Layer8 Tech Group Exit Readiness Assessment
Apex Managed Solutions 2026-08-03

Prepared by: Layer8TechGroup  ·  Framework: 10 Technology Fixes — Tier 1  ·  Documents Ingested: cached collection (previously ingested)

Overall Score
3.7/10
5-domain blend
Buyer Discount Risk
2.5 – 2.8×
SDE · Main Street
EBITDA
$378,000
most recent FY
Vertical
Technology / MSP
technology

Assessment Scores — 8-Domain Profile

Diligence Risk
4.6/10NEEDS WORK
Owner Risk
2.5/10CRITICAL RISK
Customer Quality
3.8/10NEEDS WORK
Financial Readiness
3.2/10CRITICAL RISK
Operational Scalability
3.8/10NEEDS WORK
Technology & Systems Maturity
4.7/10NEEDS WORK
Legal & Regulatory Compliance
4.0/10NEEDS WORK
Human Capital & Key Employee Risk
2.7/10CRITICAL RISK
Value Recovery RoadmapTotal Recoverable Value: $321,300
Prioritized by estimated recovery value  ·  8 scored domains  ·  90-day remediation timeline
DomainLayer8 ServiceDeal ImpactValue at RiskEst. TimelineTypical InvestmentEst. ROI
DRDiligence Risk✓ Quick Win
Security Hardening & Data Room Preparation+13%$48,195⏱ 4–6 wks$2,500 – $4,500~14x
OROwner Risk✓ Quick Win
Succession Planning & Knowledge Capture Sprint+12%$44,982⏱ 8–10 wks$6,000 – $10,000~5.5x
CQCustomer Quality
Contract Audit & CRM Implementation+12%$44,982⏱ 10+ wks$8,000 – $14,000~4x
TMTechnology & Systems Maturity
Technology Infrastructure Audit & Modernization Plan+12%$44,982⏱ 6–8 wks$3,000 – $5,500Technology gaps are an increasingly standalone underwriting factor — buyers mode…
OSOperational Scalability
Process Documentation & Systems Audit+11%$41,769⏱ 10+ wks$6,500 – $11,000~5x
FRFinancial Readiness✓ Quick Win
Books Cleanup & Add-Back Schedule+10%$38,556⏱ 6–8 wks$4,000 – $7,000~7x
LCLegal & Regulatory Compliance
Legal Compliance Audit & Contract Review+9%$32,130⏱ 6–8 wks$3,500 – $6,500Reduces deal risk and supports clean diligence — unresolved legal gaps are the #…
HCHuman Capital & Key Employee Risk
Key Employee Retention & Documentation Sprint+7%$25,704⏱ 8–10 wks$5,000 – $9,000Key employee retention is a direct deal risk — buyers model post-close talent lo…
TOTAL$321,300$38,500 – $67,500~6x

Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.

Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.

Ready to recover this value before you list?
Layer8 Tech Group delivers these services for businesses preparing for acquisition.
Schedule a Discovery Call →

Valuation Impact Analysis

Main Street  ·  SDE Technology / MSP businesses in this size range typically trade at 2.5–3.5× SDE — MSPs with high Monthly Recurring Revenue, documented contracts, and system-driven growth command premium multiples. PE-backed roll-ups are active acquirers paying 6–9× for platform-quality businesses.
Score-adjusted range   (Exit Readiness 3.7/10 — Main Street — lower range)
EBITDA (most recent FY): $378,000 (AI-extracted)
Material Gaps
High — significant discount likely
Scenario Score-Adjusted Range Implied Value (SDE)
Current (as-is) 2.5×–2.8× SDE $945,000 – $1,058,400
Post-Remediation (5.7/10 est.) 2.6×–3.1× SDE $982,800 – $1,171,800

Implementing the recommended priority fixes over 90 days could add an estimated ~$75,600 to the transaction value — a potential 8% lift on the same underlying business.

