How did you maintain compliance and security before you could have someone full time on it? How did you deal with audits? Did you hire an engineer full-time dedicated to this, outsource it, or do it yourself? (I ask because I do this now but at 8 people it's starting to take up too much of my time as CTO)
How does it work at your size now?