SeriousIT
Private equity

One standard,
every company you own.

Managed IT and compliance for private equity firms and their portfolio companies. We have stood up the same standard across acquisitions in dental, manufacturing, retail, and professional services: diligence before the close, a known build in the first hundred days, one compliance program rolled up across the portfolio, and clean IT when it is time to sell. Usually for less than the six providers you are paying now.

A team reviewing figures on laptops in a modern meeting room
Add-on closed Friday, on the standard by day 100
The hold period

IT for every stage of the deal.

Diligence, the close, the first hundred days, the hold, and the exit each ask IT for something different. We have a playbook for each, and the same standard runs through all of them.

  1. Before the close

    See what you are buying

    Two weeks, one report: what is exposed, what it costs to fix, and what it does to the model.

    • IT and cyber diligence with a priced findings list
    • Compliance and insurance exposure by industry
    • Key-person and vendor risks named
    • A first-hundred-days plan attached
  2. Day one

    Own the keys

    Every domain, tenant, admin account, and vendor contract in the company’s name by the end of the day.

    • Domain, DNS, and Microsoft 365 tenant transferred
    • Founder and departed-owner access closed
    • Backups verified before anything changes
    • Help desk number on the wall
  3. Days 1 to 100

    Bring it to the standard

    The portfolio build, applied without stopping the business.

    • Identity, MFA, and endpoint protection on the standard
    • Network segmented, backups restore-tested
    • The industry compliance program started
    • Diligence findings closed and reported
  4. The hold

    Run it, prove it, report it

    One page per company, one page for the portfolio, every quarter.

    • Same plans, same help desk, same evidence everywhere
    • HIPAA, PCI, CMMC, Safeguards where each applies
    • Vendor spend consolidated, savings dated in the model
    • Add-ons onboarded to the same build at a known cost
  5. The sale

    Pass the buyer’s diligence

    The next buyer’s IT diligence is a folder we already keep.

    • Inventory, policies, and evidence current on request
    • No key-person risk, no surprise contracts
    • Clean separation for carve-outs
    • A transition plan the buyer can keep or not

Most of our portfolio work starts in the middle: a firm with six companies, six IT providers, and one renewal questionnaire nobody can answer the same way twice. We start where you are.

One page for the portfolio

Every company, against the same standard.

The view an operating partner asks for and rarely gets: each company, where it stands on the build, and whether the evidence exists for the rules its industry answers to. Ours is a real report, refreshed every quarter and the week a new company closes.

Portfolio, one pagestandard build · MFA · tested backups · evidence
CompanyAnswers toStandard buildMFABackups testedEvidence
Dental group4 locations HIPAA donedonedonedone
Precision machiningdefense subcontracts NIST 800-171 donedonein progressin progress
Specialty retail11 stores PCI, small scope in progressdonedonein progress
Accounting roll-upclosed last month FTC Safeguards gapin progressgapgap
Home services2 markets Insurer only donedonedonedone
SoftwareSaaS SOC 2 donedonedonein progress
Shown as a picture, not a live feed. The operating partner gets the real one every quarter; the deal team gets it the week a new company closes.
Same build, different rules
Every company runs the same standard underneath. The frame on top is whatever its industry answers to, and only that.
Evidence, not assurances
Every cell is a file. A lender, an LP, or a buyer can ask for the folder behind any of them.
Add-ons land on the standard
The accounting roll-up above closed last month. It is on the page from day one, with the gaps and the plan to close them.
Do more for less

Six of everything becomes one.

A portfolio pays for the same things over and over: six IT providers, six phone bills, six security stacks, six people answering the same insurance questionnaire six different ways. Consolidating onto one standard is where the IT synergy in the model actually comes from, and it is the part most firms never collect.

What the portfolio pays forTodayOn the standard
  • IT providers and help desksOne team that knows every company, one number on every wall 6 1
  • Phone systems and billsOne hosted platform, each company keeps its numbers and call flow 6 1
  • Security stacksOne EDR, one email security, one backup platform, licensed once 6 1
  • Insurance questionnairesSame evidence, same answers, every renewal 6 answers 1 answer set
  • Vendor contracts to manageOverlapping tools cancelled, the rest renegotiated once at portfolio scale 40+ a dozen
  • Cost to onboard an add-onKnown before the LOI, because the build is fixed a project a number
Counts are illustrative for a six-company portfolio. Yours get real numbers and dates in the review, and the savings go in the model with the date they land.
  • Savings with dates, not hopes

    Every consolidation gets a date in the model: when the old provider ends, when the phone bill drops, when the duplicate tool is cancelled.

  • Licenses right-sized on the way in

    Floor staff, checkers, and machinists on Frontline plans instead of office rates. Idle licenses found and cancelled in the first hundred days.

  • Fewer vendors, fewer meetings

    The operating partner has one IT conversation a quarter instead of six, and the GMs stop managing vendors and get back to running the business.

