Module 10 · Org-Type Adaptation

Security Scaling: SMB to Enterprise

The same security controls that protect a 50-person company will cripple a 5,000-person enterprise. And the enterprise playbook will bankrupt a startup. Scaling security is not about doing more — it is about doing what is right for your size.

43% of cyberattacks target small businesses. The median SMB breach costs $120,000 — enough to end the company. Every org size has its own threat profile, budget reality, and team structure.

Under 100 Employees

SMB: Survival Mode

Strategy
Cloud-first, always
SaaS over on-prem. Microsoft has 3,500 security engineers. You have zero. Transfer operational security burden to providers with the resources to handle it.
Coverage
MDR, not SOC
Managed Detection & Response: $3-8/endpoint/month. 24/7 monitoring that one $85K analyst working 40 hours/week cannot match. MDR wins on coverage, cost, and capability.
Compliance
Insurance-driven
Cyber insurance forces the right controls: MFA, EDR, immutable backups, email filtering. These four controls prevent 90% of attacks that hit SMBs.

Total managed security cost for an SMB: $40,000-80,000/year. That buys more capability than a single full-time hire.

100-500 Employees

First Security Hire

Hire OrderRoleWhy This Order
1stSecurity generalist / engineerHands-on: configure tools, respond to incidents, run scans, support compliance. A doer, not a manager.
2ndGRC analyst / complianceCustomers demanding SOC 2, ISO 27001. Owns audits, policy docs, vendor assessments, evidence collection.
3rdSecurity engineer (AppSec/Cloud)Engineering team growing, cloud expanding. Needs to shift security left into the SDLC.
AltvCISO + managed servicesIf budget allows one FTE, hire the engineer. Supplement with vCISO (10-20 hours/month) for strategy.

The biggest hiring mistake: hiring a CISO as your first security person. Strategy without execution capability is worthless at 200 employees.

100-500 Employees

Budget Justification

Revenue
Enablement
"SOC 2 certification unlocks $2M in stalled pipeline. Cost: $80K. That is a 25x return." — speak the language of sales and revenue, not threats.
Cost
Avoidance
"Insurance requires MFA + EDR ($12K/year). Without them we lose coverage and self-insure a $4.5M average breach." — make inaction expensive.
Risk
Transfer
"MDR costs $48K/year. Replaces a $130K SOC analyst who only covers 40 hours/week. 24/7 monitoring, 15-minute SLA." — numbers, not jargon.
Remember this

Every security budget request: one-page business case with the problem, cost of inaction, proposed solution, solution cost, and measurable outcome. No fear-mongering. Numbers and outcomes only.

500-2000 Employees

Mid-Market: Professionalization

Team
3-10 security staff
Dedicated CISO or Director-level role. Specialized functions emerge: GRC, AppSec, SecOps. Budget: $500K-3M. This is where ad-hoc becomes a managed program.
Architecture
Formal security stack
SIEM/SOAR, EDR, CSPM, vulnerability management, identity governance. Tool rationalization becomes critical — avoid overlapping vendors.

The mid-market trap: buying enterprise tools designed for teams of 50, then staffing them with a team of 5. Right-size your tooling to your team's operational capacity.

Key transition: metrics-driven security. Board reporting with quantified risk, patching SLAs, detection coverage percentages. Gut-feel security no longer flies.

2000-10000+ Employees

Enterprise: Complexity at Scale

Org Design
Federated model
Central security team sets policy and standards. Business unit security teams implement. Security champions embedded in every engineering team. CISO reports to CEO or board.
Governance
Formal GRC
Multiple compliance frameworks simultaneously (SOC 2 + ISO 27001 + PCI + HIPAA). Integrated risk management platform. Third-party risk program for 500+ vendors.
Operations
24/7 SOC
In-house or hybrid SOC. Threat intelligence program. Red team/purple team. Detection engineering as a discipline. Incident response retainers with DFIR firms.

Enterprise security budget: 3-6% of IT spend or $5M-50M+ depending on industry and regulatory burden. The challenge shifts from "getting budget" to "spending it effectively."

The Progression

Maturity Stages

<100
Cloud + managed services. No FTE security staff. MDR, vCISO, compliance automation. $40-80K/year total security spend.
100-500
First security hire. Security engineer + GRC analyst. Framework selection (SOC 2 vs ISO). $200-500K/year including tools and staff.
500-2K
Security team. 3-10 staff, dedicated CISO. Formal SIEM/SOAR, vulnerability management. $500K-3M/year. Metrics and board reporting.
2K-10K
Federated model. 15-50 security staff. Central + BU teams. 24/7 SOC, red team, detection engineering. $3M-15M/year.
10K+
Full program. 50-200+ security staff. Global SOC, threat intel, dedicated AppSec, privacy engineering. $15M-50M+/year.
Key Takeaway

Right-Size Everything

Remember this

There is no universal security program. A 50-person company running ISO 27001 is wasting resources. A 5,000-person company relying on MDR alone is underinvesting. Match your program to your size, your threats, and your budget.

The four constants across all sizes: MFA everywhere, EDR on every endpoint, immutable backups, and a tested incident response plan. Everything else scales with the organization.

The most common mistake: copying what larger organizations do. The second most common: refusing to evolve as you grow. The right security program is one you can actually operate with the team and budget you have today.

1 / 8