When entrepreneurs and founders make the decision to build software and bring their idea to life, it kicks off a focused effort (and perhaps a mad dash) to create a minimum viable product (MVP) with just enough feature power to make those first few sales that may eventually fuel the tool to grow into something bigger and more impactful than the original MVP. The basic cycle might look like this:
Have software idea
Build MVP with minimal features
Find first customers
Validate MVP
Add features to MVP toward a more robust application
What may be missing if the founder isn’t locked into these topics are the focus and budget to add key organizational and software security controls that should have been included early on in the software development MVP process.
Ideally, any feature growth would be accompanied by appropriate organizational and security controls through maturity phases. Organizational controls are focused on governance and process, whereas security controls enable technical and operational safeguards.
Building Foundations for the Future
While not all leading-edge security practices can always be implemented into early-stage software tools, it is imperative that these controls keep pace to avoid the following challenges:
Creating “security debt” that will handicap your growth.
Potential customers walking away from the software because you are unable to prove certain controls are in place.
Irresponsibly developing software solutions that are insecure.
Where these controls are not implemented due to budget constraints, consider alternative technologies and process changes that might not be as efficient, but still mitigate the security risks associated.
This is a balancing act that many software tools face as they seek to build not only the software but create an organization to support it; however, not addressing product features and security foundations at the same time certainly introduces several technical and organizational challenges that may end up jeopardizing customer trust in the application and ultimately your organizational goals.
This challenge may become a lessened risk based on new AI technologies as some of the solutions to these challenges will be built into programming tools. These tools will propel development teams and solve an aspect related to the time and focus; but there will still be a cost element that shifts to the use and dependence on the AI technology. Additionally, governance and compliance expectations will continue to rise, introducing new complexities and reinforcing the need for deliberate development oversight alongside increased AI reliance.
If on reflection, you recognize that you are in a budget strapped software build, this an excellent time to look back and ask yourself three pivotal questions.
Do we really have product market fit and know we have customer commitment for the software solution?
Are we priced correctly to capture the full reality of building and maintaining a feature rich and secure solution?
Do we need to consider angel or early-stage investment opportunities to provide additional capital to build out these features?
The reality is that this concept may feel like it would only apply to small startup businesses, but this features vs. foundations challenge can be found in organizations of all sizes. Perhaps the questions above shift toward, “Do we have the organizational commitment, and is our funding challenge a budgeting exercise?” No matter the size, this becomes a question of discipline and commitment to drive toward organizational, process, operational, and security excellence which comes at a cost of time and resources.
Reality Checks
Compliance and security should be part of the plan from the beginning. If there isn’t a meaningful investment of time and money built into your operating model to address both, that is a red flag.
All business leaders have to make a strategic decision when it comes to governing and managing risk; do they chase the minimum to be compliant or do they build a business process (and operating model) that proactively addresses and mitigates risk before it becomes a liability.
Application:
Do you have a list of organizational, technical or security trade off decisions you have made?
Do you have a clear roadmap and tipping point for implementing that list of organizational, technical, or security gaps?
Would your current pricing allow for implementing these foundations and maintain a healthy margin for maintaining, investing in, and growing the business?
Would you like to discuss this topic further? Contact Brian Howell from Crestview.io


