Cybersecurity Services in Cambridge, MA
Build Your Security Strategy with SII
Cambridge is the most heavily targeted research ecosystem in the world for nation-state cyber espionage, according to explicit FBI and CISA advisories naming MIT and Harvard-affiliated organizations as targets of Chinese, Russian, and Iranian state actors seeking foundational AI algorithms, quantum computing research, CRISPR and synthetic biology platforms, and defense-funded data before patents are filed. Attack techniques are specific: spear-phishing calibrated to graduate students and postdocs, insider recruitment of research staff (documented in DOJ prosecutions involving Cambridge-area institutions), supply chain compromise of shared research software, and “harvest now, decrypt later” collection of encrypted data ahead of future quantum decryption. Organizations holding IP whose value persists a decade or more face this last threat acutely.
Cambridge’s research-to-commercial economy creates an insider threat profile distinct from corporate IT security. The most common IP compromise pattern is the departing researcher who joins a competitor or starts a venture while retaining access through a shared password, a never-deactivated institutional email, or a personal cloud account, a pattern FBI has prosecuted involving MIT and Harvard-affiliated researchers. When that researcher is also subject to export authorization for ITAR or EAR-controlled data, access governance becomes both an insider threat and export control compliance function. Post-quantum cryptography migration is the third frontier: NIST finalized its first post-quantum standards in 2024, and Cambridge’s quantum organizations, including MIT’s quantum research groups, Harvard’s Quantum Initiative, and commercial quantum companies with Cambridge ties, have the clearest obligation to begin migrating research data now.
SII has worked with Greater Boston and Cambridge organizations for over 30 years from our Wallingford, CT headquarters, about 90 minutes from Kendall Square via I-95. We design cybersecurity programs for Cambridge’s technology, research, and life sciences organizations addressing nation-state espionage defenses, insider threat controls, post-quantum migration planning, AI model security, clinical trial data security, and ITAR/EAR export control access governance.
Why Cybersecurity Matters for Cambridge Businesses
Defense Against Real-world Attacks
Cambridge’s research organizations are not facing generic commodity ransomware as their primary threat. FBI and CISA threat intelligence specifically names Cambridge-area institutions as targets of nation-state actors conducting economic and scientific espionage campaigns against AI, quantum computing, biotechnology, and defense-funded research. These campaigns use techniques — spear-phishing of research staff, insider recruitment, research software supply chain compromise — that standard commercial security programs were not designed to detect or prevent.
Operational Continuity
A security incident affecting the research data of a Cambridge AI company at the pre-commercial stage cannot be remediated the way a commercial data breach can. Pre-patent research data that is exfiltrated does not come back. A training dataset that is poisoned may produce a model with embedded vulnerabilities that are not discovered until after deployment. A clinical trial database that is compromised during an active study creates both regulatory and scientific integrity consequences that affect the trial outcome, not just IT operations. These are irreversible consequences that make security continuity a scientific and commercial obligation, not just an IT priority.
Cyber Insurance & Compliance Readiness
Cambridge organizations face compliance obligations that span multiple federal frameworks simultaneously: ITAR and EAR export control requirements governing access to controlled technical data, NIST SP 800-171 requirements for federally funded research handling controlled unclassified information, HIPAA for clinical research data, and 201 CMR 17.00 for any commercial organization handling Massachusetts personal information. A unified cybersecurity program that satisfies all of these frameworks simultaneously is more defensible to federal auditors and cyber insurance underwriters than separate compliance efforts managed independently.
Identity-Centric Protection
Cambridge’s globally distributed research teams — graduate students and postdocs from dozens of countries, research scientists whose employment status changes with funding cycles, and founding teams whose institutional affiliations shift as organizations spin out of universities — create an identity governance challenge that is fundamentally different from managing a stable corporate workforce. The access controls that protect pre-patent research, ITAR-controlled technical data, and clinical trial databases must reflect the actual current authorization status of every person who can reach them, updated continuously as researchers join, leave, and transition.
Early Detection & Containment
The nation-state campaigns targeting Cambridge operate on long timelines — months of reconnaissance before exfiltration, sustained access to research environments to monitor ongoing work, and patient collection of encrypted data for potential future decryption. Detection at this threat level requires behavioral analytics that identify the slow, methodical access patterns of a persistent adversary rather than the fast, disruptive patterns of commodity ransomware. Cambridge organizations that implement monitoring calibrated to the nation-state threat profile detect intrusions that commercial security tools miss entirely.
