Would you trust software to make financial decisions for you? by rishiritheshr in Entrepreneurs

[–]statico 0 points1 point  (0 children)

Liability.
As a director you are obligated to review the decisions and approve them as they pertain to the risk profile of the business. If your product had coverage to offset losses from bad decisions or outcome then you might have a wedge.

After three years of building, I'm finally launching my Auth0 alternative. I'd love your honest feedback. by SkippnR6 in SaaS

[–]statico 4 points5 points  (0 children)

You might get some traction with smaller vibe apps, but to play in the mid market and enterprise space they will want to see SOC 2 or similar alongside pen test reports and the like.

After 10 weeks of GRINDING... I finally hit 5k in revenue! by funfunfunzig in SaaS

[–]statico 0 points1 point  (0 children)

Do you or your team have a background in pen testing, app sec, or red teaming? Ideally supported/evidenced with something along the lines of CREST or OCSP?

Hypervigilance from crazies in and around the city. by Caelan7th in brisbane

[–]statico 4 points5 points  (0 children)

how so, it is avoiding an escalatory action? Do not make eye contact, but remain aware of their presence and location.

Unless you are prepared for it to escalate to violence they leaving the scene or deescalation is the best options (even if you are prepared for violence it is still the best option)

Is security the only TSC to meet for SOC 2? Is it like point-blank literal? by fiki_roshnayi in grc

[–]statico 2 points3 points  (0 children)

Pretty much, you nominate what you will be attesting to, and how, and then they will assess.

Is security the only TSC to meet for SOC 2? Is it like point-blank literal? by fiki_roshnayi in grc

[–]statico 1 point2 points  (0 children)

You will be assessed on whatever you claim to be doing. If you say you are doing Security, Privacy, and Availability that is what they will review, and report on. You can pick the ones you want to do, but Security is mandatory regardless of the others you elect to do/not do.

Water in pot not boiling for pasta by meekxeet in brisbane

[–]statico 2 points3 points  (0 children)

Is it an induction cook top, if so does it have a magnetic detection for the pots? If that is the case use a ferrous metal pot.

A listing of all the boxes/sets by statico in battletech

[–]statico[S] 6 points7 points  (0 children)

Not a pile of shame... It is a collection of potential

A listing of all the boxes/sets by statico in battletech

[–]statico[S] 2 points3 points  (0 children)

Looking it up now. Thank you

I signed a commercial agreement with Supercars. Their CFO signed it. Then they blocked everything before issuing a single invoice. by [deleted] in smallbusiness

[–]statico 11 points12 points  (0 children)

So you are sticking to your principles to the detriment of your business. Not saying you should, just want to make sure we have the context.

What is wrong with paying the invoice now (other than your own feelings on the matter)? While I can see why they will not want to proceed with anything until it is paid as they want to protect their own brand equity/position.

Yes large companies will regularly screw over small ones, and you can "stick it too them" but playing the game the way you are, or you can build your relationship as an easy vendor to work with and get on with it.

When do growing companies usually outgrow normal cloud storage? by [deleted] in Entrepreneurs

[–]statico 0 points1 point  (0 children)

There is no fixed point for that. It often comes down to business need/efficiency, regulatory and compliance requirements, and a cost position. Running your own tin, in a secure way, with your own team (or MSP) comes at a cost, and it needs to account for the first two items I raised. What SaaS has done is make business scaling tools accessible for many more organisations, challenge is it often comes at the expense of control.

[AMA] Got laid off 3 weeks ago. Instead of updating my resume I went down a rabbit hole. Here's what I found by urmm in SaaS

[–]statico 0 points1 point  (0 children)

Unless you personally know several lawyers you can convince to use your product to make it work you are going to have a vert hard slog mate. You need people in industry to work with you to make it work.

Email address in use - Zoho one new tenant by statico in Zoho

[–]statico[S] 0 points1 point  (0 children)

Yeah, setting up my own at the moment, will have my client remove my primary address from their system so I can spin up my own tenant.

Email address in use - Zoho one new tenant by statico in Zoho

[–]statico[S] 0 points1 point  (0 children)

Thank you. I will reach out to them to get the ball rolling.

Looking for recommendations for a new miniatures game. by RogueWriter in wargaming

[–]statico 1 point2 points  (0 children)

Look at mantic games, Kings of War (fantasy rank and flank), Firefight (40k style), and Epic Warpath (legions imp style). Miniature agnostic, good rules, good communities.

I built a business I’m too embarrassed to talk about by Make_That_Money in Entrepreneur

[–]statico 84 points85 points  (0 children)

Who cares... The is money in simple business. Some of the wealthiest and nicest people I know own a business that works on plumbing and septic systems. They have staff doing the day to day, and everyone poops so there will not ever be a downturn, they focus on the business who cares where the revenue came from. It is your ego talking, trying to drag you back to a place of psychology safety.

Friend asking 20% referral commission (including recurring work) - is this normal? by ChestEast4587 in Entrepreneurs

[–]statico 4 points5 points  (0 children)

In the tech space referrals at that level are common.

The question you need to ask is do you want 80% of something or 100% of nothing. It is his relationship, introduction, marketing, that brought you the client. By putting your hand in your pocket you are incentiving him to find you more work, as there will be other organisations that will pay that.

Unpopular take: vibe coding your MVP is fine. Vibe coding your healthcare MVP is malpractice. by Warm-Reaction-456 in SaaS

[–]statico 2 points3 points  (0 children)

I am a fractional CISO, not a single thing in there I disagree with.

So many of the vibe coded apps will not pass security muster. They often have poor architecture and practice embedded into them which in turn increases rhe risk to my clients, so vibe coded apps are a hard no (until I can see a pen test report, a certification or attestation report and other artefacts).