One standard,
every company you own.
Managed IT and compliance for private equity firms and their portfolio companies. We have stood up the same standard across acquisitions in dental, manufacturing, retail, and professional services: diligence before the close, a known build in the first hundred days, one compliance program rolled up across the portfolio, and clean IT when it is time to sell. Usually for less than the six providers you are paying now.
IT for every stage of the deal.
Diligence, the close, the first hundred days, the hold, and the exit each ask IT for something different. We have a playbook for each, and the same standard runs through all of them.
- Before the close
See what you are buying
Two weeks, one report: what is exposed, what it costs to fix, and what it does to the model.
- IT and cyber diligence with a priced findings list
- Compliance and insurance exposure by industry
- Key-person and vendor risks named
- A first-hundred-days plan attached
- Day one
Own the keys
Every domain, tenant, admin account, and vendor contract in the company’s name by the end of the day.
- Domain, DNS, and Microsoft 365 tenant transferred
- Founder and departed-owner access closed
- Backups verified before anything changes
- Help desk number on the wall
- Days 1 to 100
Bring it to the standard
The portfolio build, applied without stopping the business.
- Identity, MFA, and endpoint protection on the standard
- Network segmented, backups restore-tested
- The industry compliance program started
- Diligence findings closed and reported
- The hold
Run it, prove it, report it
One page per company, one page for the portfolio, every quarter.
- Same plans, same help desk, same evidence everywhere
- HIPAA, PCI, CMMC, Safeguards where each applies
- Vendor spend consolidated, savings dated in the model
- Add-ons onboarded to the same build at a known cost
- The sale
Pass the buyer’s diligence
The next buyer’s IT diligence is a folder we already keep.
- Inventory, policies, and evidence current on request
- No key-person risk, no surprise contracts
- Clean separation for carve-outs
- A transition plan the buyer can keep or not
Most of our portfolio work starts in the middle: a firm with six companies, six IT providers, and one renewal questionnaire nobody can answer the same way twice. We start where you are.
Every company, against the same standard.
The view an operating partner asks for and rarely gets: each company, where it stands on the build, and whether the evidence exists for the rules its industry answers to. Ours is a real report, refreshed every quarter and the week a new company closes.
| Company | Answers to | Standard build | MFA | Backups tested | Evidence |
|---|---|---|---|---|---|
| Dental group4 locations | HIPAA | done | done | done | done |
| Precision machiningdefense subcontracts | NIST 800-171 | done | done | in progress | in progress |
| Specialty retail11 stores | PCI, small scope | in progress | done | done | in progress |
| Accounting roll-upclosed last month | FTC Safeguards | gap | in progress | gap | gap |
| Home services2 markets | Insurer only | done | done | done | done |
| SoftwareSaaS | SOC 2 | done | done | done | in progress |
- Same build, different rules
- Every company runs the same standard underneath. The frame on top is whatever its industry answers to, and only that.
- Evidence, not assurances
- Every cell is a file. A lender, an LP, or a buyer can ask for the folder behind any of them.
- Add-ons land on the standard
- The accounting roll-up above closed last month. It is on the page from day one, with the gaps and the plan to close them.
Six of everything becomes one.
A portfolio pays for the same things over and over: six IT providers, six phone bills, six security stacks, six people answering the same insurance questionnaire six different ways. Consolidating onto one standard is where the IT synergy in the model actually comes from, and it is the part most firms never collect.
- IT providers and help desksOne team that knows every company, one number on every wall 6 1
- Phone systems and billsOne hosted platform, each company keeps its numbers and call flow 6 1
- Security stacksOne EDR, one email security, one backup platform, licensed once 6 1
- Insurance questionnairesSame evidence, same answers, every renewal 6 answers 1 answer set
- Vendor contracts to manageOverlapping tools cancelled, the rest renegotiated once at portfolio scale 40+ a dozen
- Cost to onboard an add-onKnown before the LOI, because the build is fixed a project a number
- Savings with dates, not hopes
Every consolidation gets a date in the model: when the old provider ends, when the phone bill drops, when the duplicate tool is cancelled.
- Licenses right-sized on the way in
Floor staff, checkers, and machinists on Frontline plans instead of office rates. Idle licenses found and cancelled in the first hundred days.
