Awakening Security

Request the PDF

Enter your email and we will send you a code; your request is then recorded at once, and once I have reviewed it a link to download your copy reaches your email.

By continuing, your email and progress are kept in your account. Privacy

* The file is for your own reading; sharing follows the terms of use, and commercial use is not permitted.

Reading progress
0 of 34 sections read
26 / 34

Chapter 24

24The Roadmap: From Freelancer to Growing Agency

4 min read26 of 34Read it in the book · page 137

“You do not need everything on day one; you need the right next step.”

The journey to better security can seem overwhelming: do you need every tool and policy from day one? The answer is no. Effective security is a maturity process that grows with the size and complexity of the business. This chapter offers a staged roadmap, so you find the right step whether you are a freelancer or a growing agency, and security becomes a manageable, incremental process rather than an all-or-nothing task.

The security roadmap: from freelancer to growing agencyThe security roadmap: from freelancer to growing agency
The security roadmap: from freelancer to growing agency
Text in this figure

Stage 1 · Freelancer (one person) · Password manager · Two-factor auth · Disk encryption · VPN and 3-2-1 backup · Stage 2 · Small agency (2–10) · Team password manager · Unified cloud platform · One-page policies · Onboarding, offboarding · Stage 3 · Growing agency (10+) · Security lead, risk assessment · Device management (MDM) · Training, phishing sims · Prepare for 27001 · Security maturity grows with the business; nobody needs everything on day one · Figure 31

Stage One: The Freelancer’s Essential Toolkit (One Person)

Focus: personal digital hygiene and securing your workstation, with low-cost, high-impact measures that protect your work and your clients’ data.

Master your passwords

  • A password manager: Non-negotiable: Bitwarden with its excellent free plan, or 1Password, for a unique, strong password for every account.
  • Two-factor authentication everywhere: On email, cloud storage, bank accounts and social media, using an authenticator app such as Google Authenticator or Authy instead of SMS wherever possible.

Secure your workstation

  • Full-disk encryption: FileVault on macOS or BitLocker on Windows Pro, so data cannot be read if the computer is stolen.
  • Antivirus and anti-malware: A reliable solution such as Malwarebytes or the built-in Microsoft Defender, kept up to date with regular scans.
  • Automate updates: The operating system and all applications set to update automatically; outdated software is a prime target for attackers.

Strengthen your workflow

  • A reliable VPN: Essential for working safely anywhere outside your home.
  • A 3-2-1 backup system: Your live files on the computer, a local copy on an external drive (Time Machine or Windows File History), and an automatic cloud service such as Backblaze.
  • Secure home Wi-Fi: As in Chapter 14: change the router’s default password and enable WPA3.

Stage Two: First Steps for a Small Agency (2–10 Staff)

With the first employee or collaborator, the model changes: from personal security to shared, consistent practices across the team. Focus: central management, foundational policies and team-wide awareness.

Centralise your tools

  • A team password manager: A business plan such as 1Password Business or Bitwarden Teams with shared vaults, and secure provisioning and revocation of access.
  • A unified business cloud platform: Google Workspace or Microsoft 365 with critical admin controls: enforcing two-factor authentication, monitoring suspicious logins, and granular sharing permissions.

Create foundational policies

You do not need a hundred-page manual, but you do need to document your expectations in one-page policies:

  • Acceptable use: How company equipment and accounts are used.
  • Passwords: Mandates the team password manager and two-factor authentication.
  • Remote work: Security requirements for working from home or on the move.
  • AI use: Approved tools and what may be entered into them, as in Chapter 18.

Formalise onboarding and offboarding

  • Onboarding checklist: Secure tools, basic security training, and signing the policy documents.
  • Offboarding checklist: The most important: on the last day, access is revoked immediately from every system: email, cloud storage, password manager, social media tools and AI tools.

Stage Three: The Growing Agency’s Path to Compliance (10+ Staff)

As you grow, your risk profile and your clients’ expectations grow too, and major clients, especially in regulated sectors, may ask about your formal security posture and certifications. Focus: formal governance, proactive risk management and preparing for certification.

Governance and risk management

  • Appoint a security lead: One person formally responsible for the agency’s security, such as the operations manager or a senior team member with technical competence.
  • A first formal risk assessment: Using the principles in Chapter 8, and the foundation of your journey to ISO 27001.

Advanced security and training

  • Endpoint management (MDM): Such as Jamf for Apple devices or Microsoft Intune, to enforce encryption and screen lock on all company devices.
  • Formal awareness training: A structured programme with regular phishing simulations, as in Chapter 23.

Preparing for ISO 27001 certification

  • An external consultant: A specialist in small businesses, saving months of effort and keeping you on track.
  • A gap analysis: Comparing your current practices with the standard’s requirements.
  • A full management system: Building the comprehensive system described in this book, so you become a certified, trusted partner even for the most security-conscious clients.

2026 Update

Add a fourth stage for anyone building or providing AI to clients: once 27001 is stable, start the AI system register and impact assessments, then extend the system towards ISO 42001. An organisation certified to 27001 shortcuts much of the way thanks to the shared structure.

Lessons Learned

  1. 1Security is a maturity journey that follows the growth of the business.
  2. 2Freelancer: password manager, two-factor authentication, encryption, 3-2-1 backup and a VPN.
  3. 3Small agency: centralised tools, one-page policies, and formal onboarding and offboarding.
  4. 4Growing agency: a security lead, risk assessment, preparation for certification, then 42001.

Tip: use ← → to move between sections.