Optivas Advisors

Optivas Advisors

Share

Americans have grappled with high prices, while business leaders have navigated tough decisions amidst ongoing tariffs and trade uncertainties.

Drawing from over 20 years of leadership experience in Fortune 500 companies, I founded Optivas Advisors.

10/11/2026

๐—ง๐—ต๐—ฒ ๐—พ๐˜‚๐—ถ๐—ฒ๐˜ ๐—ฒ๐—บ๐—ฒ๐—ฟ๐—ด๐—ฒ๐—ป๐—ฐ๐˜†

In June 2022, at the World Aquatics Championships in Budapest, American artistic swimmer Anita Alvarez finished her solo routine and lost consciousness. She slipped beneath the surface. The music had stopped, the scores were coming, and the arena was looking anywhere but the bottom of the pool.

Her coach, Andrea Fuentes, was watching. She didn't wait for anyone else to move. She went into the water and brought Anita up.

I keep coming back to that scene because it's what a cyberattack looks like inside a small business. Nobody sets off a siren. Someone gets into an inbox on a Tuesday, sits quietly, and learns how your invoices work. The phones keep ringing, payroll runs, the team hits its numbers. Everything looks fine from the stands.

In my Fortune 500 years, we never assumed someone would notice. We paid people to watch, around the clock, specifically for the things that don't make noise.

Most small businesses I meet don't have that person. They have a number to call once something breaks.

This October, ask yourself one honest question: if something went wrong in your business at 2 a.m. tonight, who would see it first?

I hope the answer is someone whose job is to dive in.

10/10/2026

๐—ง๐—ต๐—ฒ ๐—›๐—ผ๐˜ ๐——๐—ผ๐—ด ๐—ก๐—ผ๐—ฏ๐—ผ๐—ฑ๐˜† ๐—™๐—ผ๐—ฟ๐—ด๐—ผ๐˜

Picture one of the best restaurants in the world. Eleven Madison Park, New York. A table of out-of-town guests is near the end of an elaborate tasting menu when one of them mentions the one thing they never got to try on their trip: a New York street hot dog.

A team member overheard. Someone ran out to a street cart, the kitchen plated that hot dog with full fine-dining care, and it arrived at the table as a surprise course. Years later, thatโ€™s the moment those guests talk about. Not the tasting menu. The hot dog.

In Unreasonable Hospitality, Will Guidara explains how a business can afford moments like that. Manage 95% of the operation with real discipline, so youโ€™re free to spend the last 5% in ways that seem almost unreasonable.

Most of us run it backwards. We let the 95% leak through waste and loose habits, then cut the 5% because we โ€œcanโ€™t afford it.โ€

The discipline is what pays for the delight.

Whatโ€™s one small, unreasonable thing you could do for a customer this month?

10/09/2026

๐—˜๐˜ƒ๐—ฒ๐—ฟ๐˜†๐—ผ๐—ป๐—ฒ ๐—ผ๐—ป ๐˜๐—ต๐—ฒ ๐—ฐ๐—ฎ๐—น๐—น ๐˜„๐—ฎ๐˜€ ๐—ณ๐—ฎ๐—ธ๐—ฒ ๐—ฒ๐˜…๐—ฐ๐—ฒ๐—ฝ๐˜ ๐—ต๐—ถ๐—บ

In early 2024, a finance employee at a global engineering firm behind the Sydney Opera House, got an email from headquarters asking for a confidential transaction. He was suspicious, and he was right to be.

Then he joined a video call. The CFO was there, along with several colleagues he recognized. They looked right, sounded right, and walked him through the request. His doubts faded. Over the next several hours he made 15 transfers totaling about $25 million.

Every person on that call was an AI-generated deepfake, built from video and audio of real executives that was publicly available online.

This week weโ€™ve watched the same pattern grow. On Wednesday, intruders who quietly wait inside a business for weeks. On Thursday, a cloned voice on the phone. Today, a face on a screen. Each step removes one more thing we used to rely on to know who weโ€™re talking to.

