Optivas Advisors
Americans have grappled with high prices, while business leaders have navigated tough decisions amidst ongoing tariffs and trade uncertainties.
Drawing from over 20 years of leadership experience in Fortune 500 companies, I founded Optivas Advisors.
10/03/2026
๐ง๐ผ๐ฑ๐ฎ๐'๐ ๐ฎ๐ด๐ฒ๐ป๐ฑ๐ฎ: ๐ฝ๐ฎ๐ด๐ฒ ๐ผ๐ป๐ฒ
No meetings, no inbox, no projects today. Just a new book, a comfortable chair, and nowhere I need to be.
Over 35 years, some of the best ideas I ever brought to work didn't come from a conference room. They came from a book I picked up for no particular reason. Reading slows you down long enough to think, and it lets you step into someone else's world for a while.
So here's your invitation for the weekend. Pick up something you've been meaning to read, or something completely unexpected. Learn something new, or simply escape for a few hours.
What's on your nightstand right now? I'd love some recommendations for the next one.
10/02/2026
๐๐ผ๐๐ฟ ๐๐ต๐ถ๐ป๐ด๐ ๐๐ต๐ฒ ๐ฏ๐ถ๐ด ๐ฐ๐ผ๐บ๐ฝ๐ฎ๐ป๐ถ๐ฒ๐ ๐ฑ๐ผ ๐๐ต๐ฎ๐ ๐บ๐ผ๐๐ ๐๐บ๐ฎ๐น๐น ๐ฏ๐๐๐ถ๐ป๐ฒ๐๐๐ฒ๐ ๐ป๐ฒ๐๐ฒ๐ฟ ๐๐ฒ๐ฒ
This week I walked through four practices that are routine inside a Fortune 500 company and almost unheard of inside a 20-person firm. A quarterly business review where someone asks where your business is headed before they ever mention tickets. An honest look at how attackers are now using AI to write emails that sound exactly like your banker or your biggest vendor. A disaster recovery exercise where you actually find out, on a quiet Tuesday morning, whether the backups are working. And an invitation to an ethical hacker to try the front door before someone less friendly does.
None of these are exotic. For 35 years they were simply how the work was done. What made them work was who sat in the room. The people running those reviews and tests sat on the company's side of the table, with no vested interest in which product or provider came out ahead.
That's the piece that quietly goes missing in most small business IT arrangements. When the firm managing your systems is also the one grading them, the QBR drifts into a renewal conversation and the pe*******on test never quite makes it onto the calendar. Nobody is being dishonest. The model just doesn't reward asking hard questions about your own work.
You don't need an enterprise budget to get enterprise discipline. You need someone whose only job is to ask those questions, and who is free to recommend whatever answer actually fits your business.
If you can't remember the last time anyone tested your recovery plan or asked what next year looks like for you, that isn't a technology gap. It's an empty chair at the table.
10/01/2026
๐ช๐ฒ ๐ต๐ถ๐ฟ๐ฒ๐ฑ ๐ฝ๐ฒ๐ผ๐ฝ๐น๐ฒ ๐๐ผ ๐ฏ๐ฟ๐ฒ๐ฎ๐ธ ๐ถ๐ป. ๐ข๐ป๐ฐ๐ฒ ๐ฎ ๐๐ฒ๐ฎ๐ฟ.
In the enterprise, pe*******on testing was a scheduled event. We paid a firm to attack us on purpose. to find the weak spot, get inside, write it up. It took weeks and cost real money, so it happened once a year, maybe twice. And it was genuinely valuable, because a scan tells you a door might be unlocked while a pen test tells you someone walked through it and into the payroll folder.
The gap always bothered me. We'd fix everything in the report, then spend eleven more months adding a server, onboarding a vendor, opening a firewall rule for a project and the next test was a year out. That's a long time to assume nothing changed to negatively impact our vulnerabilities.
That gap is what automated pen testing closes. Platforms now run the attack themselves, chaining one weakness to the next the way a person would, and they can run weekly instead of annually. Same discipline my old employers bought by the calendar quarter, now available on a subscription.
Here's what I'd tell a small business owner. This is one of the rare places where the small firm gets the better version of an enterprise practice, because continuous beats annual and you were never going to buy annual anyway. Two honest caveats: the tooling ranges from a few thousand a year to six figures, so the enterprise platforms are not your answer, and automation doesn't replace a skilled human for anything unusual. It replaces the eleven months of silence.
You don't need a report once a year. You need to know what changed last week.
09/30/2026
๐ช๐ฒ ๐ฑ๐ถ๐ฑ๐ป'๐ ๐ท๐๐๐ ๐๐ฟ๐ถ๐๐ฒ ๐๐ต๐ฒ ๐ฝ๐น๐ฎ๐ป. ๐ช๐ฒ ๐ฟ๐ฎ๐ป ๐ถ๐.