- Fewer vendors, fewer meetings
The operating partner has one IT conversation a quarter instead of six, and the GMs stop managing vendors and get back to running the business.
- Downtime treated as a cost line
A line that stops, a register that drops, or a clinic that cannot open is a number in the model. The standard exists to keep that number small.
- One tenant design per company, owned by the company
- MFA on every login, named accounts only
- Joiners and leavers from the HR roster
- Admin access held by us, escrowed to the firm
- Managed, encrypted laptops and workstations
- Endpoint detection and response on all of them
- Patching in windows the business approves
- Personal devices only under a policy
- Segmented networks: office, production, guest, vendors
- Firewall with a backup internet path where it matters
- Backups off site, restore-tested quarterly
- Vendor remote access time-boxed and logged
- Email security and phishing training
- Logging and 24/7 detection where the plan calls for it
- The industry program on top: HIPAA, PCI, CMMC, Safeguards
- Insurance and questionnaire evidence kept current
Written once. Applied to every company.
A portfolio with six companies has six of everything, and usually six different versions. We write the build once and apply it to each company as it comes in, so the operating partner compares like with like and the next add-on has a known cost.
- A known cost per company
- Because the build is fixed, the cost to bring an add-on to the standard is a number before the LOI, not a surprise after.
- Exceptions written down
- The machine that cannot be patched, the legacy ERP, the founder’s custom app: each is documented, walled off, and on the risk list.
- Software stays the business’s
- Practice management, ERP, and point of sale are whatever the company runs. The standard is what sits underneath them.
Day one at a new portfolio company.
An inventory, not a pitch. These are the conditions we walk into after most closes, in the order we find them.
- Six companies, six IT providers, six answers
Nobody can answer the insurance questionnaire the same way twice, and nobody at the firm can say which company is exposed.
- The founder still owns the domain
And the Microsoft tenant, the DNS, and the only admin password. The company you bought does not own its own front door.
- Diligence findings that were never actioned
The report flagged the flat network and the untested backups. It went in the data room and stayed there.
- Backups nobody has restored
A job runs every night. Nobody has opened one. The first restore is the one that matters, and it fails.
- MFA where it was convenient
On the owner’s email and nowhere else. Remote access, the ERP, and the file share are a password away.
- Add-ons bolted on, never integrated
Three acquisitions, three email systems, three help desks. The synergy in the model is still on paper.
Six companies, six AI policies. Or one.
Every portfolio company is already using AI, and so is the deal team. Portfolio companies paste customer lists into chatbots. Associates paste memoranda and models into them. One policy, one approved list, and one set of vendor reviews, applied to every company, closes most of that in a quarter.
- A different AI tool in every portfolio company, none reviewed
- Deal materials, models, and memoranda in free chatbots at the firm
- Copilots switched on inside company tenants with wide-open file shares
- AI vendors signed by a GM with no one reading the data terms
The tools the portfolio pays for, with a rule for each, adopted by every company on the standard. A GM does not have to invent a policy.
An AI vendor is reviewed one time, training on company data turned off where the setting exists, and the record shared across the portfolio.
A copilot surfaces whatever the person could already open. We fix the file shares first, in every company, so it cannot surface payroll or a customer list by accident.
Memoranda, models, and LP data stay in tools the firm controls. The same rule the portfolio follows, applied at the top.
- Deal materials or LP data in free chatbots
- Portfolio-company customer or patient data in personal AI accounts
- AI vendors signed without data terms read
- Copilots on file shares nobody has permissioned
The AI rule is one page in the portfolio standard. Regulated companies get the industry-specific version on top: BAAs for healthcare, the enclave rule for defense work, the Safeguards review for accounting.
One program. Every frame. One report.
A dental group answers to HIPAA. A machine shop with defense work answers to NIST 800-171. A retail chain answers to PCI, an accounting roll-up to the FTC Safeguards Rule, and every one of them to the insurer. The build underneath is the same. We run the program each company needs and roll the evidence up to one place, so the firm sees the portfolio and each GM sees only their company.
If the firm itself is a registered adviser, the 2024 Regulation S-P amendments require an incident response program and notice to affected individuals within thirty days. We build that into the firm’s own plan, not just the portfolio’s.
