- Job title
- Field sales representative
- Sector
- Healthcare services
- Organization type
- 120-person company
- Joined
- Jan 2025
- Message
- 280
We run a 10-person logistics consulting firm based in Moscow. Last week we reached the contract stage with a large enterprise client, but they hit the brakes when their security audit form revealed we have zero documented information security processes. They said «You can't integrate into our systems without an information security policy and basic safeguards in place.»
Honestly, up until now we haven't set up anything special beyond basic antivirus software on the office PCs and a shared cloud folder. We don't have the budget to hire a dedicated cybersecurity specialist; at this stage, the absolute most we can allocate is around 100,000 rubles.
What does company information security actually mean in practice? What concrete steps should a 10-person team take without burning through huge budgets, and what's the bare minimum required to satisfy an enterprise client?