Live data from Hacker News

Be enterprise-ready: reasons not to build enterprise features

boxyhq.com

11–20 of 40 posts

Re: Be enterprise-ready: reasons not to build enterprise features

#11

I was reading an article by the other day about a person who had a disability that caused them to be highly disturbed by meaningless animations on the web. I might have voted it up but those stupid memes drag this article down to a low level.

I've got this theory. If an animated GIF is available on Slack, it isn't worth using.

Re: Be enterprise-ready: reasons not to build enterprise features

#12

I was reading an article by the other day about a person who had a disability that caused them to be highly disturbed by meaningless animations on the web. I might have voted it up but those stupid memes drag this article down to a low level.

can you share the article, i'm trying to be more littered in disability and this type of article tend to be useful.

See https://alistapart.com/article/designing-safer-web-animation...

Re: Be enterprise-ready: reasons not to build enterprise features

#13
post #6

This has been my experience, enterprises are routinely one-upping their security requirements. It used to be Shared Controls Audits, now its SOC2 Type 2, tomorrow it will be HiTrust or combinations of SOC2 and ISO controls. This has been getting more arduous every year for the last 10 years, I don't see it reversing anytime soon. As a startup, you will be out of business by the time you meet their requirements, or co…

Reading about SOC2 compliance, as a solo founder it would be impossible for me to get SOC2 compliance because there is just one of me right? Every time I read the requirements it's always: this person for X, this person for Y, this person for Z, which makes it seem like if you don't have a full team working on a project, it's impossible to get SOC2 compliance because there aren't enough people.

This is, unfortunately, a legitimate reason not to make solo suppliers a part of your supply chain. Inability to implement things like mandatory vacations and separation of duties does mean only you need to be compromised to become a threat vector, and that is easier than compromising multiple people. It doesn't mean you can't run a solo business, but you should focus on selling to organizations that are not likely to become the target of a supply chain attack.

Re: Be enterprise-ready: reasons not to build enterprise features

#14
post #6

This has been my experience, enterprises are routinely one-upping their security requirements. It used to be Shared Controls Audits, now its SOC2 Type 2, tomorrow it will be HiTrust or combinations of SOC2 and ISO controls. This has been getting more arduous every year for the last 10 years, I don't see it reversing anytime soon. As a startup, you will be out of business by the time you meet their requirements, or co…

Reading about SOC2 compliance, as a solo founder it would be impossible for me to get SOC2 compliance because there is just one of me right? Every time I read the requirements it's always: this person for X, this person for Y, this person for Z, which makes it seem like if you don't have a full team working on a project, it's impossible to get SOC2 compliance because there aren't enough people.

It depends on the risk tolerance of your customer, but you would likely fail.

The reason being: What happens if you get struck by a bus? Your business dies overnight (or until the hosting bill doesn't get paid) and now your customers are screwed.

Many of the controls are about what happens when staff depart, both planned and unplanned? What is the power structure in the org? How do you prevent employees from damaging your business operations?

Resilience is important to any enterprise, and many audits now evaluate how hardened your business is.

Maybe a morbid startup idea of "I'll ensure business continuity if you die so you can pass SOC2" lol

Re: Be enterprise-ready: reasons not to build enterprise features

#15
post #6

This has been my experience, enterprises are routinely one-upping their security requirements. It used to be Shared Controls Audits, now its SOC2 Type 2, tomorrow it will be HiTrust or combinations of SOC2 and ISO controls. This has been getting more arduous every year for the last 10 years, I don't see it reversing anytime soon. As a startup, you will be out of business by the time you meet their requirements, or co…

Reading about SOC2 compliance, as a solo founder it would be impossible for me to get SOC2 compliance because there is just one of me right? Every time I read the requirements it's always: this person for X, this person for Y, this person for Z, which makes it seem like if you don't have a full team working on a project, it's impossible to get SOC2 compliance because there aren't enough people.

Yes, it's not practical, and by design. In effect, this is simply acknowledging the reality that if they want to ensure a certain process, then someone has to bear the overhead of monitoring and control; so if a company wants to buy some sensitive service from a solo founder or a smallish company then they have to take responsibility themselves, and they can only delegate this duty to vendors only if the vendor actually has certified capability to do this high-overhead process.