Tested Recovery & Resilience
The irreversibility of the specific harms Cambridge organizations face — pre-patent IP disclosure, clinical trial data integrity compromise, export control violation through unauthorized data access — makes the case for prevention more compelling than recovery. But resilience matters for the conventional threats Cambridge also faces: the ransomware campaigns that target the research sector for the same combination of sensitive data and limited security resources that makes healthcare attractive. Tested backup and recovery for research data is the safety net that prevents a ransomware event from also destroying irreplaceable experimental results.
Why Cambridge Organizations Choose SII
SII has worked with Cambridge and Greater Boston research organizations for over 30 years — long enough to have built export control compliance programs before ITAR enforcement in research settings was a DOJ priority, long enough to have built HIPAA-aligned research data environments before clinical trial data security was a standard due diligence question, and long enough to have supported organizations through multiple generations of the research-to-commercial transition that defines Cambridge’s economy. The cybersecurity threats and compliance obligations that Cambridge organizations now face — nation-state espionage campaigns documented by federal law enforcement, NIST post-quantum cryptography standards requiring encryption migration, AI model security requirements that have no counterpart in conventional IT security, and the insider threat profile specific to research environments with global talent and export control obligations — are areas where the depth of knowledge required to build an effective program comes from working in this specific market over years, not from applying standard commercial cybersecurity frameworks to an environment they were not designed for. We build NIST- and CIS-aligned, multi-layered security programs for Cambridge organizations across identity, email, endpoints, networks, research computing, and cloud — backed by continuous monitoring, insider threat detection, and tested recovery — calibrated to the threat profile and compliance obligations of the world’s most targeted research ecosystem.
What SII Delivers with Cyber Security Services in Cambridge
- Nation-state threat defense architecture for Cambridge’s MIT and Harvard ecosystem organizations — spear-phishing defense calibrated to the research-specific lures that FBI intelligence has documented targeting Cambridge graduate students and research staff, supply chain compromise detection for research software tools and data pipeline components, and the behavioral monitoring that identifies the slow, sustained access patterns characteristic of nation-state actors conducting persistent research espionage campaigns
- Insider threat programs built for Cambridge’s research-to-commercial transition — access governance that enforces the principle of least privilege for pre-patent research data and automatically revokes credentials at the moment a researcher’s institutional affiliation changes; data loss prevention monitoring for the specific exfiltration vectors most used in documented Cambridge IP theft cases (cloud storage uploads, personal email transfers, portable media); and audit logging that produces a defensible record of who accessed which research data and when, usable in patent disputes, trade secret litigation, and DOJ investigations
- Post-quantum cryptography (PQC) migration programs for Cambridge’s quantum computing research organizations — inventory of quantum-vulnerable cryptographic implementations (RSA, ECC-based TLS, key exchange protocols) across research data stores and communication channels, migration roadmaps to NIST-standardized post-quantum algorithms (ML-KEM, ML-DSA) for data whose sensitivity will persist beyond the quantum threat horizon, and protection against “harvest now, decrypt later” campaigns by adversaries collecting encrypted research data today for future decryption
- AI model security programs for Cambridge’s MIT CSAIL, Harvard AI, and Kendall Square AI research organizations — model weight access controls and exfiltration monitoring protecting trained model artifacts with the same rigor applied to the training data that produced them; training data integrity controls that detect and alert on dataset manipulation attempts before poisoned data enters the training pipeline; and adversarial robustness assessment for Cambridge AI companies whose deployed models face adversarial example and model inversion attacks in production
- Clinical trial data security for Cambridge’s clinical-stage biotechs — electronic data capture (EDC) system security and FDA 21 CFR Part 11 audit trail protection for multi-site trials managed from Cambridge sponsor and CRO locations; access controls implementing Good Clinical Practice blinding requirements that prevent unblinded access by individuals whose awareness of randomization assignments would compromise trial integrity; and research HIPAA security architecture for the patient-identifiable information collected in Cambridge-run clinical studies
- ITAR and EAR export control access governance, federal research grant data security (NIST SP 800-171 for CUI, HIPAA for NIH research data), 201 CMR 17.00 WISP maintenance for Cambridge commercial organizations, and the continuous ITAR/EAR authorization status monitoring that detects and alerts on access by individuals whose export authorization has changed or lapsed — maintained as ongoing operational disciplines rather than one-time compliance projects
Our Cybersecurity Services in Cambridge, MA
Security Assessments & Risk Analysis
We assess Cambridge organizations’ security posture against the specific threat profile and compliance obligations of this market: nation-state espionage threat modeling for MIT and Harvard ecosystem organizations conducting pre-commercial AI, quantum, and life sciences research; insider threat risk assessment including export control access governance gaps and research-to-commercial transition credential inventory; post-quantum cryptography vulnerability inventory for organizations with long-lived data sensitivity; AI model security architecture assessment for Cambridge AI research companies; clinical trial EDC and data governance assessment for biotechs running active clinical programs; and ITAR/EAR export control compliance assessment for organizations with globally distributed research teams.
