Module 10 · Org-Type Adaptation
Security Scaling: SMB to Enterprise
The same security controls that protect a 50-person company will cripple a 5,000-person enterprise. And the enterprise playbook will bankrupt a startup. Scaling security is not about doing more — it is about doing what is right for your size.
43% of cyberattacks target small businesses. The median SMB breach costs $120,000 — enough to end the company. Every org size has its own threat profile, budget reality, and team structure.
Under 100 Employees
SMB: Survival Mode
Strategy
Cloud-first, always
SaaS over on-prem. Microsoft has 3,500 security engineers. You have zero. Transfer operational security burden to providers with the resources to handle it.
Coverage
MDR, not SOC
Managed Detection & Response: $3-8/endpoint/month. 24/7 monitoring that one $85K analyst working 40 hours/week cannot match. MDR wins on coverage, cost, and capability.
Compliance
Insurance-driven
Cyber insurance forces the right controls: MFA, EDR, immutable backups, email filtering. These four controls prevent 90% of attacks that hit SMBs.
Total managed security cost for an SMB: $40,000-80,000/year. That buys more capability than a single full-time hire.
100-500 Employees
First Security Hire
| Hire Order | Role | Why This Order |
|---|
| 1st | Security generalist / engineer | Hands-on: configure tools, respond to incidents, run scans, support compliance. A doer, not a manager. |
| 2nd | GRC analyst / compliance | Customers demanding SOC 2, ISO 27001. Owns audits, policy docs, vendor assessments, evidence collection. |
| 3rd | Security engineer (AppSec/Cloud) | Engineering team growing, cloud expanding. Needs to shift security left into the SDLC. |
| Alt | vCISO + managed services | If budget allows one FTE, hire the engineer. Supplement with vCISO (10-20 hours/month) for strategy. |
The biggest hiring mistake: hiring a CISO as your first security person. Strategy without execution capability is worthless at 200 employees.
100-500 Employees
Budget Justification
Revenue
Enablement
"SOC 2 certification unlocks $2M in stalled pipeline. Cost: $80K. That is a 25x return." — speak the language of sales and revenue, not threats.
Cost
Avoidance
"Insurance requires MFA + EDR ($12K/year). Without them we lose coverage and self-insure a $4.5M average breach." — make inaction expensive.
Risk
Transfer
"MDR costs $48K/year. Replaces a $130K SOC analyst who only covers 40 hours/week. 24/7 monitoring, 15-minute SLA." — numbers, not jargon.
Remember this
Every security budget request: one-page business case with the problem, cost of inaction, proposed solution, solution cost, and measurable outcome. No fear-mongering. Numbers and outcomes only.
500-2000 Employees
Mid-Market: Professionalization
Team
3-10 security staff
Dedicated CISO or Director-level role. Specialized functions emerge: GRC, AppSec, SecOps. Budget: $500K-3M. This is where ad-hoc becomes a managed program.
Architecture
Formal security stack
SIEM/SOAR, EDR, CSPM, vulnerability management, identity governance. Tool rationalization becomes critical — avoid overlapping vendors.
The mid-market trap: buying enterprise tools designed for teams of 50, then staffing them with a team of 5. Right-size your tooling to your team's operational capacity.
Key transition: metrics-driven security. Board reporting with quantified risk, patching SLAs, detection coverage percentages. Gut-feel security no longer flies.
2000-10000+ Employees
Enterprise: Complexity at Scale
Org Design
Federated model
Central security team sets policy and standards. Business unit security teams implement. Security champions embedded in every engineering team. CISO reports to CEO or board.
Governance
Formal GRC
Multiple compliance frameworks simultaneously (SOC 2 + ISO 27001 + PCI + HIPAA). Integrated risk management platform. Third-party risk program for 500+ vendors.
Operations
24/7 SOC
In-house or hybrid SOC. Threat intelligence program. Red team/purple team. Detection engineering as a discipline. Incident response retainers with DFIR firms.
Enterprise security budget: 3-6% of IT spend or $5M-50M+ depending on industry and regulatory burden. The challenge shifts from "getting budget" to "spending it effectively."
The Progression
Maturity Stages
<100
Cloud + managed services. No FTE security staff. MDR, vCISO, compliance automation. $40-80K/year total security spend.
100-500
First security hire. Security engineer + GRC analyst. Framework selection (SOC 2 vs ISO). $200-500K/year including tools and staff.
500-2K
Security team. 3-10 staff, dedicated CISO. Formal SIEM/SOAR, vulnerability management. $500K-3M/year. Metrics and board reporting.
2K-10K
Federated model. 15-50 security staff. Central + BU teams. 24/7 SOC, red team, detection engineering. $3M-15M/year.
10K+
Full program. 50-200+ security staff. Global SOC, threat intel, dedicated AppSec, privacy engineering. $15M-50M+/year.
Key Takeaway
Right-Size Everything
Remember this
There is no universal security program. A 50-person company running ISO 27001 is wasting resources. A 5,000-person company relying on MDR alone is underinvesting. Match your program to your size, your threats, and your budget.
The four constants across all sizes: MFA everywhere, EDR on every endpoint, immutable backups, and a tested incident response plan. Everything else scales with the organization.
The most common mistake: copying what larger organizations do. The second most common: refusing to evolve as you grow. The right security program is one you can actually operate with the team and budget you have today.