The first time I ran the scan across a batch of real small-business domains, I assumed the tool was broken.

The results were too bad to be true. Not one or two domains with a setting out of place - most of them, failing the most basic checks a business can fail. So I did what you do when a measurement looks wrong: I stopped trusting the measurement. I picked a handful of domains I could verify by hand, checked them the slow way, and compared. The tool was not broken. The domains were.

That afternoon is the closest thing Red Bridge Cyber has to an origin story, and it did not begin as a business. It began as a nagging feeling that I could not properly see my own back door.


I did not build any of this to sell it. I built it because I wanted to know whether my own systems were exposed, and I could not find an honest, affordable way to answer the question.

The market, as far as I could tell, offered two things. At the top end, enterprise security platforms priced for organisations with a security team and a budget line to match - sensible products, aimed at people who are not me. At the bottom end, a scattering of tools that were mostly a shiny interface with very little underneath: a reassuring green dial, a score out of a hundred, a PDF you could wave at someone. I have a long-standing distrust of a confident dashboard perched on top of a problem nobody has actually looked at, and these did nothing to earn it.

So I did the thing I keep doing. I started building something small to answer my own narrow question - is my email properly protected, is my domain configured the way I assume it is - and it grew, because each answer turned up two more questions standing behind it.


Before I could measure anyone, I had to decide what I was measuring. That turned out to be the hard part, and the interesting one.

"Secure" is not a number. But "the basics are in place" can be, if you are honest about what the basics are. So the first real run of the tool was not a customer engagement and was never meant to be one. It was a way to calibrate - to take a sample of ordinary Australian small-business domains and ask a plain question of each. Can a stranger send email that looks convincingly like it came from you? Does your domain quietly give away more than you would like? Are the settings that are supposed to protect you actually switched on, or merely assumed to be?

That last one deserves a plain-English aside, because it is the failure I saw most. There is a small set of records a business publishes that tells the rest of the internet, in effect, "these are the only servers allowed to send email as us - treat anything else as a forgery." Setting them up is a modest afternoon's work and costs nothing. Left undone, anyone can send email that wears your name, to your customers, and the systems on the other end have no clean way to tell it apart from the real thing. It is the loading dock left open while the front door gets a deadbolt.

I expected the sample to sort itself into a familiar shape. A few excellent, a few terrible, most somewhere in the muddling middle, getting by. That is how most things distribute, and I had no particular reason to think the security basics of a random business would break the rule.

They broke the rule. The muddling middle I expected barely existed. What I found instead was a long tail of businesses with almost nothing in place - no working defence against someone impersonating their email, domains configured years ago and never revisited since, the digital equivalent of a shop that fits a good lock to the front door and leaves the loading dock wide open, because nobody ever quite thinks about the loading dock.

The reason it stays broken is almost boring, which is exactly why it stays broken. These are settings you configure once, years ago, on a Friday, and then never look at again - because when they are wrong, nothing visibly breaks. Your email still sends. Your website still loads. There is no error message for "a stranger could send mail as you"; the failure is silent by design, and silent failures are the ones that outlive everyone who might have fixed them. A business notices a broken website in minutes. It can run for a decade without noticing a wide-open one.


I want to be careful with the numbers here, because this is exactly the kind of claim that gets inflated for effect, and I would rather undersell it than join that parade.

I am not going to quote you a precise percentage from that first sample, partly because one early sample is not a national statistic and I refuse to dress it up as one. What I will say is that the failure of the basics was not the exception. It was the pattern. Enough of the domains failed the simplest checks that I stopped being surprised when one did, and started being mildly surprised when one did not. The good ones stood out precisely because they were rare.

And these were not careless people. That is the part that stayed with me. They were competent operators running real businesses - trades, clinics, small firms with staff and customers and a decade of hard graft behind them. The gap was not effort, and it was not intelligence. It was that nobody had ever handed them a plain answer to a plain question, so the question simply never got asked. The security industry mostly talks to itself, in its own language, at its own prices. The people most exposed were, quietly, the people that conversation had never been meant to include.


Here is the turn I did not plan.

I set out to build a measurement so I could check my own systems. What I ended up with was the recognition that the measurement itself was the thing worth making - that most small businesses did not need another enterprise platform they would never finish configuring. They needed the plain answer first. Someone to run the basic checks, tell them in ordinary words what was open and what was not, and then stop, rather than upsell them into a fear they had no way to evaluate.

The baseline drove the product, in other words, not the other way around. I did not start with a thing to sell and go hunting for a problem it solved. I started with a problem I could not stop looking at, measured it as honestly as I could, and the shape of something useful fell out of the measuring. That order matters more than it sounds. A product built to justify itself will always find you a reason you need it. A measurement built to tell the truth will sometimes tell you that you are fine - and being willing to say that is most of what makes the rest of it believable.


I still think about that first afternoon, and the reflex I had when the results came back: this can't be right, the tool must be broken.

It is worth sitting with why that was the instinct. The results were not implausible. They were just uncomfortable, and a comfortable explanation - a bug - was right there for the taking. I very nearly took it. If I had, there would be no Red Bridge Cyber, and I would still be quietly assuming that most businesses had their basics sorted, because surely, in the year we live in, they must.

So the question I would put to you is the one I almost dodged that day. When a measurement of something you would rather not examine comes back worse than you hoped, what is your honest first move - do you check the thing, or do you check the tool? Most of the exposure I have seen since did not come from people who looked and failed. It came from people who never ran the scan at all, because some part of them already suspected what it would say.