Skip to content
Client login

Free Audit

Security & surveillance

Security and surveillance: the order matters more than the product

It is the only family in the pillar bought against a fear rather than a need. And fear buys in the wrong order: what can be seen, first.

Published on 13 May 2026 — Algeria Agency

The four pages below this one — cameras, access control, firewalls and IT security — are bought under particular conditions, and that particularity decides almost everything.

They are bought after an event. A theft, a break-in, a lost file, a fraudulent email, or simply a theft next door. So the decision gets taken in the week that follows, under the impression of something concrete, and it concerns whatever reassures.

What reassures is what can be seen. A camera can be seen, a badge can be seen, a box in a cabinet can be seen. A tested restore cannot be seen, and an account closed on the day somebody left cannot be seen either.

This article sells none of those four products. It gives the one-hour question that puts the family back in order, the order itself, and the four things we refuse to bill even when they are ordered and payable immediately.

The only family bought against a fear

The pillar’s other families answer a need that existed before the call: a machine has to be replaced, sockets installed, data hosted. This one answers an event, and an event creates urgency without creating information.

The consequence is visible in the shape of the requests we receive. They arrive with a product already chosen — "we need cameras", "we need a firewall" — rather than with a problem described. The product was chosen by the event, not by analysis.

That is not a failure of judgement, it is how a decision taken under pressure works. So an honest supplier’s role is to slow that decision by an hour rather than serve it immediately — and slowing an order down is exactly the opposite of what the market does.

What that urgency produces financially has to be said too: this is the family where the accepted price is highest and where comparison happens least. A quotation presented in the week after a theft gets signed without discussion.

The only protection against that effect is a decision taken beforehand. This whole page is written to be read before the event, and its value is nil during the week that follows one — which is also when it will be searched for.

What actually happens, in order

The IT pillar article already says it and this page repeats it because it is the basis of the whole ranking: what happens to a small business is almost never a targeted attack.

In the order we meet them: a laptop stolen, from a car or from premises; an account left open after an employee left; a password shared and reused across five services; a very polite email asking for a supplier’s bank details to be changed; and a key or badge never handed back.

Three of those five have no technical dimension at all. They are staffing and organisational events, and no product in this family addresses them — which explains why so many well-equipped businesses still get caught.

What comes next, less often but more expensively: malicious software that encrypts shared files, almost always entering through an attachment or a machine out of support. It is the only one on the list that stops the business rather than costing it an object.

And what almost never happens, despite the space it occupies in sales talk: a targeted technical intrusion against a twenty-person business. It exists; it is not what your budget should be built against.

The one-hour question that reorders everything

There is a question that ranks the four pages below this one correctly, it takes an hour, it is free, and it produces a written list: what, gone or copied tomorrow, would cost you most, and who would it be useful to?

The wording matters. It does not ask what has value — everything does — but what costs when it disappears. A laptop costs its price; the customer file it contained costs far more, and it appears on no accounting inventory.

The second half of the question is the one nobody asks and it is the most useful: who would it be useful to? It instantly separates the risk of an object being stolen — resaleable, opportunistic — from the risk of losing the ability to operate, which sells to nobody but stops you.

Write the list on a sheet, unranked, then add three columns: what it costs, how long before you would notice, and what you would do that same day. The third column is what empties half the quotations.

That list is the one document in this family a supplier cannot produce, including us. We know what happens in general; you alone know what, at your premises, cannot disappear.

What a camera solves, and what it does not

A camera answers one question and only one: what happened, after it happened. It is a real service, it is worth its price in several trades, and the page devoted to it handles the installation detail.

What it does not do has to be said here, at family level, because that is where the ranking is settled. It does not prevent a shared password, an account left open, a fraudulent email, or software encrypting your files — which is to say four of section 2’s five events.

It has a real deterrent effect on the fifth, opportunistic physical intrusion, and that effect is the legitimate reason to buy one. We do not dispute it; we dispute only the order in which it gets bought.

The arrangement we meet most often is this: a business equipped with recent cameras, whose backup has never been restored in front of anybody, and two of whose former employees still have access. It protected what can be seen and left open what keeps it alive.

The wording that helps a decision, and that we use systematically: if you could do only one of two things this year — install the cameras, or test a restore and close the open accounts — which would cost you more not to do? The answer has never been the cameras.