NIST & CIS Framework Implementation
We implement NIST CSF, NIST SP 800-171, and CIS Controls-based security programs for Cambridge organizations — with NIST SP 800-171 implementation for Cambridge research organizations handling federally funded CUI under DoD research awards; access governance frameworks mapped to ITAR and EAR export authorization status; NIST post-quantum cryptography standard implementations (ML-KEM, ML-DSA) for organizations beginning PQC migration; and the documented security baseline that federal funding agency site visits, export control audits, and Series B/C investor due diligence each require.
Network & Endpoint Security
We deploy next-generation firewalls, endpoint detection and response, and network segmentation for Cambridge’s research and technology environments — with research network segmentation that isolates pre-patent research data environments from internet-accessible systems in configurations that reduce the attack surface available to nation-state actors conducting external reconnaissance; endpoint data loss prevention that monitors for the cloud storage, portable media, and personal email exfiltration vectors most frequently used in documented Cambridge IP theft cases; and AI and research computing environment isolation that separates model training infrastructure from production and administrative networks.
Email Security & Phishing Protection
Cambridge’s graduate students, postdoctoral researchers, and research staff are the specific targets of spear-phishing campaigns documented in FBI threat advisories for the university research ecosystem — lures impersonating grant funding agencies, journal editors requesting peer review of sensitive research, institutional security notifications, and research collaboration invitations that deliver credential-harvesting payloads. We implement advanced spear-phishing detection and impersonation controls calibrated to the research community’s communication patterns, with simulation programs that train Cambridge research staff to recognize the specific lure types that nation-state actors and criminal groups have used against this community.
Identity & Access Management (IAM)
We implement MFA, SSO, and role-based access controls for Cambridge organizations with the insider threat and export control access governance that research environments require: automated access revocation workflows that respond immediately when a researcher’s institutional affiliation or export authorization status changes; role-based permission models that enforce the principle of least privilege for pre-patent research data, AI model weights, and clinical trial databases; and export control classification-aware access controls that enforce ITAR and EAR authorization requirements at the individual user level rather than at the network perimeter.
Threat Monitoring & Alerting
We deploy SIEM-backed continuous monitoring with behavioral analytics configured for Cambridge’s specific threat profile: nation-state actor detection using indicators of compromise and behavioral patterns documented in FBI and CISA advisories for research institution targeting; insider threat monitoring for the data access and exfiltration behaviors that characterize Cambridge IP theft cases; AI model weight access anomaly detection; export control access monitoring that alerts when ITAR or EAR-controlled data is accessed by individuals outside their authorized population; and clinical trial database access monitoring for GCP blinding control violations.
Backup & Disaster Recovery
We implement encrypted, isolated backup with immutable storage and integrity-verified recovery for Cambridge’s research data environments — protecting irreplaceable pre-commercial research output, AI model weights and training datasets, and clinical trial data with backup configurations that maintain export control data residency requirements for ITAR and EAR-controlled research artifacts, HIPAA-compliant patient data backup for clinical research programs, and federal data management plan-compatible retention configurations for NIH and NSF-funded research data.
Incident Response Planning & Support
We develop Cambridge-specific incident response plans addressing the multi-regulatory notification landscape of this market: DOJ and State Department notification considerations for suspected ITAR or EAR export control violations; HIPAA breach response for clinical research patient data; 201 CMR 17.00 Massachusetts breach notification for commercial organizations; NIH and NSF grant sponsor notification requirements for data security incidents affecting federally funded research; and the insider threat response procedures — evidence preservation, access revocation, and legal hold considerations — appropriate for incidents that may become the subject of civil trade secret litigation or federal criminal investigation.
