Back to Blog

Security Operations Playbook 2026: The 7-Function Guide for Growing Companies

The umbrella playbook for running a security program continuously at a 20-500 employee company. Seven functional areas, eight baseline controls, three business outcomes, sourced pricing, and the honest ownership matrix by headcount stage.

Quick Answer

The umbrella playbook for running a security program continuously at a 20-500 employee company. Seven functional areas, eight baseline controls, three business outcomes, sourced pricing, and the honest ownership matrix by headcount stage.

A 45-person SaaS founder gets a Sunday-night text from her lead engineer. There’s an alert on the production cluster. The IR plan she wrote 18 months ago references a Slack channel that doesn’t exist anymore and a runbook that lives in a former employee’s Notion workspace she can’t access. The security awareness training vendor hasn’t sent a phishing simulation in six months. Her SOC 2 auditor is asking for last quarter’s access review evidence and there isn’t any. This is what happens when security is treated as a series of one-time projects instead of an ongoing operational function.

Security operations at a growing company — call it 20 to 500 employees — is the continuous work of keeping the program alive between the audits, incidents, and board updates. It’s where compliance frameworks turn from checkboxes into evidence, where policies turn from documents into behavior, and where the security team’s value shows up on the P&L (deals closed, incidents avoided, insurance premiums reduced). This is the playbook for that work, sized for the SMB and mid-market SaaS company that doesn’t yet have a full security department.

The one-sentence framing

Security operations is the seven-function discipline of running a security program continuously — not the seven checklists you completed once. If your program can’t survive the departure of the one person who runs it, or the passing of six months since the last framework audit, you’re operating security as a project, not a function.

$30K–$150K/yr
Typical year-one security operations spend for a 20-100 employee SaaS across vCISO or fractional CISO ownership, tooling, awareness training, and framework audit fees — triangulated from vCISO Lite published pricing, Pivot Point Security April 2025 vCISO rate card ($4,500-$12,500/mo covers 90% of clients), and Drata 2026 SOC 2 cost guide ($12K-$30K Type II fee at SMB scale)
7 functions
Governance, identity, endpoint/cloud, vulnerability management, incident response, awareness, vendor risk — the seven functional areas every security program covers at every scale. Adapted from the six NIST CSF 2.0 Functions (Govern/Identify/Protect/Detect/Respond/Recover) with Vendor Risk elevated to a distinct operational function to match SMB reality.
60-70%
Share of incidents that begin with credential compromise, making identity + MFA the highest-ROI single control category (Verizon 2025 Data Breach Investigations Report)

The seven functional areas of security operations

Every security program at every size covers the same seven functional areas. At a 5-person company, one founder does all seven part-time. At a 5,000-person company, each is a discipline with a director and a team. What changes with scale is who owns each — not whether the function exists.

Function
What it covers
Who owns it at SMB scale (20–200 employees)
1. Governance & Policy
Information security policies, risk appetite, board reporting, compliance framework scope, security roadmap. The strategy layer.
Founder / CTO with fractional vCISO support. Board sees output every quarter.
2. Identity & Access
MFA enforcement, SSO, quarterly access reviews, privileged access management, offboarding hygiene. Prevents the credential-theft entry vector that starts 60-70% of incidents.
IT / Ops lead with security oversight. Automated where possible via IdP (Okta, Google Workspace, Microsoft Entra).
3. Endpoint & Cloud Security
EDR on all endpoints, cloud security posture management (CSPM), MDM/UEM for company devices, network segmentation. The technical control layer.
Engineering with security tooling budget. EDR (CrowdStrike, SentinelOne, or built-in options). Cloud config via native tools (AWS Security Hub, GCP Security Command Center) or third party (Wiz, Lacework).
4. Vulnerability Management
Continuous scanning, patch cadence, remediation SLAs by severity (P0 in 7 days, P1 in 30, P2 in 90), pen testing annually.
Engineering with security tooling. Vulnerability scanner (Snyk, Rapid7, Qualys). Pen test scoped and procured annually.
5. Incident Response
Documented and exercised IR plan, retained forensic capability, tabletop within 12 months, evidence-preservation procedures, communication tree.
Named incident commander (CTO), deputy (vCISO), comms lead (founder). IR retainer with a forensics firm at Series B+ scale.
6. Security Awareness & Training
Onboarding security module, contextual phishing fire drills (behavioral, threat-representative, adaptive to user response), role-specific training for finance and engineering, easy incident reporting via a one-click button.
HR partnership with a modern security awareness platform (Hoxhunt, Living Security, or KnowBe4's behavioral tier). Adaptive fire-drill cadence tuned to user risk profile — not a fixed monthly cadence that desensitizes readers.
7. Vendor & Third-Party Risk
Vendor inventory, tiering by risk (Tier 1 critical, Tier 2 important, Tier 3 utility), DPA + BAA + security addenda management, ongoing review cadence.
Ops / Legal partnership. Vendor risk platform (or spreadsheet + calendar reminders at smallest scale). 25-45 vendors typical at Series A SaaS.