Hereโ€™s the part that matters for a small business. That employee did the right thing at first. He doubted the email. What failed wasnโ€™t his judgment. It was the absence of a rule that no amount of convincing could override. A call-back to a known number. A second approver for any transfer. A question only the real person could answer.

Most small business owners have more video of themselves online than they realize, in webinars, social posts, and voicemail greetings. The tools to copy them are cheap. The defense is a simple process your team follows every time, no matter who seems to be asking.

Seeing is no longer believing. Verifying is.

10/08/2026

๐—ง๐—ต๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฆ๐—ฒ๐˜๐˜๐—ถ๐—ป๐—ด ๐—ง๐—ต๐—ฎ๐˜ ๐—•๐—น๐—ผ๐—ฐ๐—ธ๐—ฒ๐—ฑ ๐— ๐˜† ๐—ข๐˜„๐—ป ๐—˜๐—บ๐—ฎ๐—ถ๐—น

Just after 5:00 this morning I replied to a group email, and within a minute one copy came bouncing back: "Access denied. Sending domain does not pass DMARC verification." My own domain, rejected by a policy I set myself.

DMARC is one of the quiet protections every business email domain should have. Together with SPF and DKIM, it lets the receiving server confirm that a message claiming to be from you really came from you. I run mine at the strictest setting, because impersonating a small business by email is one of the easiest scams there is.

So I traced the message hop by hop, through five servers between my keyboard and her inbox. There was a gap on each side. Her filtering service was quietly breaking the signatures that prove a message is genuine. And I had only half of my proof turned on, so when that half broke in transit, there was nothing to fall back on.

One setting in my admin console and a few test messages later, my email carries both proofs. The resend went through.

In my Fortune 500 years we called this RCCA: root cause and corrective action. You don't stop at "it bounced." You find out why, and you fix your side even when the other side shares the blame.

Most small business owners I talk with have never looked at these settings. Some have none, which leaves their name wide open to impersonators. Others are half configured and don't find out until an important email quietly disappears.

Security that's half set up doesn't just leave the door open. Sometimes it locks you out of your own house.

10/07/2026

๐—ง๐—ต๐—ฒ๐˜†'๐—ฟ๐—ฒ ๐—ถ๐—ป ๐—ป๐—ผ ๐—ต๐˜‚๐—ฟ๐—ฟ๐˜†

Most business owners picture a cyberattack as a single moment. The screen goes dark, a ransom note appears, and everything stops. This is also the most common scenario I heard repeated at business events.

That moment is real, but it's usually the end of the story. Long before anything breaks, someone has often been inside for weeks, quietly reading email, learning who approves payments, and watching which vendors get paid and when. Mandiant, the Google-owned cybersecurity firm that companies call in to investigate major breaches, reports that intruders typically go unnoticed for about two weeks, and those focused on staying hidden, about four months. Verizon's annual study of data breaches found that in half of ransomware cases tied to stolen passwords, those passwords were taken within 95 days before the attack.

Criminals have no deadline and no reason to rush. They have patience, and most small businesses have no one watching.

That isn't a reason for fear. It's a reason to have someone looking. The tools that catch a quiet intruder, like 24/7 monitoring that flags a 3 AM login from somewhere it shouldn't come from, used to belong only to large companies. Today they work for a 10-person office.

All month, I'll walk through the quiet ways attackers get in and what a small business can realistically do about each one. Real numbers, practical next steps, no scare tactics.

The question isn't whether anyone is trying. It's whether anyone would notice.

10/03/2026

๐—ง๐—ผ๐—ฑ๐—ฎ๐˜†'๐˜€ ๐—ฎ๐—ด๐—ฒ๐—ป๐—ฑ๐—ฎ: ๐—ฝ๐—ฎ๐—ด๐—ฒ ๐—ผ๐—ป๐—ฒ

No meetings, no inbox, no projects today. Just a new book, a comfortable chair, and nowhere I need to be.

