← Advisory · Startup IT & Security Baseline

Know exactly where your IT and security stand — in two weeks.

A focused, fixed-scope assessment that identifies the IT and security gaps most likely to disrupt growth, delay enterprise sales, or create avoidable operational risk. You get a clear executive picture and a prioritized 90-day plan you can actually execute.

baseline · maturity scorecard
Baseline maturity scorecard across identity, endpoint, cloud, SaaS, DNS and incident-readiness domains
The challenge

Informal IT stops scaling right when it matters most.

At 20–150 people, employee onboarding, SaaS access, device management, cloud ownership and customer security reviews are often handled informally across several people. Nothing is written down, no one owns it end-to-end, and the risk is invisible until a security questionnaire, an audit, or an incident forces the issue.

The Baseline replaces guesswork with a fact-based picture: what you have, where the real exposure is, and the order in which to fix it.

Who it's for
  • Founder / CEO, COO, CTO, VP Engineering or Head of Operations at a 20–150-person startup.
  • Growing fast — rapid or remote hiring, new leadership, cloud/SaaS sprawl.
  • Selling up-market — enterprise security reviews and SOC 2 pressure arriving.
  • Seed through Series B — recently funded, entering enterprise sales.
What we review

The control domains that decide whether you scale cleanly

A structured review across the areas most likely to disrupt growth or surface in customer diligence.

Identity & access

MFA, SSO, privileged access, administrator accounts, joiner/mover/leaver and offboarding.

Endpoints & devices

Inventory, encryption, patching, EDR/AV, device management and remote-work controls.

Workspace & email

Google Workspace / Microsoft 365, email security, SaaS ownership and account lifecycle.

Cloud & data

Cloud accounts, production access, secrets, logging, backup and recovery ownership.

Domains & DNS

Domain and registrar control, DNS, and email authentication — SPF, DKIM and DMARC.

Readiness & ownership

Incident-readiness roles, key vendors, continuity basics, security ownership, and enterprise security-questionnaire readiness.

baseline · risk register
Prioritized risk register with owner, impact, urgency and recommended remediation
What you receive

Deliverables leadership can act on.

  • Executive findings summary — written for CEO, COO and CTO stakeholders.
  • Prioritized risk register — each item with owner, impact, urgency and recommended remediation.
  • Maturity scorecard — a rating across every reviewed control domain.
  • 30/60/90-day roadmap — practical sequencing with dependencies.
  • Recommendations — technology, process and accountability.
  • Executive readout — a live walkthrough, plus a phase-two recommendation if appropriate.
How it runs

Fixed scope. One to two weeks.

1 · Scope & authorize

We agree a fixed fee and a defined 1–2 week scope in a SOW — responsibilities, required access, assumptions, schedule and acceptance criteria. Any technical validation is covered by explicit written authorization.

2 · Review & interview

We work through the control domains with short working sessions and the evidence you already have — no rip-and-replace, no disruption to the team.

3 · Readout & roadmap

You get the findings summary, risk register, maturity scorecard and a sequenced 30/60/90-day roadmap, walked through live with your leadership.

Authorization-first. We don't scan, test, or access any client system until an agreement and written authorization are in place. The Baseline is a review and planning engagement — clear, low-disruption, and confidential under NDA.

Book a 20-minute readiness call.

A short conversation to confirm fit and whether the Baseline is your right next step.