↑ What drives higher multiples

  • High MRR percentage >70%
  • Documented service contracts
  • NOC/helpdesk not owner-dependent
  • Stack standardization across clients

↓ What buyers will flag

  • Break-fix revenue dominant
  • No formal service agreements
  • Owner is primary engineer

Domain Detail & Findings

Diligence Risk4.6/10  NEEDS WORK (15% blend)
Deal Impact: Documentation gaps will extend diligence and require owner availability — expect timeline delays and buyer leverage.
IDCriterion & FindingScoreRatingBar
fix_01Documented Processes & SOPs
AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Financials.csv — High confidence — multiple documents corroborated
Apex Managed Solutions has minimal formal documentation of processes, with critical knowledge held by individual team members rather than in documented SOPs. The cybersecurity assessment explicitly identifies "documentation formality" as a gap requiring remediation before sale, and the HC Profile reveals that the company lacks formal succession plans, cross-training programs, or employment agreements for technical staff, indicating processes exist primarily in people's heads rather than in standardized, documented form.
4/10NEEDS WORK
fix_02Cybersecurity Posture
AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated
Apex maintains a solid baseline cybersecurity posture appropriate for an MSP, with MFA enforced across Microsoft 365/Azure AD, Huntress EDR deployed on all 11 endpoints, Datto BCDR with tested restores, and network security controls (FortiGate with IPS, segmentation). However, critical gaps exist in privileged access management—shared administrative credentials are stored in IT Glue without dedicated vaulting, creating credential exposure risk—and no formal, documented incident response plan exists despite informal procedures being followed, both of which are rated as HIGH and MEDIUM priority remediation items before sale.
7/10ADEQUATE
fix_03Owner Dependency
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The owner holds direct relationships with 11 of 14 managed services clients with no documented succession plan or cross-training program, and is involved in all hiring decisions and onboarding for technical staff. The departure of the Senior Network Engineer in [DATE_TIME] required the owner to cover client calls post-departure, and the only [LOCATION]-certified engineer represents a single point of failure whose departure would eliminate the company's ability to service network-heavy clients. Additionally, no employment agreements exist for technical staff, providing the buyer with no contractual retention protections for key engineers.
3/10CRITICAL RISK
fix_04Revenue Quality & Concentration
AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt — High confidence — multiple documents corroborated
Apex Managed Solutions demonstrates solid revenue quality with 62% recurring revenue from managed services and monitoring contracts across 34 active clients averaging $3,200/month, with an average client tenure documented in the CIM. However, concentration risk exists as the owner maintains direct relationships with 11 of 14 managed services clients, creating key-person dependency, and the largest client concentration is not explicitly disclosed in the documents, though the pipeline shows significant deal size variance suggesting potential unevenness in the revenue base.
7/10ADEQUATE
fix_05Customer Contracts
AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The retrieved documents contain no information regarding customer contracts, transferability, change-of-control clauses, contract standardization, assignment language, centralized repositories, or renewal rate tracking. While the CIM mentions "34 active managed services clients with average tenure of [DATE_TIME]" and "recurring contracts averaging $3,200 per month per client," there is no evidence of documented contract terms, assignment provisions, renewal tracking mechanisms, or contract management infrastructure required for exit readiness.
2/10CRITICAL RISK
fix_06IT Infrastructure & Asset Documentation
AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt — High confidence — multiple documents corroborated
The company maintains basic service delivery tools (ConnectWise Manage, IT Glue, Huntress EDR) but lacks formal IT infrastructure documentation and asset lifecycle management. The cybersecurity assessment identifies significant gaps including no documented incident response plan, no external penetration testing in the relevant period, and credential exposure risks through IT Glue without a dedicated privileged access management vault. Critical infrastructure dependencies are concentrated with single points of failure (the senior network engineer is the only employee capable of servicing network-heavy clients), indicating undocumented systems and no formal DR testing or lifecycle tracking.
4/10NEEDS WORK
fix_07CRM & Pipeline Documentation
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
Apex uses ConnectWise Manage as its CRM system and maintains a documented sales pipeline with 15 active opportunities tracked across defined stages (Discovery, Qualified, Proposal, Negotiation, Closed Won) with assigned probabilities and close dates. However, all pipeline opportunities are owned by a single individual ([PERSON]), indicating concentration risk and limited forecast validation discipline, which prevents a higher score despite the CRM system being actively used and reasonably current.
7/10ADEQUATE
fix_08Key Employee Risks
AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The company has multiple critical single points of failure with no formal succession planning or retention agreements. The Senior Network Engineer ([PERSON]) is the only [LOCATION]-certified engineer and his departure would eliminate the company's ability to service network-heavy clients; the Owner holds direct relationships with 11 of 14 managed services clients with no documented succession plan; and the Cisco/Network Architecture role has "None" listed as backup status. Technical staff compensation is 6–10% below market benchmarks with no retention bonuses or equity, resulting in 38% technical staff turnover in the review period, and no employment agreements exist for technical staff to provide contractual retention protections for key engineers.
3/10CRITICAL RISK
fix_09Financial Trajectory & EBITDA Quality
AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