Over 35 years, some of the best ideas I ever brought to work didn't come from a conference room. They came from a book I picked up for no particular reason. Reading slows you down long enough to think, and it lets you step into someone else's world for a while.

So here's your invitation for the weekend. Pick up something you've been meaning to read, or something completely unexpected. Learn something new, or simply escape for a few hours.

What's on your nightstand right now? I'd love some recommendations for the next one.

10/02/2026

๐—™๐—ผ๐˜‚๐—ฟ ๐˜๐—ต๐—ถ๐—ป๐—ด๐˜€ ๐˜๐—ต๐—ฒ ๐—ฏ๐—ถ๐—ด ๐—ฐ๐—ผ๐—บ๐—ฝ๐—ฎ๐—ป๐—ถ๐—ฒ๐˜€ ๐—ฑ๐—ผ ๐˜๐—ต๐—ฎ๐˜ ๐—บ๐—ผ๐˜€๐˜ ๐˜€๐—บ๐—ฎ๐—น๐—น ๐—ฏ๐˜‚๐˜€๐—ถ๐—ป๐—ฒ๐˜€๐˜€๐—ฒ๐˜€ ๐—ป๐—ฒ๐˜ƒ๐—ฒ๐—ฟ ๐˜€๐—ฒ๐—ฒ

This week I walked through four practices that are routine inside a Fortune 500 company and almost unheard of inside a 20-person firm. A quarterly business review where someone asks where your business is headed before they ever mention tickets. An honest look at how attackers are now using AI to write emails that sound exactly like your banker or your biggest vendor. A disaster recovery exercise where you actually find out, on a quiet Tuesday morning, whether the backups are working. And an invitation to an ethical hacker to try the front door before someone less friendly does.

None of these are exotic. For 35 years they were simply how the work was done. What made them work was who sat in the room. The people running those reviews and tests sat on the company's side of the table, with no vested interest in which product or provider came out ahead.

That's the piece that quietly goes missing in most small business IT arrangements. When the firm managing your systems is also the one grading them, the QBR drifts into a renewal conversation and the pe*******on test never quite makes it onto the calendar. Nobody is being dishonest. The model just doesn't reward asking hard questions about your own work.

You don't need an enterprise budget to get enterprise discipline. You need someone whose only job is to ask those questions, and who is free to recommend whatever answer actually fits your business.

If you can't remember the last time anyone tested your recovery plan or asked what next year looks like for you, that isn't a technology gap. It's an empty chair at the table.

10/01/2026

๐—ช๐—ฒ ๐—ต๐—ถ๐—ฟ๐—ฒ๐—ฑ ๐—ฝ๐—ฒ๐—ผ๐—ฝ๐—น๐—ฒ ๐˜๐—ผ ๐—ฏ๐—ฟ๐—ฒ๐—ฎ๐—ธ ๐—ถ๐—ป. ๐—ข๐—ป๐—ฐ๐—ฒ ๐—ฎ ๐˜†๐—ฒ๐—ฎ๐—ฟ.

In the enterprise, pe*******on testing was a scheduled event. We paid a firm to attack us on purpose. to find the weak spot, get inside, write it up. It took weeks and cost real money, so it happened once a year, maybe twice. And it was genuinely valuable, because a scan tells you a door might be unlocked while a pen test tells you someone walked through it and into the payroll folder.

The gap always bothered me. We'd fix everything in the report, then spend eleven more months adding a server, onboarding a vendor, opening a firewall rule for a project and the next test was a year out. That's a long time to assume nothing changed to negatively impact our vulnerabilities.

That gap is what automated pen testing closes. Platforms now run the attack themselves, chaining one weakness to the next the way a person would, and they can run weekly instead of annually. Same discipline my old employers bought by the calendar quarter, now available on a subscription.

