Guides & Checklists
IT setup for startups: what to put in place from day one
A practical IT setup guide for UK startups: the day-one stack, identity and security basics, devices, backup, when to outsource and what to avoid.
By Dig IT SolutionsUpdated 8 September 20267 min read
Short answer
A startup should set up a business Microsoft 365 or Google Workspace tenant with MFA enforced, company-owned or managed devices with disk encryption, a password manager, an independent backup of cloud data, and a documented starter and leaver process before hiring. Add endpoint protection and Cyber Essentials once there is customer data, and outsource support rather than improvising.
New businesses spend their first months on the product, the customers and the money. IT is usually set up in an afternoon by whoever is least busy, on whichever accounts are to hand. That works until the third hire, the first customer security questionnaire or the first lost laptop. This guide sets out what to put in place from day one, what can wait, and when to hand it to someone else.
Why the first setup matters
Most of the IT problems that growing businesses bring to us trace back to decisions made in the first weeks: a domain registered in a founder's personal name, files scattered across personal Google Drives and Dropbox accounts, a shared password for the company bank feed, a developer who left with the only admin login to the cloud platform. Untangling this once there are twenty staff and paying customers costs far more than doing it properly at the start.
The good news is that the right foundation is small and cheap. It is a handful of decisions rather than a big investment.
The day-one stack
| Component | What to do | Why |
|---|---|---|
| Domain and DNS | Register in the company's name, in a registrar account owned by the company with MFA | Losing the domain means losing email and the website |
| Email and productivity | One Microsoft 365 or Google Workspace tenant on the company domain | One identity for everything, one place to remove access |
| Multi-factor authentication | Enforced for every user from the first account | Stolen passwords are the most common way in |
| Password manager | Business tier, shared vaults for team credentials | Ends passwords in chat and spreadsheets |
| Devices | Company-owned or company-managed laptops with disk encryption | A lost unencrypted laptop is a data breach |
| File storage | SharePoint or Google Drive with a simple folder structure and permissions | Files belong to the company, not to individuals |
| Backup | An independent backup of the tenant (mail, files) | Cloud providers give availability, not a backup service |
| Admin accounts | Two named admins, separate from daily-use accounts, documented | Nobody is locked out when a founder is unavailable |
Microsoft's own documentation at Microsoft Learn describes what the platform does and does not protect, and our comparison of Microsoft 365 plans explains which tier makes sense at each stage. Our Microsoft 365 services cover the setup itself.
Security basics that scale
Startups are attacked because they are easy, not because they are valuable. The GOV.UK Cyber Security Breaches Survey consistently finds that phishing is the most common attack, and small organisations are hit as often as large ones. The controls that matter early are:
- MFA on every account, including the registrar, the bank, the cloud platform and any code repository.
- Least privilege. Most staff are not admins. Founders should have a separate admin account they use only for admin.
- Managed devices. Microsoft 365 Business Premium includes device management, so laptops can be encrypted, patched and wiped from the console.
- Endpoint protection on every laptop. Built-in antivirus is the floor, and endpoint detection and response is the standard once there is customer data.
- A leaver process. When someone goes, their account is disabled, their device is returned or wiped, and shared credentials they knew are rotated, on the same day.
- Short staff training. Ten minutes a quarter on what phishing looks like now.
The NCSC's small business guide covers this ground in plain language, and Cyber Essentials turns it into a certification that customers and insurers recognise. A startup built on the stack above can usually certify without major changes.
Data, compliance and investor due diligence
A startup handling customer data is subject to UK GDPR from its first customer. The ICO's guidance for organisations is the primary source. The practical requirements at this stage are modest: know what personal data you hold and where, restrict access to it, protect it with the controls above, and be able to delete it when asked.
Investors and enterprise customers will ask about this. A typical due diligence or vendor security questionnaire wants to know whether accounts and code belong to the company, whether MFA is enforced, how customer data is stored, whether backups exist and whether there is a written security policy. Answering "yes, and here is the evidence" takes an hour if the foundation is right. Answering "we will sort that out" delays the deal.
Devices, remote work and the office question
Many startups have no office, or a desk in a shared space, and staff in several countries. That is fine if identity and devices are managed. A remote worker on a managed, encrypted laptop signing in with MFA is more secure than an office worker on an unmanaged PC.
When an office does arrive, the requirements are covered in our new office IT setup checklist. The short version: order connectivity early, do not put a consumer router on the network, and keep guest Wi-Fi separate from staff.
Backup and continuity
Cloud services fail rarely, but accounts get deleted, files get overwritten, and ransomware reaches synced folders. An independent backup of Microsoft 365 or Google Workspace costs a few pounds per user per month and is the difference between a bad hour and a bad month. Once the business has a product in production, the same question applies to code repositories, databases and any platform where customer data lives.
Continuity at startup scale is a short written answer to three questions: what happens if the founder with the admin rights is unavailable, what happens if a laptop is lost, and what happens if the main cloud service is down for a day. Write the answers down, store them somewhere that does not depend on the systems in question, and revisit them when the team doubles. Our backup and disaster recovery service covers the tooling, but the written answers are the part most startups skip.
In-house or outsourced
A startup cannot justify an IT hire, so IT lands on a founder or the most technical developer. The usual result is a setup that was right at five people and never revisited. Outsourcing support and security to a managed provider gives:
- Monitoring, patching and endpoint protection that run without anyone remembering.
- A helpdesk for staff, so the CTO is not resetting passwords.
- Someone to answer the security questionnaires and the insurer.
- Predictable monthly cost that scales per user.
The business keeps ownership of its accounts, data and decisions. What it hands over is the routine work and the specialist attention. Our managed IT support service is priced per device and user for this reason, and the cost calculator gives an indicative figure for a team of any size.
A phased plan by headcount
IT needs change with the size of the team. The table below is a reasonable sequence for a UK startup that handles customer data.
| Stage | Put in place | Typical trigger |
|---|---|---|
| Founders to 5 people | Company domain, one tenant, MFA, password manager, encrypted laptops, tenant backup, two named admins | Incorporation and first hires |
| 5 to 20 people | Device management, endpoint detection and response, a starter and leaver form, a written security policy, Cyber Essentials | First enterprise customer, first security questionnaire, first funding round |
| 20 to 50 people | Managed IT support contract, a proper office network with firewall and managed Wi-Fi, VoIP phones, an incident response plan, cyber insurance | First office, first customer requiring evidence of controls, first insurer questionnaire |
| 50 people and beyond | Conditional access policies, privileged access management, regular access reviews, a tested disaster recovery plan, possibly Cyber Essentials Plus or ISO 27001 depending on customers | Regulated customers, larger contracts, a compliance function |
The point of the sequence is that each stage builds on the last. A business that put the first row in place at incorporation can add the second row in a week. A business that reaches twenty people on personal accounts and unmanaged laptops has to migrate everything while trading, which is the expensive version.
Two things are worth doing earlier than the table suggests if the business is in a regulated sector or sells to large organisations: the written security policy and Cyber Essentials. Both are frequently requested before a contract is signed, and neither is difficult if the foundation is right.
What can wait
Not everything needs doing on day one. A dedicated firewall, a phone system, structured cabling, a formal disaster recovery plan and advanced security tooling become worthwhile as headcount, revenue and data grow. What cannot wait is ownership of accounts, MFA, encrypted managed devices, a password manager and a backup, because retrofitting those is where the cost and risk sit.
What to do next
If your business is running on personal accounts, unmanaged laptops or a shared password document, the fix is a few days' work now rather than a painful project later. Use our IT support cost calculator for an indicative monthly figure, or talk to an engineer about setting up the foundation before the next hire.

