- Don't worry about proper password storage until you are at 4-10 employees and have a prototype out the door? No, proper password storage is one of those things you deal with at the very beginning.
- Not worrying about a password safe until 11-30 employees? Using something like keepass, lastpass, etc, is trivial and should be started from day one as well. Your developers should already be in the habit of using one anyway.
- There should be decent password-locking screensavers on all computers. That way a smash-and-grab computer theft only amounts to a $1,500 asset loss, no critical data loss. There is nothing here about hard drive encryption, so a password locking screensaver is going to do nothing to prevent loss of sensitive data in a smash and grab.
I also dislike this attitude, mentioned in the 1-3 employees stage:
And from a security standpoint, you shouldn’t be doing very much.
In our industry, we keep on complaining about horribly poor security practices all over the internet. Attitudes like that just persist the poor state of affairs.