Here's what I'd tell a small business owner. This is one of the rare places where the small firm gets the better version of an enterprise practice, because continuous beats annual and you were never going to buy annual anyway. Two honest caveats: the tooling ranges from a few thousand a year to six figures, so the enterprise platforms are not your answer, and automation doesn't replace a skilled human for anything unusual. It replaces the eleven months of silence.

You don't need a report once a year. You need to know what changed last week.

09/30/2026

๐—ช๐—ฒ ๐—ฑ๐—ถ๐—ฑ๐—ป'๐˜ ๐—ท๐˜‚๐˜€๐˜ ๐˜„๐—ฟ๐—ถ๐˜๐—ฒ ๐˜๐—ต๐—ฒ ๐—ฝ๐—น๐—ฎ๐—ป. ๐—ช๐—ฒ ๐—ฟ๐—ฎ๐—ป ๐—ถ๐˜.

In my Fortune 500 years, disaster readiness wasn't a binder sitting on the shelf. It was a calendar item. One year we executed the plan end to end โ€” failed systems over, brought them back, and watched the clock. The next year we did a walk-through instead: everyone in a room, someone reads the scenario out loud, and each person says what they'd do and who they'd call. Then we alternated again. Every year, one or the other, without exception.

The walk-through years taught us as much as the live ones. That's where you find out the recovery contact retired in March, or that two people both assumed the other one had the vendor's after-hours number.

Ask a small business owner about this and the answer is almost always "we have backups." I believe them. But a backup is a claim, not a capability, until someone has restored from it and timed how long it took. I've seen backups running faithfully for two years that couldn't be restored, and nobody knew, because nobody ever asked them to prove it.

The small-business version of this costs an afternoon a year. Restore something real and see how long it takes. On the off year, sit down for thirty minutes and talk through a scenario out loud โ€” the server's gone, it's Tuesday morning, what happens now, who calls whom. You'll find the gap in that conversation, not during the actual outage.

Enterprises don't test because they're big. They test because they learned what untested plans are worth.

What's your restore time? If the answer is a shrug, that's your afternoon.

09/29/2026

๐—”๐—œ ๐—œ๐˜€ ๐—ช๐—ผ๐—ฟ๐—ธ๐—ถ๐—ป๐—ด ๐—•๐—ผ๐˜๐—ต ๐—ฆ๐—ถ๐—ฑ๐—ฒ๐˜€ ๐—ก๐—ผ๐˜„

Attackers are using AI to find and test weaknesses faster than ever. They probe websites, try logins, and adjust on the fly until something gives. The good news is that defenders now have AI tools that do the same thing on our side. These tools don't just flag a possible problem; they test whether an attacker could actually use it, so the team knows exactly what to fix first.

Those tools matter most for businesses running custom software, cloud applications, and customer-facing portals. For many small businesses, though, the more likely AI attack looks like this.

It's 4:45 on a Friday. Your office manager gets a call, and the voice sounds exactly like you. You're traveling, a vendor needs payment today, and could she please take care of it before the weekend. The voice is right, the urgency is familiar, and the request isn't unusual.

No scanning tool stops that call. What stops it is a simple rule everyone knows and follows: any payment request gets a callback to a number you already have, never the one that called. MFA on every account, staff who've practiced spotting these moments, and a clear plan for what happens if something slips through.

The right protection starts with an honest look at where your real exposure is. A tool built for someone else's risks won't cover yours. If you're not sure where yours are, that's exactly the conversation worth having before a Friday afternoon phone call forces it.

Want your business to be the top-listed Business in Fenton?
Click here to claim your Sponsored Listing.

Telephone

Address


476 Old Smizer Mill Road, Suite 144
Fenton, MO

Alerts

Be the first to know and let us send you an email when Optivas Advisors posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Subscribe

We will notify you when anything happens in Fenton.