Employee Security Awareness Training
We deliver security awareness training calibrated to Cambridge’s research community: nation-state spear-phishing recognition using the specific lure types documented in FBI and CISA advisories for the university research sector; insider threat awareness training that addresses the legal and professional consequences of unauthorized IP transfer during research-to-commercial transitions; ITAR and EAR export control data handling training for research staff with access to controlled technical data; AI model and training data security awareness for research engineers handling model artifacts and datasets; and clinical trial data security training for Cambridge biotech staff with access to patient data and blinded trial databases.
Our Multi-layered Security Process
1
Identify
We map Cambridge organizations’ specific threat surface and compliance obligations before any remediation begins: classifying technical data against ITAR and EAR export control schedules and identifying who currently has access; inventorying quantum-vulnerable cryptographic implementations for organizations with long-lived data sensitivity; assessing AI model weight and training data access governance gaps; identifying clinical trial EDC access control and GCP blinding implementation gaps for biotech sponsors and CROs; and assessing insider threat control gaps against the specific exfiltration vectors documented in Cambridge IP theft cases.
2
Protect
We implement layered technical controls calibrated to Cambridge’s threat environment: export control classification-aware access governance with automated authorization status verification; data loss prevention monitoring for the cloud storage, portable media, and personal email exfiltration vectors most used in research IP theft; endpoint protection and network segmentation that reduces the external attack surface available to nation-state reconnaissance; post-quantum cryptography migration for data requiring long-term confidentiality; AI model weight and training data access controls; and clinical trial EDC access controls implementing GCP blinding requirements.
3
Detect
We deploy behavioral monitoring configured for Cambridge’s specific threat actors and insider risk profile: nation-state behavioral indicators from FBI and CISA intelligence integrated into detection rules; insider threat behavioral analytics that identify the access patterns preceding documented Cambridge IP exfiltration cases; export control access monitoring alerting on access by individuals outside their authorized population; AI model artifact access anomaly detection; clinical trial database access monitoring for blinding control violations; and post-quantum threat harvest-and-exfiltrate pattern detection for organizations with long-lived data sensitivity.
4
Respond
We execute incident response procedures mapped to Cambridge’s multi-authority notification obligations: HIPAA breach response for clinical research data; 201 CMR 17.00 Massachusetts breach notification for commercial organizations; NIH and NSF data security incident notification for federally funded research programs; evidence preservation and legal hold procedures for incidents that may involve trade secret misappropriation or export control violations subject to DOJ or State Department inquiry; and insider threat response protocols that revoke access immediately while preserving the forensic evidence record that subsequent civil or criminal proceedings require.
5
Recover
We restore Cambridge organizations’ research and business environments with the integrity verification that federal compliance and scientific validity require: federal research data management plan-compatible recovery documentation for NIH and NSF programs; export control access governance verification confirming that restored access permissions reflect current authorization status; AI model weight and training data integrity verification confirming that recovered artifacts are identical to the pre-incident versions and have not been modified; clinical trial data recovery with chain-of-custody documentation appropriate for an FDA review of data integrity following a cybersecurity event; and insider threat post-incident access remediation that closes the credential gaps the incident exposed.
Serving Cambridge and the Surrounding Research and Technology Corridor
SII is approximately 90 minutes from Cambridge via I-95 from Wallingford, CT. Our remote monitoring and management covers every Cambridge-area client environment continuously, with on-site engineering available for research lab infrastructure, specialized installations, and situations requiring physical presence. Our Cambridge-area cybersecurity practice extends into the research and technology communities surrounding Kendall Square:
- Acton, MA
- Billerica, MA
- Chelsea, MA
- Concord, MA
- Winchester, MA
Acton on the Route 2 corridor anchors one of the most concentrated R&D clusters west of Cambridge, with life sciences companies, research-stage technology organizations, and engineering firms that carry the same export control, pre-patent IP protection, and federal grant data security obligations as their Kendall Square counterparts, in a market that is substantially underserved by the Cambridge-area cybersecurity providers who concentrate on the dense inner urban research ecosystem. Concord’s Route 2 and Route 62 corridors extend this R&D geography further west, hosting life sciences and technology organizations with a similar compliance profile. Billerica on the Route 3 and I-495 corridor adds the commercial technology and engineering company market that connects Cambridge’s research economy to the broader Massachusetts technology sector. Winchester’s professional services and research-adjacent business community north of Cambridge rounds out the geography with the financial advisory, legal, and business services organizations serving Cambridge’s research economy whose security obligations derive from their proximity to and service of research-stage clients. Chelsea’s commercial economy adjacent to East Boston and Logan Airport adds the logistics, commercial, and professional services organizations that serve Cambridge’s research community from its eastern periphery.
