Direct answer. On day one I would build the controls that are cheap now and very expensive to retrofit: identity, tenant isolation, encryption and key handling, logging, and an automated build pipeline. I would defer controls that are expensive to run and easy to add later. I would deliver them as platform defaults so developers get them for free, and defend the cost as a small, explicit share of engineering spend tied to the enterprise deals it unlocks.
1. Deciding what goes in from day one. Score each candidate control on three questions: How hard to retrofit once data and customers exist? How much risk does it remove (what could we lose)? Do enterprise buyers ask for it? Retrofit pain is the main sorting rule.
| Build now | Why | Defer or keep light |
|---|
| Central sign-in with multi-factor and least-privilege roles | Hard to untangle later | Fine-grained attribute-based access for every feature (permissions decided by attributes such as department, region and data label rather than a few fixed roles) |
| Tenant isolation in the data layer | Retrofitting after launch is a rewrite | Separate infrastructure per tenant (offer later, as a paid tier) |
| Encryption in transit and at rest, managed keys | Cheap with cloud defaults | Customer-managed keys (the customer holds the encryption key and can cut off access by revoking it) |
| Audit logging with tenant and user context | Evidence and detection depend on it | Full security analytics platform |
| Infrastructure as code (the cloud setup written as reviewed text files instead of clicked together), dependency and secret scanning in the pipeline | Cheap, catches issues early | Formal bug bounty (a paid program inviting outside researchers to report vulnerabilities) |
| Backups, tested restore | Resilience baseline | Multi-region active-active (full copies running in several regions, all serving traffic at once) |
The right-hand column holds real options that a specific trigger brings forward: a bank customer asks for customer-managed keys, an outage review demands multi-region, a regulator asks for finer access rules. The other three deferred options get triggers too: separate infrastructure per tenant when a customer will pay for a dedicated tier, a formal bug bounty once the first external audit or penetration test has been closed out, and a full security analytics platform when log volume makes manual search unworkable. Each deferred option has a named trigger, so deferring is a scheduled decision rather than neglect.
2. Without hurting performance or speed.
- Secure by default (paved road): a service template with authentication, tenant scoping, logging and secure headers (response headers that make browsers enforce protections such as HTTPS-only) already wired in. The secure path is the easiest path.
- Cheap on the hot path: token verification and authorisation checks happen at the gateway with caching; heavy work (scanning, analytics) is asynchronous, off the request path. Measure latency in load tests with controls on, and set a budget agreed with the performance owner.
- Fast feedback: pipeline checks run in minutes and block only high-severity findings; the rest become tickets. Exceptions need an owner and an expiry date.
3. Evidence as a by-product. Because controls are code and pipeline steps, they leave records automatically: access reviews from the identity system, change approvals from pull requests, configuration state from infrastructure as code, logs from the platform. When an enterprise customer asks for a SOC 2 report (an independent auditor's attestation report on controls, measured against the AICPA Trust Services Criteria), much of the evidence already exists.
4. Estimating and defending cost (illustrative numbers). Assume 20 engineers at a loaded cost of 200,000 each (salary plus benefits, equipment and overhead, not salary alone), so engineering costs 4,000,000 a year. If the paved road and review process consume 3 percent of engineering time, that is 120,000. Add 60,000 for tooling. Total 180,000, which is 4.5 percent of engineering cost. Compare it with revenue at stake: if enterprise security reviews are blocking two deals of 250,000 annual value each, that is 500,000 a year. The point is not the figures (replace them with your own) but the shape: a named cost, a named benefit, and a review each quarter of whether the spend still earns its place. The 180,000 excludes the SOC 2 audit fee and an annual penetration test, which I would add as separate lines once an audit is scheduled, and the 500,000 is revenue, so I would compare the cost with the margin on it rather than the revenue. Retrofitting later is the alternative cost, and it is usually larger and arrives during a deal.
Pitfalls. Buying a tool stack before knowing the risks; adding a heavy gate that developers route around; promising maturity you cannot evidence. What would change my call: if the first customers are regulated, move audit logging and key management forward; if the data is low-sensitivity, defer more.