HireACISO

Security with no budget: what to do free

Most of what a customer security review asks about is configuration and process rather than product. A company with no budget and one focused week can honestly answer yes to a majority of a standard questionnaire.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A Canadian startup of 10 to 50 people with no security budget can do most of what matters for nothing. The highest value controls are settings you already own and processes you already half do. Turning on multi-factor authentication, removing access on the day people leave, writing down who owns security and keeping a vendor list will carry you through most of a customer questionnaire. What free work cannot get you is a report someone else signs. A first audit, a penetration test or a certification all cost real money.

This site sells matches to security providers. Treat the list below as the work to finish before you speak to any of them, including us.

The free list, in order of value

Ordered by risk removed per hour spent, not by how a framework groups them. The whole list is roughly 25 to 40 hours of work for one person who knows your systems, spread over three or four weeks.

What does the free list get you past?

What free work answers, and what it does not
The askFree work isBecause
A customer security questionnaireMostly sufficientMost items are about configuration and process, and a dated no is acceptable on the rest
A cyber insurance applicationMostly sufficientUnderwriters ask about access control, backups, endpoint protection and a response plan
Investor diligence at a Series ASufficientThey check ownership, disclosure and contracts rather than certification
A buyer asking for a penetration test reportNot sufficientAn independent third party has to run it. $8,000 to $25,000 CAD
A buyer asking for SOC 2 or ISO 27001Not sufficientBoth require an external firm to issue an opinion or certificate
A regulated buyer with a supplier standardPartly sufficientDepends entirely on their standard, and you should ask to read it

Two of the three common security pressures on a company under 50 people can be handled without buying anything. The third, insurance, gets cheaper when the free work is done: the application is a control questionnaire with a premium attached.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Free tiers that are genuinely adequate at this size

Not an endorsement of products, which change, but of categories where the free or included tier does the job at 10 to 50 people.

Identity and single sign-on
Whatever your email suite includes. Both major business suites include enforced multi-factor authentication and conditional access on tiers most companies already pay for. Check what you own before buying an identity product.
Dependency and secret scanning
Included free in the major code hosting platforms for private repositories. Turning it on is a settings change, and the value is in triaging the first batch rather than in the tool.
Cloud configuration checks
Every major cloud provider has a built-in posture or security hub view with a free tier that surfaces the obvious problems. It will find open storage and over-broad roles without a third party product.
Policy templates
Freely available, and worth what a template is worth: a starting structure. A policy describing something you do not do is worse than no policy. An auditor or a customer will test it against reality.
Log retention
Not a product. A retention setting, usually defaulted low to save money, and the difference between being able to answer what happened and not.

What not to do when you have no budget

Three shortcuts that cost more than they save.

Do not download a policy pack and publish it unread. Twenty policies describing a company you are not creates commitments you will fail. Five that match what you do is stronger, and it is what an experienced reviewer expects at your size.

Do not put a trust badge or a certification claim on your site without the certificate. Buyers check, and being caught ends the review.

Do not run your own penetration test and call it independent. Internal testing is worth doing and it is not what the question asks. Answer honestly and put a date beside it. What a real test costs is on penetration testing cost in Canada.

The one thing worth paying for first

If a small amount of money appears, spend it on advisory hours against a specific decision rather than on a tool. Canadian hourly advisory runs $200 to $400 CAD. Four hours on choosing between SOC 2 and ISO 27001, or on reading a customer's security addendum before you sign it, beats a year of a product subscription. The wrong framework choice costs a year of the wrong work.

When free work stops being enough

Any one of these means the free list has done its job and something has to be bought. A customer has named a report and a date. You had an incident, or a near miss you could not investigate because the logs were gone. The person doing the free work has stopped, which is the most common and the least noticed.

The cheapest useful purchase is usually a one-off assessment at $5,000 to $15,000 CAD that tells you what to do next in your own environment, not a monthly retainer. Engagement models compares what each purchase buys, and the vCISO check will tell you if it is still too early.

When the free list runs out

Tell us what you have done and what triggered the search. We will tell you the smallest thing worth buying next, which is often a single assessment rather than a retainer.

Get matched

Common questions

Can a 25 person company really pass a security review with no spend?

Pass, often yes. Pass with every answer as a yes, no. A reviewer at a mid-sized buyer expects a supplier of 25 people to have gaps and is assessing whether you know where they are. The free list above turns a company from one that cannot answer into one that can answer accurately with a small number of dated commitments, and that is usually the difference between a stalled review and a signed contract.

What is the highest value hour we can spend?

Enforcing multi-factor authentication on the accounts that can change production or read all the email. It takes an afternoon, it is free on tiers you already pay for, and it removes the attack path behind the majority of small company incidents. Nothing else on this page competes with it per hour spent.

Are free policy templates worth using?

As a structure, yes. As a deliverable, no. Take the headings, write two paragraphs each about what your company actually does, and delete every section that describes a control you do not operate. Five honest policies beat a twenty document pack, and the pack is easy for a reviewer to test by asking one question about the fourth one.

Should we buy a compliance platform on its free tier?

There is rarely a useful free tier, and the paid ones start around $8,000 CAD a year. More importantly the tool solves evidence collection for an audit you have not committed to. If a customer has named a report and a date, the platform becomes a reasonable purchase alongside the audit. If they have not, it is a subscription for a dashboard.

Who should do this work if nobody owns security?

One named person, given the time, ideally whoever set up your cloud account. Splitting the list across four people means none of it finishes. Who owns security when there is no CISO covers how to make the assignment stick, which mostly comes down to protecting the time rather than choosing the right person.