Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
OPINION 11 JUN 2026 · 3 MIN

Our first year: what we got wrong

We started by handing people a long report and a number. Neither helped them. Here is what we changed, and why.

TOMOS BEVAN · FOUNDER
SHARE LinkedIn X Email
OPINION cover image

In our first year we did the thing every security company does. We ran the checks, we found everything there was to find, and we handed it over: forty-odd items, ranked by a severity scale we understood and nobody else did. It felt thorough. It was, in truth, a way of moving the work from us to the customer and calling it a report.

The problem showed up quickly. People read the first two pages, felt vaguely alarmed, and did nothing - not because they did not care, but because we had given them no way in. A sole trader does not have an afternoon to triage findings. A growing team does not want a document; they want to know the one thing to fix before Friday. We had confused completeness with usefulness.

The jargon made it worse. We wrote “TLS misconfiguration” when we meant “the padlock on your website is set up wrong and some browsers will warn your customers.” We wrote a score out of a hundred that no client could ever explain to their accountant or their insurer. A number you cannot defend is not reassurance; it is another thing to worry about.

So we rebuilt the whole thing around a shorter question: what are the three changes that remove the most risk for the least effort, and what does each one actually protect? Everything else still gets recorded, but it sits behind that. The report leads with plain sentences and an order to do them in. The score went in the bin.

We are writing this down because we would rather be honest about the version we got wrong than pretend the good version arrived fully formed. If you took a report from us early on and felt buried by it, that was our fault, not yours. Ask us to send the short version. It is the only one we produce now.

WHAT TO DO
  • ✓Ask any security supplier for the three highest-value fixes first, in order.
  • ✓Refuse a single risk score unless they can explain what it measures.
  • ✓Insist findings are written in plain English, with the real-world effect named.
  • ✓Book a short follow-up to check the top fixes actually landed.