Skip to main content
Dig IT Solutions logo

Guides & Checklists

IT setup for startups: what to put in place from day one

A practical IT setup guide for UK startups: the day-one stack, identity and security basics, devices, backup, when to outsource and what to avoid.

By Dig IT SolutionsUpdated 8 September 20267 min read

Short answer

A startup should set up a business Microsoft 365 or Google Workspace tenant with MFA enforced, company-owned or managed devices with disk encryption, a password manager, an independent backup of cloud data, and a documented starter and leaver process before hiring. Add endpoint protection and Cyber Essentials once there is customer data, and outsource support rather than improvising.

New businesses spend their first months on the product, the customers and the money. IT is usually set up in an afternoon by whoever is least busy, on whichever accounts are to hand. That works until the third hire, the first customer security questionnaire or the first lost laptop. This guide sets out what to put in place from day one, what can wait, and when to hand it to someone else.

Why the first setup matters

Most of the IT problems that growing businesses bring to us trace back to decisions made in the first weeks: a domain registered in a founder's personal name, files scattered across personal Google Drives and Dropbox accounts, a shared password for the company bank feed, a developer who left with the only admin login to the cloud platform. Untangling this once there are twenty staff and paying customers costs far more than doing it properly at the start.

The good news is that the right foundation is small and cheap. It is a handful of decisions rather than a big investment.

The day-one stack

ComponentWhat to doWhy
Domain and DNSRegister in the company's name, in a registrar account owned by the company with MFALosing the domain means losing email and the website
Email and productivityOne Microsoft 365 or Google Workspace tenant on the company domainOne identity for everything, one place to remove access
Multi-factor authenticationEnforced for every user from the first accountStolen passwords are the most common way in
Password managerBusiness tier, shared vaults for team credentialsEnds passwords in chat and spreadsheets
DevicesCompany-owned or company-managed laptops with disk encryptionA lost unencrypted laptop is a data breach
File storageSharePoint or Google Drive with a simple folder structure and permissionsFiles belong to the company, not to individuals
BackupAn independent backup of the tenant (mail, files)Cloud providers give availability, not a backup service
Admin accountsTwo named admins, separate from daily-use accounts, documentedNobody is locked out when a founder is unavailable

Microsoft's own documentation at Microsoft Learn describes what the platform does and does not protect, and our comparison of Microsoft 365 plans explains which tier makes sense at each stage. Our Microsoft 365 services cover the setup itself.

Security basics that scale

Startups are attacked because they are easy, not because they are valuable. The GOV.UK Cyber Security Breaches Survey consistently finds that phishing is the most common attack, and small organisations are hit as often as large ones. The controls that matter early are:

  1. MFA on every account, including the registrar, the bank, the cloud platform and any code repository.
  2. Least privilege. Most staff are not admins. Founders should have a separate admin account they use only for admin.
  3. Managed devices. Microsoft 365 Business Premium includes device management, so laptops can be encrypted, patched and wiped from the console.
  4. Endpoint protection on every laptop. Built-in antivirus is the floor, and endpoint detection and response is the standard once there is customer data.
  5. A leaver process. When someone goes, their account is disabled, their device is returned or wiped, and shared credentials they knew are rotated, on the same day.
  6. Short staff training. Ten minutes a quarter on what phishing looks like now.

The NCSC's small business guide covers this ground in plain language, and Cyber Essentials turns it into a certification that customers and insurers recognise. A startup built on the stack above can usually certify without major changes.

Data, compliance and investor due diligence

A startup handling customer data is subject to UK GDPR from its first customer. The ICO's guidance for organisations is the primary source. The practical requirements at this stage are modest: know what personal data you hold and where, restrict access to it, protect it with the controls above, and be able to delete it when asked.

Investors and enterprise customers will ask about this. A typical due diligence or vendor security questionnaire wants to know whether accounts and code belong to the company, whether MFA is enforced, how customer data is stored, whether backups exist and whether there is a written security policy. Answering "yes, and here is the evidence" takes an hour if the foundation is right. Answering "we will sort that out" delays the deal.

Devices, remote work and the office question

Many startups have no office, or a desk in a shared space, and staff in several countries. That is fine if identity and devices are managed. A remote worker on a managed, encrypted laptop signing in with MFA is more secure than an office worker on an unmanaged PC.

When an office does arrive, the requirements are covered in our new office IT setup checklist. The short version: order connectivity early, do not put a consumer router on the network, and keep guest Wi-Fi separate from staff.

Backup and continuity

Cloud services fail rarely, but accounts get deleted, files get overwritten, and ransomware reaches synced folders. An independent backup of Microsoft 365 or Google Workspace costs a few pounds per user per month and is the difference between a bad hour and a bad month. Once the business has a product in production, the same question applies to code repositories, databases and any platform where customer data lives.