The transition points where security operations changes shape

Programs don’t change linearly with headcount. There are three transition points where the operational shape shifts materially:

First regulated framework enters scope (any headcount)

SOC 2, HIPAA, ISO 27001, or PCI DSS. Security operations shifts from ad-hoc to evidence-driven — every control now has an evidence artifact and a cadence. Weekly access reviews, monthly vulnerability triage, quarterly policy reviews, annual pen tests. This is when the platform-augmented vCISO tier starts to pay for itself.

First enterprise customer with a security review function (~$50K+ ACV)

The security review questionnaire arrives. Now security operations includes questionnaire response, security artifact packaging (SOC 2 report, pen test summary, security whitepaper), and enterprise-buyer sales support. This is when named security ownership becomes non-negotiable — the security function is now part of the revenue flywheel.

~100-150 employee threshold

Head count crosses the point where any one person can hold the whole picture. Governance splits from operations, and either a full-time head of security or a bench of specialists (network, identity, cloud, IR) becomes necessary. The fractional vCISO becomes a strategic advisor to a named in-house security lead rather than the sole owner.

The founder mistake that costs the most

The single most common founder mistake in security operations: treating it as a compliance project that ends when the SOC 2 report is signed. The report is a milestone, not a destination. Every framework requires ongoing evidence, every audit cycle needs the underlying program alive, and every incident tests whether the paper controls actually work. Companies that stand down the program after the first audit rebuild from scratch for year-two, at 2-3x the cost.

How each function connects to the business outcomes that matter

Security operations at a growing company has three visible business outcomes. Every function above maps to at least one:

Outcome
Which functions produce it
How the CFO sees it
Enterprise deals close
Governance (roadmap + framework certification), Vendor Risk (documented supply chain security), Awareness (customer-facing security literacy), Incident Response (documented plan buyers ask for)
Revenue that wouldn't have closed without SOC 2 / ISO 27001 attribution. Track deal-close time as a security-program KPI.
Cyber insurance premiums stay flat or decline
Identity (MFA enforcement), Endpoint (EDR + backups), Vulnerability Mgmt (patch SLAs), Incident Response (documented + exercised)
Premium delta at renewal vs market. Underwriters price directly against control attestation — five controls drive 80% of premium variance.
Incidents don't turn into breaches
Incident Response (detection to containment speed), Endpoint (EDR alerting), Identity (credential compromise prevention)
Loss-avoided estimates when the SOC alert fires and doesn't become a 6-figure incident. Track detection-to-containment time as a security-program KPI.

The security operations spokes — where to go deeper on each function

Every function above has enough depth to be its own article. The playbook below indexes the seven; each linked article goes into the specific playbook, tooling choice, and tradeoffs.

