
Security Baseline: What It Actually Means for a Company With No Security Team
A 70-person professional services firm gets a vendor security questionnaire from a prospective enterprise client. Question four asks whether the company maintains a documented security baseline. The COO forwards it to the office manager who handles IT vendor renewals, because there is no one else to send it to, and the honest answer is that nobody is entirely sure what the term covers. The company has antivirus software, a firewall, and a password policy nobody enforces. Whether that adds up to a "baseline" depends on who is asking and what they mean by the word.
That confusion is common, and it is not really about technology. It is about the fact that "security baseline" gets used as a catch-all term without a shared definition, which makes it easy for a growing company to assume it has one when it does not.
What "Security Baseline" Actually Means
A security baseline is a documented, minimum set of security controls that a company applies consistently across every device, account, and system it manages, tied to a recognized framework rather than improvised in-house. Three words in that definition do the actual work. Documented means it exists as a written standard, not tribal knowledge held by whoever set up the laptops. Consistently means it applies to every device and account, not the ones someone remembered to configure. Recognized framework means the baseline maps to an established standard that a client, insurer, or auditor can check against, not a list a well-meaning IT contractor put together from memory.
Buying an endpoint protection tool or turning on a firewall is not a baseline. Those are individual controls. A baseline is the documented floor that says which controls are mandatory, how they are configured, and how compliance is verified, applied the same way to the fifth employee's laptop as the seventieth. Most companies in the 25-to-200-employee range have pieces of a baseline scattered across different tools and vendor relationships. Very few have it written down as a single standard anyone in the company could produce on request.
The Confidence Gap the Data Keeps Finding
The clearest evidence that "we have security covered" and "we have a documented baseline" are different claims comes from the National Cybersecurity Alliance's 2026 Small Business Cybersecurity Awareness & Practices Survey, conducted in partnership with the Cybersecurity and Infrastructure Security Agency (CISA). The survey polled 1,000 small and midsize business leaders across ten industries, ranging from two-person shops to mid-market companies with a thousand employees.
The headline finding is a confidence-readiness gap. 86.3% of respondents rated their confidence in managing cyber risk as medium to very high. But more than half, 56.1%, could not confidently say their organization had maintained a clean security record over the past twelve months. Confidence and actual readiness are tracking two different realities in the same companies.
The same gap shows up at the control level. 86.8% of surveyed organizations have implemented multi-factor authentication somewhere in their environment, which sounds like strong adoption. Only 51.1% require it across all key business accounts. The report frames this as tools that get adopted but not operationalized: a company buys the control, switches it on for the systems that are top of mind, and never circles back to apply it everywhere it matters. A baseline exists specifically to close that gap, because it defines "everywhere it matters" in writing instead of leaving it to memory.
MFA is a useful example of why the gap matters. Microsoft's identity security team has found that multi-factor authentication blocks more than 99.9% of automated account compromise attempts, making it one of the highest-return controls available. A company that has MFA turned on for half its accounts is leaving most of that protection on the table, and without a documented baseline, nobody is tracking which half.
The Two Reference Standards Worth Building From
A company does not need to invent a baseline from scratch. Two vendor-neutral standards exist specifically for organizations without a dedicated security team, and they complement each other rather than compete.
CIS Controls Implementation Group 1 (IG1), maintained by the nonprofit Center for Internet Security, is described in its own documentation as essential cyber hygiene: a foundational set of 56 safeguards built specifically for organizations with limited in-house IT and cybersecurity expertise. IG1 is deliberately the highest-value, lowest-effort slice of CIS's full control set, designed to stop the most common, non-targeted attacks without requiring specialized staff to implement.
CISA's Cross-Sector Cybersecurity Performance Goals (CPG), updated to version 2.0 in December 2025, take a different angle on the same problem. The CPGs define the highest-impact cybersecurity outcomes any organization should reasonably achieve as a baseline, regardless of industry or size, and version 2.0 aligns them directly to the NIST Cybersecurity Framework 2.0, adding a "Govern" function that puts leadership accountability on the same footing as technical controls.
The practical relationship between the two: CPG answers what a leadership team should be accountable for and why it matters, organized around governance, identification, protection, detection, and response. IG1 answers exactly which technical safeguards make that accountability real, safeguard by safeguard. A company building its first baseline does not have to choose between them. Mapping CPG's outcomes to IG1's specific safeguards is how a documented baseline gets written in the first place, instead of staying a list of good intentions.
