forumNew topic

They told us «You need information security» — where do we start with a 10-person company?

MMerve A***Member
Job title
Field sales representative
Sector
Healthcare services
Organization type
120-person company
Joined
Jan 2025
Message
280
#1

We run a 10-person logistics consulting firm based in Moscow. Last week we reached the contract stage with a large enterprise client, but they hit the brakes when their security audit form revealed we have zero documented information security processes. They said «You can't integrate into our systems without an information security policy and basic safeguards in place.»

Honestly, up until now we haven't set up anything special beyond basic antivirus software on the office PCs and a shared cloud folder. We don't have the budget to hire a dedicated cybersecurity specialist; at this stage, the absolute most we can allocate is around 100,000 rubles.

What does company information security actually mean in practice? What concrete steps should a 10-person team take without burning through huge budgets, and what's the bare minimum required to satisfy an enterprise client?

BBurak U***Member
Job title
Marketing manager
Sector
Construction
Organization type
boutique agency
Joined
Jul 2025
Message
67
Most Helpful#2

Short answer: Company information security is simply the set of rules and technical measures that prevent your data from being accessed by unauthorized eyes, deleted, or altered. For a ten-person team, this doesn't mean buying expensive servers; it means locking down access permissions, enforcing two-factor authentication, and putting a basic procedure in writing.

What your corporate client actually wants to see isn't a massive security operations center, but proof that you actively manage the risk of negligent leaks. You can start with zero-cost steps: 1) Mandate two-factor authentication across all company emails and cloud services with zero exceptions. 2) Ban shared passwords immediately; give every employee their own account, and revoke offboarded staff's access right away. 3) Shut down wide-open sharing on cloud drives and set role-based access so only relevant personnel can view client data.

On the technical side, keep OS auto-updates turned on across all workstations and enable native full-disk encryption using built-in system tools for free. Define a clear backup policy: back up client data weekly to an encrypted, off-site location.

Finally, you can use your 100,000-ruble budget to hire an independent consultant to draft an internal baseline security guideline and an NDA summarizing these exact policies. Once you present these procedures to the client and show that your staff signed off on them, you should pass their audit without issues.

ÜÜlkü A***New memberCommunity member
Joined
Jul 2026
Message
70
#3

Disk encryption should be your first step. Turn on native OS encryption on every laptop in the office. If an employee leaves a device behind at a cafe, all contracts and files on it stay encrypted. Also, restrict USB drive access via group policies—it costs nothing and cuts off half of all data leak vectors right away.

HHakan V***Member
Job title
Data Analyst
Organization type
regional distributor
Joined
Apr 2024
Message
104
#4

Go through the client's questionnaire carefully. Enterprises usually blast the exact same boilerplate security survey to everyone. Most items can be waived or relaxed for small vendors. Before you blow that 100,000 rubles ask their procurement contact which controls are hard requirements versus nice-to-haves.

SSinan B***Expert
Job title
Product Manager
Sector
Media and publishing
Organization type
two-branch business
Joined
Apr 2025
Message
223
#5

Ran into the exact same issue last year with our 12-person team. Paid an outside security consultant 70,000 rubles to put together a basic access matrix, roll out 2FA, and write up a one-page employee security guideline. Once the enterprise client saw the policy doc and screenshots of everything implemented, they signed off immediately.

SSevilMember
Job title
Educational institution
Organization type
chain store
Joined
May 2024
Message
88
#6

First thing Monday morning, roll out a password manager. Stop employees from logging into shared dashboards with simple passwords or credentials saved directly in their browsers. Put a rule in place requiring complex passwords and quarterly rotations.

TTülay Y***Veteran
Job title
Warehouse Manager
Sector
Security services
Organization type
a company within a holding
Joined
Aug 2025
Message
12
#7

Is your client a public institution or private sector? If you'll be connecting directly via API to a private database containing personal data, could they be legally mandated to require locally licensed security software or specific certifications?

FFadimeNew member
Job title
Food manufacturer
Organization type
a company within a holding
Joined
Sep 2024
Message
42
#8

Don't let it intimidate you at all. When they first brought it up to us we thought we'd need hundreds of thousands of rubles worth of servers and hardware. It's actually way more about office discipline than technical gear. Simply making sure everyone uses their own account and never leaves an unlocked screen unattended will shield you from a ton of risks.

MMurat Z***Member
Job title
Field sales representative
Sector
Glass
Organization type
chain store
Joined
Jan 2025
Message
27
#9

don't leave a single email account without 2fa and the client's real fear is your employee geting hacked and them using that email to launch a phishing attack on their internal network. btw lock that down and the rest is smooth sailing.

KKoray B***MemberCommunity member
Joined
Jul 2024
Message
87
#10

Information security requirements from corporate firms typically stem from third-party risk management procedures. The information security policy you draft must clearly outline how data is processed, where it is stored, who has access to it, and the procedures governing data destruction.

PPerihan T***New memberCommunity member
Joined
Jun 2026
Message
203
#11

Let me speak from the other side; I'm on the supplier side. Just because everyone does it doesn't mean it's right.

Processes without records never improve, because you don't know what to fix. Good luck with that.

SSultan K***Member
Job title
Logistics planning
Sector
Food wholesale
Organization type
early-stage startup
Joined
Dec 2025
Message
105
#12

The answer above hits the nail on the head. Hasty decisions become decisions you have to fix six months later.

Proven by experience.

TTaner D***Member
Job title
Intern
Sector
Plastic
Organization type
20-person company
Joined
Feb 2026
Message
5
#13

Exactly, and not many people know this. The real issue isn't the number, but what it's based on.

If you don't write this down from the start, it leads to arguments later. I'm also curious if anyone does it differently.

SSelin V***Veteran
Job title
Operations manager
Sector
Law
Organization type
a company within a holding
Joined
Feb 2022
Message
21

Doki · Phishing awareness training · 2023

#14

I went through the same thing. Forgotten test environments are more often the entry point than live systems.

If you have questions write them; I'll answer as best I can.

OOkan T***VeteranCommunity member
Joined
Jan 2023
Message
7
#15

Let me share my experience. Mistakes made on the company information security side are usually reversible but expensive.

If I were you, I'd go this route.

YYiğitMember
Job title
Video production
Joined
May 2024
Message
88
#16

we've heard this a lot but it never happened like that for us but honestly everyone ruhsing into company information security gets stuck at the same point.

if you post the resullt here it will help others too.

KKader Y***New member
Job title
Quality Assurance Manager
Sector
IT services
Organization type
boutique agency
Joined
Jun 2026
Message
126

Doki · Backup setup · 2026

#17

Thanks for posting. The answer varies greatly by industry; there is no one-size-fits-all rule.

Of course it varies if your situation is different.

HHavva K***Member
Job title
Content Editor
Sector
Packaging
Organization type
workshop
Joined
Oct 2022
Message
2
#18

i'm in the same situation that's why I'm asking. the answer varies greatly by industry; there is no one-size-fits-all rule.

proven by experience.

YYasemin E***MemberCommunity member
Joined
Mar 2026
Message
2
#19

Let's separate the concepts, they're getting mixed up. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Correct me if I'm wrong.

ÖÖmer O***Member
Job title
Field sales representative
Sector
Software
Organization type
sole proprietorship
Joined
Feb 2023
Message
135
#20

We need to make a distinction here. Payment information changes are never verified through the channel they came from.

Good luck with that.

Reply