Our Commitments
What clients can expect from SSB Defence in every recommendation, conversation and engagement.
Version 1.0 — August 2026
1. Business First. Technology Second.
Technology exists to support the business—not the other way around. Before recommending a product, platform or technical change, we seek to understand the business function it supports, the problem being addressed and the consequences of changing it.
2. We Will Explain the Reason
Clients should understand why a recommendation is being made. Where we recommend a significant change, we should be able to explain what problem it addresses, what risk it reduces, what it will cost, what disruption may be involved, what alternatives were considered and what may happen if no action is taken. The final decision belongs to the client.
3. We Will Not Recommend Change Simply for the Sake of Change
Existing technology may remain appropriate where it can continue to be supported, secured, recovered and operated responsibly. Where aging or unsupported technology creates material risk, we will identify that risk and discuss practical options rather than assuming complete replacement is always the answer.
4. We Will Consider the Total Cost
Where appropriate, our recommendations consider hardware, software and subscriptions, licensing, implementation, migration, IT administration, backup and recovery, security, training, support, Internet or provider dependency, upgrade requirements, business disruption and eventual replacement or exit costs.
5. We Will Respect Client Ownership and Control
The client's business information belongs to the client. We believe organizations should understand where their information is stored, who can access it, how it is backed up and how it can be recovered or moved if circumstances change.
Where practical, we favour decisions that preserve reasonable data ownership, portability, recoverability, administrative control and vendor choice.
6. We Will Be Clear About Risk
Cybersecurity does not eliminate risk. Our responsibility is to help clients identify, understand, prioritize and manage risk. Where risk cannot reasonably be eliminated, we will discuss ways it may be reduced, transferred, monitored or consciously accepted.
7. We Will Distinguish Requirements From Recommendations
A legal requirement, contractual obligation or mandatory security control is different from a recommended improvement. Where something represents our professional recommendation rather than a mandatory requirement, we will say so.
8. We Will Not Use Fear as a Sales Tool
Cybersecurity risks are real. They do not need to be exaggerated. We will not intentionally use fear, uncertainty or technical complexity to pressure a client into purchasing unnecessary products or services.
9. We Will Respect Operational Reality
A technically ideal solution that prevents the business from operating is not necessarily a good solution. We seek to understand operational realities before recommending changes. Where immediate replacement is impractical, interim controls, isolation, recovery planning or staged modernization may sometimes provide a better path.
10. We Will Prioritize Recovery as Well as Prevention
We consider backup, recovery, business continuity, system restoration, provider outages, hardware failure, ransomware, data corruption and operational workarounds. A resilient business should understand not only how it protects technology, but how it continues operating when technology fails.
11. We Will Verify Where Verification Matters
A configured control is not necessarily a functioning control. Where appropriate, important technology processes should be verified rather than assumed.
- Scheduled updates → verify installation.
- Backups → test restoration.
- Security controls → confirm operation.
- Access removal → verify access is gone.
- System changes → verify the business function still works.
12. We Will Protect Confidential Information
Information entrusted to SSB Defence will be handled according to appropriate privacy, confidentiality and information-security practices. Sensitive client information should not be placed into public website forms or inappropriate third-party services.
13. We Will Use AI Responsibly
Artificial intelligence can improve research, documentation and analysis, but it does not replace professional accountability. Where AI is used, we remain responsible for evaluating its output and applying appropriate human judgment.
14. We Will Acknowledge What We Do Not Know
Technology is too broad and changes too quickly for any individual or organization to be an expert in everything. Where an issue falls outside our expertise or requires another qualified professional, we will identify that limitation rather than pretend otherwise.
15. We Will Seek Practical Solutions
Not every business needs enterprise-scale technology. We seek recommendations proportionate to an organization's size, risk, operations, regulatory obligations, technology environment, internal capabilities and budget.
16. Our Commitment
Our relationship with a client should leave that organization with a better understanding of its technology—not greater dependence on us simply because the technology has become more complicated.
Questions about these commitments may be directed to Email SSB Defence.
Version 1.0 — August 2026