Apex Managed Solutions reported $2.1M in revenue with an 18% EBITDA margin ($378K) and normalized EBITDA of $412K after add-backs, demonstrating reasonable profitability, but the documents provide no evidence of audited or reviewed financials, multi-year growth trajectory, or detailed documentation of add-back justifications. The CIM presents only a single-year financial snapshot with normalized adjustments, and no historical financial statements, audit reports, or detailed add-back schedules are included in the retrieved excerpts to assess EBITDA quality or growth consistency.
6/10ADEQUATE
fix_10Data Room Readiness
AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated
The retrieved documents show critical gaps in data room preparation for a sale process. While a Confidential Information Memorandum and Cybersecurity Assessment exist, there is no evidence of a comprehensive, organized data room structure with version control, access management, or systematic documentation of key operational, financial, legal, and HR records. The documents reveal significant underlying business issues (key person dependencies, high turnover, compensation gaps, cybersecurity gaps) that require extensive remediation documentation, but no organized repository or checklist of due diligence materials is evident from the excerpts provided.
3/10CRITICAL RISK
Owner Risk2.5/10  CRITICAL RISK (14% blend)
Deal Impact: Critical owner dependency — high probability of deal restructuring, escrow requirement, or significant price reduction.
IDCriterion & FindingScoreRatingBar
owr_01Succession Readiness
AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
No formal succession plan exists at Apex Managed Solutions. The documents explicitly state "No succession plan or cross-training program exists for any role," and the owner holds direct relationships with 11 of 14 managed services clients with no documented handoff protocols. Additionally, the owner is the sole decision-maker for all hires and is directly involved in technical onboarding, creating critical single-points-of-failure (particularly the owner's relationships and the Cisco/Network Architect role) that would destabilize the business if the owner departed unexpectedly.
2/10CRITICAL RISK
owr_02Institutional Knowledge Capture
AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
The company has minimal institutional knowledge documentation with critical expertise held by individual contributors rather than in accessible systems. The documents reveal that the owner holds direct relationships with 11 of 14 managed services clients with no succession plan, the only location-certified engineer has no backup, basic onboarding is "handled by [PERSON] (not documented)," and "no formal training program; learning is on-the-job." Additionally, there are no employment agreements for technical staff, creating significant flight risk for key personnel like the Senior Network Engineer who has raised compensation concerns twice and whose departure would eliminate the company's ability to service network-heavy clients without emergency hiring.
2/10CRITICAL RISK
owr_03Management Team Depth
AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
The business lacks formal management depth and cannot operate independently for 60+ days. The owner holds direct relationships with 11 of 14 managed services clients and is involved in all hiring decisions and technical orientations, while the only backup for critical technical roles (Cisco/Network Architecture, Tier-2 Lead) is either non-existent or informal, creating single points of failure. Additionally, no employment agreements exist for key technical staff, no succession plan or cross-training program is documented, and the 38% technical staff turnover rate (including the loss of the primary engineer for the largest client) demonstrates the organization cannot sustain operations without owner involvement during extended absences.
3/10CRITICAL RISK
owr_04Key Person Concentration Beyond Owner
AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The company has multiple critical single points of failure beyond the owner. Section 4 documents that the Cisco/Network Architect is a "single-point-of-failure" whose departure would eliminate the practice's ability to service network-heavy clients, and the Senior Network Engineer is significantly underpaid (7% below market) and has raised compensation concerns twice, creating high flight risk. Additionally, no employment agreements exist for technical staff, providing the buyer with no contractual retention protections, and there is no succession plan or cross-training program for any key role.
3/10CRITICAL RISK
Customer Quality3.8/10  NEEDS WORK (14% blend)
Deal Impact: Customer concentration or churn risk increases buyer discount risk — expect sensitivity analysis and possible escrow.
IDCriterion & FindingScoreRatingBar
cq_01Top Customer Concentration
AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_Financials.csv — High confidence — multiple documents corroborated
Apex Managed Solutions exhibits significant customer concentration risk with the largest client, Hendricks Medical Group, representing 18% of revenue according to the Human Capital Profile document. The top 7 customers shown in the Financials excerpt represent approximately 21% of total revenue, indicating heavy reliance on a small number of accounts, and the departure of the senior systems engineer who was "the primary engineer for the largest client" demonstrates vulnerability to key person dependencies that could further destabilize these critical relationships.
3/10CRITICAL RISK
cq_02Revenue Predictability & Recurring Mix
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
Apex generates 62% recurring revenue from managed services and monitoring contracts with 34 active clients averaging $3,200 per month and an average tenure documented in the files, providing a solid recurring base. However, predictability is moderately constrained by the absence of multi-year contract documentation, a 31% all-staff voluntary turnover rate with 38% technical staff turnover including loss of the primary engineer for the largest client (18% of revenue), and no formal renewal tracking or documented renewal rates in the materials provided.
7/10ADEQUATE
cq_03Contract Transferability
AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The documents provide no evidence of formal customer contracts, assignment clauses, or change-of-control provisions. The CIM states that Apex serves "34 active clients under recurring contracts averaging $3,200 per month per client," but no contract templates, assignment language, or transferability terms are included in any retrieved documents. Most critically, the HC Profile reveals that the Owner "[PERSON] holds direct relationships with 11 of 14 managed services clients," indicating that a majority of the revenue base is personality-dependent and lacks institutional contract documentation, making transfer without individual customer consent highly unlikely.
2/10CRITICAL RISK
cq_04Churn Rate & Retention Metrics
AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_Financials.csv · AMS_CIM.txt — High confidence — multiple documents corroborated
The company does not track customer churn rate or retention metrics—no documented gross churn percentage, net revenue retention figures, or formal retention programs appear in any of the provided documents. While the CIM references 34 active managed services clients with average tenure and 62% recurring revenue, there is no evidence of monthly or quarterly churn tracking, root-cause analysis, or retention playbooks. The internal focus appears reactive rather than proactive, with significant operational instability evidenced by 38% technical staff turnover and the recent departure of a senior engineer responsible for 18% of revenue from the largest client.
3/10CRITICAL RISK
Financial Readiness3.2/10  CRITICAL RISK (12% blend)
Deal Impact: Financial readiness is a deal blocker — books must be restructured before any formal sale process can begin.
IDCriterion & FindingScoreRatingBar
fr_01Books Quality & CPA Relationship
AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The retrieved documents contain no information regarding financial statements, audit or review status, CPA relationships, or books quality. The available excerpts focus on cybersecurity assessment, HR profiles, CRM pipeline, and company overview, but do not address accounting practices, financial statement preparation, or auditor engagement. Without evidence of financial statement quality or CPA involvement, exit readiness in this critical area cannot be assessed from the provided documentation.
2/10CRITICAL RISK
fr_02Add-Back Documentation
AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
The documents provide no formal add-back schedule, supporting documentation, or CPA verification of EBITDA adjustments. While the CIM references "Normalized EBITDA of $412K after add-backs" compared to reported EBITDA of $378K, the specific add-backs are not detailed or supported. The only add-back items identified in the HC Profile are owner S-corp distributions ($180,000 requiring conversion to employment agreement), discretionary tech bonuses (paid via owner check, not payroll), and owner vehicle expense ($680/mo), but these lack formal documentation or buyer-ready support schedules that a buyer's accountant could independently verify.
3/10CRITICAL RISK
fr_03Revenue Recognition & Consistency
AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated
The retrieved documents contain no information regarding revenue recognition policies, GAAP compliance, deferred revenue tracking, or revenue consistency practices. The available excerpts address cybersecurity posture, company overview, and human capital metrics, but provide no evidence to assess revenue recognition methodology or documentation. This absence of critical financial policy documentation represents a significant gap that would require immediate clarification during due diligence before any revenue-related assessment can be made.
1/10CRITICAL RISK
fr_04Three-Year Financial Trend
AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated
The company generated $2.1M in revenue with an 18% EBITDA margin ($378K EBITDA, normalized to $412K) as of the assessment date, demonstrating solid profitability. However, the documents provide only a single-year financial snapshot with no multi-year revenue or EBITDA trend data, making it impossible to assess consistency of growth, CAGR performance, or margin trajectory over three years. Without historical financial statements showing year-over-year comparability across 2023-2025, the assessment cannot confirm whether growth has been sustained or margins stable.
7/10ADEQUATE
Operational Scalability3.8/10  NEEDS WORK (13% blend)
Deal Impact: Technology or process gaps require post-close investment — buyers will model remediation cost into their offer.
IDCriterion & FindingScoreRatingBar
ops_01Process Documentation & Repeatability
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
Apex Managed Solutions has minimal formal process documentation with heavy reliance on key individuals. The onboarding section explicitly states "No formal training program; learning is on-the-job" with "Basic system access setup handled by [PERSON] (not documented)" and helpdesk onboarding consisting only of "[DATE_TIME] ticket shadowing; no documented playbook." Critical operational knowledge is person-dependent, as evidenced by single points of failure: the owner holds direct relationships with 11 of 14 managed services clients, the Senior Network Engineer is the only [LOCATION]-certified engineer with no backup, and "No succession plan or cross-training program exists for any role."
3/10CRITICAL RISK
ops_02Technology & Systems Scalability
AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
The company relies on undocumented systems and processes with critical knowledge concentrated in key individuals. The cybersecurity assessment identifies significant gaps including "No documented incident response plan exists. Informal procedures are followed but not written down" and credential management risks, while the HR profile shows the senior network engineer ([PERSON]) is a "single-point-of-failure" for Cisco/network architecture with "no succession plan or cross-training program." Scaling to 3x growth would require material documentation, formalization of undocumented onboarding procedures, and replacement of the owner-dependent hiring and approval processes currently described as "ad-hoc."
4/10NEEDS WORK
ops_03Vendor & Supplier Concentration
AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