  • Downtime treated as a cost line

    A line that stops, a register that drops, or a clinic that cannot open is a number in the model. The standard exists to keep that number small.

Portfolio IT standard
one page per company, exceptions documented
Same standard, every company
Identity
  • One tenant design per company, owned by the company
  • MFA on every login, named accounts only
  • Joiners and leavers from the HR roster
  • Admin access held by us, escrowed to the firm
Endpoints
  • Managed, encrypted laptops and workstations
  • Endpoint detection and response on all of them
  • Patching in windows the business approves
  • Personal devices only under a policy
Network and backup
  • Segmented networks: office, production, guest, vendors
  • Firewall with a backup internet path where it matters
  • Backups off site, restore-tested quarterly
  • Vendor remote access time-boxed and logged
Security and compliance
  • Email security and phishing training
  • Logging and 24/7 detection where the plan calls for it
  • The industry program on top: HIPAA, PCI, CMMC, Safeguards
  • Insurance and questionnaire evidence kept current
Specified once, applied at each close, and kept as the drawing of record so nobody has to guess what a company runs.
The portfolio standard

Written once. Applied to every company.

A portfolio with six companies has six of everything, and usually six different versions. We write the build once and apply it to each company as it comes in, so the operating partner compares like with like and the next add-on has a known cost.

A known cost per company
Because the build is fixed, the cost to bring an add-on to the standard is a number before the LOI, not a surprise after.
Exceptions written down
The machine that cannot be patched, the legacy ERP, the founder’s custom app: each is documented, walled off, and on the risk list.
Software stays the business’s
Practice management, ERP, and point of sale are whatever the company runs. The standard is what sits underneath them.
Investors reviewing financial charts in an office
Day one

Day one at a new portfolio company.

An inventory, not a pitch. These are the conditions we walk into after most closes, in the order we find them.

  1. Six companies, six IT providers, six answers

    Nobody can answer the insurance questionnaire the same way twice, and nobody at the firm can say which company is exposed.

  2. The founder still owns the domain

    And the Microsoft tenant, the DNS, and the only admin password. The company you bought does not own its own front door.

  3. Diligence findings that were never actioned

    The report flagged the flat network and the untested backups. It went in the data room and stayed there.

  4. Backups nobody has restored

    A job runs every night. Nobody has opened one. The first restore is the one that matters, and it fails.

  5. MFA where it was convenient

    On the owner’s email and nowhere else. Remote access, the ERP, and the file share are a password away.

  6. Add-ons bolted on, never integrated

    Three acquisitions, three email systems, three help desks. The synergy in the model is still on paper.

AI, done right

Six companies, six AI policies. Or one.

Every portfolio company is already using AI, and so is the deal team. Portfolio companies paste customer lists into chatbots. Associates paste memoranda and models into them. One policy, one approved list, and one set of vendor reviews, applied to every company, closes most of that in a quarter.

Already happening on your network
  • A different AI tool in every portfolio company, none reviewed
  • Deal materials, models, and memoranda in free chatbots at the firm
  • Copilots switched on inside company tenants with wide-open file shares
  • AI vendors signed by a GM with no one reading the data terms
Nobody meant to create a risk. They wanted the work done faster. The fix is a short list and a few settings, not a ban.
One approved list, portfolio-wide

The tools the portfolio pays for, with a rule for each, adopted by every company on the standard. A GM does not have to invent a policy.

Vendor terms reviewed once, for everyone

An AI vendor is reviewed one time, training on company data turned off where the setting exists, and the record shared across the portfolio.

Copilots scoped by fixing permissions first

A copilot surfaces whatever the person could already open. We fix the file shares first, in every company, so it cannot surface payroll or a customer list by accident.

The firm’s own rule for deal data

Memoranda, models, and LP data stay in tools the firm controls. The same rule the portfolio follows, applied at the top.

Never leaves the building
  • Deal materials or LP data in free chatbots
  • Portfolio-company customer or patient data in personal AI accounts
  • AI vendors signed without data terms read
  • Copilots on file shares nobody has permissioned

The AI rule is one page in the portfolio standard. Regulated companies get the industry-specific version on top: BAAs for healthcare, the enclave rule for defense work, the Safeguards review for accounting.

Portfolio compliance, rolled up

One program. Every frame. One report.

A dental group answers to HIPAA. A machine shop with defense work answers to NIST 800-171. A retail chain answers to PCI, an accounting roll-up to the FTC Safeguards Rule, and every one of them to the insurer. The build underneath is the same. We run the program each company needs and roll the evidence up to one place, so the firm sees the portfolio and each GM sees only their company.

If the firm itself is a registered adviser, the 2024 Regulation S-P amendments require an incident response program and notice to affected individuals within thirty days. We build that into the firm’s own plan, not just the portfolio’s.

