A 45-person SaaS founder gets a Sunday-night text from her lead engineer. There’s an alert on the production cluster. The IR plan she wrote 18 months ago references a Slack channel that doesn’t exist anymore and a runbook that lives in a former employee’s Notion workspace she can’t access. The security awareness training vendor hasn’t sent a phishing simulation in six months. Her SOC 2 auditor is asking for last quarter’s access review evidence and there isn’t any. This is what happens when security is treated as a series of one-time projects instead of an ongoing operational function.
Security operations at a growing company — call it 20 to 500 employees — is the continuous work of keeping the program alive between the audits, incidents, and board updates. It’s where compliance frameworks turn from checkboxes into evidence, where policies turn from documents into behavior, and where the security team’s value shows up on the P&L (deals closed, incidents avoided, insurance premiums reduced). This is the playbook for that work, sized for the SMB and mid-market SaaS company that doesn’t yet have a full security department.
Security operations is the seven-function discipline of running a security program continuously — not the seven checklists you completed once. If your program can’t survive the departure of the one person who runs it, or the passing of six months since the last framework audit, you’re operating security as a project, not a function.
The seven functional areas of security operations
Every security program at every size covers the same seven functional areas. At a 5-person company, one founder does all seven part-time. At a 5,000-person company, each is a discipline with a director and a team. What changes with scale is who owns each — not whether the function exists.
The transition points where security operations changes shape
Programs don’t change linearly with headcount. There are three transition points where the operational shape shifts materially:
First regulated framework enters scope (any headcount)
SOC 2, HIPAA, ISO 27001, or PCI DSS. Security operations shifts from ad-hoc to evidence-driven — every control now has an evidence artifact and a cadence. Weekly access reviews, monthly vulnerability triage, quarterly policy reviews, annual pen tests. This is when the platform-augmented vCISO tier starts to pay for itself.
First enterprise customer with a security review function (~$50K+ ACV)
The security review questionnaire arrives. Now security operations includes questionnaire response, security artifact packaging (SOC 2 report, pen test summary, security whitepaper), and enterprise-buyer sales support. This is when named security ownership becomes non-negotiable — the security function is now part of the revenue flywheel.
~100-150 employee threshold
Head count crosses the point where any one person can hold the whole picture. Governance splits from operations, and either a full-time head of security or a bench of specialists (network, identity, cloud, IR) becomes necessary. The fractional vCISO becomes a strategic advisor to a named in-house security lead rather than the sole owner.
The single most common founder mistake in security operations: treating it as a compliance project that ends when the SOC 2 report is signed. The report is a milestone, not a destination. Every framework requires ongoing evidence, every audit cycle needs the underlying program alive, and every incident tests whether the paper controls actually work. Companies that stand down the program after the first audit rebuild from scratch for year-two, at 2-3x the cost.
How each function connects to the business outcomes that matter
Security operations at a growing company has three visible business outcomes. Every function above maps to at least one:
The security operations spokes — where to go deeper on each function
Every function above has enough depth to be its own article. The playbook below indexes the seven; each linked article goes into the specific playbook, tooling choice, and tradeoffs.
- Governance: Security Policies for a 10-Person Company — the lean policy stack that satisfies audits without becoming shelfware.
- Documentation: Security Documentation That Satisfies Auditors (Without Becoming Shelfware) — what to document, what to skip, what auditors actually read.
- Identity: Zero Trust Architecture for Startups — the identity-first approach to access control that scales from 20 to 500 employees.
- Endpoint: Cloud Security Checklist: AWS, GCP, and Azure Essentials — the baseline cloud posture every SaaS company should have running by default.
- Data: Data Classification for Growing Companies — how to know what data you have, where it lives, and how to protect it based on sensitivity.
- API surface: API Security Checklist for SaaS Companies — the pre-launch checklist for keys, auth, rate limits, and the vulnerabilities that keep pen testers busy.
- Vulnerability Mgmt: Penetration Testing Guide: How to Buy, Scope, and Use Pentests — the annual pen-test playbook plus the continuous scanning that fills the gaps.
- Incident Response: How to Build an Effective Cyber Attack Incident Response Plan — the plan you write before you need it and exercise before the incident.
- First-time IR: Why Your 50-Person Company Needs an Incident Response Plan — the founder-audience explainer.
- Prevention: How to Build a Robust Data Breach Prevention Strategy — the preventive controls that keep alerts from becoming breaches.
- Awareness: How Cybersecurity Awareness Training Reduces Breach Costs by 58% — the ROI math on the training program the board wants a business case for.
- Vendor Risk: Third-Party Risk Management for Growing Companies — the vendor tiering, review cadence, and questionnaire response playbook.
