The SST Insider – March 2026
From the Helm
March gave us an opportunity to talk about something we consistently see across the organizations we work with: the gap between having technology and governing it.
Our campaign this month focused on governance, specifically how identity management, access control, and privileged account oversight form the foundation of a well-run environment. These aren’t topics that generate excitement, but they matter more than most. Most cyber incidents we read about trace back to something preventable: an account that stayed active too long, permissions that grew beyond what a role required, or credentials that were shared without a clear owner.
Our March case study reinforced a related point from a different angle. A professional services client was overspending on availability infrastructure because no one had ever connected those decisions to actual business requirements. Once we introduced a structured framework, a Business Impact Analysis, revenue-based risk modeling, and a tiered architecture approach, the path forward became clear.
Both stories reflect the same underlying principle. When organizations govern their environments intentionally, they make better decisions, reduce unnecessary cost and risk, and build confidence in their operations.
That is what we are here to help you do.
— SST Leadership
Client Success Story
Optimizing Availability Through Business-Aligned Architecture and Recovery Strategy
A professional services organization came to SST with a familiar problem: infrastructure costs were climbing, and nobody could clearly define what the organization actually needed from its systems in a recovery scenario.
Availability decisions had been made on technical assumptions rather than business requirements. Most systems were configured for high availability regardless of their importance, and backup systems were not set up for rapid recovery. Leadership had no way to connect downtime risk to financial impact.
SST began with a Business Impact Analysis and introduced revenue-per-hour modeling to quantify exposure to downtime. Systems were classified into tiers: Tier 1 cloud platforms with built-in availability, and Tier 2 workloads where the priority shifted from eliminating downtime to improving recovery speed. Tier 2 systems were transitioned to an instant-on backup solution that can bring systems online in minutes.
Within 60 days, the organization reduced unnecessary infrastructure spending, improved recovery times, and established a repeatable process for evaluating availability decisions. Leadership gained a clear understanding of their recovery posture and confidence that IT investment was aligned with business requirements.
— Operations Manager
Proactive Insights
Four Questions Worth Asking Now
Governance and availability are business decisions before they are technical ones. Ask yourself these four questions this month:
Who has access to your critical systems, and when was it last reviewed? Gaps in access visibility surface at the worst possible time, such as during an incident or an insurance review.
Are you applying the same availability standard to every system? Uniform infrastructure investment drives unnecessary costs. Tier classification based on actual business impact changes that equation.
Can you trace every administrative action to a specific individual? Shared logins make accountability impossible during an investigation. Individual, auditable credentials are essential, not optional.
Is your recovery strategy built around speed or around eliminating downtime entirely? For most systems, getting back online quickly is the right goal and a more achievable one.
AI Corner
6 Ways Attackers Use AI
- Phishing emails sound legitimate.
- Voice cloning mimics executives.
- Targets researched automatically at scale.
- Deepfakes impersonate company leadership.
- Spear phishing campaigns built instantly.
- Poor grammar no longer a warning.
SST News & Events
- Right of Boom Cyber Call – 3/2 & 3/9
- La Crosse Chamber Annual Meeting – 3/5
- Waunakee Chamber Annual Meeting – 3/5
- MedTRANS Insurance Conference – 3/16 – 17
- Bi-annual SST Culture Engagement Survey – 3/23
- Unscripted with SST Episode 16 – 3/27
- New team member Damon started – 3/30
Is Your IT Strategy Aligned with Your Growth Goals?
Schedule your FREE Technology Assessment today and uncover hidden risks, inefficiencies, and opportunities in your current environment.