4
2 Comments

Ask IH : What security measures do you take for early stage SaaS ?

Hello IH Family,
I am Shyam. I work in Fin-Tech space focusing on Fraud Detection and Risk Management.
I am exploring the problems in the Trust/Security in the SaaS space recently.
I believe startups need to have Security/Risk management built right from the beginning instead of bolting it on later. Patching things later causes more pain and inefficient architectures.
What better venue to get input than IH !.

Here are my questions.

  1. Is security important for your SaaS product in early stages ? Why / Why not ?
  2. What do you currently do to make sure your SaaS product is secure given that you will be handling sensitive customer data ?
  3. What is stopping you from doing more for security/trust ? what are your current blockers ?

I sincerely appreciate your input. It will really help me to get the ball rolling to understand the market.

Thanks
Shyam

on October 6, 2019
  1. 1

    As a non-technical guy I would love to know what steps to take to make your product less​ vulnerable.

    1. 1

      Thanks Steve for your reply.
      what steps you take will depend on how your software/application is architected.

      If it is something you got built [ say with a tech co-founder or using some 3rd party developers], there are certain things you should do.
      For example, taking care of OWASP top ten, is a good hygiene.
      https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project
      Basic things like salting passwords, not storing passwords etc in cleartext, Having 2nd Factor authentication for your production access should definitely be done.

      If you are hosting your application/store on a well built platform like say shopify, you would rely on Shopfiy etc to do the heavy lifting for you. Then it would be on them to do all the above said things. For your part, you should focus on using the security levers these platforms provide [ like 2FA ]..
      Hope this helps.

      Are there any specific risks are you concerned about ?