Continuity at startup scale is a short written answer to three questions: what happens if the founder with the admin rights is unavailable, what happens if a laptop is lost, and what happens if the main cloud service is down for a day. Write the answers down, store them somewhere that does not depend on the systems in question, and revisit them when the team doubles. Our backup and disaster recovery service covers the tooling, but the written answers are the part most startups skip.

In-house or outsourced

A startup cannot justify an IT hire, so IT lands on a founder or the most technical developer. The usual result is a setup that was right at five people and never revisited. Outsourcing support and security to a managed provider gives:

  • Monitoring, patching and endpoint protection that run without anyone remembering.
  • A helpdesk for staff, so the CTO is not resetting passwords.
  • Someone to answer the security questionnaires and the insurer.
  • Predictable monthly cost that scales per user.

The business keeps ownership of its accounts, data and decisions. What it hands over is the routine work and the specialist attention. Our managed IT support service is priced per device and user for this reason, and the cost calculator gives an indicative figure for a team of any size.

A phased plan by headcount

IT needs change with the size of the team. The table below is a reasonable sequence for a UK startup that handles customer data.

StagePut in placeTypical trigger
Founders to 5 peopleCompany domain, one tenant, MFA, password manager, encrypted laptops, tenant backup, two named adminsIncorporation and first hires
5 to 20 peopleDevice management, endpoint detection and response, a starter and leaver form, a written security policy, Cyber EssentialsFirst enterprise customer, first security questionnaire, first funding round
20 to 50 peopleManaged IT support contract, a proper office network with firewall and managed Wi-Fi, VoIP phones, an incident response plan, cyber insuranceFirst office, first customer requiring evidence of controls, first insurer questionnaire
50 people and beyondConditional access policies, privileged access management, regular access reviews, a tested disaster recovery plan, possibly Cyber Essentials Plus or ISO 27001 depending on customersRegulated customers, larger contracts, a compliance function

The point of the sequence is that each stage builds on the last. A business that put the first row in place at incorporation can add the second row in a week. A business that reaches twenty people on personal accounts and unmanaged laptops has to migrate everything while trading, which is the expensive version.

Two things are worth doing earlier than the table suggests if the business is in a regulated sector or sells to large organisations: the written security policy and Cyber Essentials. Both are frequently requested before a contract is signed, and neither is difficult if the foundation is right.

What can wait

Not everything needs doing on day one. A dedicated firewall, a phone system, structured cabling, a formal disaster recovery plan and advanced security tooling become worthwhile as headcount, revenue and data grow. What cannot wait is ownership of accounts, MFA, encrypted managed devices, a password manager and a backup, because retrofitting those is where the cost and risk sit.

What to do next

If your business is running on personal accounts, unmanaged laptops or a shared password document, the fix is a few days' work now rather than a painful project later. Use our IT support cost calculator for an indicative monthly figure, or talk to an engineer about setting up the foundation before the next hire.

Frequently asked questions

What IT does a startup need on day one?
A business email and productivity tenant (Microsoft 365 or Google Workspace) on your own domain with MFA enforced, a password manager, laptops with disk encryption that the business controls, cloud file storage with sensible folder permissions, and a backup of that cloud data. Write down who has admin rights. That foundation costs little per person and avoids the untangling that happens when a startup grows on personal accounts.
Should a startup use Microsoft 365 or Google Workspace?
Both work. Microsoft 365 suits businesses that will use Windows laptops, Teams, SharePoint and Office files, and its Business Premium tier bundles device management and security tooling that startups otherwise buy separately. Google Workspace suits teams that live in the browser and Google Docs. Pick one, use it for everything, and avoid mixing the two or running personal accounts alongside.
When should a startup get Cyber Essentials?
As soon as you sell to larger organisations or the public sector, apply for grants, or want cyber insurance at a sensible price. Cyber Essentials is the UK government-backed baseline covering firewalls, secure configuration, access control, malware protection and patching. A startup that builds on managed devices and a properly configured tenant can usually certify with little extra work.
Should a startup handle cyber security in-house or outsource it?
Unless you are a security business, outsource it. A founder or developer doing security part-time tends to set things up once and never revisit them. A managed provider handles monitoring, patching, endpoint protection and the questionnaires investors and customers send, for a predictable monthly cost. You keep ownership of decisions and data while getting specialist attention without hiring for it.
What do investors look at in a startup's IT during due diligence?
Whether accounts and code are owned by the company rather than by individuals, whether MFA and access controls exist, how customer data is stored and protected, whether backups exist, and whether the business could show compliance with UK GDPR. Weak answers rarely kill a deal, but they add conditions and delay. A tidy tenant, a password manager and a written policy answer most questions.
What are the most common IT mistakes new businesses make?
Running the company on a founder's personal email and cloud accounts, letting staff use personal laptops with no encryption or management, sharing passwords in chat, giving everyone admin rights, assuming cloud services back themselves up, and having no process for removing access when someone leaves. Each is cheap to avoid at the start and expensive to fix after the first hire or the first incident.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us