I haven’t published anything here for a month. Not out of laziness: I’ve been building something, and I’d rather write about it once it stands up on its own. It stands up. It’s called Foundation, and here’s why I started.
Your company will never have an information security policy
That isn’t a reproach. It’s arithmetic.
The document every large group owns — the information systems security policy — costs, when produced the classic way, tens of thousands of euros in consulting. A company of 10 to 80 people will never spend that. And it is right not to: at that price the sums don’t add up.
So the problem isn’t technical, it’s economic. An economic problem is solved by changing how the thing is produced, not by lecturing the owner. That is exactly the bet behind Foundation: industrialise that production so it becomes affordable for an SME.
FOUNDATION IN ONE SENTENCE
Foundation is the Ezohiko platform: it carries the work of your fractional IT manager, and it hands the evidence of that work back to you, continuously.
It isn’t sold separately. There’s no licence, no per-seat software subscription, no mobile app. It is included in the Fractional IT Manager package — it’s the backbone of the service, not another product on the invoice.
The real deliverable isn’t the document
A security document asleep in a drawer has never protected anyone. What I’m trying to trigger is somewhere else:
The idea is to surface, as early as possible, the things a business owner would rather sweep under the rug than face.
The real deliverable is the moment an owner sees in black and white what they’d been avoiding — and either decides, or formally accepts it, dated and signed. Everything else follows from that.
And the split of roles is clear: the client answers because they hold the knowledge, we guide because we hold the method. Nobody is caught out. A business owner understands their own company better than anyone; what they lack isn’t knowledge, it’s a framework to lay it out.
How the security policy is built inside Foundation
In plain language, the full journey:
- Scoping — the perimeter, and who does what. A register of roles, activity by activity.
- Interviews — management, IT, HR, finance, operations, users: each person gets a link and answers from their own desk, in plain words, with no need to sound like an expert.
- Estate — a record of the hardware and software actually in service. Not the ones on the contract: the ones that are running.
- Risk register — answers and estate are analysed. A rules engine for the mechanical findings (an operating system past end of support, a missing category of tool…), an analysis engine for what can only be inferred from the interviews.
- Action plan, then management sign-off, timestamped and traced, then the document is generated.
- And then it lives — reviewed on schedule, but also after an incident, a change of scope, or an outside request.
“SO AN AI WRITES MY DOCUMENT?”
No. A suggestion is never written into the document automatically: the IT manager arbitrates. The machine proposes findings from the facts; a human decides what goes in, what gets rewritten, and what is thrown out. It’s production help, not a signature.
The methodological base is public and checkable: the ANSSI guides — the small-business guide (ANSSI-GP-086) and the guide to drafting a security policy, with its sixteen domains of security principles. I sell no regulatory compliance, and I promise none. What actually lands on an SME’s desk today isn’t a European directive: it’s the security questionnaire sent by a major customer, and the need to answer it credibly.
Two rules that won’t move
“To be defined” sections stay printed in the document. We don’t paper over a gap. An unsettled topic stays visibly unsettled — which is precisely what makes the document useful next time round.
A risk endured is not a risk accepted. When an owner has no choice — one person holding roles that ought to be separated, for instance — we don’t write “risk accepted by management”. We inform, and we propose compensating measures. A role held by Ezohiko is one of those measures: the offer appears in the document at the exact point where it answers a risk, and nowhere else.
The other side: your day-to-day IT, made readable
The security policy is a moment in time. The rest of the year, Foundation answers three very simple questions a business owner actually asks: is it running? what happened? what’s expected of me? That’s where the real work sits: making the day-to-day of an information system readable to someone whose job it isn’t.
Health status, component by component
Your Proxmox hypervisors, your Synology NAS units, your UniFi network and access points, your Microsoft 365 or Google Workspace tenant: monitoring is built into the platform, not bolted on beside it. Every component reports its state continuously, and that state appears where you already read things — not in an admin console you will never open.
Backups, including what leaves the building
Backup tracking gets its own place: what ran last night, what actually left for off-site storage, what didn’t go through and how it ended. A backup nobody checks the result of isn’t a backup — it’s an intention. You can see the difference on screen, without having to ask.
Translation is the real work
A raw monitoring message means nothing to a business owner, and sending three hundred of them a month amounts to telling them nothing at all. In Foundation, every event is first recorded as a dated fact, then rewritten in plain language. You never read the technical message: you read what it means, and what became of it.
It’s also where we talk
Foundation isn’t only a dashboard to look at: it’s the conversation channel between you and us. You ask a question, you raise a request for action; it’s attached to your file, it lives beside the facts that prompted it, and its outcome is written in the same place. No more decision buried in an email thread nobody can find six months later.
Joiners and leavers
Someone joins: you declare it from your space, and an onboarding sheet is triggered — accounts, access, rights, hardware, licences. Someone leaves: the offboarding sheet walks the same path in reverse, and you know what was disabled, returned and recovered, and when. It’s the most ordinary subject in the world, and the one that leaves the most doors open when nobody follows it properly.
And the rest, in the same place
The health bulletin of your IT on a single screen. A statement of what your subscription produced this month, intervention by intervention, event by event, with its outcome. The progress of your security policy, step by step, and what’s still to be decided. The inventory used to calculate your fee, down to the point. And your invoices, without digging through a mailbox.
BUILT SO IT CANNOT FLATTER
Most IT provider reports are good-news reports. This one is built to be held against us. Four rules are written into the product:
- Silence is never counted as success.
- An alert is never shown without its outcome.
- “0” never means “not assessed”: when data is missing, it says so.
- Nothing is hidden without saying so.
A dashboard that cannot embellish is worth a lot, because you can use it to decide.
The three things this changes, concretely
You know what you’re paying for
The fee is calculated by the point: your information system added up, multiplied by €20. And the inventory behind that calculation sits in your own space. You can check for yourself what you pay, and why.
You see what it produces
The health bulletin and the activity statement are fed by monitoring, continuously. This isn’t a write-up composed to please you at quarter end: they are dated facts, with their outcome.
You get what an SME never gets
A living security policy, signed off by management, revised when reality changes. The kind of document everyone assumed was reserved for thousand-person companies.
And all of it with no lock-in. That’s a deliberate bet: the only thing keeping a client is what they see on screen. You stay because you’re satisfied, not because you have no choice.
Where I actually stand
I’d rather say it before I’m asked. Ezohiko is its own client zero: my own security policy file lives in Foundation and I went through the whole journey, interviews included. It’s easier to defend a method you’ve applied to yourself first.
What you’ve just read exists and runs today: the client space and its health bulletin, built-in monitoring of your hypervisors, NAS units, network and tenants, backup and off-site tracking, the translation of events into plain language, the conversation channel and requests for action, joiners and leavers with their sheets, the security policy journey end to end, and the point-based inventory.
Other pieces are under construction. I won’t announce them here until they run — announcing a feature that doesn’t exist is the exact opposite of what I sell. But yes: I’m preparing what comes next, and it’s ambitious.
INTERESTED?
If you run a company of 10 to 80 people and this rings true, tell me. Thirty minutes, no commitment: I’ll show you the tool, we’ll look at your information system, and you’ll leave with at least your fee calculation and a clear idea of what needs deciding on your side.
