2
2 Comments

Nobody buys security until they've been hacked. I'm building a business around that frustrating truth

"Eh, we're a small shop, who would hack us?"

I've heard this exact sentence more times than I can count. And I've watched the sequel play out just as many times: six months later the same store owner emails me in a panic. Site's serving pharma spam, Google slapped a red warning on the domain, orders dropped to zero. Suddenly budget is not a problem.

For a long time this drove me crazy. Now I'm trying to build around it instead of against it.

My project is Guardfos - flat monthly security plans for WooCommerce stores. Malware cleanup, hardening, off-site backups, monitoring. Nothing revolutionary, just done properly, by a human, without hourly billing.

The bet I'm most curious about: I don't lead with a sales page full of scary statistics. I lead with a free scanner. You paste your URL, it shows you what's actually wrong with your site - misconfiguration, exposed data, that kind of thing. No signup.

Our free online WordPress security scanner guardfos.com/scanner

My theory is that someone staring at a list of problems found on their own domain is 10x more likely to act than someone reading "43% of websites get hacked" for the hundredth time. But it's a theory.

So, question for the room: anyone else selling something people only want after the disaster? Insurance, backups, monitoring, legal protection... how do you reach them before the panic? Because "after" is a terrible business model for the customer, even if it pays better.

posted toAvatar for product Guardfos
Guardfos
  1. 1
    The scanner-first approach makes sense because it replaces an abstract risk with evidence from the customer’s own site. The part I would watch is whether the result creates useful urgency or simply fear. A score without a clear next action can still leave the owner waiting for the disaster. While building Cyber Decision Lab, the more useful pattern has been to separate observation, limitation and action: this is what the tool found; this is what it cannot prove; this is the next step you can take safely. That keeps a free check from being mistaken for a diagnosis or guarantee. Another way to create a meaningful pre-disaster moment is a short rehearsal rather than another statistic. Ask the owner to imagine that email, shared files and the store backend are unavailable, then see whether they can find the contact list, verify a backup and decide who has authority. The gaps become visible without manufacturing a scare. For your scanner, I would test whether a short prioritized “fix, verify, prepare” result converts better than a single risk score. It gives people progress they can understand before anything bad happens.
  2. 1

    I'd be careful with one thing.

    The challenge may not be getting people to care before the disaster.

    It may be deciding what event should feel like the disaster in their mind before one actually happens.

    That sounds subtle, but it can shape who acts, who ignores it, and how the scanner gets interpreted.

    I wouldn't make that call casually in a thread.