- Portfolio IT standard, written and adopted current current
- Every company on the standard 5 of 6 watch
- MFA everywhere, every company enforced current
- Backups restore-tested 6 of 6 current
- Per-industry programs current HIPAA, PCI, CMMC, Safeguards current
- Cyber-insurance renewals, one answer set ready current
- Key-person and vendor risks tracked 2 open scheduled
- Incident response rehearsed portfolio-wide Q2 current
- Exit-readiness folder current current
Identity, endpoints, network, backups, and security stack written once and applied to every company, with the exceptions documented.
HIPAA, PCI scoping, NIST 800-171 and CMMC, FTC Safeguards, and client questionnaires, run for the company that needs each and kept current on a schedule.
Every renewal across the portfolio answered from the same evidence, the same way, so the firm is not surprised by an exclusion after a claim.
Who calls whom at each company and at the firm, what gets preserved, and who is notified, rehearsed once a year.
An acquisition gets the day-one transfer, the first-hundred-days plan, and the same build, with a known cost before the LOI is signed.
One page per company, one page for the portfolio. Every cell is a file, so a lender, an LP, or a buyer gets the folder, not a call.
Six providers become one, six phone bills become one, and the savings show up in the model with dates.
Inventory, policies, contracts, and evidence kept current, so the buyer’s IT diligence is a folder we hand over the same week.
What changes for the people around the deal.
The operating partner, the portfolio company GM, and the deal team each feel it differently. This is what each of them gets.
One page per company, one for the portfolio.
- Every company against the same standard, every quarter.
- Six providers become one, and the savings show up with dates.
- Add-ons onboarded to a known build with a known cost.
IT that shows up on day one and gets out of the way.
- A help desk that answers, and knows the standard before the first ticket.
- The founder’s keys transferred without the business stopping.
- The compliance program for their industry run for them, not assigned to them.
Diligence with a price on it.
- A findings list with cost to fix and what it does to the model.
- IT synergies in the model with dates, not hopes.
- At exit, the buyer’s diligence answered from a folder we already keep.
Most portfolio companies land on Secured. Regulated ones on Hardened.
Same plans as every SeriousIT client, priced per company, with Frontline plans for floor and shared-station staff so nobody pays office rates for a checker or a machinist. The standard is the same on both; Hardened adds the compliance program and the round-the-clock detection a regulated company needs.
One team for every company.
Phones, fiber, and the cabling, cameras, and access control for a new location, on the same standard and the same statement as the IT.
Company phones
Hosted phones on one platform across the portfolio, with each company’s numbers and call flow kept, and a main line that survives a rebrand.
Business phonesBusiness fiber
UTOPIA Fiber for the Utah locations, supported by the team that runs the network, with a backup path where the business cannot go dark.
Business fiberNew locations and consolidations
Structured cabling, cameras, and door access for openings, moves, and the office you close after the merger, managed after install.
InfrastructureStraight answers.
Can you do diligence before we close?
Yes. Two weeks, one report: what is exposed, what it costs to fix, what it does to the model, and a first-hundred-days plan attached. We have done it under LOI timelines.
Do all the companies have to use SeriousIT?
No. We run the standard across the companies you give us and audit the rest against it, so the operating partner still gets one page for the portfolio.
How do you handle add-on acquisitions?
The same way every time: day-one transfer of the keys, the first-hundred-days plan, and the standard build, with the cost known before the LOI is signed.
What does the operating partner actually get?
A quarterly page per company and one for the portfolio: standard-build status, MFA, tested backups, compliance program status, insurance readiness, and open risks, every cell backed by a file.
Will this cost more than what the companies pay now?
Usually less in total. Six providers, six phone bills, and six overlapping security tools cost more than one standard run by one team, and the licenses get right-sized on the way in. The savings are dated in the model, not promised in a deck.
Can the portfolio companies keep their own software?
Yes. The standard is identity, endpoints, network, backups, and security. Practice management, ERP, and point of sale stay what the business runs, and we support them.
Can you help with the sale?
Yes. The exit-readiness folder is kept current through the hold, so the buyer’s IT diligence is answered the same week, and carve-outs get a clean separation plan.
Start with one company.
Send us the portfolio list, the last insurance questionnaire, and what each company pays for IT today. We come back with where each stands against a standard, what closing the gaps would cost, what consolidating would save, and where the first hundred days should start.