What Belongs in the Baseline When Nobody Owns Security Full-Time
Both standards cover more ground than a growing company without a security team can tackle at once. The controls below are the highest-leverage starting point, based on where IG1 and CPG overlap most directly.
| Control Area | What "Baseline" Requires | Why It's High Priority | Typical Owner |
|---|---|---|---|
| Identity and access | MFA enforced on every account, not just email | Blocks 99.9%+ of automated account attacks | IT lead or outside partner |
| Patch management | Defined patch cadence with tracked completion | Closes the gap attackers exploit fastest | IT lead or outside partner |
| Backup and recovery | Backups tested with an actual restore, not just running | A backup that has never been restored is unverified | IT lead or outside partner |
| Endpoint protection | Managed, centrally monitored across every device | Extends coverage past whatever shipped with the laptop | IT lead or outside partner |
| Access reviews | Quarterly review of who has access to what | Catches access nobody remembered to revoke | Operations or IT lead |
Each row is a documented standard, not a one-time project. Turning on MFA once is a task. Requiring it on every account, checking that requirement quarterly, and writing down what happens when a new account does not comply is a baseline. That distinction is exactly where the National Cybersecurity Alliance data shows most companies currently fall short.
Who Owns This When There Is No CISO
Below roughly 25 employees, an owner or office manager can usually hold this informally. Above 200, most companies have been forced to formalize it, often by a cyber insurance renewal, a client's vendor security review, or a compliance deadline. Companies in between are the ones most likely to have pieces of a baseline scattered across tools with no single owner and no document tying it together.
The most common ownership model at this size is not a full-time security hire. It is an existing IT lead or operations executive who holds nominal responsibility, paired with an outside partner whose job is specifically to keep the baseline enforced day to day: patching on schedule, MFA verified quarterly, backups actually tested. That is the core of what Elevaire's Foundation IT service is built to do: device management, patch oversight, security baseline enforcement, and a quarterly review that keeps the baseline a living document instead of a one-time write-up that goes stale within a year. For companies whose existing IT support already handles day-to-day tickets well, Foundation IT is commonly layered in specifically to own the baseline itself, rather than replacing support that is already working.
What This Costs Compared to a Dedicated Hire
The alternative most companies consider is hiring a dedicated security analyst. According to the Bureau of Labor Statistics, the median annual wage for information security analysts was $124,910 as of May 2024, the most recent published figure. That number buys one person's time, not full baseline coverage. A single analyst does not typically cover governance documentation, quarterly access reviews, backup testing, and 24/7 patch monitoring on top of whatever else lands on their desk.
For most organizations in the 25-to-200-employee range, closing the baseline gap does not require that hire at all. It requires deciding which standard to build from, writing the baseline down, and putting a specific owner, internal or outside, against enforcing it on a fixed schedule rather than leaving it to whoever remembers.
Frequently Asked Questions
How much does building a security baseline actually cost?
It depends far more on labor than on tooling. Most of the underlying controls, MFA, patch management, endpoint protection, are features of platforms many companies already pay for; the cost is usually in the work of documenting the standard and enforcing it consistently. That is typically a fraction of the $124,910 median cost of one dedicated security analyst, whether delivered through existing IT staff time or an outside partner engaged specifically for baseline enforcement.
Do we need to replace our current IT support or MSP to do this?
No. A documented security baseline sits on top of whatever device and network support a company already has. The gap at most growing companies is not that IT support is doing a bad job; it is that nobody has been assigned to own writing the baseline down and checking it on a schedule. That ownership can be added alongside existing IT support rather than in place of it.
Is a security baseline the same thing as SOC 2 or HIPAA compliance?
No, though they overlap. A security baseline is the set of technical controls a company applies to every device and account. A compliance framework like SOC 2 or HIPAA is a formal audit process built on top of controls like these, with its own documentation, evidence, and third-party verification requirements. A solid baseline makes pursuing a compliance framework later considerably faster, since most of the underlying controls are already in place.
Do we need to hire a security specialist to have a real baseline?
Not necessarily. CIS Controls IG1 was built specifically for organizations without dedicated security staff, and CISA's CPGs are designed to be achievable by any organization regardless of size. Most companies in Elevaire's client range close the gap by assigning ownership to an existing IT lead paired with an outside partner for ongoing enforcement, rather than adding a full-time security hire.
How long does it take to put a baseline in place?
The core controls in the table above, MFA enforcement, a patch cadence, tested backups, managed endpoints, and quarterly access reviews, can typically be documented and largely implemented within 60 to 90 days for a company that has not started. The harder part is not the initial rollout; it is keeping the baseline enforced afterward, which is why ongoing ownership matters more than the first sprint.
How do we get started?
Start by writing down what currently exists against the control areas above: where MFA is and is not enforced, whether patches follow a defined schedule, and when backups were last actually restored rather than just running. That audit alone usually reveals which gaps are most urgent. From there, CIS Controls IG1 or CISA's CPGs give a ready-made structure for turning that list into a documented standard instead of a set of good intentions.
Ready to Put This Into Practice?
Schedule a free consultation and let's talk through what this means for your organization specifically.
Schedule a Free Consultation