What Breaks First — Free Technical Checklist · ElevexMedia
US businesses · owners & CEOs · $2M–$50M or a funded launch
Free checklist · no call required

It works today. That is not the same as surviving next quarter.

A 20-point checklist you run yourself, on the setup you already have, in about an evening. It doesn't tell you that systems fail — you've seen that. It shows you the specific places a technical layer gives way first, what each answer should look like, and which gap is yours.

Written by the person who gets the 2 a.m. call No call, no pitch Runs on the setup you already have

12 pages. No email sequence hiding inside it.

What's inside

A technical layer fails in a fixed order — and the cheap fixes are all near the top

Four stages, each one a different kind of failure. Most businesses lose money at the first, which is why "we bought better servers" usually changes nothing. Every check runs on the setup you already have — no new tools, no audit, no meeting.

IT WORKS TODAY IT SURVIVES GROWTH A Uptime minutes · 5 checks B Access standing · 5 checks C Your data the bad day · 5 checks D Manual work every week · 5 checks
Stages are gates, not scores — a system nobody watches makes every answer below it a guess
STAGE A

Does it stay up?

5 checks
  1. You learn about outages before customers do — if the first report comes from a customer email, you have no monitoring, whatever the dashboard is called.
  2. Someone is named as on call, in writing — a name and an agreed response window, not "whoever is free".
  3. Peak load has been tested, not assumed — the last time traffic doubled, was it a plan or a surprise?
  4. One failure can't take the whole system — find the single machine, service or account that everything depends on. There usually is one.
  5. The last incident has a written cause — "it started working again" is not a cause, and it will happen again.
STAGE B

Who can get in?

5 checks
  1. Everyone who left has actually lost access — check the last three departures by name, across every system, not just email.
  2. Nobody shares a login — a shared account means an action nobody can be held to and a password nobody can rotate.
  3. Two-factor is on everywhere it can be — especially the domain registrar, the cloud console and the payment provider.
  4. Contractors have their own accounts, with an end date — access that outlives the engagement is the cheapest way in.
  5. Somebody would notice a login from nowhere — if no alert fires on an unusual sign-in, the breach is found by its consequences.
STAGE C

What survives a bad day?

5 checks
  1. Backups exist for everything that matters — including the systems nobody calls a database: file storage, configuration, the spreadsheet operations actually runs on.
  2. A restore has been tested this year — an untested backup is a belief. The test is the only thing that turns it into a fact.
  3. You know how much data a failure would cost you — stated in hours, agreed by the owner, not inferred from the backup schedule.
  4. Backups can't be deleted by whoever gets in — a copy inside the same account as the thing it protects is not a copy.
  5. Customer and payment data are held deliberately — you can say what is stored, where, and why it's still there.
STAGE D

What is your team doing by hand?

5 checks
  1. You can name the three longest manual routines — and roughly how many hours a week each one takes. Most owners are surprised by the total.
  2. No data is re-keyed between two systems — every copy-paste between tools is an error rate you're paying for twice.
  3. The month-end report isn't assembled by hand — if a person builds it, it is late, expensive and occasionally wrong.
  4. Nothing critical lives only in one person's head — the procedure for what breaks most often is written down where the team can find it.
  5. New starters don't need a week of shadowing — if the setup can only be operated by memory, it can't be handed over or grown.
And what the checklist won't do
It won't tell you which cloud to move to — that needs someone who reads your setup and your roadmap. It tells you which parts of what you already run would not survive a bad week. The first question is what the free Express Audit is for, and it's the next section.

Four stages · 20 checks · about an evening with the setup you already have.

The same setup, read twice
One business, one real setup. Nothing was added between these two readings — the second only asked what would happen on the day it doesn't work.
As described "Everything is on the cloud and we have backups" The site is up, the team is working, nothing has gone badly wrong in a year. Backups run nightly. The developer who set it up is responsive and knows the system well. Where it hides: nothing on this list has been tested against a failure. Every statement is about the normal day.
Same setup, tested Backups in the same account · one login shared by four · no alerting A restore had never been attempted. Two contractors who finished last year still had access. Outages were discovered by customers. The developer who knew the system had never written any of it down. What changed: the same setup was read forward, from the day it fails — who gets told, what comes back, and who can still get in.

Illustrative example, not a client. It exists to show the shape of the reading — your setup will be your own.

Checklist vs Express Audit

The checklist finds. The Express Audit decides.

They answer different questions, and one is not a trial version of the other.

The checklist · free, instant

A document. You run it yourself, on your own setup, at your own pace.

What it is
20 checks in the order a technical layer fails, with the standard behind each one.
Who does the work
You. About an evening, and a few questions for whoever runs your systems.
What you end with
A list of the checks you failed — and which one to fix first.
What it can't do
Tell you what a failed check would cost your business on the day it matters.
Nothing to book. It arrives by email and the exchange ends there unless you write back.
The Express Audit · free, in writing

A written read of your situation, by a named person.

What it is
Bagrat Urumov reads your setup and writes back the risks he sees, in priority order.
Who does the work
He does. You describe the stack, or give read access — whichever you're comfortable with.
What you end with
The priority infrastructure and security risks, and where to start — in writing.
What it costs
Nothing, and there is no call to schedule. There is a limit per month, because a real person writes each one.
Start with the checklist if you'd rather look first. Both routes end in the same inbox.

