A Security Program From Scratch

Jesse Harris (Application Security at Filevine · Sr. Security Engineer)

SAINTCON 2025 · Day 3 · Main Track 3

Overview

In this insightful SAINTCON talk, Jesse Harris, an Application Security Engineer at Filevine, shares a pragmatic blueprint for establishing a security program from the ground up within an organization. The presentation targets a common, yet daunting, scenario: a security professional starting with "007" – zero budget, zero headcount, and seven years of accumulated technical debt. Harris distills his extensive experience into actionable strategies, focusing on cost-effective, high-impact solutions that can be implemented rapidly.

Watch on YouTube

Visual summary for A Security Program From Scratch by Jesse Harris
Visual summary for A Security Program From Scratch by Jesse Harris

Key moments

  1. 0:00 Introduction: Building a security program from scratch
  2. 2:00 Defining 'From Scratch': Zero budget, headcount, tech debt
  3. 2:40 Identifying core constraints: Time, budget, user acceptance
  4. 4:00 Leveraging time for research; 'good enough' is better
  5. 6:00 Prioritizing communication skills over hard technical skills
  6. 6:50 Three main pillars of a security program: Identity, Patching, Education

A Security Program From Scratch

Speakers: Jesse Harris (Application Security at Filevine, Sr. Security Engineer)

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=MAlSTRukT8E

Overview

In this insightful SAINTCON talk, Jesse Harris, an Application Security Engineer at Filevine, shares a pragmatic blueprint for establishing a security program from the ground up within an organization. The presentation targets a common, yet daunting, scenario: a security professional starting with "007" – zero budget, zero headcount, and seven years of accumulated technical debt. Harris distills his extensive experience into actionable strategies, focusing on cost-effective, high-impact solutions that can be implemented rapidly.

The talk emphasizes foundational security principles, leveraging free or freemium tools, and cultivating essential soft skills like communication. Harris provides a roadmap for organizations that are nascent in their security journey, demonstrating how to build a robust defense posture without significant financial investment or a large team. His approach prioritizes practical implementation over aspirational perfection, acknowledging that "good enough is better than the nothing that you're probably doing now."

This article delves into Harris's methodology, dissecting the core pillars of Identity, Patching, and Education, alongside specific tool recommendations and strategic advice for navigating common organizational constraints. It serves as a comprehensive guide for security practitioners tasked with initiating or significantly improving a security program under resource-limited conditions, highlighting the critical balance between technical controls and human factors.

Background

▶ Watch: Introduction: Building a security program from scratch (0:00)

The premise of Jesse Harris's talk resonates with many security professionals: inheriting a security landscape characterized by significant challenges and minimal resources. He paints a vivid picture of the "007" scenario – zero budget, zero headcount, and seven years of technical debt. This situation often arises in organizations that, in their early stages, prioritize rapid growth and feature development over dedicated security investment, leading to a reactive security posture and a backlog of unaddressed vulnerabilities.

Harris's personal journey into security, starting from support roles and progressing through companies like PGP, RSA, and Micro Focus, provides a relatable context. He highlights the common path where security responsibilities often fall to individuals who "just kind of follow into it" from IT or development, often becoming the first dedicated security hire. This individual is then faced with the monumental task of building a security program without the luxury of established processes, tools, or team support.

The core problem, as Harris identifies, is navigating a triumvirate of constraints: time, budget, and user acceptance.

  • Budget: Often, the initial security hire barely has a budget for their salary, let alone expensive security solutions. This necessitates a strong focus on free tiers, freemium models, and dirt-cheap alternatives. Harris notes that many companies have cottoned onto the "home lab" phenomenon, offering free personal use tiers hoping users will recommend their products professionally.
  • Time: While being the first security hire means no predefined job duties, offering a window for research and experimentation, this luxury diminishes rapidly as responsibilities accumulate. The initial period is crucial for leveraging this research time effectively.
  • User Acceptance: Users inherently resist change, especially if it's perceived as hindering their work. Security solutions must be largely transparent or clearly demonstrate a benefit to the user, requiring significant finesse and communication skills to implement successfully.