Baseline controls every growing company should implement

Before pursuing any specific framework or buying any specific tool, the baseline set of controls that satisfy the majority of SOC 2, ISO 27001, HIPAA, and cyber insurance underwriter expectations:

Enforced MFA on every account with elevated privileges — no exceptions

The single highest-ROI security control. Credential compromise is the entry vector in 60-70% of incidents that carriers ultimately pay claims on. Enforced at the identity provider (not app-by-app). Verified weekly. Documented in a one-page evidence artifact. Removes exception lists that quietly grow.

EDR on 100% of endpoints with monitored alerting

Every endpoint including developer laptops, executive devices, and contractor devices with persistent network access. Alerts route to an SOC or MDR provider with documented response SLA. Deployed EDR without monitoring is shelfware. Common commercial options: CrowdStrike, SentinelOne, Microsoft Defender for Endpoint. Free-tier options exist for very small deployments.

Immutable backups with tested recovery in the last 90 days

Object-lock or WORM-configured storage that admin credentials cannot delete. Recovery tested within the past 90 days with data-integrity verification and recovery-time measurement. Ransomware defense stops working when backups can be encrypted; testing recovery is what proves the backup will actually restore.

DMARC at reject policy, SPF + DKIM aligned across all sending domains

Published DMARC is table stakes; enforced DMARC (p=reject) actually reduces phishing risk. Underwriters and framework auditors distinguish between the two. DNS-verifiable, publicly checkable — no room for the questionnaire answer to differ from reality.

Documented incident response plan exercised within 12 months

Named incident commander, deputy, comms lead, technical lead, customer-notification lead, legal lead. 6-8 page operational document, not a 60-page policy. Tabletop exercise within the last 12 months with documented after-action items. The plan is what the auditor and the cyber insurance underwriter both ask to see.

Security awareness training with contextual phishing fire drills

Behavioral, threat-representative phishing fire drills from a modern security awareness platform (Hoxhunt, Living Security, KnowBe4 behavioral tier). Google's Trusted Advisor and Alphabet security teams moved off fixed monthly-cadence simulations years ago because they desensitized readers — the current best practice is adaptive fire drills that mimic real active threat campaigns and adapt in cadence to each user's risk profile. Metrics tracked: click rate (target under 5%), report rate (target above 20%) via a one-click Report Phish button, time-to-report (target under 60 min). Repeat clickers get additional coaching, not public shaming. Program is measurable and auditable.

Quarterly access reviews with named reviewer per system

Identity provider report per critical system (production access, admin access, financial systems). Reviewed and signed off by a named human (not the security lead reviewing their own access). Terminated employees confirmed offboarded within 24 hours. Documented as evidence for the framework audit.

Vendor inventory with tiering and review cadence

Every vendor with data access catalogued: name, tier (1 critical / 2 important / 3 utility), data classification touched, compliance posture (SOC 2 report on file? DPA signed?), annual review date. 25-45 vendors typical at Series A SaaS. The vendor inventory is the artifact both auditors and cyber insurance underwriters ask to see.

Why these eight

These are the controls that produce the largest gap between the buyers who have them and the buyers who don’t — on framework audit findings, on cyber insurance premium bands, on incident containment time, and on enterprise buyer trust signal. A company running all eight consistently has a defensible security operations program. A company running fewer than five is telling itself a story it can’t defend under scrutiny.

Ownership at each stage — the seven-function-by-stage matrix

Function
1–20 employees
20–100 employees
100–500 employees
Governance
Founder writes 3 policies
Fractional vCISO drives; board reviews quarterly
Named Head of Security; formal ISMS; risk committee
Identity
Google Workspace + MFA
SSO consolidation + quarterly access reviews
Identity governance platform; PAM for privileged
Endpoint / Cloud
OS-default endpoint tools; native cloud
EDR + native CSPM + email security
SIEM + third-party CSPM + dedicated security engineering
Vuln Mgmt
Dependency scanner in CI (Snyk / Dependabot)
Vuln mgmt platform + annual pen test
Continuous pen testing + red team + bug bounty
Incident Response
Founder + on-call engineer
IR plan + tabletop annually; IR retainer at Series B
SOC (in-house or MDR) + IR retainer + tabletop biannually
Awareness
Onboarding checklist + Slack tips
SA platform + monthly phishing simulation
Role-based training program + culture measurement
Vendor Risk
Spreadsheet + DPA at signing
Vendor risk platform + quarterly Tier-1 review
Formal TPRM function + supply chain risk mgmt

