ASD

You Lead Two Lives. You Only Guard One.

By The Most Secure Man Alive | WISECLICK Ambassador

You live two lives. You only guard one.

Humour me with a small experiment.

Reach over and turn off your internet connection — switched off at the wall, the way you would before a long weekend away.

Now look at your business.

The email's gone. The banking with it. The calendar, the client files, the accounting, the card reader, the quotes half-written in the cloud, the folder with everything in it. The phone still rings — I'll grant you that — but the thing you'd reach for to deal with whatever it's ringing about has gone dark too.

In the space of one switch, most of your business simply stopped existing. Which tells you something it's easy to go years without noticing: that it was never really living where you thought.

There are two businesses trading under your name. The first is the one you can see — the premises, the keys, the float, the door you lock by pure instinct every night of your life. You're magnificent at guarding it, because it shouts: the client who needed it yesterday, the inbox that fills as fast as it empties, the quarterly tap on the shoulder from the tax office. It takes every hour you have, and it gets them.

The second is the one that just went dark in your hand. It has no premises and keeps no hours. It's made of nothing you can touch — the logins, the records, the trust account, the years of correspondence — and every last piece of it runs through that one connection you just pulled. It holds far more of your real worth than the premises ever did. And you leave it running, unattended, every hour of every day, because it has never once asked you not to.

Two lives, then. The smaller one, you guard by instinct. The larger one, you've never quite looked at.

So switch the connection back on — you can't run a business without it. But understand what you've switched back on to.

The door to your premises opens onto a quiet street: a few dozen souls a day, most of whom you'd know by sight. The connection opens onto the busiest thoroughfare that has ever existed — every machine on earth, filing past, day and night, without pause. And a great many try the handle as they go. Leave that connection sitting there and it'll be tried thousands of times over before tomorrow, by passers-by you'll never see or hear. A silent siege is a remarkably easy thing to underrate.

Here's where everyone braces for the bad news. So let me hand you the opposite, because it's true and it's better.

Whatever is rattling that connection has no idea you exist.

There's no clever figure in a hood who studied your business and chose it. The thing trying your handle is a machine — bored, tireless, indifferent — running down every connection on the internet in turn and trying them all exactly alike. It doesn't know your name, your trade, or your turnover. And here's the part to hold onto: it cannot pick a lock. It hasn't the wit or the patience. It can only walk through something it finds already open.

Which quietly dismantles the thing you were afraid of. You're not in a duel of cunning with a genius. You're one of several million connections on an endless street, and the only question that has ever mattered is whether yours happens to be left open.

The Australian Signals Directorate keeps the national count, and it's blunt about how this goes: a cybercrime reported in this country every six minutes. The serious ones rarely begin with anything ingenious — most often it's a borrowed password or a convincing email, the connection eased open from the inside rather than broken down from without. And professional-services firms — legal, accounting, consulting, advisory — are exactly the businesses where the valuables now live entirely in email, files, accounts and trust. When it lands on a small business, the bill tends to run into the tens of thousands; fifty-odd thousand dollars, on the most recent count. Very nearly always the price of one thing nobody got round to.

Because that's all it ever is. Not a dramatic failure — a forgotten thing. The account no one closed when the contractor moved on. The password reused because it was a Tuesday with nineteen other things on it. The update postponed to a quieter day that never came. The ordinary residue of a busy life — and the busier the life, the more of it there is.

So here is the one useful idea in all of this.

Before you simply switch it back on and forget what you just saw — have someone check the second business first. The old accounts. The reused passwords. The logins left exposed. The backup nobody's tested. The things that stay open only because no one's had a spare hour to look. Find them, shut them, and see they stay shut. Then get on with your day — same business, same hour, only now nothing's ajar.

That's the whole of what we do. The Ransomware Readiness Check is where it begins — thirty minutes, plain English, nothing to hand over — and at the end of it you'll know what you couldn't tell me at the start of this: whether anything's been left open, and what to see to first. Whatever turns up afterwards is usually the sort of thing dealt with in an afternoon, not a project.

30 minutes. No tech knowledge needed. $149.

Take the Ransomware Readiness Check →

Understand your exposure. Know what matters most.

I turned mine off once, years ago, and saw to it properly before I switched it back on. I've not had cause to think about it since. The least interesting afternoon of my year — and comfortably one of the best spent.

Stay protected, my friends.
— The Most Secure Man Alive


Frequently Asked Questions

How much does a cyber attack cost a small business?

The Australian Signals Directorate puts the average self-reported cost of a cybercrime incident to a small business in the tens of thousands of dollars — around fifty thousand on its most recent count. For a sole practice or small firm, that's rarely just the money — it's lost time, lost records, and lost client trust on top.

Are small professional firms — like legal or accounting practices — really at risk?

Yes. Legal, accounting and advisory firms hold exactly what attackers value: client records, financial details and confidential correspondence — and almost all of it now lives online. It rarely has anything to do with size. Most attacks are automated and impersonal, landing on whichever business left something open.

What is the Ransomware Readiness Check?

A plain-English review of the ways ransomware most often gets into a small business — passwords, devices, backups, email and account access — so you can see clearly what's already shut and what's quietly standing open. No jargon, nothing to install.

Do I need any technical knowledge, and how long does it take?

No technical knowledge at all — it's built for busy business owners, not IT people. It takes about 30 minutes.

What happens afterwards?

You'll know what's already shut, what's open, and what to see to first. From there, if you'd like, keeping it shut is handled for you — so it stays off your plate.


Get articles like this delivered to your inbox

Reading next

Leave a comment

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.