It has some parallels to earlier initiatives like PCI DSS for payment cards which effectively said "If you can't do this list of requirements, then you'll have to delegate the sensitive stuff to someone who can", ensuring that every mom&pop pizza shop doesn't have a full list of their customers credit card numbers unencrypted on a publicly exposed database. It doesn't prevent all breaches, of course, but it did make them fewer.

Re: Be enterprise-ready: reasons not to build enterprise features

#16
IMO this is a pretty narrow definition of enterprise-ready, which is often actually more of a focus on being able to map a large organisations process into your application, and also how it scales with the number of users (ie your app is made for 1000 people to use rather than 10, and scales from a process/organisational perspective not just a technical perspective).

Small organisations are more willing to change processes to match your application than large companies, particularly if your process hasn’t been battle tested in other large organisations.

Re: Be enterprise-ready: reasons not to build enterprise features

#17
Seems like these enterprise-in-a-box services are taking off and I like the role that they play in the ecosystem. That said there's a lot more to it than what Boxy offers – a lot of what enterprises need is about configurability and flexibility for wildly varying use-cases, as well as general compliance. It looks like Boxy (authors of this post) are building more logging and governance features soon which I think will be useful for them.

We wrote about some of the broader flexibility features on our blog as well – https://staysaasy.com/product/2022/02/19/enterprise-selling-...

Re: Be enterprise-ready: reasons not to build enterprise features

#18
post #6

This has been my experience, enterprises are routinely one-upping their security requirements. It used to be Shared Controls Audits, now its SOC2 Type 2, tomorrow it will be HiTrust or combinations of SOC2 and ISO controls. This has been getting more arduous every year for the last 10 years, I don't see it reversing anytime soon. As a startup, you will be out of business by the time you meet their requirements, or co…

Reading about SOC2 compliance, as a solo founder it would be impossible for me to get SOC2 compliance because there is just one of me right? Every time I read the requirements it's always: this person for X, this person for Y, this person for Z, which makes it seem like if you don't have a full team working on a project, it's impossible to get SOC2 compliance because there aren't enough people.

I wonder if you can hire a law firm or a consultancy to help with this. They would have people on staff who can be legally designated as your point-of-contact for a given role?

Re: Be enterprise-ready: reasons not to build enterprise features

#19
post #6

This has been my experience, enterprises are routinely one-upping their security requirements. It used to be Shared Controls Audits, now its SOC2 Type 2, tomorrow it will be HiTrust or combinations of SOC2 and ISO controls. This has been getting more arduous every year for the last 10 years, I don't see it reversing anytime soon. As a startup, you will be out of business by the time you meet their requirements, or co…

Isn't this sort of necessary, given the miniature wave of ransomware/cybercrime that we've been going through? We've been saying that companies need to improve their security - isn't this it?

------------------------------------

This is somewhat tangential, but a really good "emotional transfer moment":

This is exactly how some people feel about government regulation - this emotion, right here - that it's arduous, stifles innovation, hurts startups trying to get off the ground with a shoestring budget, and just gets worse every year.

(now, of course, the thing that those people need to understand is that some amount of regulation is necessary. but, the thing that other people need to understand is that just because some amount of regulation is necessary, doesn't mean that you can be loose with it and allow it to metasize - law needs to be written with the same care and eye toward the future as code, and then also like code, needs to be refactored to reduce "tech debt" and keep it sane. this, currently, does not happen, and virtually nobody advocates for it)

(ironically, we have way more leverage over what kinds of regulations the government puts in place than over the effective regulations like SOC2/HiTrust that are "enacted" on clients of larger companies. not sure what to do about that one...)

Re: Be enterprise-ready: reasons not to build enterprise features

#20

Seems like these enterprise-in-a-box services are taking off and I like the role that they play in the ecosystem. That said there's a lot more to it than what Boxy offers – a lot of what enterprises need is about configurability and flexibility for wildly varying use-cases, as well as general compliance. It looks like Boxy (authors of this post) are building more logging and governance features soon which I think wil…

Sure; see also https://WorkOS.com in this space.
Post reply on HN