Starter Kit. Idea 307 of 500. Cluster 15

Cybersecurity monitoring as a service for the small firms of the region

Back to the idea

Written for this site as a starting point, not from the book. Rules and fees change: ask the bodies named below before you spend money.

The mechanism, from the book

The proof exists in Malabe. What is missing is a thousand small versions of it.

The first step

Offer 10 small firms a free external security check, with their written permission: the websites they run, the email settings that allow spoofing, the exposed logins. Write each owner a one-page report in plain language with the three fixes that matter most. Then offer monthly monitoring at a fixed fee. The firms that sign after reading the report are your proof.

Who pays first
A small firm owner who has had a scare, a spoofed email or a hacked site, and will pay monthly not to have another.
What leaves today
Small firms in the region buy security from large foreign providers or go without, so the monitoring fees leave or the risk stays.

Ask first

  • Data Protection Authority. Ask what duties apply when your monitoring sees clients' personal data.
  • Information and Communication Technology Agency. Ask whether any national security guidance exists that small firms are asked to follow.

Check before you spend

Written permission from every firm before any test, what you may lawfully scan, and what liability cover you need if a client is breached.

Find out these three numbers

  1. What would a small firm pay each month for monitoring?
  2. How many of the firms you checked had a serious gap?
  3. What does one monitored firm cost you in tools and time?

The test

Does it keep value that now leaves the island, or build the proof that lets somebody else do so?

WITH500BUSINESS IDEASTO STARTTOMORROW

From the appendix of Why Not Sri Lanka? by Dr Maheshika Halbeisen. The idea and the mechanism are the book's; this kit was written for the site.