Baseline controls every growing company should implement
Before pursuing any specific framework or buying any specific tool, the baseline set of controls that satisfy the majority of SOC 2, ISO 27001, HIPAA, and cyber insurance underwriter expectations:
Enforced MFA on every account with elevated privileges — no exceptions
The single highest-ROI security control. Credential compromise is the entry vector in 60-70% of incidents that carriers ultimately pay claims on. Enforced at the identity provider (not app-by-app). Verified weekly. Documented in a one-page evidence artifact. Removes exception lists that quietly grow.
EDR on 100% of endpoints with monitored alerting
Every endpoint including developer laptops, executive devices, and contractor devices with persistent network access. Alerts route to an SOC or MDR provider with documented response SLA. Deployed EDR without monitoring is shelfware. Common commercial options: CrowdStrike, SentinelOne, Microsoft Defender for Endpoint. Free-tier options exist for very small deployments.
Immutable backups with tested recovery in the last 90 days
Object-lock or WORM-configured storage that admin credentials cannot delete. Recovery tested within the past 90 days with data-integrity verification and recovery-time measurement. Ransomware defense stops working when backups can be encrypted; testing recovery is what proves the backup will actually restore.
DMARC at reject policy, SPF + DKIM aligned across all sending domains
Published DMARC is table stakes; enforced DMARC (p=reject) actually reduces phishing risk. Underwriters and framework auditors distinguish between the two. DNS-verifiable, publicly checkable — no room for the questionnaire answer to differ from reality.
Documented incident response plan exercised within 12 months
Named incident commander, deputy, comms lead, technical lead, customer-notification lead, legal lead. 6-8 page operational document, not a 60-page policy. Tabletop exercise within the last 12 months with documented after-action items. The plan is what the auditor and the cyber insurance underwriter both ask to see.
Security awareness training with contextual phishing fire drills
Behavioral, threat-representative phishing fire drills from a modern security awareness platform (Hoxhunt, Living Security, KnowBe4 behavioral tier). Google's Trusted Advisor and Alphabet security teams moved off fixed monthly-cadence simulations years ago because they desensitized readers — the current best practice is adaptive fire drills that mimic real active threat campaigns and adapt in cadence to each user's risk profile. Metrics tracked: click rate (target under 5%), report rate (target above 20%) via a one-click Report Phish button, time-to-report (target under 60 min). Repeat clickers get additional coaching, not public shaming. Program is measurable and auditable.
Quarterly access reviews with named reviewer per system
Identity provider report per critical system (production access, admin access, financial systems). Reviewed and signed off by a named human (not the security lead reviewing their own access). Terminated employees confirmed offboarded within 24 hours. Documented as evidence for the framework audit.
Vendor inventory with tiering and review cadence
Every vendor with data access catalogued: name, tier (1 critical / 2 important / 3 utility), data classification touched, compliance posture (SOC 2 report on file? DPA signed?), annual review date. 25-45 vendors typical at Series A SaaS. The vendor inventory is the artifact both auditors and cyber insurance underwriters ask to see.
These are the controls that produce the largest gap between the buyers who have them and the buyers who don’t — on framework audit findings, on cyber insurance premium bands, on incident containment time, and on enterprise buyer trust signal. A company running all eight consistently has a defensible security operations program. A company running fewer than five is telling itself a story it can’t defend under scrutiny.
Ownership at each stage — the seven-function-by-stage matrix
Common security operations mistakes at growing companies
- Buying tooling before defining ownership. An EDR license without an owner is money spent on nothing. Name the person accountable for each of the seven functions before writing the check for the tool.
- Treating awareness training as compliance theater. Sending an annual computer-based training module and calling it done. Awareness works when it’s continuous (monthly phishing simulations), role-specific (finance gets wire-fraud content; engineering gets supply-chain content), and measured (click rate and report rate, not completion rate).
- Skipping the tabletop until after the first incident. The IR plan you wrote and never exercised will not work under stress. Every documented IR plan needs at least one tabletop within 12 months, and the after-action items need to actually get implemented.
- Confusing SOC 2 evidence collection with a security program. Evidence collection is the paper trail. The security program is what the paper trail evidences. A company can have perfect evidence collection and a mediocre security program if the underlying controls are minimally implemented.
- Under-investing in identity governance. Identity is the highest-ROI control category at every scale. Companies that skimp on SSO, MFA enforcement, and access reviews inherit the credential-compromise risk that starts most incidents.
- Standing the vCISO down after the first audit. The vCISO built the program. Ending the engagement after the report signs means the program has no owner during the observation window for the next audit. Renewal costs 3-4x more than continuous operation.
- Not measuring the program. Security operations without metrics is opinion. Phishing click rate, mean time to remediate, access review completion rate, vendor review currency, incident-to-containment time. Five metrics tracked monthly, reported quarterly to the board.
The KPIs that show the security program is actually operating
Frequently asked questions
What is security operations at a growing company?