In my Fortune 500 years, disaster readiness wasn't a binder sitting on the shelf. It was a calendar item. One year we executed the plan end to end โ failed systems over, brought them back, and watched the clock. The next year we did a walk-through instead: everyone in a room, someone reads the scenario out loud, and each person says what they'd do and who they'd call. Then we alternated again. Every year, one or the other, without exception.
The walk-through years taught us as much as the live ones. That's where you find out the recovery contact retired in March, or that two people both assumed the other one had the vendor's after-hours number.
Ask a small business owner about this and the answer is almost always "we have backups." I believe them. But a backup is a claim, not a capability, until someone has restored from it and timed how long it took. I've seen backups running faithfully for two years that couldn't be restored, and nobody knew, because nobody ever asked them to prove it.
The small-business version of this costs an afternoon a year. Restore something real and see how long it takes. On the off year, sit down for thirty minutes and talk through a scenario out loud โ the server's gone, it's Tuesday morning, what happens now, who calls whom. You'll find the gap in that conversation, not during the actual outage.
Enterprises don't test because they're big. They test because they learned what untested plans are worth.
What's your restore time? If the answer is a shrug, that's your afternoon.
09/29/2026
๐๐ ๐๐ ๐ช๐ผ๐ฟ๐ธ๐ถ๐ป๐ด ๐๐ผ๐๐ต ๐ฆ๐ถ๐ฑ๐ฒ๐ ๐ก๐ผ๐
Attackers are using AI to find and test weaknesses faster than ever. They probe websites, try logins, and adjust on the fly until something gives. The good news is that defenders now have AI tools that do the same thing on our side. These tools don't just flag a possible problem; they test whether an attacker could actually use it, so the team knows exactly what to fix first.
Those tools matter most for businesses running custom software, cloud applications, and customer-facing portals. For many small businesses, though, the more likely AI attack looks like this.
It's 4:45 on a Friday. Your office manager gets a call, and the voice sounds exactly like you. You're traveling, a vendor needs payment today, and could she please take care of it before the weekend. The voice is right, the urgency is familiar, and the request isn't unusual.
No scanning tool stops that call. What stops it is a simple rule everyone knows and follows: any payment request gets a callback to a number you already have, never the one that called. MFA on every account, staff who've practiced spotting these moments, and a clear plan for what happens if something slips through.
The right protection starts with an honest look at where your real exposure is. A tool built for someone else's risks won't cover yours. If you're not sure where yours are, that's exactly the conversation worth having before a Friday afternoon phone call forces it.
09/28/2026
๐ง๐ต๐ฒ ๐ ๐ฒ๐ฒ๐๐ถ๐ป๐ด ๐ ๐ผ๐๐ ๐ฆ๐บ๐ฎ๐น๐น ๐๐๐๐ถ๐ป๐ฒ๐๐๐ฒ๐ ๐ก๐ฒ๐๐ฒ๐ฟ ๐๐ฎ๐๐ฒ
For most of my 35 years in Fortune 500 IT, every quarter ended the same way. Business and technology leaders sat down in a conference room with a simple scorecard and one hour on the calendar. We looked back at the quarter: what worked, what broke, what it cost, and what was coming next. We called it the Quarterly Business Review, and nobody skipped it.
When I started working with small business owners, I noticed that meeting almost never happens. The only IT conversation is the one that starts with "it's down again." The fix gets made, everyone gets back to work, and the same issue shows up a few months later. Nobody ever stopped to ask why it happened in the first place.
A good QBR asks the questions busy owners never have time for. Why did the same problem keep coming back? Are we still paying for licenses for people who left in the spring? Did anyone click a suspicious email? You're hiring two people next quarter, so is the technology ready for them? Is the contract up for renewal coming due before anyone has compared options?
One detail matters more than it seems: who's at the table. If the only person grading the work is the person who did the work, it isn't much of a review.
One hour a quarter. That's the whole investment. Most of the expensive surprises I've seen in small businesses would have come up in that hour.
09/27/2026
๐ ๐ฒ ๐๐ถ๐ฟ๐๐
This morning our pastor preached a sermon titled "Me First." It named something most of us don't like to admit: that's our default setting. Me first in line, me first in the conversation, me first when the credit gets handed out.
Then he shared the words that made Gale Sayers' life story famous: "The Lord is first, my friends are second, and I am third." A Hall of Fame running back, one of the most gifted athletes of his generation, and he put himself third.
I've been thinking about what that looks like in business. It usually isn't dramatic. It's the moment someone mentions a problem and you realize you know exactly who could help, and you make the introduction, even when there's nothing in it for you. A quick email. A phone call. "You two should talk."
Some of the most meaningful help I've received over the years came from people who simply connected me to someone else. They didn't have to do it. They chose to put me ahead of themselves for a moment.
This week, I'm going to look for one person I can connect with someone who can help them. God first. Others second. Me third.
Who's someone you could introduce this week?