Each Cambridge-area cybersecurity engagement SII manages is led by a program owner who understands the specific threat profile and compliance environment of research-to-commercial organizations — responsible for the Kendall Square AI company protecting model weights against nation-state exfiltration, the quantum computing startup beginning its post-quantum cryptography migration, the Cambridge biotech managing clinical trial EDC security, the MIT spin-out implementing insider threat controls during its academic-to-commercial transition, and the Acton R&D organization maintaining ITAR and EAR export control access governance for its internationally staffed engineering team.
FAQs
FBI has issued warnings about nation-state actors targeting university research. What specifically are they doing, and what cybersecurity controls actually stop them?
The FBI’s advisories on nation-state targeting of university research describe a consistent set of attack techniques that differ from the commodity ransomware campaigns affecting commercial businesses. The primary techniques documented against Cambridge-area institutions are four. First, spear-phishing of research staff: unlike broad-based phishing campaigns, these attacks are personalized to the target’s specific research topic, institutional relationships, and communication patterns. A graduate student working on a quantum error correction algorithm may receive a message appearing to come from a journal requesting peer review of a related paper, from a funding agency requesting documentation, or from a collaborating institution at another university — all crafted to induce credential disclosure or malware installation. Second, insider recruitment: documented DOJ prosecutions have involved nation-state intelligence services identifying researchers with access to valuable technical data and approaching them with financial or professional offers in exchange for data. Third, research software supply chain compromise: tools used in research computing pipelines — data processing libraries, analysis frameworks, collaboration platforms — have been compromised to create access points into research environments. Fourth, cloud research storage misconfiguration exploitation: research teams using commercial cloud storage without proper access controls have inadvertently made research data accessible to adversaries monitoring for exposed research artifacts. The controls that address these techniques are specific: behavioral spear-phishing simulation programs that train research staff to recognize the specific lure types documented in FBI advisories; insider threat monitoring that detects access patterns inconsistent with a researcher’s normal workflow; software supply chain controls that verify the integrity of research tools before installation; and cloud storage access governance that enforces authentication and access logging across research data repositories.
We run an AI research organization in Cambridge. What does AI model security mean in practice, and how is it different from standard data security?
AI model security addresses threat categories that do not exist in conventional data environments. The first is model weight exfiltration: the trained weights of a large language model, computer vision model, or domain-specific foundation model represent the distillation of months or years of compute time and the proprietary training data that shaped the model’s capabilities. Model weights are a high-value intellectual property artifact whose theft is economically equivalent to stealing the source code of a software product — but they are often stored in file systems and cloud storage with access controls designed for research convenience rather than IP protection. The access governance and DLP monitoring that protects research datasets must also cover model artifacts, including the checkpoints, fine-tuned variants, and production weights that AI companies accumulate through the development lifecycle. The second is training data integrity: adversarial manipulation of training data before or during model training — data poisoning — can produce models that behave differently when they encounter specific inputs, models with embedded backdoors that activate under controlled conditions, or models that systematically fail in ways that are predictable to the attacker. Data integrity controls that verify the authenticity and completeness of training datasets, and monitoring that detects unauthorized modification of training data stores, are cybersecurity requirements for Cambridge AI companies, not just data management practices. The third is adversarial robustness for deployed models: Cambridge AI companies whose research models are deployed in products face model inversion attacks (reconstructing training data from model outputs), membership inference attacks (determining whether specific data was in the training set), and adversarial example attacks (crafting inputs that cause systematic misclassification). Addressing these threats requires security architecture at the model serving layer, not just at the data and infrastructure layers where conventional cybersecurity operates.
