"Eh, we're a small shop, who would hack us?"
I've heard this exact sentence more times than I can count. And I've watched the sequel play out just as many times: six months later the same store owner emails me in a panic. Site's serving pharma spam, Google slapped a red warning on the domain, orders dropped to zero. Suddenly budget is not a problem.
For a long time this drove me crazy. Now I'm trying to build around it instead of against it.
My project is Guardfos - flat monthly security plans for WooCommerce stores. Malware cleanup, hardening, off-site backups, monitoring. Nothing revolutionary, just done properly, by a human, without hourly billing.
The bet I'm most curious about: I don't lead with a sales page full of scary statistics. I lead with a free scanner. You paste your URL, it shows you what's actually wrong with your site - misconfiguration, exposed data, that kind of thing. No signup.
Our free online WordPress security scanner guardfos.com/scanner
My theory is that someone staring at a list of problems found on their own domain is 10x more likely to act than someone reading "43% of websites get hacked" for the hundredth time. But it's a theory.
So, question for the room: anyone else selling something people only want after the disaster? Insurance, backups, monitoring, legal protection... how do you reach them before the panic? Because "after" is a terrible business model for the customer, even if it pays better.
I'd be careful with one thing.
The challenge may not be getting people to care before the disaster.
It may be deciding what event should feel like the disaster in their mind before one actually happens.
That sounds subtle, but it can shape who acts, who ignores it, and how the scanner gets interpreted.
I wouldn't make that call casually in a thread.