Some are like lions. They spend fortunes on technology and do not worry about predators. But lions are almost extinct and live in zoos. The lion answers every threat by buying something: a larger firewall, another appliance, the premium tier. A tool that no one configures or watches is scenery, not defense, and throwing more money than necessary at an IT problem is far more likely to waste time than to save any. The predator walks past the expensive box because there is no one standing behind it.
Some are like ostriches and ignore IT threats as if they were inventions of consultants and big tech. Who has not seen this? On a first discovery call, a business is found using one password for everything, and an extortion email has already arrived telling them to surrender. The warning is waved off. Within three days everything is locked, with no recovery possible. The business loses its records, and with them its hundreds of small clients, because all of it lived in one aging desktop contact manager on a single machine that was never backed up. The threat was not the invention. The refusal to hear it was the exposure.
Others are like zebras. They count on the size of their herd and hope that it's another zebra that will be eaten. This is the comfort of the crowd, and it is exactly what a supply-chain attacker feeds on. On 2 July 2021, the REvil gang exploited an authentication bypass in Kaseya VSA, the remote-management tool that managed service providers run across all their clients at once. One break reached about sixty providers and, by Kaseya's own count, between 800 and 1,500 downstream businesses were ransomwared in a single stroke, by outside estimates considerably more, against a demand near 70 million dollars.1 Sweden's Coop grocery chain, reached through its checkout provider, closed roughly 800 stores for nearly a week. The herd did not protect the zebra; it was the delivery route. The failure was not trusting a provider but trusting one blindly: a single shared key across thousands of clients, and no one asking who else a single break would open.
Then there are the gazelles that think that the most modern and nimble technology will outrun everything, as do the cheetahs. There is always something faster. In November 2025, Anthropic disclosed that a state-sponsored group had manipulated an AI coding assistant into running 80 to 90 percent of a live espionage campaign on its own, with human hands needed at only four to six decision points and requests firing at times several per second, against roughly thirty large organizations.2 Those targets were global banks, technology firms, and government agencies, not small businesses. The point is not that an adversary of that scale is coming for you; it is that the effort a single attacker can spend has collapsed, so the old wager, being too small and too quick to be worth the trouble, no longer holds. You cannot outrun a machine. You can shrink what it finds when it looks, and be a harder target than the firm next door.
Finally there's the pigeon who thinks he is safe in the cloud until an eagle comes out of nowhere and eats him in mid-air. The cloud is not safety; it is someone else's building. Amazon and Microsoft secure the datacenter, the hardware, and the walls, but their own model draws the line plainly: you own your data and identities, and you stay responsible for accounts, endpoints, and access, in every kind of cloud deployment.3 The security that decides who can reach you is the layer you add on top, not the one you rent, and the cloud will not supply it for you. In February 2024, an authentication bypass in the ScreenConnect remote-access tool that thousands of MSPs use, rated a maximum 10.0 in severity, was exploited across the internet, with researchers counting 18,188 internet-facing instances in a single day.4 For any that had not patched, the cloud they ran in did nothing to close the hole, because the broken lock was on the application, where the host's protection does not reach.
Nobody's ever completely safe with information technology, but the safest in both technology and the savanna is the one who is willing to learn from and trust others.
The creature with the highest chance of survival in the savanna is the youth. Walking side by side in the savanna, Masai tribesmen know that they can scare away lions, because lions are ambush predators that expect weaker animals to run.
The inability to learn, trust and adapt is the number one security vulnerability of the small and midsize business owner and CFO.
Instincts and habits are poor advisers in matters of security. Hubris is the ultimate vulnerability.
The animal that survives is the one with a guide it trusts and keeps learning from, and that is the work our Stewards do. They are senior technologists who stay current so a client does not have to: they close the door the lion left open, hear the threat the ostrich waved off, and add the layer the pigeon assumed was already there. Humility, not speed, is the security paradigm that lasts.
Concierge CIO Partners is a unified Guild of senior technologists providing dedicated, long-term fiduciary IT leadership to midmarket service firms. It offers a strategic alternative to fragile internal IT silos and to Managed Service Providers who advise you on what to buy and are paid on what you buy. With transparent unit pricing and an automated service catalog, the Guild eliminates administrative bloat and ensures every IT dollar spent and decision made directly drives your financial performance. The tools its Stewards run are not the shared commercial platforms installed across hundreds of thousands of businesses; each is dedicated and self-hosted on a server hardened to the applicable CIS Benchmark, so a break in someone else's tool is not a break in yours.
1 On 2 July 2021 the REvil ransomware group exploited an authentication-bypass vulnerability in Kaseya VSA; Kaseya estimated between 800 and 1,500 downstream businesses were affected, though researchers who responded to the incident put the number higher, with Huntress citing well over 1,000 and potentially thousands of small businesses; REvil demanded about 70 million dollars: CISA. Sweden's Coop closed roughly 800 stores after its checkout provider was hit: The Record. 2 Anthropic reported that a state-sponsored actor manipulated its Claude Code tool into performing 80 to 90 percent of an espionage campaign autonomously, with humans required at only four to six decision points and requests peaking at several per second, across roughly thirty targets: Anthropic, November 2025. 3 Microsoft: "For all cloud deployment types, you own your data and identities," and remain responsible for endpoints, accounts, and access management: Microsoft Learn. NSA and CISA: "Security in the cloud is a shared responsibility," and managed services "can open new conduits for potential malicious activities": NSA/CISA joint guidance, March 2024. 4 CVE-2024-1709, an authentication-bypass in ConnectWise ScreenConnect, carries a CVSS base score of 10.0 and was actively exploited on disclosure in February 2024: NIST NVD. Unit 42 observed 18,188 internet-facing ScreenConnect instances on 21 February 2024: Palo Alto Networks Unit 42.
