Most systems are built for the good day.

Software gets designed around the path where every input is valid, the network holds, and everyone behaves. That path is the easy half, and it is the half most vendors test. The expensive half is everything else.

A wall-mounted network panel of uniform grey switches with a single switch flipped to red.

Assume the credential gets reused

People reuse passwords across the tools they use for work, and no policy document has ever changed that. So the design question is not whether a password leaks, it is what an attacker can reach once one does. Separating access by role limits the blast radius to something survivable.

Assume the backup is untested

Most small businesses have backups running. Far fewer have ever restored one. Those are completely different states, and you find out which one you are in on the worst possible day. Restores get tested on a schedule here, and you get the result in writing.

Assume the vendor disappears

Any setup that only one company can maintain is a bet on that company staying reachable and reasonable. Domains, hosting, and administrator access are registered in your name so the answer to a bad relationship is a transfer, not a rebuild.

Assume nobody reads the manual

A control that gets in the way of doing the job gets worked around, and the workaround becomes the real system. Security that survives contact with a busy office has to be the easier path, not the harder one. That constrains what is worth deploying at your size.

Security is an economic argument.

Attackers are rational operators working a cost and return calculation. They are not chaotic, and they are not personally interested in you. They spend effort where the return is highest for the least work.

That is good news for a small business, because it means you do not need an enterprise budget. You need to stop being the cheapest target in your bracket. Most of that is unglamorous work: current patches, separated accounts, real backups, and an offboarding process that actually runs.

What you get

  • A written map of what you have
  • The failure modes that matter at your size
  • A fixed quote to close the worst of them
  • Documentation that outlives the engagement

What you will not get

  • A compliance checklist sold as security
  • Tooling you cannot operate without us
  • Fear used as a closing technique
  • Recommendations we cannot justify in dollars

Where the effort goes

  • Access separation before new products
  • Tested recovery before detection tooling
  • Patching before policy documents
  • The boring controls, done properly

Where this comes from.

This is not a marketing position invented for a services page. Chris Armour is the author of The Adversarial Architect, a book series on designing systems from the attacker's point of view, covering the shift from building software that works to understanding how it gets taken apart.

The same reasoning drives the client work. Publication details will be posted here when the first book is released.

Find out what breaks first.

The audit is the honest starting point. It tells you what you have and what it would cost to fix, whether or not you hire us to do it.

Get a quote