Complexity from chaos. Insight from complexity.
Serious security expertise has always been aimed at governments and large companies. Unamok exists to point it at everyone who never had it: your home, your business, and — through consulting and seminars — anyone who would rather understand the problem than be sold a fix for it.
The problem
Understanding what could actually affect you is the first step to preventing it. But almost all security advice aimed at homes and small businesses is either fear-driven marketing for a product, or a checklist written by someone who has never sat at your kitchen table, or in your back office, and looked at your actual router.
Meanwhile the exposure is real and growing. A household now runs more internet-connected devices than an office did fifteen years ago, and a small business runs what a mid-size company did — in both cases with none of the staff, budget or policy that came with it. The gap between what people are expected to manage and what they have been equipped to manage keeps widening.
Large organizations answer that gap by spending — collectively billions a year on monitoring, segmentation, patching programs and people whose whole job is watching. A household gets whatever configuration the hardware shipped with, and keeps it, because nobody ever said otherwise. The default password, the remote administration left switched on, the single flat network carrying the doorbell camera and the laptop with the tax returns on it: those are not mistakes anyone made. They are just what came in the box.
The same is true one rung up. A ten-person business, a church office, a library branch or a club that meets on Tuesdays has exactly the household’s problem with a payroll attached — the same defaults, the same flat network, and nobody whose job it is to notice. They are too small for the vendors who sell to enterprises and too exposed to ignore it.
The uncomfortable part is that the people scanning for those defaults are not scaling their effort down because it is a house, or a small office. Automated scanning does not care whose network it found.
The background
Our experience spans two decades of military, federal and enterprise security. It includes U.S. Army cyber warfare operations at warrant officer level on a Cyber Protection Team — the units that hunt intrusions on defense networks, where the adversaries are frequently nation-state actors rather than opportunists.
On the civilian side, we have held principal security architect roles defending a Fortune 50 internet service provider, hunting threats across network traffic measured in petabytes per week and building machine-learning detection pipelines to find behavior that signature-based tools miss. Before that, cloud security architecture for federal agencies and the Department of Defense, including the first cloud development platform at its agency cleared to operate on live government data.
Explaining it is half the job
Depth is worth nothing if you cannot use it. Alongside the enterprise work, we teach cyber security to older adults through a community resource center — how to recognize a scam call, how to judge whether an email is real, how to think about the smart devices arriving in their homes, and more recently what AI actually is and where it is being used against them.
That teaching is not a side note to this business, it is the method — and it is what the seminars are built from. If an explanation only works for people who already understand it, it is not an explanation.
Start where it makes sense
Most people begin with an assessment. If you would rather talk it through first, that is genuinely fine.