Harris stresses that the security professional in this role will wear many hats, making specialization difficult. The guiding philosophy is "good enough is better than nothing," viewing initial implementations as stepping stones. He also champions leveraging community resources (like the SAINTCON Discord, 801 Labs, Utah Home Labs) as invaluable, free sources of knowledge and support. Crucially, Harris argues that communication skills are paramount, even more so than hard technical skills, enabling the translation of technical risks into business terms for executives and fostering cooperation with end-users to prevent "shadow IT."

Key Findings

▶ Watch: Identifying core constraints: Time, budget, user acceptance (2:40)

Jesse Harris structures his approach to building a security program around three fundamental pillars: Identity, Patching, and Education. These pillars form the bedrock upon which any successful security program, especially one built from scratch, must stand.

  1. Identity as the Foundation: Harris emphasizes that understanding "who your users are" and "what devices they use" is the absolute starting point. This extends beyond simple HR lists to uncovering contractors, unmanaged devices (from eBay servers in closets to no-name IoT webcams), and employee-owned "bring your own disaster" devices. The ultimate goal is to centralize identity management through an Identity Provider (IdP), implementing Single Sign-On (SSO) across all possible services, and supplementing with a password manager where SSO is not feasible. This strategy directly combats password reuse, a primary vector for breaches, and leverages the advanced security features (like 2FA and anomalous login detection) inherent in modern IdPs.
  1. Patching as Continuous Hygiene: The talk highlights that technical debt, particularly in patching, is rampant. Many organizations operate with end-of-life operating systems or unpatched applications because there's no systematic refresh cycle or management. Harris advocates for robust endpoint management solutions that deploy agents to user devices and on-prem servers to identify and install missing patches for operating systems and applications. He extends this to network devices, emphasizing manual subscription to vendor updates and careful review of release notes. A significant finding in the application security realm is the pervasive issue of outdated dependencies in custom software, with Harris noting that "95% of my time is begging devs, please update your dependencies." Proactive dependency management and continuous scanning of cloud environments and codebases are crucial.
  1. Education as Empowerment: While acknowledging that users won't become cybersecurity experts, Harris insists on the necessity of user education. Beyond compliance-driven training (often mandated by cyber insurance questionnaires, which have grown from half a page to 10-20 pages), he advocates for positive, engaging, and practical security awareness. This includes gamified phishing simulations and regular, short, focused training sessions on topics like securing home networks or using password managers. However, a critical finding is that education alone is insufficient. Harris introduces "galaxy brain" defenses: highly effective, low-cost, and transparent technical controls like DNS filtering and email threat filtering. These act as a safety net, protecting users from common attacks (like Business Email Compromise, identified as a top financial loss vector) even when they inevitably make mistakes, recognizing that "computers are a lot easier to fix than users."

Overall, Harris's key findings underscore that a successful security program is built on foundational visibility and control (Identity, Patching), reinforced by informed human behavior (Education), and robust technical safeguards that protect users from themselves. The emphasis on communication and "saying yes" to user needs (while guiding them to secure alternatives) is a recurring theme, highlighting that security is ultimately a collaborative effort.

Technical Deep Dive

▶ Watch: Leveraging time for research; 'good enough' is better (4:00)

Building a security program from scratch requires a strategic selection of tools and methodologies, especially when constrained by budget and headcount. Jesse Harris provides a detailed technical roadmap, heavily favoring free or low-cost solutions that punch above their weight.

Identity Management

The first pillar, Identity, begins with comprehensive asset inventory:

  • User Inventory: Start with HR records but expect to find gaps like unrecorded contractors. Work with HR and accounts payable to close these.
  • Device Inventory: For physical assets, a simple spreadsheet is adequate initially. For a more robust, self-hosted solution, Snipe-IT offers a free version that can be run on a spare desktop. A hosted version costs around $400/year.
  • Network Asset Discovery: For office networks, RunZero (founded by Metasploit creator HD Moore) is highly recommended. Its free tier covers up to 100 devices and excels at deep fingerprinting (e.g., identifying specific printer models and firmware versions, or discovering rogue FTP services on network devices). While the free tier is limited, the paid tiers start at $5,000/year for 500 assets, reflecting its advanced capabilities. For basic network scanning, Nmap is a free alternative.
  • Identity Provider (IdP): Standardize on Microsoft Intra ID (formerly Azure AD) or Google, as most organizations already pay for one for productivity suites. Harris leans towards Microsoft due to their strong identity management capabilities, noting Intra ID's underlying Active Directory architecture. The goal is to implement Single Sign-On (SSO) "on all the things" to eliminate password reuse and leverage the IdP's built-in security features like strong two-factor authentication (2FA) and anomalous login detection. He points out the "SSO tax" by some vendors (e.g., GitHub requiring enterprise plans for SSO), but stresses its value.
  • Password Managers: Where SSO isn't possible, a password manager is crucial. 1Password is recommended for its reliability and affordability, avoiding the security issues seen with LastPass. Bitwarden is another good option. For extreme budget constraints, KeyPass can be self-installed, with databases stored on cloud drives (e.g., OneDrive, Google Drive) for accessibility. Even browser-built-in password managers are better than nothing.

Patching and Vulnerability Management

The second pillar focuses on ensuring systems and applications are up-to-date and secure:

  • Endpoint Management (User Devices):
  • Action1: A powerful free option for up to 200 endpoints, offering agents for Windows and Mac. It provides OS and application patching, a one-time vulnerability scan (paid for continuous updates), and the ability to run PowerShell or Bash scripts (e.g., to manage third-party packages via Winget or Chocolatey). It supports remote employees as a hosted solution.
  • NinjaOne: A paid alternative with Linux support and the option to bundle Endpoint Detection and Response (EDR) solutions like SentinelOne for as little as $3/device/month, significantly cheaper than retail.
  • EDR: SentinelOne is highly regarded, especially when acquired through RMM bundles due to volume discounts. Microsoft Defender for Endpoint (the enterprise version, not home) is a viable option if the organization already has E5 licenses.
  • Mac MDM: For Mac-specific management, Mosul is a cost-effective choice at $3/month/seat, compared to Jamf ($12/month/seat) or Intune (expensive). Apple's MDM capabilities are praised for robust features like firmware-level device locking.
  • Network Device Patching: For on-prem network gear (e.g., UniFi, Cisco, Palo Alto, Ruckus, Brocade), automated patching solutions are expensive. Harris advises a manual approach: subscribe to vendor email updates, meticulously read release notes, and schedule recurring maintenance windows to investigate and apply patches.
  • Cloud and Code Vulnerability Management:
  • Iikido: Strongly recommended for developers and cloud environments. It offers a free tier for up to 10 repositories and combines Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Cloud Security Posture Management (CSPM). Iikido prioritizes actionable vulnerabilities, only flagging issues with available patches, distinguishing it from more complex platforms like Wiz or Snyk.
  • Dependency Management: Developers often neglect updating software dependencies. Harris suggests integrating dependency updates into every sprint and leveraging tools like Large Language Models (LLMs) to identify breaking changes in package.json or similar files.

Education and User Protection

The third pillar focuses on informing and protecting users:

  • Compliance Training: KnowBe4 is the industry standard for comprehensive security awareness training, covering regulatory requirements like HIPAA, SOC 2, PCI DSS, and even OWASP Top 10 for developers. It also offers gamified phishing simulations.
  • Internal Training: Supplement compliance training with short (15-minute) monthly or quarterly sessions on practical topics like home network security, laptop physical security, or password manager usage. Emphasize positive reinforcement and practical code examples for developers.
  • "Galaxy Brain" Defenses (Automated User Protection):
  • DNS Filtering: Harris rates this as more critical than EDR. NextDNS is highlighted as a highly performant, effective, and cheap option at $4/year per employee. Cloudflare offers free DNS filtering and Zero Trust Network Access (ZTNA) for up to 50 users.
  • Email Threat Filtering: Given that Business Email Compromise (BEC) is a leading cause of financial loss, robust email protection is vital. Microsoft and Google's built-in tools require tweaking. Cloudflare provides free email threat filtering for up to 50 users (then $7/month/user). Proofpoint is a good paid alternative without a free tier.

