In-House, On-Demand, or YOLO? How Startups Should Staff Security
There are only three ways a startup can handle security. Most are doing the third one right now, some of them correctly. Here's how to tell which one fits the work you have, and when the answer changes.
Every startup handles security one of three ways: hire someone to own it, pull in outside expertise when the work shows up, or (the unofficial default) nobody owns it and everybody hopes. The third option has a bad reputation and a worse nickname, but let’s be honest about it: YOLO is where every startup begins, and at day zero it’s usually the right call. A five-person team with no revenue and no sensitive data has exactly one existential risk, and it isn’t ransomware. It’s building something nobody wants.
The problem isn’t starting in YOLO mode. The problem is that the YOLO era ends silently. No alert fires on the day the bet flips; teams usually find out months later, from a prospect’s security questionnaire, an auditor’s timeline, or an attacker who found the opening first. So the useful question is which model fits the work you have right now, and how you’ll notice when the answer changes. This post is the framework we use, with receipts from the people who lived it on the podcast. At the end there’s a ten-question quiz that runs it against your situation, and yes, one of its possible answers is “go hire in-house.”
What are the three ways a startup can handle security?
In-house means a full-time security lead on your payroll, and eventually a team, who owns the program and answers for it. On-demand means outside operators (fractional, embedded, virtual CISO, pick your label) who carry the work in the shape it actually arrives and step back when it stops. YOLO, as in you only live once, means nobody owns security and the team leans on defaults: the framework’s auth, the cloud provider’s encryption, whatever the laptop shipped with.
Each model has a stage where it’s the smart choice and a stage where it becomes the expensive one, and the model matters far less than the timing. A security lead hired two years early is a very well-paid person writing policies nobody reads. A security lead hired two years late is a founder answering a 300-question spreadsheet at midnight while the deal waits.
When is YOLO the right call? (Yes, really)
A security company defending no-security sounds like a dentist defending candy, so let’s be precise about the bet. YOLO is rational while three things stay true: you hold no data anyone else would prize (no health records, no payment flows, no customer secrets), nobody with money is examining your posture (no enterprise prospects, no regulator, no diligence underway), and the blast radius of your worst day is your own runway rather than your customers’ business.
Under those conditions, pouring founder attention, a startup’s scarcest resource, into a security program is a misallocation. Turn on MFA everywhere, put SSO in front of what supports it, patch what you run, back up what you can’t recreate, and get back to product-market fit. That’s an afternoon of hygiene, not a hire. (If you want the afternoon to count for more, phishing-resistant, device-bound credentials are the single upgrade that removes an entire category of breach.)
Daniel Marashlian, who co-founded Drata after seven earlier startups, described the default arrangement on episode 64 without any embarrassment: “As the first engineer, I had to be the security engineer. Not only from the engineering AppSec side: IT, networking, firewalls, all that fun goody stuff, offense, defense.” As each company grew, that job went to a real security engineer. Early on it was his, and that was correct.
Two things quietly erode the bet. First, attackers stopped price-discriminating. Reconnaissance is automated and increasingly autonomous, and a scanner doesn’t check your headcount or your funding stage before trying the door. Being small used to be camouflage; now it’s just being unpatched. Verizon’s 2025 Data Breach Investigations Report found ransomware in 88% of breaches at small and medium businesses, against 39% at large organizations. Second, the three conditions above get re-checked at moments you don’t control. The day a prospect’s procurement team shows up with a questionnaire, the bet has already ended; you’re just late reading the result.
Phil Howie, founder and CTO of Sydekick, builds security programs for exactly these companies, and his framing on episode 83 is the right one for the YOLO stage: the goal is security a small team can run, not a shrunken copy of an enterprise program.
“The ‘fortune five million’ deserve security tools built for them, not leftovers from the enterprise world.”
