/year, your security budget should be $50,000-$100,000/year. This percentage tends to decrease at scale because security tooling costs do not grow linearly with team size.

The most important thing is not the exact number. It is having a security budget at all. Most startups spend exactly $0 on security until an enterprise customer requires SOC 2 or a security incident forces their hand. By then, they are playing catch-up and spending 3x what they would have if they had started earlier. If the budget does not stretch to a full-time hire, a fractional CISO is the usual way to get the strategy without the salary.

Need help building your security budget?

traztech helps startups allocate security budgets based on their stage, risk profile, and customer requirements. We make sure every dollar goes toward reducing real risk.

Book a free strategy call

What to buy first when the budget is smaller than the list

The stage tables above assume you can fund the whole line. Most seed companies cannot, so the more useful question is what order to buy in when you have $600 a month and a list that adds up to $1,400. The ordering that has held up across the engagements we run is: identity first, then endpoints, then backups, then visibility.

Identity first because almost every incident that actually hurts a small company starts with a credential. A password manager and enforced MFA on email, cloud provider, source control and the billing system costs under $100 a month for a team of ten and closes the path attackers actually use. Endpoints second because a compromised laptop bypasses everything else you buy. Backups third, tested rather than merely configured, because the failure mode that ends companies is not data theft, it is data loss with no restore. Visibility last, because logs you never read are the most commonly bought and least commonly used security spend at this stage.

What people buy instead, when they are anxious rather than deliberate, is a tool with a dashboard. Dashboards are reassuring and they do not stop anything. If you can only fund one line this quarter, fund the one that removes an attack path rather than the one that would tell you about it afterwards.

The lines nobody budgets for

The SSO surcharge. Many SaaS vendors put single sign-on on their enterprise tier, which means centralising access can multiply your per-seat cost on tools you already pay for. Before you commit to an SSO rollout, price the upgrades across your top fifteen applications. Teams routinely discover the identity provider costs $8 a user and the tier upgrades required to use it cost four times that.

Log retention. Audit and compliance frameworks generally expect logs retained for a defined period, commonly a year. Retention is where observability bills grow, and it grows with traffic rather than headcount, so it is the line most likely to surprise a company having a good year.

Engineering time. This is the largest security cost at every stage and it never appears in a security budget because it is already in payroll. A first audit typically consumes weeks of senior engineering attention on access reviews, deploy pipeline changes, infrastructure hardening and evidence collection. If you do not account for it, you will still pay it, just out of the roadmap.

Cyber insurance. Premiums are a security line, and underwriter questionnaires now ask about MFA coverage, endpoint detection, backup testing and privileged access. Companies that already funded the basics get cheaper policies, which means part of your security spend returns as a lower premium. Get the questionnaire early and use it as a checklist.

The audit itself. Readiness and attestation are separate costs with separate vendors. Budget both, and budget the penetration test alongside them, because the audit firm and the enterprise buyer will each want one and it is the same test if you scope it properly.

Your data type moves the number more than your headcount

A fifteen-person company handling anonymous analytics data and a fifteen-person company handling patient records do not have the same budget, and stage tables hide that. Three adjustments matter.

If you handle health information, add the cost of business associate agreements, access logging at record level, and a considerably heavier documentation burden. Our HIPAA work for digital health exists because that gap between a general security program and a defensible one is wider than most founders expect.

If you touch cardholder data, the biggest budget lever is not tooling, it is architecture. Moving to a hosted payment page or tokenised flow can remove most of your environment from scope and take the annual compliance effort from a large project to a short questionnaire. Spending two engineering weeks on that is cheaper than spending every subsequent year proving controls over a system you did not need to keep.

The fractional CISO versus first hire calculation

The stage table lists both, and the choice between them is usually made emotionally. Here is the arithmetic. A first security hire at $180,000 costs roughly $215,000 fully loaded with employer costs, equipment and recruiting fees amortised over the first year. That is around $18,000 a month for one person's full attention, and the recruiting process itself will take three to five months during which nothing is owned.

A fractional CISO from $3,000 a month gets you strategy, security questionnaire responses, buyer security calls and program ownership, but not implementation capacity. That distinction is the whole decision. If your problem is that nobody knows what to do, fractional is the efficient answer. If your problem is that you know exactly what to do and there is nobody to do it, you need an engineer, and quite possibly a platform or infrastructure engineer with security interest rather than a security specialist.

The pattern that works at Series A is usually one fractional owner setting direction and answering the buyer-facing demands, plus a named internal engineer with a defined percentage of their time formally allocated to security work. The pattern that fails is hiring a strategic security leader with no team, who then spends the year writing policies nobody implements.

How to defend the number to a CFO or board

Security budgets get cut when they are presented as insurance against an abstraction. They survive when they are tied to revenue that is already identified. The most effective framing we have seen is a short list of named deals or renewals with the specific requirement attached to each: this customer's contract requires an annual penetration test, this prospect's security review is blocked on an attestation report, this renewal has a clause about breach notification timelines we cannot currently meet.

The second framing that works is cost avoidance with real numbers rather than industry breach averages, which nobody believes. Compliance work done early is genuinely cheaper than compliance work done under deadline, and the effect shows up in the audit quote as well as in engineering hours: on one engagement the audit firm reduced its own quote by $11,000 once the readiness position was documented, which we walk through in the auditor vetting case study.

What does not work is a percentage benchmark presented on its own. The rule of thumb earlier in this article is useful for sanity-checking your own plan, and it is weak as an argument to a finance team, because it says nothing about what happens if the answer is no.

When the right budget is close to zero

There is a real case for spending almost nothing, and it applies more often than vendors will tell you. If you are pre-product, pre-revenue, and handling no customer data beyond a waitlist of email addresses, the correct security budget is a password manager, MFA everywhere, and full-disk encryption on laptops. That is perhaps $150 a month for a small team. Buying compliance tooling at that stage is buying a subscription to a problem you do not yet have, and the evidence it collects will be worthless because the environment will be rebuilt before anyone audits it.

Do not buy an audit before a customer asks for one by name. "Enterprise customers will eventually want SOC 2" is true and it is not a reason to spend $40,000 this year rather than next. Do not buy a penetration test to satisfy an internal feeling; buy it when a contract requires it, when you have shipped something structurally new, or when you are about to hand a buyer a report they will read. Our published pricing starts penetration testing at $1,000 precisely so a small company can scope a real test against the part that matters instead of skipping it entirely.

And do not hire us, or anyone, to build a security program for a company that has not decided what it sells. Consultants are most valuable when the requirement is specific and external. When the requirement is vague and internal, the honest advice is to spend the money on the product and revisit this in two quarters. If you want a second opinion on whether you are in that position, ask, and we will tell you when the answer is to wait.

Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.

Fractional CISOOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on security posture. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.