Philosophy

Core Principles

The cybersecurity principles this site is designed around - not a marketing list, the actual reasoning behind how the assessment, scoring, and recommendations are built.

01

Proactive, not reactive

Waiting for an incident to find your gaps is the most expensive way to learn about them. Assessing, monitoring, and fixing ahead of time is consistently cheaper than recovering afterward - the entire reason this site exists is to move that discovery earlier.

02

People, process, and technology - not technology alone

A well-configured firewall behind an untrained employee and no documented process is still a weak posture. Real security improvement requires progress across all three, together, not a single expensive tool standing in for the other two.

03

A culture, not a department

Security isn't something the IT team owns on everyone else's behalf. Every person who clicks a link, sets a password, or handles data is part of the control surface - the goal is a culture people grow into, not a policy document nobody reads.

04

Defense in depth

No single control is perfect, so no single control should be load-bearing. Layer defenses so that one failure - a missed patch, a clicked phishing link - doesn't cascade into a full compromise on its own.

05

Assume adversaries have AI-augmented capabilities

Convincing phishing and voice/video impersonation are now cheap and fast to produce - an attacker doesn't need to have adopted AI themselves to benefit from tools that already do. This site treats AI-powered social engineering as a baseline assumption for every organization, not a special case reserved for those running AI systems - the same reasoning behind why its AI Readiness & Governance questions apply to everyone, not just organizations using AI.

06

Zero trust

Trust is not something a network location should grant automatically. Every request gets verified explicitly, regardless of whether it originates inside or outside the perimeter - the perimeter itself is no longer the control.

07

Least privilege

Access should match what a role genuinely needs to do its job, nothing more. Excess privilege sits quietly until the one day an account is compromised, at which point it becomes the attacker's privilege too.

08

The CIA triad

Confidentiality, Integrity, and Availability - the three properties "secure" actually breaks down into. A control that protects one can quietly undermine another; good security design keeps all three in view at once, not just the one that feels most urgent.

09

Segment the problem, not just the network

Looking at an entire security program at once is paralyzing. Breaking it into smaller, contained pieces - by function, by system, by risk - the same way network segmentation contains a breach, makes the work tractable and the containment real.

10

Decide from data, not instinct

Gut feeling about where the risk is usually points at the most visible problem, not the most likely one. Structured assessment, scoring, and trend tracking exist precisely to replace that instinct with evidence.

11

Improvement is a loop, not a destination

There's no final state where an organization is simply "done" being secure. Threats, infrastructure, and staff all change continuously, so the assessment is built to be re-run on a cadence, not completed once and filed away - the same loop this site's own animation is built around.