DEV Community

Discussion on: Why Startups Suck at Security

Collapse
 
leober_ramos33 profile image
Leober Ramos

With the introduction that you make, you tell people that in their Startups they do not have to worry about security, for a Startup that has just started and that has almost (or no) clients, security should be their last concern.

That's very debatable, but I think security is necessary even for startups that are just starting out, but they don't have to worry about it as much. Do the things that everyone should do on any web server even if it's not going to be visited much, like keeping the operating system up to date, configuring firewalls, fail2ban, ModSecurity, disabling root authentication over SSH, etc, etc.

That is, things that are configured in less than 1 minute and provide that security that your Startup needs that is just starting. Since it is just starting, security should be the last thing you worry about, but not schedule it in the "not important".