Phil Howie, founder and CTO of Sydekick, on episode 83
What ends the YOLO era? Six triggers that put security on the critical path
In practice the YOLO era doesn’t fade out. It ends on a specific day, usually one of these:
- A security questionnaire lands. The most common ending. In Vanta’s State of Trust survey of 2,500 IT and business leaders (a vendor survey, so read it as directional), 65% said customers, investors and suppliers are increasingly requiring proof of compliance, and time spent on compliance tasks had grown to eleven working weeks, up from ten the year before. The deal is real, and so is the clock.
- A certification becomes a deal condition. SOC 2 Type 2 or ISO 27001 moves from “nice to have” to a line in procurement’s checklist.
- Regulated data enters the product. Store or process health records for a provider or health plan and you are a HIPAA business associate, directly liable for parts of the HIPAA rules. Defense work brings ITAR and CMMC, the Pentagon’s program for contractors handling federal contract information and controlled unclassified information. Payments bring an alphabet of their own.
- An incident, or a near miss. Nothing reorders a roadmap faster.
- Diligence. A fundraise or an acquisition puts your posture in a data room.
- You ship AI agents. Buyers now ask how agents are governed before they’ll connect one to their data, and the attackers are using agents too.
Notice what these have in common: almost none of them are security events. They’re growth events with security requirements attached, which is why each one arrives on a customer’s, regulator’s, or investor’s schedule rather than yours. The expensive version of this moment is discovering that a compliance program sits on the critical path of a deal that closes this quarter. Daniel again, describing his own trigger a decade ago, when university CIOs kept asking for a report he’d never heard of: “That was me a decade-plus ago. I need this SOC 2 report, and it’s like, what the hell is that? … I need help. Shepherd me through this process. I need this as fast as possible. I’ll do whatever.”
What he did next is the part every founder should hear, because it’s the reflex most teams have:
“Once I did, it’s like, you don’t know what you don’t know. Hire a consultant, rip engineers off the roadmap, go through the whole gamut. And for a small startup, I think we had six engineers at that startup, ripping three engineers off to help go get a SOC 2 report is no joke. It’s a big decision.”
Daniel Marashlian, co-founder and CTO of Drata, on episode 64
That’s half the engineering team, for a document. It is what the YOLO era costs when it ends on a customer’s schedule instead of yours, and it’s why the timing question matters more than the model question.
Should a startup hire a security engineer? The in-house math
When the trigger hits, the reflex is “we should hire someone.” Sometimes the reflex is right, so let’s steel-man it. In-house is the strong answer when security is close to what you sell (fraud prevention, auth, infrastructure other companies run their business on), when a steady 20 to 40-plus hours of security work arrives every week, and when you can actually attract and evaluate senior security talent.
Be honest about all three, because the math is less forgiving than the org chart. A senior security lead realistically runs $350K to $650K fully loaded. The search takes months: ISC2’s 2024 workforce study estimated the global cybersecurity workforce at about 5.5 million people against roughly 4.8 million unfilled roles, and in ISACA’s 2025 State of Cybersecurity survey 65% of organizations reported open security positions, with 39% saying a non-entry-level role takes three to six months to fill. A Series A startup is competing for the same people as Apple, and most hires need up to half a year to reach full speed once they start. Open req to full velocity is about a year.
There’s also a chicken-and-egg problem nobody warns you about: evaluating a senior security candidate takes security expertise you don’t have yet. Get it wrong and the mis-hire costs $500K-plus by the time you count the salary, the re-search, and the program that didn’t happen in between.
Then there’s breadth. “Security” is several specialties wearing one job title. On episode 2 of the podcast, Pure Storage CISO Andrew Gontarczyk needed a 42-minute conversation just to walk through when to build a security team and what kinds there are: product security, infrastructure security, DevSecOps, red, blue, purple. He also got into what still keeps him up at night with a full team in place. No one person covers that spread, so the best in-house programs start with a hands-on engineer matched to the dominant workload and add specialties as the work proves it needs them. (Asking your existing developers to absorb all of it instead is the pattern we took apart in Why Shift-Left Security Keeps Failing.)
