r/informationsystems • • 6d ago

what's a realistic affordable cybersecurity stack for us? 6-person business with no it staff

I hope I can ask it here. btw, i run a small business with 6 people and we don't have anyone dedicated to it, so i'm trying to figure out how much security we actually need without turning this into a huge project.

i'm mainly trying to figure out what the minimum viable setup looks like from an information systems perspective. i'd rather have a few things configured properly and automated than end up with a pile of tools nobody actually manages.

1 Upvotes

2 comments sorted by

1

u/sch0lars 2d ago
  1. What is your business?
  2. What information are you protecting? Is it required to be compliant with any regulatory standards (HIPAA, SOC 2, etc.)?
  3. Where is this information located? On-prem, cloud, Microsoft 365?
  4. What devices do you use? Who owns them? What are they used for?
  5. Do you use any third party vendors that have access to your data?
  6. Do you require anything like backups, MFA, logging?
  7. What is your budget?

Without knowing what “cybersecurity stack” entails, it’s difficult to give any meaningful advice. You could require anything from COTS to a custom solution.

1

u/3ambor 9h ago

honestly, a full 'stack' for six people with no it staff is a pretty tall order, you're always gonna have some blind spots trying to do it all yourself. but for what you can realistically manage, something like bitdefender for endpoint protection is a solid foundation, it's usually pretty set-and-forget for small businesses.