The ongoing, continuous work of running a security program across seven functional areas: governance, identity, endpoint/cloud, vulnerability management, incident response, awareness training, and vendor risk. At smaller companies, one person or a fractional vCISO owns all seven; at larger companies, each becomes a discipline with its own lead.
How do you build a security program from scratch?
In order: name the owner, baseline the seven functions, implement foundational controls (MFA, EDR, backups, DMARC, IR plan, awareness training, access reviews, vendor inventory), draft the minimum policy library, start framework evidence collection if applicable, and formalize measurement. 6-12 months to a defensible program at SMB scale.
What security controls should every growing company have?
Eight baseline controls: enforced MFA, EDR with monitored alerting, tested immutable backups, DMARC at reject policy, documented and exercised IR plan, monthly phishing simulation, quarterly access reviews with named reviewer, vendor inventory with tiering. These satisfy the majority of what SOC 2, ISO 27001, HIPAA, and cyber insurance underwriters ask about.
When does a growing company need a CISO or vCISO?
The moment a regulated framework enters scope, an enterprise customer with a security review function shows up in pipeline, or headcount crosses ~50. Full-time CISO ($415K SMB total comp per IANS 2025) is typically Series B/C. Fractional / vCISO ($299-$1,499/mo published on vCISO Lite, $3,000-$12,500/mo on traditional consultancy) covers 60-80% of the CISO role at 5-15% of the cost.
How much does security operations cost for a growing company?
Year-one all-in for a 20-100 employee SaaS: $30,000-$150,000. Fractional CISO or vCISO, compliance automation, EDR + tooling, awareness training, vulnerability scanning, annual pen test, and audit fees if pursuing SOC 2 or ISO 27001. Low end uses platform-augmented vCISO subscriptions; high end runs multi-framework programs with dedicated tooling.
Bottom line
Security operations is a seven-function ongoing discipline, not a compliance project. Every SMB security program covers all seven — governance, identity, endpoint/cloud, vulnerability management, incident response, awareness training, and vendor risk — and the question is who owns each function and how well it’s running. Companies that build the operational discipline first and pursue framework certification second end up with real security programs that produce the three visible business outcomes: enterprise deals close, insurance premiums stay flat or decline, and incidents don’t turn into breaches. Companies that reverse the order end up with paper compliance and real risk.
Run the seven-function program without hiring a full security team
vCISO Lite is the platform-augmented option for SMBs running the seven-function program without a full security department. $299 to $1,499 per month across four tiers, published rate card, no per-seat fees. Bundles compliance automation + vCISO hours + policy library + evidence collection + board reporting, sized for the SaaS company that needs security operations to actually run continuously between audits. For companies evaluating a full-time in-house security lead against the fractional / vCISO alternative: IANS Research + Artico Search’s 2025 CISO Compensation Benchmark (n=566) puts SMB CISO total compensation at $415K — the alternative most companies under 200 employees can’t justify.
If you’re building a security program from scratch, evaluating whether the current setup will survive the next audit, or figuring out which of the seven functions is under-owned, visit vcisolite.com to learn more and get started.
Sources
- IANS Research / Artico Search, 2025 CISO Compensation Benchmark (n=566 US and Canadian CISOs; $415K SMB total comp): iansresearch.com
- Pivot Point Security (CBIZ Pivot Point), vCISO Pricing and Cost Drivers ($4,500-$12,500/mo covers 90% of clients, April 2025): pivotpointsecurity.com
- vCISO Lite published pricing ($299-$1,499/mo across four tiers): vcisolite.com/pricing
- Verizon 2025 Data Breach Investigations Report (credential compromise as primary entry vector for 60-70% of incidents): verizon.com/dbir
Where this matters next
How to Build an Effective Incident Response Plan — the incident response function deep-dive — the playbook that turns the IR checklist into an operational plan you can actually run under pressure.
How Cybersecurity Awareness Training Reduces Breach Costs by 58% — the awareness function ROI math — the business case for the training program the board wants justified before approving budget.
Cloud Security Checklist: AWS, GCP, and Azure Essentials — the endpoint + cloud function baseline — the technical controls that ship as the default posture for a SaaS on AWS, GCP, or Azure.
Third-Party Risk Management for Growing Companies — the vendor risk function playbook — vendor tiering, review cadence, and questionnaire response as an operational discipline.
Security Policies for a 10-Person Company — the governance function starter kit — the lean policy library that satisfies audits without becoming shelfware.
vCISO Pricing in 2026: Three Honest Tiers — the pricing tiers for the vCISO who owns the seven-function program continuously — platform-augmented, traditional consultancy, and heavy multi-jurisdictional.
Platform: Security Scanning — the ML-tier of the seven-function playbook wired into the platform — CI/CD scanning, cloud misconfig, endpoint telemetry, all in one weekly review.
Use Case: Build Your Security Program — how the fractional vCISO tier delivers the seven-function program at $299-$1,499/mo — not the $415K in-house alternative.