About

Most assessments ask
what you have.

Almost none ask what happens next. I built the one that does.

I have spent 27 years responsible for keeping businesses running — the kind of role where one person handles the servers, the network, the backups, the email, the vendors, and the phone that rings at 2 a.m.

In that time I have learned that the businesses that come through an attack and the businesses that do not are not separated by which security products they own. They are separated by how many of their assumptions turn out to be true.

Every business has a set of beliefs about its own security that nobody has ever checked. The backup that runs but has never been restored. The tool that is installed but not monitoring what you think it is monitoring. The provider you assume is handling something that was never in scope. The plan in a folder nobody has read.

None of that is carelessness. It is what happens when the people responsible are busy, which is always.

An incident is where you find out which beliefs were true.
That is a terrible time to find out.

What an incident actually looks like

Most people picture
the wrong thing.

They picture files getting encrypted, restoring from backup, and going back to work. That is not usually how it goes.

You do not know how long they were inside

Encryption is the end of the intrusion, not the beginning. Attackers are commonly in an environment for weeks before anything visible happens. Which means your backups may already contain what let them in — and that single unknown is what turns a restore into a rebuild.

Recovery is not the end

Modern ransomware operators take the data before they encrypt it. A business can restore successfully, get back to work, and be contacted days later demanding payment to stop the data being published. Recovering your systems does not recover your leverage.

The real cost is running without systems

Not the ransom, and usually not the technology. It is the weeks of manual process, the double entry into two systems while the new one comes up, the exhaustion of the two or three people carrying it. That bill arrives long after the attack is over and appears in nobody's cost-of-breach statistic.

The questions come fast

Which systems are affected. Whether you can still take orders. When a backup was last actually restored — not “the job reported success.” Who has authority to shut things down. What access an outside provider still has. How long until you are operating again. Every one is answerable in advance. Almost nobody has looked.

Why nothing existing solved it

A questionnaire records what you believe.
It cannot tell you whether it is true.

That is the whole problem. Answer sixty questions, get a score and a PDF. The tool takes the exact assumptions that fail during an incident and converts them into a number that makes you feel prepared. It is worse than nothing, because nothing at least leaves you appropriately uncertain.

The serious alternatives are real, and they are priced for organisations with a security department and a budget line to match. The businesses I have spent my career inside — 10 to 250 people, one IT generalist or an outside provider, an owner who knows something matters but not what — have had nothing between a $99 checklist and a $50,000 engagement.

That gap is where most of the economy operates.

Why trust it

What I bring to it.

  • 27 years in IT operationsLong enough to have watched several waves of “this changes everything,” and to know which parts actually did.
  • Accountable, not advisoryA career as the person responsible for the decision, not the person recommending it to someone else. That changes what you pay attention to.
  • Small-business constraints, first-handNo team to delegate to, no budget for redundancy, a hundred other things needing attention. This is built for that reality because it is the only one I have worked in.
  • Operations experience, not theoryMost security guidance is written by people who have never been responsible for restoring a business to working order. That shapes what you think matters — and most of what matters is not technical.
  • Translation between technology and the businessThe hardest part of security in a small company is getting leadership, IT, and outside providers working from the same facts. That problem is why this product exists.

What I won't tell you

The limits, stated plainly.

It will not tell you that you are secure. Nobody can say that honestly, and anyone who does is selling you something.

It will not make you compliant or certified. It uses recognised security guidance — including NIST 800-171 — as a source of good recommendations. That is not a certification, and I will not let the product imply otherwise.

It will not scare you into buying. The report is built to give you a credible picture, including what you are already doing well. Fear is easy to manufacture and it produces bad decisions.

It will not replace your IT provider. It will make the conversation with them considerably more specific.

The assessment
I wish had existed.

If something in the back of your mind says you do not really know where you stand, that instinct is right.

Start your Guided Preview

Free. No credit card. No sales call.