Common security operations mistakes at growing companies

  • Buying tooling before defining ownership. An EDR license without an owner is money spent on nothing. Name the person accountable for each of the seven functions before writing the check for the tool.
  • Treating awareness training as compliance theater. Sending an annual computer-based training module and calling it done. Awareness works when it’s continuous (monthly phishing simulations), role-specific (finance gets wire-fraud content; engineering gets supply-chain content), and measured (click rate and report rate, not completion rate).
  • Skipping the tabletop until after the first incident. The IR plan you wrote and never exercised will not work under stress. Every documented IR plan needs at least one tabletop within 12 months, and the after-action items need to actually get implemented.
  • Confusing SOC 2 evidence collection with a security program. Evidence collection is the paper trail. The security program is what the paper trail evidences. A company can have perfect evidence collection and a mediocre security program if the underlying controls are minimally implemented.
  • Under-investing in identity governance. Identity is the highest-ROI control category at every scale. Companies that skimp on SSO, MFA enforcement, and access reviews inherit the credential-compromise risk that starts most incidents.
  • Standing the vCISO down after the first audit. The vCISO built the program. Ending the engagement after the report signs means the program has no owner during the observation window for the next audit. Renewal costs 3-4x more than continuous operation.
  • Not measuring the program. Security operations without metrics is opinion. Phishing click rate, mean time to remediate, access review completion rate, vendor review currency, incident-to-containment time. Five metrics tracked monthly, reported quarterly to the board.

The KPIs that show the security program is actually operating

KPI
What good looks like at SMB scale
Where the number lives
MFA enforcement %
100% on privileged accounts; documented weekly
Identity provider report
EDR coverage %
100% of endpoints; monitored alerting
EDR management console
Phishing fire-drill click rate
Below 5% (industry benchmark)
Security awareness platform
Phishing fire-drill report rate
Above 20% via one-click Report Phish button
Security awareness platform
P0 vulnerability MTTR
Under 7 days from detection
Vuln mgmt platform
P1 vulnerability MTTR
Under 30 days from detection
Vuln mgmt platform
Access review completion
100% quarterly, signed by named reviewer
Access review platform or documented process
Vendor review currency
Tier-1 vendors reviewed within last 12 months
Vendor risk platform or inventory spreadsheet
IR tabletop recency
Within last 12 months, with documented after-action
IR program documentation
Backup recovery test recency
Within last 90 days with recovery-time measurement
Backup platform + test log

Frequently asked questions

What is security operations at a growing company?

The ongoing, continuous work of running a security program across seven functional areas: governance, identity, endpoint/cloud, vulnerability management, incident response, awareness training, and vendor risk. At smaller companies, one person or a fractional vCISO owns all seven; at larger companies, each becomes a discipline with its own lead.

How do you build a security program from scratch?

In order: name the owner, baseline the seven functions, implement foundational controls (MFA, EDR, backups, DMARC, IR plan, awareness training, access reviews, vendor inventory), draft the minimum policy library, start framework evidence collection if applicable, and formalize measurement. 6-12 months to a defensible program at SMB scale.

What security controls should every growing company have?

Eight baseline controls: enforced MFA, EDR with monitored alerting, tested immutable backups, DMARC at reject policy, documented and exercised IR plan, monthly phishing simulation, quarterly access reviews with named reviewer, vendor inventory with tiering. These satisfy the majority of what SOC 2, ISO 27001, HIPAA, and cyber insurance underwriters ask about.

When does a growing company need a CISO or vCISO?