What a covered portfolio looks like
What we keep current across every company we run
  • Portfolio IT standard, written and adopted current current
  • Every company on the standard 5 of 6 watch
  • MFA everywhere, every company enforced current
  • Backups restore-tested 6 of 6 current
  • Per-industry programs current HIPAA, PCI, CMMC, Safeguards current
  • Cyber-insurance renewals, one answer set ready current
  • Key-person and vendor risks tracked 2 open scheduled
  • Incident response rehearsed portfolio-wide Q2 current
  • Exit-readiness folder current current
Every line is documented and evidence-backed, so when a lender, an insurer, an LP, or the next buyer asks, the answer is a folder, not a scramble.
The portfolio year, item by item
A year of the program, item by item. Dots are the months we act; bars run all year.
The portfolio standard

Identity, endpoints, network, backups, and security stack written once and applied to every company, with the exceptions documented.

Per-industry programs

HIPAA, PCI scoping, NIST 800-171 and CMMC, FTC Safeguards, and client questionnaires, run for the company that needs each and kept current on a schedule.

Cyber insurance answered once

Every renewal across the portfolio answered from the same evidence, the same way, so the firm is not surprised by an exclusion after a claim.

Incident response across the portfolio

Who calls whom at each company and at the firm, what gets preserved, and who is notified, rehearsed once a year.

Add-ons onboarded to the standard

An acquisition gets the day-one transfer, the first-hundred-days plan, and the same build, with a known cost before the LOI is signed.

Evidence rolled up

One page per company, one page for the portfolio. Every cell is a file, so a lender, an LP, or a buyer gets the folder, not a call.

Vendor consolidation, priced

Six providers become one, six phone bills become one, and the savings show up in the model with dates.

Exit readiness

Inventory, policies, contracts, and evidence kept current, so the buyer’s IT diligence is a folder we hand over the same week.

After go-live

What changes for the people around the deal.

The operating partner, the portfolio company GM, and the deal team each feel it differently. This is what each of them gets.

Operating partner

One page per company, one for the portfolio.

  • Every company against the same standard, every quarter.
  • Six providers become one, and the savings show up with dates.
  • Add-ons onboarded to a known build with a known cost.
Portfolio company GM

IT that shows up on day one and gets out of the way.

  • A help desk that answers, and knows the standard before the first ticket.
  • The founder’s keys transferred without the business stopping.
  • The compliance program for their industry run for them, not assigned to them.
Deal team

Diligence with a price on it.

  • A findings list with cost to fix and what it does to the model.
  • IT synergies in the model with dates, not hopes.
  • At exit, the buyer’s diligence answered from a folder we already keep.
Which plan

Most portfolio companies land on Secured. Regulated ones on Hardened.

Same plans as every SeriousIT client, priced per company, with Frontline plans for floor and shared-station staff so nobody pays office rates for a checker or a machinist. The standard is the same on both; Hardened adds the compliance program and the round-the-clock detection a regulated company needs.

Securedmost common
The portfolio standard for most companies: identity and MFA, managed endpoints with EDR, segmented networks, tested backups, email security, and the insurance evidence, reported up every quarter.
Hardened
Companies with HIPAA, defense work, card scope worth managing, or the Safeguards Rule: the standard plus the compliance program, 24/7 detection and response, and log retention.
Managed
Rarely right for a company you are preparing to sell. We will tell you if it is.
Questions we get

Straight answers.

Can you do diligence before we close?

Yes. Two weeks, one report: what is exposed, what it costs to fix, what it does to the model, and a first-hundred-days plan attached. We have done it under LOI timelines.

Do all the companies have to use SeriousIT?

No. We run the standard across the companies you give us and audit the rest against it, so the operating partner still gets one page for the portfolio.

How do you handle add-on acquisitions?

The same way every time: day-one transfer of the keys, the first-hundred-days plan, and the standard build, with the cost known before the LOI is signed.

What does the operating partner actually get?

A quarterly page per company and one for the portfolio: standard-build status, MFA, tested backups, compliance program status, insurance readiness, and open risks, every cell backed by a file.

Will this cost more than what the companies pay now?

Usually less in total. Six providers, six phone bills, and six overlapping security tools cost more than one standard run by one team, and the licenses get right-sized on the way in. The savings are dated in the model, not promised in a deck.

Can the portfolio companies keep their own software?

Yes. The standard is identity, endpoints, network, backups, and security. Practice management, ERP, and point of sale stay what the business runs, and we support them.

Can you help with the sale?

Yes. The exit-readiness folder is kept current through the hold, so the buyer’s IT diligence is answered the same week, and carve-outs get a clean separation plan.

A modern office meeting room with a city view

Start with one company.

Send us the portfolio list, the last insurance questionnaire, and what each company pays for IT today. We come back with where each stands against a standard, what closing the gaps would cost, what consolidating would save, and where the first hundred days should start.