A company of twenty people has usually arrived there without ever deciding how its technology should work. Accounts were created as needed, access was granted by whoever asked, laptops were bought individually, and the shared drive grew organically. Nothing is broken, so nothing gets attention — until the first security questionnaire from a customer, or the first departure that turns awkward.
The single highest-return decision is one identity provider. Every account — email, code repository, cloud console, design tools, payroll, project tracker — reachable through one login, with multi-factor authentication enforced. This is not primarily a security purchase, though it is the best one available; it is an operational one. It means adding someone takes minutes and removing someone takes one action rather than a mental list of eleven services that nobody has written down.
That list is the second decision. Write down every service the company pays for or depends on, who owns it, what it costs, and who has administrative access. Most companies at this size discover a handful of subscriptions nobody remembers buying, one paid on a former employee's personal card, and at least one system where the only administrator has left. Producing this list takes an afternoon and it is the foundation for everything else.
Then offboarding, treated as a checklist rather than as goodwill. Someone leaving is not a security problem because people are dishonest — it is a problem because access nobody revoked stays valid indefinitely, and an account with no owner is an account no one is watching. The checklist is short: disable the identity, revoke tokens and application passwords, transfer file ownership, remove from shared accounts, collect the laptop, rotate any shared credential they knew. Run it the same day.
Fourth, decide about devices before you have forty of them. Full-disk encryption on, screen lock enforced, operating system updates not indefinitely deferrable, and a way to wipe a lost laptop remotely. Lightweight device management achieves all of that and is not expensive. It is also the thing enterprise customers ask about most often after multi-factor authentication, so doing it early converts later into a sales advantage rather than a remediation project.
What you do not need at twenty people is a security policy suite, a compliance platform, or a dedicated hire. What you do need is one named person who owns this — usually whoever is most organised rather than most technical — with a few hours a month and the authority to say no. The companies that struggle at fifty people are the ones where this stayed nobody's job until a customer made it urgent.