Apex has moderate vendor concentration with identified dependencies on key platforms (ConnectWise Manage, IT Glue, Huntress EDR, Microsoft 365, and Datto) but lacks documented formal SLAs or formal alternatives for critical services. The cybersecurity assessment identifies a specific single-source risk with IT Glue credentials and recommends migration to BeyondTrust/CyberArk as an alternative, and recommends evaluating Barracuda Message Archiver as an alternative to M365 retention—indicating some switching costs and alternatives are acknowledged but not yet formalized or contractually secured.
6/10ADEQUATE
ops_04Financial Controls & Reporting Cadence
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The retrieved documents contain no information about financial controls, reporting cadence, monthly close timelines, budget vs. actual reviews, or documentation of accounting procedures. The only financial data present relates to compensation levels and owner distributions, which are insufficient to assess the company's financial reporting infrastructure. Without evidence of a CFO, Controller, or formal close process, this company appears to fall into the lowest tier of financial maturity for M&A readiness.
2/10CRITICAL RISK
Technology & Systems Maturity4.7/10  NEEDS WORK (14% blend)
Deal Impact: Technology gaps will require buyer attention — expect technical due diligence deep-dive and possible price adjustment.
IDCriterion & FindingScoreRatingBar
tm_01Core Systems Documentation & Ownership
AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt — High confidence — multiple documents corroborated
Core business systems are partially documented but have significant personal account dependencies and ownership gaps. The cybersecurity assessment identifies that "shared administrative credentials for client environments [are] stored in IT Glue without dedicated vaulting" (Gap 1, HIGH risk), and critical technical roles lack succession planning—notably, "[PERSON] is the only [LOCATION]-certified engineer" with "no succession plan or cross-training program" and the owner holds "direct relationships with 11 of 14 managed services clients" with no documented transfer mechanism. Additionally, basic system access setup and onboarding are "handled by [PERSON] (not documented)," indicating undocumented processes tied to individual staff members rather than formalized entity-owned procedures.
4/10NEEDS WORK
tm_02Cybersecurity & Data Protection Posture
AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_Customer_Contract_Hendricks.txt · AMS_Financials.csv · AMS_Customer_Onboarding_SOP.txt — High confidence — multiple documents corroborated
Apex Managed Solutions deploys EDR (Huntress) across client endpoints and maintains RMM monitoring with patch management as standard offerings, but significant gaps exist in internal security maturity. The internal cybersecurity assessment identifies critical missing controls including no documented incident response plan, no privileged access management vault (credential exposure risk via IT Glue), no recent penetration testing, and unenforced mobile device policies—with no evidence of cyber insurance or annual vendor security reviews in the retrieved documents.
6/10ADEQUATE
tm_03Data Integrity & Business Intelligence
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
The company lacks reliable, accessible operational data and exhibits significant individual dependencies across critical functions. The cybersecurity assessment identifies "credential exposure on staff departure" with passwords managed through IT Glue without a dedicated privileged access management (PAM) system, and the human capital profile reveals that the owner holds "direct relationships with 11 of 14 managed services clients" with "no succession plan or cross-training program" and key technical staff (like the Senior Network Engineer) representing single points of failure. Additionally, compensation is set "ad-hoc" by the owner with "no formal benchmarking process," and the incident response plan is "informal" with "procedures followed but not written down," indicating scattered, undocumented operational data without reliable audit trails or systematic BI reporting.
3/10CRITICAL RISK
tm_04Technology Vendor & Subscription Management
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
Core technology vendor relationships are partially known but lack formal documentation and transfer mechanisms. The cybersecurity assessment identifies critical gaps including shared administrative credentials stored in IT Glue without dedicated vaulting, no formal PAM solution, and credentials documented under individual IT staff rather than entity-owned systems—creating significant transfer risk on staff departure. Additionally, key technical personnel dependencies (e.g., the single CCNP-certified network engineer) suggest that access to vendor relationships and client system credentials may be concentrated with individuals rather than formally transferred to the entity.
4/10NEEDS WORK
tm_05Technical Debt & Modernization Risk
AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated
The company operates a mixed technology stack with modern cloud components (Microsoft 365 with Azure AD, Huntress EDR, Datto BCDR) but carries material technical debt in privileged access management and documentation. The cybersecurity assessment identifies a HIGH-priority gap where "shared administrative credentials for client environments stored in IT Glue without dedicated vaulting" create credential exposure risk, along with missing formal incident response documentation and no external penetration testing in the assessment period—issues requiring post-close remediation at modest cost ($8,000-12,000 for pen test alone) but nonetheless deferred from the current operation.
6/10ADEQUATE
▲ Layer8's primary practice area. Technology & Systems Maturity is where Layer8 delivers directly — not just identifies gaps. Where this domain shows deficiencies, remediation is available immediately through Layer8 engagements.
Legal & Regulatory Compliance4.0/10  NEEDS WORK (10% blend)
Deal Impact: Compliance gaps will surface in diligence — expect buyer requests, timeline extension, and potential price adjustment.
IDCriterion & FindingScoreRatingBar
lc_01Business Licenses & Permits
AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_Financials.csv — High confidence — multiple documents corroborated
