Sentry CTO

Fit

We are a bad fit for plenty of businesses.

Every provider's website says they are right for you. Most of the time that is not true, and both sides find out several months and a signed agreement later.

So here is the list we would give you privately if you asked. If you recognise your business in it, we would genuinely rather you found out now.

Lowest price is your deciding factor

We are not the cheapest option in Arizona and we are not trying to become it. If two quotes are in front of you and the cheaper one wins by default, take it. You will be happier, and we would spend the whole engagement defending line items.

You just want to call after something breaks

To be clear, you absolutely do get to call us when something goes wrong, and we will fix it. But if reactive support is the whole arrangement you want, we are the wrong firm and an expensive way to buy it. Most of our work happens before anything breaks, which means most of our value is invisible on any given Tuesday. Clients who only value the fixing end up feeling they are paying a lot for a quiet month.

Nobody has final authority on security decisions

This is the one that actually predicts failure, and we learned it the hard way. If every partner has an equal veto and there is no agreed process for settling disagreements, security controls get eroded one exception at a time until nothing is left.

You want the controls but not the constraints

Real security means people lose administrator rights on their own laptops, logins take an extra step, and some software cannot be installed on a whim. We will work hard to make that as painless as possible. We cannot make it invisible.

You do not have time to be involved

The assessment needs access to your people. Implementation needs decisions from someone with authority. Quarterly reviews need an hour. If nobody on your side has that time, the work stalls and you pay for something you are not receiving.

Your technology genuinely is not critical

If your business would carry on largely unaffected without computers for two weeks, you do not need what we sell. Very few businesses are in this position, but the ones that are should not be paying us.

You are larger than about 250 people

We can comfortably support organizations up to roughly 250 employees today. Past that, you are better served by a firm with a larger bench, and we would tell you so rather than stretch and let service slip.

What went wrong once

A client we lost, and why.

A software company came to us through an assessment. The briefing went well, well enough that they were ready to sign at the end of it. Three-year agreement, everyone pleased.

Then the controls went in, and the friction started. Conditional access rules on their Microsoft accounts meant sign-ins from unexpected places got challenged. Application controls meant developers could not install whatever they wanted, whenever they wanted. Nobody had administrator rights on their own laptop any more.

Individually, every one of these complaints was reasonable. Developers genuinely do need to install things. That is not the part we got wrong.

What we got wrong was not establishing, at the start, who decided.

They were a partnership where everyone held roughly equal authority. When one partner wanted a control loosened, there was no process for weighing that against the risk, just a request, and then frustration when we asked to talk it through first.

We proposed fixes more than once. Dedicated development machines, kept deliberately outside the strict controls so their engineers could experiment freely without exposing the rest of the business. Cloud workstations that could be rebuilt in minutes. We offered to remove specific controls outright if they would document the decision.

None of it was taken up, and none of it was formally declined. The conversations simply did not happen. At renewal they left and hired one of their interns to manage IT instead.

What we actually learned

The temptation is to conclude they were a difficult client. That is not the lesson, and it would not have helped.

The lesson is that security is a series of trade-off decisions, and trade-off decisions require someone empowered to make them. We had assumed that because the leadership team agreed in the briefing, they would agree later when it cost them something. Agreement in a room where nothing is being given up is not the same as agreement.

We now ask, before an engagement starts: when we recommend something your team finds inconvenient, who decides? If the honest answer is “everyone, and we would have to discuss it,” we say so plainly, and sometimes we recommend against working together.

It cost us a three-year client to learn that. We would rather it did not cost you anything.

The other side

Who this does work for.

Technology failure would genuinely hurt, lost days cost you real money or real trust

Someone has the authority to make a decision and make it stick

You would rather hear an uncomfortable finding than a reassuring summary

You handle information other people trusted you with, client files, donor records, member data

You have outgrown whatever arrangement got you this far

You want a technology function, not a vendor you call when something breaks

If you are still reading

You are probably the sort of business we work well with.

Fifteen minutes. We will ask what prompted you to look and tell you honestly whether we are the right people for it, including when we are not.

We would rather disqualify ourselves on the first call than on the fourth.