Our first year: what we got wrong
We started by handing people a long report and a number. Neither helped them. Here is what we changed, and why.
In our first year we did the thing every security company does. We ran the checks, we found everything there was to find, and we handed it over: forty-odd items, ranked by a severity scale we understood and nobody else did. It felt thorough. It was, in truth, a way of moving the work from us to the customer and calling it a report.
The problem showed up quickly. People read the first two pages, felt vaguely alarmed, and did nothing - not because they did not care, but because we had given them no way in. A sole trader does not have an afternoon to triage findings. A growing team does not want a document; they want to know the one thing to fix before Friday. We had confused completeness with usefulness.
The jargon made it worse. We wrote “TLS misconfiguration” when we meant “the padlock on your website is set up wrong and some browsers will warn your customers.” We wrote a score out of a hundred that no client could ever explain to their accountant or their insurer. A number you cannot defend is not reassurance; it is another thing to worry about.
So we rebuilt the whole thing around a shorter question: what are the three changes that remove the most risk for the least effort, and what does each one actually protect? Everything else still gets recorded, but it sits behind that. The report leads with plain sentences and an order to do them in. The score went in the bin.
We are writing this down because we would rather be honest about the version we got wrong than pretend the good version arrived fully formed. If you took a report from us early on and felt buried by it, that was our fault, not yours. Ask us to send the short version. It is the only one we produce now.
- ✓Ask any security supplier for the three highest-value fixes first, in order.
- ✓Refuse a single risk score unless they can explain what it measures.
- ✓Insist findings are written in plain English, with the real-world effect named.
- ✓Book a short follow-up to check the top fixes actually landed.
- Small Business Guide: cyber security NATIONAL CYBER SECURITY CENTRE ↗
- Choosing a cyber security supplier GOV.UK ↗
- What good security advice looks like for small firms COMPUTER WEEKLY ↗
Links open each publisher’s live coverage of this topic.