Live data from Hacker News

SaaS CTO Security Checklist

sqreen.com

11–20 of 114 posts

Re: SaaS CTO Security Checklist

#11
post #7

"At Sqreen, for example, if someone catches another person’s laptop unlocked while they’re AFK, they can type “Cookies!” in that person’s Slack. That person will then have to bring in cookies for the office!" This sounds like a fun idea, but has anyone ever refused to bring in cookies?

This is exactly what the team I'm in does as well. It's fun, and people actually learn to lock their machines as a routine pretty quickly.

Re: SaaS CTO Security Checklist

#12
The slider of funding rounds is a neat idea but it's kind of hard to read in chronological order without mentally keeping track of which items appeared each time I slid it forward.

Would love to see a plain, non-javascript version of this content.

Re: SaaS CTO Security Checklist

#13
post #7

"At Sqreen, for example, if someone catches another person’s laptop unlocked while they’re AFK, they can type “Cookies!” in that person’s Slack. That person will then have to bring in cookies for the office!" This sounds like a fun idea, but has anyone ever refused to bring in cookies?

As our team is growing, having to bring cookies for a larger group can be a lot. Also, you're a bit less inclined if this happens to you two days in a row...

(message for Tyler: we're still waiting on those cookies)

Re: SaaS CTO Security Checklist

#14
post #8
post #7

"At Sqreen, for example, if someone catches another person’s laptop unlocked while they’re AFK, they can type “Cookies!” in that person’s Slack. That person will then have to bring in cookies for the office!" This sounds like a fun idea, but has anyone ever refused to bring in cookies?

I'd be more inclined to do a "drinks" option.

Except for those that obstain. Of course, not all people can eat cookies either, I suppose.

Re: SaaS CTO Security Checklist

#15
I really like this idea - alot.

But aimed perhaps at everyone, not just the CTO.

In fact the CTO probably needs one thing on their checklist.

Checklist item 1: Hire an outside security auditing firm to report on the state of this checklist quarterly".

And if the company has the financial resources:

Checklist item 2: Hire a second, independent outside security auditing firm to report on the state of this checklist quarterly".

I don't see any value in relating anything to the financial stage of the company because it's irrelevant.

Security also needs a time and priority aspect to it. For example if your company hasn't done anything on the checklist yet then what should come first, what is most important? Also it would be good to know what are the biggest typical weaknesses - a security chedclist can have so much stuff on it that it becomes hard to know where to focus.

Re: SaaS CTO Security Checklist

#16
post #7

"At Sqreen, for example, if someone catches another person’s laptop unlocked while they’re AFK, they can type “Cookies!” in that person’s Slack. That person will then have to bring in cookies for the office!" This sounds like a fun idea, but has anyone ever refused to bring in cookies?

I don't think you can enforce this, would be horrible for morale and probably illegal. I like to have similar "punishments" in my teams, people generally have fun with it. (And the rules apply to me too of course) But if someone doesn't want to, they can just ignore it. (Usually 1 in 10-20)

Re: SaaS CTO Security Checklist

#17
post #7

"At Sqreen, for example, if someone catches another person’s laptop unlocked while they’re AFK, they can type “Cookies!” in that person’s Slack. That person will then have to bring in cookies for the office!" This sounds like a fun idea, but has anyone ever refused to bring in cookies?

In my experience, when someone refused was because he/she forgot to bring the reward. Some time ago, before Slack, we used to type "donuts" in the email's composer and send the message to the team's mailing list or to the full office.

Imagine your co-worker on the next day with two or three dozens of Krispy Kreme products.

Re: SaaS CTO Security Checklist

#18
> Enforce a password policy

> (links to https://www.digicert.com/blog/creating-password-policy-best-...) where they give the usual (at least 2 special characters, but not " or \) advice

This is counterproductive and is actually discouraged by the latest NIST guidelines, that prefer passwords that are easy to remember, but still hard to guess [1].

[1] https://auth0.com/blog/dont-pass-on-the-new-nist-password-gu...

Re: SaaS CTO Security Checklist

#19

I really like this idea - alot. But aimed perhaps at everyone, not just the CTO. In fact the CTO probably needs one thing on their checklist. Checklist item 1: Hire an outside security auditing firm to report on the state of this checklist quarterly". And if the company has the financial resources: Checklist item 2: Hire a second, independent outside security auditing firm to report on the state of this checklist qua…

> Checklist item 1: Hire an outside security auditing firm to report on the state of this checklist quarterly

Security auditing firms cost a lot of money. Money you don’t have when you’re a small startup. Besides, an auditor audits and the hard part about this list is implementing it. Until you can afford to hire someone to take care of security, it’s usually the CTO’s job to make sure security is not an afterthought.

> I don't see any value in relating anything to the financial stage of the company because it's irrelevant.

It is extremely relevant, for at least two reasons. The first one is that the company’s financial resources dictate what you can or cannot do (e.g. hire a dedicated security resource, pay for pen testing). The second is that some recommendations just don’t make sense before a certain size (e.g. there’s no sense in setting up an AD and GPOs when there’s just 3 of you in the company).

Re: SaaS CTO Security Checklist

#20

I really like this idea - alot. But aimed perhaps at everyone, not just the CTO. In fact the CTO probably needs one thing on their checklist. Checklist item 1: Hire an outside security auditing firm to report on the state of this checklist quarterly". And if the company has the financial resources: Checklist item 2: Hire a second, independent outside security auditing firm to report on the state of this checklist qua…

> Checklist item 1: Hire an outside security auditing firm to report on the state of this checklist quarterly Security auditing firms cost a lot of money. Money you don’t have when you’re a small startup. Besides, an auditor audits and the hard part about this list is implementing it. Until you can afford to hire someone to take care of security, it’s usually the CTO’s job to make sure security is not an afterthought…

[deleted]
Post reply on HN