The moment a regulated framework enters scope, an enterprise customer with a security review function shows up in pipeline, or headcount crosses ~50. Full-time CISO ($415K SMB total comp per IANS 2025) is typically Series B/C. Fractional / vCISO ($299-$1,499/mo published on vCISO Lite, $3,000-$12,500/mo on traditional consultancy) covers 60-80% of the CISO role at 5-15% of the cost.

How much does security operations cost for a growing company?

Year-one all-in for a 20-100 employee SaaS: $30,000-$150,000. Fractional CISO or vCISO, compliance automation, EDR + tooling, awareness training, vulnerability scanning, annual pen test, and audit fees if pursuing SOC 2 or ISO 27001. Low end uses platform-augmented vCISO subscriptions; high end runs multi-framework programs with dedicated tooling.

Bottom line

Security operations is a seven-function ongoing discipline, not a compliance project. Every SMB security program covers all seven — governance, identity, endpoint/cloud, vulnerability management, incident response, awareness training, and vendor risk — and the question is who owns each function and how well it’s running. Companies that build the operational discipline first and pursue framework certification second end up with real security programs that produce the three visible business outcomes: enterprise deals close, insurance premiums stay flat or decline, and incidents don’t turn into breaches. Companies that reverse the order end up with paper compliance and real risk.

Run the seven-function program without hiring a full security team

vCISO Lite is the platform-augmented option for SMBs running the seven-function program without a full security department. $299 to $1,499 per month across four tiers, published rate card, no per-seat fees. Bundles compliance automation + vCISO hours + policy library + evidence collection + board reporting, sized for the SaaS company that needs security operations to actually run continuously between audits. For companies evaluating a full-time in-house security lead against the fractional / vCISO alternative: IANS Research + Artico Search’s 2025 CISO Compensation Benchmark (n=566) puts SMB CISO total compensation at $415K — the alternative most companies under 200 employees can’t justify.

If you’re building a security program from scratch, evaluating whether the current setup will survive the next audit, or figuring out which of the seven functions is under-owned, visit vcisolite.com to learn more and get started.

Sources

  • IANS Research / Artico Search, 2025 CISO Compensation Benchmark (n=566 US and Canadian CISOs; $415K SMB total comp): iansresearch.com
  • Pivot Point Security (CBIZ Pivot Point), vCISO Pricing and Cost Drivers ($4,500-$12,500/mo covers 90% of clients, April 2025): pivotpointsecurity.com
  • vCISO Lite published pricing ($299-$1,499/mo across four tiers): vcisolite.com/pricing
  • Verizon 2025 Data Breach Investigations Report (credential compromise as primary entry vector for 60-70% of incidents): verizon.com/dbir

Where this matters next

How to Build an Effective Incident Response Planthe incident response function deep-dive — the playbook that turns the IR checklist into an operational plan you can actually run under pressure.

How Cybersecurity Awareness Training Reduces Breach Costs by 58%the awareness function ROI math — the business case for the training program the board wants justified before approving budget.

Cloud Security Checklist: AWS, GCP, and Azure Essentialsthe endpoint + cloud function baseline — the technical controls that ship as the default posture for a SaaS on AWS, GCP, or Azure.

Third-Party Risk Management for Growing Companiesthe vendor risk function playbook — vendor tiering, review cadence, and questionnaire response as an operational discipline.

Security Policies for a 10-Person Companythe governance function starter kit — the lean policy library that satisfies audits without becoming shelfware.

vCISO Pricing in 2026: Three Honest Tiersthe pricing tiers for the vCISO who owns the seven-function program continuously — platform-augmented, traditional consultancy, and heavy multi-jurisdictional.

Platform: Security Scanningthe ML-tier of the seven-function playbook wired into the platform — CI/CD scanning, cloud misconfig, endpoint telemetry, all in one weekly review.

Use Case: Build Your Security Programhow the fractional vCISO tier delivers the seven-function program at $299-$1,499/mo — not the $415K in-house alternative.

Share this article:

Ready to build your security program?

See how easy it can be.