Most cybersecurity conversations with clients start in the wrong place. Someone brings up ransomware or ties it to a recent headline, and within minutes the discussion is about which tools to buy. That’s backwards. A strategy that starts with products ends up as a pile of overlapping licences nobody fully understands, including the client.
A practical strategy starts with what the business needs to protect, how much disruption it can tolerate, and what it can realistically operate. Everything else follows from those three answers.
Start with what actually matters to the business
Before recommending anything, you need a short, honest list of what would genuinely hurt the client if it were lost, exposed, or unavailable. For most small and mid-sized businesses this is a shorter list than they expect: customer records, financial systems, email, and whatever line-of-business application runs their core operation.
This isn’t a formal risk assessment with a scoring matrix. It’s a conversation with the owner or finance lead that answers one question: if this system went down for a day, or this data leaked, what would it cost us? That conversation tells you where to spend effort first, and it gives you language to justify the plan later when someone asks why you’re recommending a particular control.
Separate what’s foundational from what’s situational
Every client needs a baseline regardless of industry: patched systems, managed endpoint protection, multi-factor authentication, filtered email, and backups that are actually tested, not just scheduled. None of this is exciting, but skipping it to jump to more advanced controls is how most breaches happen. Attackers overwhelmingly go after the gaps in basic hygiene, not sophisticated zero-days.
On top of that baseline, some clients need more because of what they do. A firm handling client funds needs tighter access controls and more rigorous logging than a local retailer. A business with remote staff needs stronger identity controls than one where everyone works from a single office with a locked door. The baseline is non-negotiable; the layer above it should match the actual risk profile, not a generic checklist.
Build the strategy around three questions, not a tool list
Once you know what matters and what’s foundational versus situational, frame the strategy around three questions: how do we stop the common stuff, how do we notice when something gets through anyway, and how do we recover if it does. Every control you propose should answer one of these, and if it doesn’t, it probably doesn’t belong in the plan yet.
This framing also makes it much easier to explain to a non-technical owner.