The technical deep dive reveals a strategy of layering free and affordable tools to achieve broad security coverage, focusing on high-impact areas like identity, patching, and automated user protection. The speaker consistently emphasizes that these tools, while often basic or free, provide a significant improvement over no security at all.

Demo / Proof of Concept

▶ Watch: Prioritizing communication skills over hard technical skills (6:00)

Jesse Harris included live demonstrations of two key tools during his talk, showcasing their practical application in a home lab environment. While one demo encountered a minor hiccup, the descriptions and the successful demo provided concrete examples of his recommended solutions.

The first demonstration involved RunZero, a network asset discovery and fingerprinting tool. Harris intended to show his home lab's asset inventory dashboard. Unfortunately, the dashboard did not load during the live presentation due to a temporary issue ("mine's not working. Cool. I need to go figure that out."). Despite this, he effectively described RunZero's capabilities:

  • Deep Fingerprinting: RunZero excels at identifying devices with incredible detail, down to specific models of printers (e.g., "model Brother printer") and their firmware versions.
  • Service Discovery: It can uncover unexpected services running on devices, such as an FTP service on a printer, highlighting potential vulnerabilities.
  • Network Visibility: The tool reveals far more devices and services than anticipated on any given network, emphasizing the "bonkers" amount of hidden assets.
  • Cost: He reiterated that while the free tier supports up to 100 devices, the paid tier is now $5,000 annually for 500 assets, a significant increase from its original $99 offering. He noted that he would still pay for it due to its utility.

The second and more successful demonstration featured Action1, a free endpoint management solution for up to 200 endpoints. This demo provided a clear view of its capabilities:

  • Dashboard Overview: The Action1 dashboard displayed a summary of the environment, including vulnerability remediation status and device update compliance.
  • Endpoint Inventory: Harris navigated to a list of endpoints, showing details like endpoint names, comments, pending reboots, OS versions, and pending patches. This "at a glance" view helps identify devices needing attention.
  • Installed Software Report: A particularly useful feature was the installed software report, which helps discover "rogue stuff" installed by users on corporate laptops. Harris cited examples like Steam (for "carjacking simulator" – Grand Theft Auto) or even a Blue Iris NVR (Network Video Recorder) on a laptop with a small drive, highlighting inappropriate use of company assets. This report is valuable for identifying unauthorized or non-business critical applications.
  • Patch Management: He demonstrated the process of approving and forcing updates. Users can be given a 24-hour window for critical updates (like Patch Tuesday releases) before a forced reboot, ensuring timely patching.
  • Agent Deployment: Harris explained that Action1 provides a small installer package (e.g., an MSI for Windows) that can be easily distributed to users for self-installation, simplifying the initial setup process, especially for remote employees.

These demos, despite the RunZero glitch, underscored the talk's emphasis on practical, accessible tools that provide significant security benefits without requiring a large budget or complex on-prem infrastructure. Action1, in particular, was presented as a robust solution for managing and patching user endpoints effectively.

Defensive Implications

▶ Watch: Three main pillars of a security program: Identity, Patching, Education (6:50)

Jesse Harris's framework for building a security program from scratch offers several critical defensive implications for organizations, particularly those with limited resources.