The physical door is a computing measure

The separation between physical and computing security is a catalogue convenience, and it is false at one precise point: physical access to a machine cancels most software protections.

The simplest case is a stolen laptop. The session password does not protect the data if the disk is not encrypted: taking the disk out is enough. That is why encryption, a software measure, is in reality the answer to a physical risk.

The second case is the plant room. An open network cabinet in a corridor allows a device to be plugged in, a recorder unplugged, or a backup disk carried away. A door that locks is, on that basis, the cheapest security measure in the whole pillar.

The third is the machine left open. An unlocked session in a space visitors pass through gives anybody an employee’s complete access, with no technical skill, for as long as a coffee.

Those three cases have a ranking consequence: the page on access control is not a comfort page, and automatic session locking is not a detail. They are computing measures dressed as building measures.

The order we impose

Here is the sequence we apply, in this order, whatever product was asked for at the outset. It is short and the first three steps cost nothing.

First: a restore tested, on real data, in front of you. Until that has been done, no spending in this family is justified, because an untested backup is what turns an incident into a permanent stop.

Second: closing the access of people who have left, and the access list from the audit article. It is free, it takes an afternoon, and it addresses section 2’s commonest event.

Third: a distinct password per critical service, a second verification on the mail, and the call-back rule on any change of bank details — a call to a number you already had, never to the one in the message. Three habits, no purchase.

Fourth, and only then: the products. Laptop encryption, firewall, access control, cameras — in the order your section 3 list imposes. A supplier who starts at the fourth point is selling you their catalogue, and selling it all the more easily because you have just suffered something.

An employee leaving is the commonest event

It is the commonest security event in the businesses we audit, it has nothing technical about it, and it is addressed by none of this family’s four products.

What stays open after a departure, in order: an active mailbox, an account on an online service the company pays for, access to the file share, a badge or a key, a number in an internal discussion group, and the owner account of a service that person created.

The last is the most serious and it brings back the subject of the hosting and audit articles: a service whose owner account is somebody who has left is a service the company no longer controls, however good the parting was.

The correction costs nothing and it is administrative: a written list of accesses to remove, prepared in advance, applied on the day of departure rather than the following month. It fits on a page and it gets updated at every arrival.

One clarification avoids a misunderstanding: that list is not a mark of distrust towards people who leave. Most forgotten accesses are never used; they become a problem when that person’s mailbox is compromised somewhere else, two years later, for a reason nothing to do with you.

Filming and recording: what gets settled first

Installing a camera or access control creates obligations towards the people filmed or recorded, and they get settled before installation rather than after an incident.

Four points recur whatever the system. People have to be informed that they are being filmed or that their passages are recorded. The retention period has to be decided and limited. Who is entitled to view the images or the logs has to be known. And the conditions under which they can be passed to a third party have to be known.

The question of zones deserves separate treatment, because it causes the most problems in practice: some spaces are not filmed, and a workstation filmed permanently raises a different question from an entrance.

Find out what applies to your case before installation, from somebody whose trade that is. We give no legal advice on these pages and we will not pretend otherwise: what we can say is that the installer is not the right source for that question, because they are selling the installation.

One practical consequence applies to all four leaves in this family: anything recording something about people — images, passages, connections, calls — gets decided with a written retention period. A recording with no period becomes a store nobody is responsible for, and it is exactly the store that causes a problem on the day it is asked for.

What protects on its own, and what needs a habit

A useful distinction for arbitrating a budget: some measures work once installed, others require somebody to do something every month. The second kind almost always fails, and that has to be taken into account before buying them.

Work on their own: disk encryption, a second verification on an account, automatic locking of an idle session, the network separations from the network family article, and automatic updates on a system still receiving them.

Require a habit: reviewing access, checking that a backup is running, checking camera recordings, updating equipment that does not update itself, and reviewing who holds which badge.

The budget consequence is sharp and it contradicts intuition: systematically prefer a measure that works on its own to a better one that requires a routine, unless you have named the person who will keep the routine and the moment they will keep it.

And for those that require a habit, only one format survives: a recurring hour, with a list of five checks, kept by a named person. Without an appointment, the routine lasts three months — we have observed that often enough to write it here rather than discover it with you.