And still: when the conditions hold, hire. Yes, a security vendor’s blog is telling you to build in-house. When the workload is steady and security is what you sell, it’s the right call, and telling you anything else would cost us the only thing a post like this is for. Just don’t leave the function empty for the year the search-plus-ramp takes, and don’t make the interview loop your first security decision.
What is on-demand security, and when does it fit?
On-demand security (fractional, embedded, pick your label) exists because most startup security work is the wrong shape for a full-time role. It spikes. A certification push, then quiet. A pentest and its findings, then quiet. Enterprise review season, then quiet. A hire priced for the spikes idles between them; a hire priced for the quiet drowns in the spikes.
The other reason is the breadth problem above. A bench of specialists you can draw on as the work changes shape covers product, infrastructure, compliance, and response without asking one person to be all of them, and it starts the week you sign rather than two quarters from now. When the blocker is a certification, that’s the difference between SOC 2 Type 2 in as little as five months and a deal that died waiting. When it’s a buyer’s pentest requirement, it’s a penetration test this month rather than after the hire. When it’s “who watches production at 3 a.m.,” it’s monitoring and response that doesn’t depend on one person’s sleep.
Daniel makes the build-versus-buy version of this argument about his own vendors at Drata, where he runs a technology org of a couple hundred people: “We could have built it all, but hey, let’s go see if anyone else is waking up every single day and only thinking about this one problem. And if that’s the case, let’s go partner with them.” His bar for what a partner has to feel like is the bar we’d hold any on-demand team to:
“When I work with companies, I want them to be an extension of my team, shared Slack channel. I can hit them up almost any time.”
Daniel Marashlian, Drata, episode 64
The failure mode of on-demand: drive-by consulting
The same honesty cuts against our side of the table. The failure mode of on-demand is drive-by consulting: a findings PDF, an invoice, and nobody who owns the outcome. You’ve met this consultant, or you will. The compliance-platform version of the same failure is buying the automation and assuming the program will run itself. Phil Howie, whose whole company is built on making security doable for small teams, is blunt about it on episode 83: “Even simple tools require human guidance. Software alone doesn’t fix security.” The platform collects the screenshots. Someone still designs the controls, runs them, and answers the auditor.
What good on-demand looks like: embedded, and built to hand off
What works is the embedded version: operators inside your stack and your Slack who own outcomes, not deliverables, and who write the AI acceptable-use policy in language your team will actually follow rather than a template nobody opens. The other half of the definition is a model that expects to hand off. On-demand done right builds toward your in-house team; when the workload stabilizes, it should help you scope the role, interview the candidates, and make the recommendation rather than protect the retainer. That’s the deal we offer, and it’s the reason the quiz at the end of this post is allowed to tell you to hire.
How to decide between in-house and on-demand security
Strip out the anxiety and the decision reduces to three questions: what shape is the work (steady or spiky), whose clock is the trigger on (yours, or a customer’s), and could you run a senior security search today?
| Signal | Points to |
|---|---|
| Security is part of what you sell, or a steady 20–40+ hours/week of work | In-house |
| Deadline-attached spikes: a certification push, questionnaires, a pentest | On-demand |
| Under ~5 people, no product, no sensitive data, no B2B pipeline | YOLO, deliberately, with a revisit date |
| Steady workload, but nobody who can run the search | On-demand now, hire in parallel |
The fourth row is the one founders miss. A steady workload says “hire,” but a steady workload plus nobody who can evaluate a security candidate says “hire, and don’t leave the seat empty for the year that takes.” The two models are sequential more often than they’re rivals. Phil’s advice to founders on episode 83 applies to the decision as much as to the tooling: “Founders don’t need more jargon. They need clear steps that make them safer.” Pick the model that fits the work in front of you, write down the signal that would change your answer, and check it every quarter.
Run the framework on your company
A framework you read is a framework you argue about in Slack. So we turned this one into something you can run: a ten-question quiz, under two minutes, no email gate, that weighs how fast the function needs to be filled, what the work looks like, how steady it is, what you’d budget, and whether you could interview for the role tomorrow. It returns one of three answers, and all three are real: hire the security lead (with what to plan for while the search runs), bring in outside help (with what the first month looks like), or you’re between models (with the signal that says it’s time to start the search). Either way, it shows which answers pushed your result, so you can argue with the reasoning, not just the conclusion.
If you’d rather work through it with people instead of a form, join us for The $300K Mistake Most Founders Make on October 6: thirty minutes on the hire-versus-rent decision, the case studies where the right call turned into growth, and a live Q&A to map it to your company. And if you want the conversation that started us down this road, Andrew Gontarczyk’s episode on when and how to build a security team is still the best 42 minutes on the subject.
The model matters less than what it buys you: walking into the next questionnaire, audit, or diligence call as the vendor who looks like the safe choice, because you are one. Take the quiz, and take the win, whichever one it is.
Startup security staffing frequently asked questions
- When should a startup hire its first full-time security engineer?
- When the work is steady and close to the product: security is part of what you sell (auth, fraud prevention, infrastructure other companies run on) and a consistent 20 to 40-plus hours a week of security work shows up. Hire when you can also run the search. Senior security roles take months to fill and most hires need up to half a year to reach full speed, so cover the work while the search runs rather than leaving the function empty.
- What is on-demand security for startups?
- On-demand security (also called fractional, embedded, or virtual CISO services) means outside operators own your security work without joining your payroll. It fits when the work arrives in spikes, such as a SOC 2 push, a wave of customer security questionnaires, or a penetration test and its fixes. Done well, the team works inside your stack and your Slack, owns outcomes rather than deliverables, and helps you hire in-house when the workload becomes steady.
- How much does a senior security hire cost a startup?
- Plan on roughly $350K to $650K a year fully loaded for a senior security lead at a venture-backed startup, before recruiting fees and before the tooling they will ask for. The larger cost is time: a search plus onboarding runs about a year from open req to full velocity, and a mis-hire can cost $500K or more once you count salary, the repeated search, and the program that did not get built in between.
- Is it OK for an early-stage startup to have no security program?
- Early on, yes, as long as it is a deliberate bet with a revisit date. Under roughly five people, with no product in customers' hands, no sensitive data, and no B2B pipeline, founder attention is better spent on product-market fit. Do the afternoon of hygiene anyway: MFA everywhere, SSO where it is supported, patching, and backups. Revisit the bet the day an enterprise prospect, a regulator, an investor, or an incident enters the picture.
- What triggers the need for a security program at a startup?
- Six events end the do-nothing era: a customer security questionnaire, a certification such as SOC 2 or ISO 27001 becoming a deal condition, regulated data (health, defense, payments) entering the product, an incident or near miss, fundraising or acquisition diligence, and shipping AI agents that buyers want governed. Almost none are security events. They are growth events with security requirements attached, which is why they arrive on someone else's calendar.
- How long does it take to hire a security lead?
- Longer than most founders budget. In ISACA's 2025 State of Cybersecurity survey, 65% of organizations reported unfilled security positions and 39% said a non-entry-level role takes three to six months to fill, before onboarding starts. Add up to half a year for a senior hire to reach full speed and the realistic path from open req to a fully effective security lead is about a year, so start the search well before the workload demands it.
- Should our first security hire be a CISO or an engineer?
- Match the hire to the work. If the work is building security into the product, hire a senior product security engineer who ships code. If the work is a compliance program, customer reviews, and vendor management, that is program work an operator or on-demand team handles well, and a CISO title is premature at startup scale. Most first hires are hands-on engineers. The executive role comes when there is a team to lead.
- Do we still need a person if we buy a compliance automation platform?
- Yes. Platforms such as Vanta or Drata automate evidence collection, and Drata's own figure is that they cut SOC 2 upkeep from roughly 500 hours a year to about 50. Someone still has to design the controls, run them, answer the auditor, and fix what the platform flags. As Phil Howie of Sydekick put it on the podcast, "Software alone doesn't fix security." Decide who that someone is before the observation window opens.