The retrieved documents contain no information regarding business licenses, permits, their current status, or transferability in a change-of-control event. While the company operates as a managed services provider and cybersecurity services firm, there is no documentation of required licenses (such as professional certifications, vendor certifications, or regulatory compliance licenses), their renewal status, or any legal review of transferability to a buyer, representing a material compliance gap for exit readiness.
2/10CRITICAL RISK
lc_02Contract Change-of-Control Provisions
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
The retrieved documents contain no evidence of contract review, assignment clause analysis, or change-of-control provision assessment for any vendor, customer, or lease agreements. While the CRM pipeline lists 14 active customer opportunities and the compensation section references a portable Cigna health plan and entity-owned retirement benefits, there is no documentation of legal review of material customer MSAs, vendor contracts, or lease agreements for assignability or change-of-control triggers—creating material deal risk for a potential acquirer.
2/10CRITICAL RISK
lc_03Employment Law Compliance
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
The company lacks critical employment law compliance documentation and controls. No employment agreements exist for technical staff, creating no contractual retention protections for key personnel; compensation is set ad-hoc without formal benchmarking, with technical staff earning 6-10% below market rates and at least one key engineer ([PERSON], Senior Network Engineer) having raised compensation concerns twice; and the documents show no evidence of I-9 verification processes, non-compete agreements, or formal classification documentation. Additionally, the owner's compensation structure ($180,000 S-corp distributions plus discretionary bonuses paid via owner check rather than payroll) requires formalization and cleanup before a transaction.
4/10NEEDS WORK
lc_04Intellectual Property Ownership
AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
The documents do not contain evidence of formal IP ownership documentation, assignment agreements, or an IP schedule. While the CIM references the company's Microsoft Gold Partner designation and vendor relationships (Dell, Datto), and the cybersecurity assessment mentions tools like ConnectWise Manage, IT Glue, and Huntress EDR, there is no explicit statement that all software, processes, or IP are formally assigned to the entity or free from founder/personal overlap. The absence of IP ownership documentation, trademark registration status, or a data room IP schedule places this assessment in the "assumed but not formally documented" range.
5/10NEEDS WORK
lc_05Litigation & Contingent Liability
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_CIM.txt · AMS_Customer_Contract_Hendricks.txt — High confidence — multiple documents corroborated
The documents reveal no active material litigation or undisclosed contingent liabilities threatening the business. However, there are several operational and compliance gaps that create moderate legal exposure: the cybersecurity assessment identifies missing incident response documentation and no external penetration testing performed (creating "regulatory exposure with healthcare-adjacent clients"), and the HC profile notes $18,000 in accrued PTO liability and informal owner compensation arrangements requiring formalization before close. These are disclosed, addressable issues rather than hidden claims, placing the company in the "minor open matters" category with standard commercial risk.
7/10ADEQUATE
Human Capital & Key Employee Risk2.7/10  CRITICAL RISK (8% blend)
Deal Impact: Key employee dependency is a deal risk -- high probability of post-close talent loss will trigger buyer discount or escrow requirement.
IDCriterion & FindingScoreRatingBar
hc_01Employee Documentation & Compensation
AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated
Employee roles lack formal documentation and succession planning, with critical single points of failure across technical functions. The company has no employment agreements for technical staff, ad-hoc compensation setting by the owner with no formal benchmarking process, and acknowledged compensation gaps of 6–10% below market for technical roles, creating retention risk—particularly for the Senior Network Engineer who has "raised this concern twice" and is identified as the "highest flight risk." Onboarding is undocumented (basic system access setup "not documented," helpdesk training has "no documented playbook"), and no formal roles matrix exists beyond an informal bench depth table showing multiple single-point-of-failure positions with "no succession plan or cross-training program."
3/10CRITICAL RISK
hc_02Retention Agreements & Non-Competes
AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
No employment agreements exist for technical staff, creating significant post-close retention risk. The documents explicitly state "No employment agreements for technical staff — buyer has no contractual retention protections for [PERSON] or other key engineers," and there are no retention bonuses or equity incentives in place. With 38% technical staff turnover, compensation 6-10% below market for key roles (particularly the Senior Network Engineer at $88,000 vs. $95,000 market), and the critical Senior Network Engineer identified as "the highest flight risk given his compensation gap and market value," the company presents minimal contractual safeguards for key personnel retention through a transition.
2/10CRITICAL RISK
hc_03Bench Depth & Succession
AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated
The company has severe bench depth deficiencies with multiple critical single points of failure. The Senior Network Engineer [PERSON] is the only [LOCATION]-certified engineer and holds exclusive responsibility for Cisco/Network Architecture with "None" documented backup, creating a single-point-of-failure that would eliminate the company's ability to service network-heavy clients without emergency hiring. Additionally, the Owner [PERSON] holds direct relationships with 11 of 14 managed services clients (78% of the client base) with no succession plan or cross-training program in place, and no employment agreements exist for technical staff to provide contractual retention protections.
3/10CRITICAL RISK
▲ Automation Maturity IndexScored separately — excluded from overall score and buyer discount risk band
0.9/10MANUAL (raw: 1/16)

