Start with a Framework and Policy
Pick a framework first. NIST CSF provides an overarching umbrella. CIS gives an opinionated path through IG1, IG2, and IG3. Write policies next. ChatGPT produces 90-95% correct drafts. Assign a single owner per policy. Too few or too many owners means zero ownership. Put security responsibilities into every job description on day one. Tie compensation to those outcomes. Threat modeling is simply risk mitigation. Figure out what you protect and how.
Identity and Access Management on a Budget
Apply least privilege from day one. Start with minimum access and grant more over time. Phish-resistant MFA and passkeys are now built into devices. Use short-lived credentials. Force SSO and SCIM wherever vendors offer them for free. Avoid SSH by making boxes ephemeral. AWS SSM logs every keystroke without exposing port 22. Get a password manager. OnePassword offers a 10-user plan for $20 a month. Run quarterly user audits. A former employee still receiving AI note-taker summaries cost one company a lawsuit.
DNS, Headers, and Third-Party Risk
DMARC is no longer optional. Set SPF and DKIM records to quarantine or reject. Use securityheaders.com to check CSP and force HTTPS everywhere. Build CSP up from staging; tearing down a production policy breaks software. Read SOC 2 reports. s2c2.org provides a free rubric. Scoped reports can cover a single server. Send 10-15 pointed questions instead of a 100-question SIG. Customize them based on the vendorโs SOC 2 scope.
Application Security and Centralized Logging
OWASP Top 10 still includes SQL injection after 20 years. Vibe coders reintroduce the same bugs. Use ZAP or Burp Suite for free testing. AI code review accelerates lone developers but is not a replacement. Enable Dependabot and GitHub SBOMs. SonarCube and Claude Code provide free SAST. Centralized logging: DataDog charges $2.50 per million logs per month. Set up alerting with PagerDuty or OpsGenie (free for under five developers). EDR costs $50 per year per employee. MDM is useless without enforced full-disk encryption and screen locks.
Thrift Shopping and the Bottom Line
Time is free. Use free expo hall passes at RSA. Negotiate every vendor contract. Ask resellers to sell single licenses if minimums block you. An entire program fits under $5,000 per year: $300 for logs, $2 for IDS per 10 instances, $500 for EDR, $240 for password manager, plus MDM. Start like a 401k. Small investments from day one compound. Waiting until a customer demands SOC 2 makes the cost ten times higher.
Q&A
How do you start a home lab security environment? Defer to Tom Lawrence or Matt Lee in the front row; they can talk home lab for hours. โถ 31:04
As a solo founder who needs SOC 2 in a month, what is the path? Walk the customer through your NIST CSF alignment and explain your program. Ask for a contract term that lets you become SOC 2 certified after signing. Good fundamentals bought time at a fintech when Mastercard called. โถ 31:33
Notable Quotes
if you have too few owners or too many owners, you essentially have zero ownership Jared Casner ยท โถ 7:40
you canโt protect what you donโt know about Jared Casner ยท โถ 26:56
youโre talking about an entire security program for less than $5,000 per year Jared Casner ยท โถ 28:57
your security journey gets easier the earlier you start Jared Casner ยท โถ 29:04
Key Takeaways
- Start a security program with a framework like NIST CSF or CIS.
- Apply least privilege from day one and audit users quarterly.
- Build a full program for under $5,000 per year with free and cheap tools.
About the Speaker(s)
Jared Casner is the cofounder of Blacksmith InfoSec, where he helps MSPs and SMBs build audit-ready security programs without enterprise budgets. He has been building secure software for more than 25 years. For the past 15 years, heโs led software and cybersecurity at Silicon Valleyโฆ