09/26/2026
๐๐๐๐ฒ๐ป๐๐ถ๐ผ๐ป ๐๐ ๐๐๐ฟ๐ฟ๐ฒ๐ป๐ฐ๐
This week I sat down with a group of business owners and leaders at the third meeting of the West St. Louis County Chamber of Commerce men's group. We had coffee, a one-page worksheet, and one question I expected to answer easily: Where has most of your attention gone lately?
It wasn't easy. As business owners, we track money to the penny and guard our calendars closely. The worksheet put a third currency next to those two, and it's the one most of us never audit. Time is how long you're there. Attention is whether you're actually there.
Most of us know what it's like to sit through a whole dinner and never really show up for it. Part of your mind is on a proposal, part on a client issue, part on tomorrow's list. You're in the chair, but the people across the table can tell you're somewhere else.
The worksheet also asked something men rarely get asked: what are you actually feeling? It came with a reminder I haven't been able to shake. "Good," "fine," "busy," and "stressed" aren't the finish line. Dig one level deeper.
We left with a challenge. For the next seven days, give someone or something 30 minutes of undivided attention. No phone, no multitasking, just be there. It could be your wife, your kids, a friend, your health, your faith, or even the business you keep saying you'll work on instead of in.
So let me ask you the question that ended our morning. If you gave more attention to one thing this week, what would it be, and how would your life be better because of it?
The business will always take whatever we give it. The people we love deserve more than what's left over.
09/25/2026
$๐ญ๐ฎ๐ฏ,๐ฌ๐ฌ๐ฌ. ๐ง๐ต๐ฎ๐'๐ ๐๐ต๐ฒ ๐ฎ๐๐ฒ๐ฟ๐ฎ๐ด๐ฒ.
The FBI's latest crime report which was released earlier this year contained one figure in it that is worth ending our week on. Business email compromise produced just over $3 billion in reported losses in 2025 from 24,768 complaints. That is approximately $123,000 per incident.
Let that number sit with you for a second. Not $3 billion, which is too large to feel. $123,000. That's a hire you don't make. That's a year of margin for a lot of the firms I talk to. And 86% of those losses happened through a wire or ACH, which is the polite way of saying the money was gone before anyone noticed it had left.
Here's what gets me, though. Phishing and spoofing drew nearly eight times more complaints than BEC, which stands for business email compromise. The expensive attacks aren't the common ones. The common ones are the practice swings, and one of them eventually connects with a person who was busy.
Which is why yesterday's post was about testing your own team. Industry benchmarks put the click rate for an untrained office around a third of employees. Sustained training and regular exercises bring that under 5%. Not perfect. Nothing is. But that's the gap between a bad Tuesday and a $123,000 Tuesday, and it costs a fraction of one incident to close.
Good weekend, everyone. Monday, ask your bookkeeper what happens when a vendor emails new bank details. Whatever the answer is, you'll want to know it before the test comes from someone else.
09/24/2026
๐ง๐ต๐ฒ ๐๐ฎ๐ณ๐ฒ๐๐ ๐ฝ๐ต๐ถ๐๐ต๐ถ๐ป๐ด ๐ฒ๐บ๐ฎ๐ถ๐น ๐๐ผ๐๐ฟ ๐๐ฒ๐ฎ๐บ ๐๐ถ๐น๐น ๐ฒ๐๐ฒ๐ฟ ๐ด๐ฒ๐ ๐ถ๐ ๐๐ต๐ฒ ๐ผ๐ป๐ฒ ๐๐ผ๐ ๐๐ฒ๐ป๐ ๐๐ต๐ฒ๐บ.
Recently I wrote about reporting a suspicious email instead of deleting it. Fair question came back: how do you know your people would actually do that?
You don't. Not until you test it. And there's only one way to find out that doesn't cost you anything and that is to send the test email yourself.
A phishing exercise is a harmless lookalike email sent to your team's inbox on an ordinary Tuesday. Nobody's data moves. Nothing installs. You simply learn what happens next: who paused, who clicked, and here's the number that actually matters, how long it took the first person to raise a hand. Click rate tells you where you're exposed. Time-to-report tells you whether you'd find out in eight minutes or eight days.
Two things make this work, and one of them isn't the software. Do it often and in small tests. A short exercise on a regular frequency beats one long annual training video that's forgotten inside a month. And run it as a measurement, not a trap. The minute your team believes the exercise exists to catch them, they stop reporting real threats to avoid looking foolish, and you've made yourself less safe by trying to get safer. Same email, opposite outcome, depending entirely on how the owner frames it.
The first test is usually humbling. That's the point. Better to learn it from an email you sent than from one you didn't.
Click here to claim your Sponsored Listing.
Category
Contact the business
Telephone
Website
Address
476 Old Smizer Mill Road, Suite 144
Fenton, MO
Alerts
Be the first to know and let us send you an email when Optivas Advisors posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.