  1. Prioritize Foundational Visibility and Control: Defenders should initially focus on gaining complete visibility into their assets and establishing core controls. This means meticulously inventorying all users (including hidden contractors) and all devices (managed, unmanaged, and IoT). Tools like Snipe-IT for asset management and RunZero for network discovery are crucial for this first step, as you cannot protect what you don't know exists.
  1. Centralize Identity and Enforce SSO: The most impactful defensive move is to centralize user identity through a robust Identity Provider (IdP) like Microsoft Intra ID. Implementing Single Sign-On (SSO) across all possible applications significantly reduces the attack surface by eliminating password reuse, leveraging stronger authentication mechanisms (like 2FA), and enabling the IdP's capabilities to detect anomalous login patterns. For services without SSO, a managed password manager (e.g., 1Password, Bitwarden) should be mandated to further combat password reuse.
  1. Automate Endpoint Patching and Implement EDR: Manual patching is unsustainable. Defenders must deploy endpoint management solutions (like Action1 or NinjaOne) to automate OS and application patching across all user devices and on-prem servers. This drastically reduces the window of vulnerability to known exploits. Furthermore, integrating an Endpoint Detection and Response (EDR) solution (e.g., SentinelOne, Microsoft Defender for Endpoint) provides crucial visibility into endpoint activities, enabling detection and response to advanced threats that bypass traditional antivirus.
  1. Proactive Vulnerability Management in Development: For organizations developing their own software, security must be integrated into the development lifecycle. This involves actively managing and updating software dependencies (a task often overlooked by developers) and using tools like Iikido for continuous SAST, DAST, and CSPM. Prioritizing vulnerabilities based on patch availability (as Iikido does) ensures that limited developer resources are focused on actionable fixes.
  1. Layer "Galaxy Brain" Defenses for Users: Recognizing that users will inevitably make mistakes, defenders must implement highly effective, low-cost, and transparent technical controls to protect them. DNS filtering (e.g., NextDNS, Cloudflare) and robust email threat filtering (e.g., Cloudflare, Proofpoint, or tweaked built-in IdP features) are paramount. These act as a crucial perimeter defense against prevalent threats like phishing and Business Email Compromise (BEC), which are major sources of financial loss.
  1. Cultivate Communication and "Say Yes": Perhaps the most critical defensive implication is the need for security professionals to be enablers, not gatekeepers. By mastering communication skills and adopting a "yes, and here's how we can do it securely" approach, defenders can build trust, foster user acceptance, and prevent shadow IT. This collaborative mindset ensures that security initiatives are embraced rather than circumvented, leading to a more resilient overall security posture.

In essence, Harris's advice empowers defenders to rapidly establish a strong, multi-layered security program by strategically deploying free or low-cost tools, focusing on core vulnerabilities, and building bridges with both management and end-users. The emphasis is on tangible progress and continuous improvement, rather than waiting for an ideal, fully funded security environment.

Key Takeaways

  • Prioritize the Three Pillars: Begin building a security program by focusing on Identity, Patching, and Education. These foundational elements provide the highest return on investment for organizations starting with limited resources.
  • Leverage Free and Freemium Tools: Utilize cost-effective solutions like Snipe-IT, RunZero (for small networks), Action1, Iikido, NextDNS, and Cloudflare to establish robust controls without significant budget outlays.
  • Centralize Identity with SSO: Implement a strong Identity Provider (IdP) (e.g., Microsoft Intra ID) and enforce Single Sign-On (SSO) across all possible services to combat password reuse and leverage advanced authentication features like 2FA.
  • Automate Patching and Deploy EDR: Implement endpoint management solutions for automated OS and application patching, and deploy Endpoint Detection and Response (EDR) (e.g., SentinelOne or enterprise Defender) for enhanced visibility and threat detection across all devices.
  • Implement "Galaxy Brain" User Defenses: Supplement user education with highly effective, low-cost technical controls like DNS filtering and email threat filtering to proactively protect users from common attack vectors such as phishing and Business Email Compromise (BEC).
  • Master Communication and Collaboration: Develop strong communication skills to translate security risks into business terms for executives and foster user acceptance by framing security as an enabler, not a blocker, adopting a "yes, and here's how we can do it securely" approach.

About the Speaker(s)

Jesse Harris, known online by his handle "Elto," is a seasoned security professional currently serving as an Application Security Engineer at Filevine. His journey into technology began early, cutting his teeth on a Commodore 64 in preschool and receiving a hand-me-down 286 PC from his grandfather in 1989. This early exposure to computing sparked a lifelong passion, leading him to maintain an extensive home lab with over-engineered networks and numerous servers.

Harris's professional career followed a common trajectory into security, starting in support roles before transitioning into dedicated security positions. His experience includes working at well-known companies such as PGP and RSA, as well as time at Micro Focus (which encompassed entities like Novell, Attachmate, and OpenText). He recounts his first significant security incident in 1999, involving busting a credit card fraud ring and collaborating with "three-letter agencies," an experience that further solidified his path in cybersecurity. Jesse Harris brings a wealth of practical knowledge and a pragmatic approach to security challenges, particularly those faced by organizations with limited resources.

All talks from SAINTCON 2025