Most people take the checklist, run it, and never write back. That's a fair outcome — the method was the part worth giving away.

Fair questions

Before you give us your email

"Is this just a lead magnet with your sales pitch inside?"

It's a lead magnet — that's why it's free and why we ask for an email. What's inside is the checklist and nothing else: no case studies, no pricing page, no sequence that starts on day two. If it turns out to be useful and you never reply, the exchange was still fair.

"We have a developer already. Won't this look like I don't trust them?"

A good developer passes most of these and will be relieved someone finally asked, because several of the checks are decisions only an owner can make — how much data loss is acceptable, who is on call, what a response window should be. The ones that fail are usually the things nobody was ever asked to own.

"I'm not technical. Can I actually run this?"

Yes — that's who it's written for. Every check is phrased as a question you can ask out loud and understand the answer to. Several are answered by trying something yourself, not by reading a configuration file.

"What happens to my email address?"

It goes into no list, no platform and no automation. A person sends the checklist and, at most, one useful email a week, written by hand. One line back and it stops. It is never sold, rented or shared.

Honest fit

This is written for one kind of reader

It's free either way. But it's built for a specific situation, and it's fair to say which.

Probably not for you if
  • You have a CTO and an SRE team — you already run all of this, and you'll pass in ten minutes
  • You want a vendor to click through a compliance form for you; that's certification, and it's a different product
  • You're looking for a guaranteed "we'll never go down" — nobody can promise that, and we won't
  • Your business doesn't depend on anything staying up, and manual work isn't costing you hours
Written for you if
  • Your service slows down or falls over at peak, and nobody can tell you why
  • Nobody is systematically responsible for security — and you'd rather find that out now than after a breach
  • Your team moves data between tools by hand, and it's quietly eating a headcount
  • One person knows how everything works, and that has started to worry you
  • You're owner-led with no CTO yet, and you need to know which technical risk to spend on first
Who wrote it

Bagrat Urumov

14+ years owning infrastructure, security and automation — not advising on them. The standards in this checklist are the ones applied when a system has to keep running, written from the side that gets the call at 2 a.m., not the side that sells the tooling.

The premise
Most technical advice is written by people who never carried the pagerIt describes what to build. This describes what happens on the day it stops working — which is where the real cost is.
The standard
Tested, not assumedA backup that was never restored, a peak that was never load-tested, an on-call rota nobody agreed — three beliefs, not three systems. Every check here is written to be verified.
The format
Ownership, end to endServers, security, integrations, automation, owned as one layer rather than split across whoever is free. That's also why this checklist is written to be run by an owner, not by a specialist.
Now
The System ArchitectsThe technical practice at ElevexMedia — alongside operations, PR and marketing practices, which is a combination we've found in few other places.
Where the standards come from
Led SRE and DevOps teams through Series B/C scaleIn e-commerce and fintech — the stage where the setup that got you here stops holding, which is exactly what stages A and C of this checklist read for.
SOC 2 Type II passed on first attempt, for multiple companiesMost of stage B is what an auditor asks for — asked earlier, and in plain language.
Critical incident MTTR cut by up to 85%Almost none of that came from better servers. It came from the things stage A checks: alerting, a named owner, and a written cause.
30+ hrs/week of manual work automatedAcross finance, logistics and reporting — the routines stage D asks you to name and count.
US, EU and LatAm — cross-border SaaS and high-load platformsAWS and GCP, Kubernetes, PostgreSQL, CI/CD and Terraform, OWASP and SOC 2 readiness.

This checklist isn't a summary of DevOps articles. It's the order a technical layer is actually read when someone has to keep it running — the same sequence, the same questions, the same standards.

It's published as-is because the method isn't the scarce part. Applying it to your stack, at your stage, in the week something is already straining — that's the scarce part.

The System Architects is the technical practice at ElevexMedia. Infrastructure, security, integrations and automation, owned as one layer — for US owners and CEOs.

What the industry numbers say, and what they don't. Published research puts the average cost of downtime for a small business at around $427 per minute, finds 43% of cyberattacks aimed at small and mid-sized businesses, and estimates that over 20% of team time goes to work software should be doing. Sources: Datto downtime report, Verizon DBIR, McKinsey automation studies.

Those are industry averages, not a forecast for your business. The checklist exists precisely because an average tells you nothing about which of the twenty checks is the one that would cost you. No result is promised here, and none of the checks is a guarantee.

We work with US-based businesses. We never sell or share personal information (Do Not Sell or Share My Personal Information). See the Privacy Policy for how we handle your address.

Get the checklist

Send me the 20 checks

Free, no call, and a real person on the other end of the reply.

1
20 checks across 4 stagesIn the order a technical layer fails, not in the order they're easy to explain.
2
What "normal" looks likeFor each check — the standard behind it, so an answer you get means something.
3
The first move when you fail oneThe first corrective step for each finding. Several cost nothing but an afternoon.
Our rule about your inbox
  • No mailing platform, no automation, no sequence running in the background
  • Your address goes to no one — never sold, never rented, never shared
  • A person writes it and a person sends it
  • One line back and it stops — there was never a list running you

Why give the method away? It's fourteen years of practice, and handing it over costs us nothing but the pride of keeping it secret. If it helps and we never hear from you, that's a fair outcome. If one day you'd rather someone did this work with you, you'll already know how we operate.