MSP revenue infrastructure is evaluated on lead-to-contract automation, after-hours responsiveness, and client retention sequences — critical signals for buyers assessing whether ARR growth is system-driven or founder-dependent.

Automation maturity is scored separately from the valuation composite. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not valuation discounts.

#Criterion & FindingScoreRatingBar
R01AI Voice / After-Hours Call Handling
AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt
The retrieved documents contain no evidence of AI voice agents or automated after-hours call handling capabilities at Apex Managed Solutions. The company uses ConnectWise Manage for service delivery but there is no mention of any call handling automation, voicemail systems, or after-hours telephony infrastructure in the provided excerpts.
0/2MANUAL
R02CRM Presence & Workflow Automation
AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt
Apex uses ConnectWise Manage as its CRM platform with documented client contracts and a tracked pipeline ($380K active with $195K weighted value), but the documents provide no evidence of automated workflows—follow-up activities, escalations, and client communication appear to be manually managed, particularly given the owner's direct involvement in 11 of 14 client relationships and ad-hoc operational processes throughout the organization.
1/2PARTIAL
R0324/7 Lead Capture
AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt
No evidence of after-hours or 24/7 lead capture capability exists in the retrieved documents; the company operates with manual, owner-dependent processes and no mention of contact forms, chatbots, or automated lead routing systems. As an MSP with a remote-first service delivery model, lead capture infrastructure is entirely absent from the operational documentation.
0/2MANUAL
R04SMS Appointment Reminders & Confirmations
AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt
The retrieved documents contain no evidence of automated SMS appointment reminders, confirmations, or follow-up workflows. The company uses ConnectWise Manage for service delivery and IT Glue for documentation, but there is no mention of SMS automation capabilities, appointment reminder systems, or confirmation workflows in any of the operational or technical assessments provided.
0/2MANUAL
R05Automated Review Solicitation
AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt
There is no evidence of any automated or manual post-service review solicitation process in the retrieved documents. The company uses ConnectWise Manage and IT Glue for service delivery but no review automation or systematic follow-up mechanism is mentioned, indicating reviews are organic only.
0/2MANUAL
R06Smart Follow-Up Sequences
AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt
No evidence of automated follow-up sequences exists in the retrieved documents; the company operates with manual sales processes dependent on owner relationships, as evidenced by the owner holding direct relationships with 11 of 14 managed services clients and no documented sales automation or CRM-driven nurture workflows mentioned in any operational materials.
0/2MANUAL

Interpretation: Manual — buyer will underwrite operational risk, expect discount

A low Automation Maturity score for an MSP signals that growth is relationship-driven rather than systematic. Buyers will apply a meaningful discount and may require remediation commitments as a condition of close.

