Professional Standards
How SSB Defence approaches competence, independence, documentation, professional judgment and client responsibility.
Version 1.0 — August 2026
1. Our Professional Standard
SSB Defence is a trade name used by StartSmartBusiness.com Inc.
We seek to provide technology, cybersecurity and risk-management services with professionalism, care, objectivity and respect for the client’s business.
2. Competence and Scope
We seek to perform work only where we have the knowledge, experience and capability required to provide meaningful assistance.
Where an issue requires expertise outside our scope, we will identify that limitation and, where appropriate, recommend involvement from another qualified professional. This may include legal counsel, privacy specialists, accountants, insurance professionals, certified assessors, specialist engineers, penetration-testing professionals, forensic investigators or other technical specialists.
We do not believe professional credibility requires pretending to know everything.
3. Evidence Before Assumption
Recommendations should be based on the best information reasonably available. Where appropriate, this may include direct technical observations, system configuration, vendor documentation, logs and records, interviews with business or technical personnel, applicable standards, authoritative regulatory guidance, testing and verification, and the client’s actual operational requirements.
We seek to distinguish between what we know, what we reasonably believe, and what still needs to be verified.
4. Business Context Matters
A technical finding does not exist in isolation. Before recommending a significant change, we seek to understand the business function involved, operational consequences, existing controls, business continuity requirements, cost, compliance obligations, technology dependencies and practical alternatives.
A technically ideal solution that creates unacceptable business disruption may not be the best recommendation.
5. Clear Communication
We seek to communicate findings and recommendations in language appropriate to the audience. Business owners and managers should understand what the issue is, why it matters, how serious it appears, what may happen if it is not addressed, what reasonable options exist and which decisions belong to management.
6. Professional Independence
Our recommendations should be based on what we reasonably believe is appropriate for the client.
Where SSB Defence may receive a referral fee, reseller margin, commission or other financial benefit connected with a recommendation, that relationship should be disclosed where it could reasonably affect the client’s understanding of the recommendation.
We do not believe a client should be unknowingly steered toward a product simply because it is financially advantageous to the advisor.
7. Conflicts of Interest
Potential conflicts of interest should be identified and managed appropriately. Where a conflict could reasonably impair—or appear to impair—our objectivity, we will seek to disclose it, manage it transparently, obtain appropriate agreement from the client, or decline or modify the engagement where necessary.
8. Confidentiality
Information obtained through a client relationship should be treated as confidential unless disclosure is authorized, required by law, necessary under an applicable professional or contractual obligation, or another legitimate basis exists.
Client information should not be used for unrelated purposes merely because we have access to it.
9. Responsible Access
Technology service providers may receive significant administrative access to client systems. That access creates responsibility.
We seek to follow principles such as least privilege, individual accountability, secure authentication, appropriate MFA, controlled remote access, logging where appropriate, removal of access when no longer required and avoidance of unnecessary shared credentials.
Administrative access should exist because it is needed—not because it is convenient.
10. Documentation
Important work should be documented at a level appropriate to the engagement. Depending on scope, documentation may include findings, recommendations, risks, decisions, exceptions, technology dependencies, changes made, recovery information, administrative arrangements and follow-up items.
Documentation should support continuity, accountability and informed decision-making.
11. Verification
Where a recommendation or control depends on something functioning correctly, verification should be considered.
- Patch deployed → confirm installation.
- Backup configured → test restoration.
- Account disabled → confirm access is removed.
- Firewall rule changed → confirm intended traffic behavior.
- System upgraded → confirm the business application still functions.
We do not consider configuration alone to be proof of effectiveness.
12. Change Management
Significant changes should be planned with reasonable consideration for business impact, backup and rollback, timing, compatibility, user communication, testing, recovery, security and operational verification.
Critical systems should not be changed casually simply because a technical update is available.
13. Risk Classification
Not every issue has the same urgency. We seek to prioritize findings according to factors such as likelihood, potential business impact, exposure, recoverability, regulatory or contractual consequences, safety or operational effect, and availability of practical controls.
Risk ratings should help management make decisions—not create unnecessary alarm.
14. Requirements vs. Best Practice
Where possible, we seek to distinguish among legal or regulatory requirements, contractual obligations, insurance requirements, industry standards, vendor requirements, recommended best practices and optional improvements.
A recommendation should not be represented as mandatory unless there is a reasonable basis for doing so.
15. Continuous Learning
Technology, cybersecurity threats, legislation, standards and vendor platforms evolve continuously. SSB Defence seeks to maintain relevant knowledge through ongoing technical learning, vendor and standards documentation, regulatory guidance, industry developments, testing and practical experience, and periodic review of our own methods and materials.
Professional competence requires ongoing learning.
16. Responsible Use of Tools and AI
Automation and artificial intelligence may assist research, analysis, documentation and workflow. They do not replace professional accountability.
Where tools materially influence an important recommendation, appropriate verification and human review should remain part of the process. Our broader approach is described in the Responsible AI Statement.
17. Escalation and Specialist Referral
Some situations require capabilities beyond general technology consulting. Examples may include active security breaches, complex digital forensics, significant privacy incidents, regulatory investigations, formal legal interpretation, specialized penetration testing, critical industrial safety systems, or certification and audit requirements.
Where appropriate, we will recommend escalation to a qualified specialist rather than attempt work outside our competence.
18. Honest Limitations
No assessment can identify every possible risk. No cybersecurity control can guarantee complete protection. No consultant can predict every technology failure or threat.
Professional service requires acknowledging uncertainty where it exists.
19. Client Responsibility
Professional advice works best when the client provides accurate information, appropriate access and timely decisions. Clients remain responsible for business decisions, unless a separate agreement expressly assigns a particular responsibility elsewhere.
Where a client chooses not to implement a material recommendation, the decision may be documented for clarity.
20. Our Standard
Our objective is to leave the client with a clearer understanding of the environment, better information for decision-making, reduced unnecessary risk, practical next steps and technology that better supports the business.
Questions regarding these standards may be directed to Email SSB Defence.
Version 1.0 — August 2026