Our Cambridge organization works in quantum computing research. We keep hearing about post-quantum cryptography. When do we need to actually do something about it?
The answer for Cambridge quantum computing organizations is: now, for data that will retain its sensitivity for more than five to ten years. NIST finalized its first post-quantum cryptographic standards in August 2024 after an eight-year evaluation process — specifically ML-KEM (for key encapsulation and encryption) and ML-DSA (for digital signatures). These standards exist because the intelligence community and the cryptographic research community agree that quantum computers capable of breaking current public-key encryption (RSA, ECC-based systems) are likely to become available within a timeframe that is meaningful for data with long-lived sensitivity. The threat this creates for Cambridge research organizations is the “harvest now, decrypt later” attack: adversaries — specifically nation-state actors with the resources to store large volumes of encrypted data and the institutional motivation to acquire quantum computing capabilities — are collecting encrypted research data, communications, and intellectual property today, with the intention of decrypting it once quantum computing makes that possible. For a quantum computing company in Cambridge whose foundational algorithms will retain commercial value for decades, or a biotech whose pre-clinical research will remain competitively sensitive through a drug development timeline, the data they are encrypting today with RSA or ECC may be decryptable by a well-resourced adversary within the patent’s useful life. Migrating to post-quantum cryptographic algorithms for data requiring long-term confidentiality is not a future project — it is a current one. We conduct post-quantum cryptography readiness assessments for Cambridge organizations, inventory quantum-vulnerable cryptographic implementations across their infrastructure, and develop migration roadmaps to NIST-standardized post-quantum algorithms.
We are a Cambridge biotech running a clinical trial. What does “GCP cybersecurity” mean, and how is clinical trial data security different from standard HIPAA?
Good Clinical Practice (GCP) — the FDA-enforced international standard for the design, conduct, and reporting of clinical trials — creates cybersecurity requirements that are distinct from standard HIPAA obligations, even though both apply to clinical trial data simultaneously. The GCP-specific cybersecurity requirements center on two areas. The first is trial integrity and blinding: in a randomized controlled trial, the treatment assignment (which subjects are in the active arm versus the control arm) must be maintained confidential from individuals whose knowledge of that assignment would bias the trial outcome — including investigators, clinical staff, and data analysts. Electronic clinical trial databases must have access controls that enforce this blinding in a technically defensible way, with audit trails that document who had access to unblinded data and under what circumstances. An FDA inspector reviewing trial data integrity will examine whether the blinding was maintained throughout the conduct of the trial, and a system-level compromise that allowed an unblinded individual unauthorized access to randomization data creates a trial integrity question that cannot be resolved retroactively. The second is electronic data capture security: EDC systems that collect clinical data from trial sites must satisfy FDA 21 CFR Part 11 requirements for electronic records, including audit trails capturing every data entry, modification, and deletion, access controls that attribute each record change to a specific authorized user, and data integrity controls that protect the collected records from unauthorized modification. For Cambridge biotechs managing multi-site trials from a Cambridge sponsor office, the security of the EDC system’s access control and audit trail architecture is a regulatory submission consideration, not just an IT operational matter. We design and implement the access control and audit trail architecture for clinical trial EDC environments and provide ongoing monitoring that can detect the access anomalies that would compromise trial integrity.
What is the first step to getting cybersecurity services for our Cambridge organization?
The starting point is a Cambridge cybersecurity assessment scoped to your organization’s specific threat profile and compliance obligations. For MIT and Harvard ecosystem organizations, we begin with a nation-state threat modeling session and an export control access governance inventory. For quantum computing organizations, we conduct a post-quantum cryptography readiness inventory. For AI research companies, we assess model weight access governance and training data integrity controls. For clinical-stage biotechs, we assess EDC security and GCP blinding control implementation. For research organizations with federal funding, we identify the specific NIST SP 800-171 or HIPAA gaps relevant to each funding source. The assessment produces a written findings summary and a prioritized security architecture plan before any commitment is required. Call us at 860-513-0100 or visit sys-int.com/contact-us to schedule.
The Research Happening in Cambridge Is Too Valuable for Standard Cybersecurity.
Request a Cambridge cybersecurity assessment. We’ll evaluate your nation-state threat exposure, insider threat control gaps, post-quantum cryptography readiness, AI model security architecture, or clinical trial data protection posture — and deliver a plan built for this market before you commit.