📈 Buyer Opportunity: A buyer who systematizes these automation gaps post-close would deploy a proven playbook: AI voice handling, CRM workflows, and follow-up sequences that collectively recover 15–25% of leads currently lost to slow response. This is a predictable, acquirable value-creation lever.
Layer8 delivers exactly this. Our 90-day Automation Sprint closes AI voice, CRM workflow, lead capture, and follow-up gaps — the same gaps that increase buyer discount risk. The work is defined, the timeline is fixed, and the ROI is measurable before you go to market.
► Operational Automation OpportunitiesVertical-specific — excluded from overall score
0.0/10MANUAL (raw: 0/10)

Vertical-specific operational automation gaps identified in MSP & Technology Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.

Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not valuation buyer discount risk reduction. Layer8 delivers these implementations directly.

Automation OpportunityScoreStatusBarLayer8 Opportunity
Ticket Triage & Auto-Assignment0/2MANUAL
Ticket automation reduces mean time to first response — the metric buyers use most heavily to benchmark MSP operational maturity and client satisfaction.
Patch Management & Compliance Reporting0/2MANUAL
Automated patch compliance reporting is a premium tier differentiator — it demonstrates systematic security management and supports cyber insurance requirements.
Client Onboarding & Offboarding0/2MANUAL
Onboarding automation is the most visible quality signal to new clients — and the fastest way to surface the gap between an MSP that runs on people and one that runs on systems.
Client Health Scoring & Churn Risk Alerts0/2MANUAL
Client health automation converts churn prevention from a reactive fire drill to a proactive managed process — directly protecting the MRR base that drives MSP valuation.
QBR Scheduling & Preparation0/2MANUAL
QBR automation enables consistent executive engagement across the entire client base — not just the accounts that squeaky-wheel their way to attention.
These operational automation gaps represent post-close value creation opportunities for a buyer — and immediate efficiency gains for the current owner. Layer8 Tech Group delivers these implementations directly.

Top 3 Strengths

Top 3 Risks

Recommended Priority Fixes

Actions the company should take in the next 90 days to maximise exit readiness:

Fix 1
Weeks 1-4: Conduct a comprehensive customer contract audit and centralize all 34 managed services contracts in a single repository with documented terms, change-of-control provisions, renewal dates, and assignment language. Create a contract standardization template for all future renewals and obtain written confirmation from the 11 directly-owned clients that they will transfer to new ownership (addressing Customer Contracts: 2/10).
Fix 2
Weeks 2-6: Document all critical SOPs across service delivery, client onboarding, incident response, and network architecture in standardized templates stored in a centralized wiki or knowledge management system. Prioritize documentation of the [LOCATION]-certified network engineer's configuration standards, troubleshooting workflows, and client-specific network architecture to eliminate single points of failure (addressing Documented Processes & SOPs: 4/10).
Fix 3
Weeks 1-8: Execute written employment agreements for all three technical staff members that include 12-month post-close retention incentives (cash bonuses at close), non-compete clauses, and defined transition responsibilities. Conduct formal succession planning meetings to assign backup ownership of the Cisco/Network Architecture role and establish cross-training for the [LOCATION]-certified engineer (addressing Key Employee Risks: 3/10; Owner Dependency: 3/10).
Fix 4
Weeks 3-8: Implement a dedicated privileged access management solution (e.g., Keeper or similar) to replace shared administrative credential storage in IT Glue, document the incident response plan formally with defined escalation procedures and tested workflows, and conduct external penetration testing to validate the remediated security posture (addressing Cybersecurity Posture: 7/10 gaps—HIGH and MEDIUM priority items).
Fix 5
Weeks 1-12: Organize a comprehensive data room with version control and access management, including audited or reviewed financial statements for the prior two years, detailed EBITDA add-back schedules with supporting documentation, multi-year growth trajectory analysis, customer contract repository, all employment agreements, IT asset inventory, and incident response documentation. Assign a single data room administrator to maintain version control and ensure all due diligence materials are current and retrievable (addressing Data Room Readiness: 3/10).

Compliance Notes

No PII was detected in the ingested documents.