You've been putting off cybersecurity like a middle school book report, and now you're dreading the hours of time and effort it will take. What is worse, you don't even know where to start with the paperwork, asking your developers questions, buying expensive advice just to get told what else you need to spend time and money on. Maybe you tried to google around a bit, but that probably made you feel even more overwhelmed. Stop! Take a step back. Now let's think simply and logically about cybersecurity. Who are your stakeholders (usually customers, vendors, suppliers, employees and regulators)? What data do you collect? Where are you and your stakeholders located? If you can answer these questions, we're making progress!
Broadly speaking, if you know the types of data you're gathering and the location of your stakeholders you can figure out what framework to follow (this is not legal advice). Often, when you finally engage a cybersecurity professional you'll have some concrete goal in mind. Whether you need to provide due diligence to investors, certify that you are compliant to a regulator, or provide evidence to your customers to gain their trust, you don't want to be thinking about security for the first time. Since security is a property of a system, the best time to think about security and privacy is at the start.
This principle, of planning around your security/privacy goals, is known as "security by design." It is even enshrined in laws like the European General Data Protection Regulation. Of course, businesses outside of Europe would also do well to follow this principle. It will save you a lot of difficulty down the road and engender trust with your stakeholders. Regardless of industry, and whether you are focused more on security (as U.S. law tends to) or privacy (as European law tends to), gathering requirements that your system designers and engineers can plan for is well worth the extra effort up front.
But what if you don't know all the types of data or locations you have to plan for? If you're a startup, you may not have product market fit yet. That's ok! You're likely going to have to re-architect your application at some point anyway. One approach is to start with the widest array of use cases. I don't recommend this approach. Another way would be to drastically limit the scope that your business/software is targeting. If you take a lean approach, you won't have to discard as much, when you do find something interesting! You're going to discard much of that prototype or early version as your features and use cases change anyway. The worst case scenario is building an expensive app that you don't want to part with only to shoehorn it into another market addressing a different problem.
Finally, use existing frameworks. One thing that I often say that sometimes gets a laugh among cybersecurity folks is, "nobody wants another framework." Make sure the set of controls and approach suggested by the framework is appropriate for your business, but don't reinvent the wheel. If you need some help getting started, click the image to download the pdf flowchart with links to some tried and true frameworks that can get you on your way!