SECURITY PROGRAMME
Building a Security Programme from Zero: A Practical Framework
Most growing businesses have security tools and good intentions, but no programme. This page sets out what a real security programme is, how to build one in around 90 days, and how to do it without a full-time hire.
Book a conversationTools are not a programme
Almost every SME has bought security along the way: antivirus, a firewall, multi-factor authentication, perhaps a backup tool. What most do not have is a programme, meaning a managed, risk-based way of deciding what to protect, how, and in what order, with someone accountable for it. A pile of tools with no owner leaves gaps that nobody sees until an incident finds them. A programme turns scattered spending into a defensible posture.
What a security programme actually is
A security programme is the management system around your controls, not the controls themselves. It answers who owns security risk, how decisions are made, what the organisation is protecting and why, and how the board gains assurance that the controls work. Governance, risk, controls, people and assurance are its five moving parts. Get those working together and the individual tools finally pull in the same direction.
The framework, in around 90 days
You do not build this all at once, and you do not need to. A structured first quarter gets you from nothing to a working, defensible programme.
- Establish accountability and scope: who owns security, and what the programme covers
- Assess risk and current state against a recognised baseline, so priorities are evidence-based
- Remediate in priority order, closing the highest-risk gaps first rather than the easiest
- Embed policy, basic cyber hygiene and staff training so good practice sticks
- Stand up measurement and board reporting so progress and risk are visible
Anchor it to a recognised framework
You do not need to invent the controls. Anchor the programme to an established framework so it is credible to customers, insurers and auditors: the NCSC 10 Steps to Cyber Security for a plain-language baseline, Cyber Essentials for a certifiable minimum, and ISO 27001 or the NIST Cybersecurity Framework where customers expect a managed system. Our guides on ISO 27001 and SOC 2 versus ISO 27001 help you choose which one your market actually requires.
Building it without a permanent hire
Most organisations building their first programme cannot yet justify a full-time security chief, and do not need one. A virtual CISO, also delivered as CISO as a service, owns the programme end to end for an agreed number of days a month, then hands over a running system rather than a dependency. Part of that programme is a tested incident response plan, so a breach becomes a process rather than a panic.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
Daniel has built security programmes from the ground up inside multi-site and private-equity-backed businesses, and knows how to sequence the work so the highest risks close first and the board can see progress from the start.
Frequently asked questions
What is a security programme?
A security programme is the managed, risk-based system around your controls: who owns security risk, how decisions are made, what you are protecting and why, and how the board gains assurance the controls work. It is what turns scattered security tools into a defensible posture.
How long does it take to build a security programme?
A structured first quarter, around 90 days, is enough to get from nothing to a working, defensible programme: accountability, a risk-based assessment, priority remediation, embedded policy and training, and board reporting. Maturing it continues from there.
What framework should we use?
Anchor to a recognised one so it is credible externally: the NCSC 10 Steps for a plain baseline, Cyber Essentials for a certifiable minimum, and ISO 27001 or the NIST Cybersecurity Framework where customers expect a managed system. Let your market’s requirements decide which.
Do we need a full-time CISO to build a security programme?
No. Most organisations building their first programme cannot justify a full-time security chief and do not need one. A virtual or fractional CISO owns the programme for an agreed number of days a month and hands over a running system rather than a dependency.
Where should we start?
Start by establishing who owns security and assessing your current state against a recognised baseline, so your priorities are evidence-based. Closing the highest-risk gaps first beats buying more tools, which is the usual instinct and rarely the right one.
NEXT STEP
See where your security actually stands
The free Board Cyber Governance check shows where the accountability and control gaps sit before a customer, insurer or regulator finds them. When you want to talk it through, a conversation is the next step.
Board Cyber Governance check Book a conversation