How to read a security quotation

A quotation in this family is read backwards, like an infrastructure one: start from what is not on it, because the absences decide.

Look for the tested restore line. If a quotation proposes cameras, a firewall or access control without mentioning that check, it is selling section 5’s fourth point while skipping the first three, and that gets said politely but gets said.

Look for the retention period for recordings, written in days. Its absence means section 7’s question was not asked, and it is you who bears the consequence, not the installer.

Look at who holds administrative access to the equipment installed. It is the same line as everywhere else in this pillar, and it gets settled at order time: a recorder, a firewall or a controller you have no access to is equipment you can neither check nor have taken over.

Finally, the question that sorts faster than any other, and it is the pillar article’s: ask what they would refuse to sell you. A supplier in this family with no answer has no ranking, and without a ranking they sell in the order they are asked.

The supplier who sells all four lines

One feature of this family deserves naming: the four products under this page are often sold by the same company, and that company rarely has all four skills.

Cameras and access control belong to an installation trade: cabling, mounting, power, and a controller to configure. Firewalls and IT security belong to a trade of configuration and follow-up, with almost nothing to mount.

Those are two different trades and they recruit different people. A company that installs cameras very well may configure a firewall very badly, and the reverse is just as true — without it indicating any lack of seriousness on either side.

The check fits in one question per line, asked separately: how many installations of this precise type have you done this year? A confident answer on cameras and a hesitant one on firewalls is a useful answer, and it is more honest than what you get by asking whether the company can do everything.

The practical consequence is not to multiply suppliers on principle: it is to know which of the four lines you are entrusting to somebody who practises it rarely, and to decide whether that line can afford to be the least well done.

What we do, and what we will refuse to do

What we will refuse: installing cameras, a firewall or access control at a business whose backup has never been restored in front of it. It is the refusal the pillar article announces, and this page is what makes it applicable rather than declarative.

We will refuse to bill anything in this family before the three free steps in section 5 have been done. They earn us nothing, they take an afternoon, and they address most of what actually happens.

We will refuse to install any recording — of images, passages or connections — without a written retention period and without the question of informing people having been handled with somebody whose trade that is.

What we do: section 3’s one-hour list, written by you and not by us; section 5’s sequence in that order, even when another product has already been chosen; laptop encryption treated as the answer to theft rather than as an option; the list of accesses to remove prepared before the first departure; and a named recurring appointment for the measures that need a habit.

And what you can do this week without us: write the list of what, gone or copied tomorrow, would cost you most — and against each line, who it would be useful to. Then count how many people who have left still have access. Those two documents decide this family better than any quotation.

Frequently asked questions

Where should security start?

With a restore tested on real data, then closing the access of people who have left, then three habits that cost nothing. The products — encryption, firewall, access control, cameras — come fourth, in the order your own list imposes.

Are cameras a security expense?

They answer "what happened", after the fact, and they deter opportunistic intrusion. They prevent neither a shared password, nor an account left open, nor a fraudulent email, nor malicious encryption — four of the five commonest events.

What actually happens to small businesses?

A stolen laptop, an account left open after a departure, a reused password, an email asking for bank details to be changed, a key never returned. Three of those five have no technical dimension and no product addresses them.

What should happen when an employee leaves?

Apply a written list prepared in advance, on the day: mail, online services the company pays for, file share, badge or key, internal groups, and above all any service where that person was the owner account.

What has to be settled before installing cameras?

Informing the people filmed, the retention period written in days, who is entitled to view the images, and the conditions for passing them to a third party. Ask somebody whose trade that is rather than the installer.

How do we judge a security quotation?

By what is not on it: the tested restore, the retention period, and who holds administrative access to the equipment installed. Then ask the supplier what they would refuse to sell you — without a ranking, they sell in the order they are asked.

Where we come in

An hour spent listing what would cost you most if it vanished or was copied tomorrow decides the order better than any quote you receive.

  • We read your list and take the sequence from it, without adding our preferences.
  • We write a retention period before installing any recording at all.
  • We wait for the free steps to be done before invoicing anything.

Until a restore has been proven at your company we will install neither cameras nor a firewall: the order is not negotiable.

Read next

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy