Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
| Domain | Layer8 Service | Deal Impact | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|---|
DRDiligence Risk✓ Quick Win | Security Hardening & Data Room Preparation | +13% | $48,195 | ⏱ 4–6 wks | $2,500 – $4,500 | ~14x |
OROwner Risk✓ Quick Win | Succession Planning & Knowledge Capture Sprint | +12% | $44,982 | ⏱ 8–10 wks | $6,000 – $10,000 | ~5.5x |
CQCustomer Quality | Contract Audit & CRM Implementation | +12% | $44,982 | ⏱ 10+ wks | $8,000 – $14,000 | ~4x |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | +12% | $44,982 | ⏱ 6–8 wks | $3,000 – $5,500 | |
OSOperational Scalability | Process Documentation & Systems Audit | +11% | $41,769 | ⏱ 10+ wks | $6,500 – $11,000 | ~5x |
FRFinancial Readiness✓ Quick Win | Books Cleanup & Add-Back Schedule | +10% | $38,556 | ⏱ 6–8 wks | $4,000 – $7,000 | ~7x |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | +9% | $32,130 | ⏱ 6–8 wks | $3,500 – $6,500 | |
HCHuman Capital & Key Employee Risk | Key Employee Retention & Documentation Sprint | +7% | $25,704 | ⏱ 8–10 wks | $5,000 – $9,000 | |
| TOTAL | — | $321,300 | — | $38,500 – $67,500 | ~6x | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Valuation Impact Analysis
| Scenario | Score-Adjusted Range | Implied Value (SDE) |
|---|---|---|
| Current (as-is) | 2.5×–2.8× SDE | $945,000 – $1,058,400 |
| Post-Remediation (5.7/10 est.) | 2.6×–3.1× SDE | $982,800 – $1,171,800 |
Implementing the recommended priority fixes over 90 days could add an estimated ~$75,600 to the transaction value — a potential 8% lift on the same underlying business.
↑ What drives higher multiples
- High MRR percentage >70%
- Documented service contracts
- NOC/helpdesk not owner-dependent
- Stack standardization across clients
↓ What buyers will flag
- Break-fix revenue dominant
- No formal service agreements
- Owner is primary engineer
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Financials.csv — High confidence — multiple documents corroborated Apex Managed Solutions has minimal formal documentation of processes, with critical knowledge held by individual team members rather than in documented SOPs. The cybersecurity assessment explicitly identifies "documentation formality" as a gap requiring remediation before sale, and the HC Profile reveals that the company lacks formal succession plans, cross-training programs, or employment agreements for technical staff, indicating processes exist primarily in people's heads rather than in standardized, documented form. | 4/10 | NEEDS WORK | |
| fix_02 | Cybersecurity Posture AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated Apex maintains a solid baseline cybersecurity posture appropriate for an MSP, with MFA enforced across Microsoft 365/Azure AD, Huntress EDR deployed on all 11 endpoints, Datto BCDR with tested restores, and network security controls (FortiGate with IPS, segmentation). However, critical gaps exist in privileged access management—shared administrative credentials are stored in IT Glue without dedicated vaulting, creating credential exposure risk—and no formal, documented incident response plan exists despite informal procedures being followed, both of which are rated as HIGH and MEDIUM priority remediation items before sale. | 7/10 | ADEQUATE | |
| fix_03 | Owner Dependency AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The owner holds direct relationships with 11 of 14 managed services clients with no documented succession plan or cross-training program, and is involved in all hiring decisions and onboarding for technical staff. The departure of the Senior Network Engineer in [DATE_TIME] required the owner to cover client calls post-departure, and the only [LOCATION]-certified engineer represents a single point of failure whose departure would eliminate the company's ability to service network-heavy clients. Additionally, no employment agreements exist for technical staff, providing the buyer with no contractual retention protections for key engineers. | 3/10 | CRITICAL RISK | |
| fix_04 | Revenue Quality & Concentration AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt — High confidence — multiple documents corroborated Apex Managed Solutions demonstrates solid revenue quality with 62% recurring revenue from managed services and monitoring contracts across 34 active clients averaging $3,200/month, with an average client tenure documented in the CIM. However, concentration risk exists as the owner maintains direct relationships with 11 of 14 managed services clients, creating key-person dependency, and the largest client concentration is not explicitly disclosed in the documents, though the pipeline shows significant deal size variance suggesting potential unevenness in the revenue base. | 7/10 | ADEQUATE | |
| fix_05 | Customer Contracts AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no information regarding customer contracts, transferability, change-of-control clauses, contract standardization, assignment language, centralized repositories, or renewal rate tracking. While the CIM mentions "34 active managed services clients with average tenure of [DATE_TIME]" and "recurring contracts averaging $3,200 per month per client," there is no evidence of documented contract terms, assignment provisions, renewal tracking mechanisms, or contract management infrastructure required for exit readiness. | 2/10 | CRITICAL RISK | |
| fix_06 | IT Infrastructure & Asset Documentation AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt — High confidence — multiple documents corroborated The company maintains basic service delivery tools (ConnectWise Manage, IT Glue, Huntress EDR) but lacks formal IT infrastructure documentation and asset lifecycle management. The cybersecurity assessment identifies significant gaps including no documented incident response plan, no external penetration testing in the relevant period, and credential exposure risks through IT Glue without a dedicated privileged access management vault. Critical infrastructure dependencies are concentrated with single points of failure (the senior network engineer is the only employee capable of servicing network-heavy clients), indicating undocumented systems and no formal DR testing or lifecycle tracking. | 4/10 | NEEDS WORK | |
| fix_07 | CRM & Pipeline Documentation AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Apex uses ConnectWise Manage as its CRM system and maintains a documented sales pipeline with 15 active opportunities tracked across defined stages (Discovery, Qualified, Proposal, Negotiation, Closed Won) with assigned probabilities and close dates. However, all pipeline opportunities are owned by a single individual ([PERSON]), indicating concentration risk and limited forecast validation discipline, which prevents a higher score despite the CRM system being actively used and reasonably current. | 7/10 | ADEQUATE | |
| fix_08 | Key Employee Risks AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company has multiple critical single points of failure with no formal succession planning or retention agreements. The Senior Network Engineer ([PERSON]) is the only [LOCATION]-certified engineer and his departure would eliminate the company's ability to service network-heavy clients; the Owner holds direct relationships with 11 of 14 managed services clients with no documented succession plan; and the Cisco/Network Architecture role has "None" listed as backup status. Technical staff compensation is 6–10% below market benchmarks with no retention bonuses or equity, resulting in 38% technical staff turnover in the review period, and no employment agreements exist for technical staff to provide contractual retention protections for key engineers. | 3/10 | CRITICAL RISK | |
| fix_09 | Financial Trajectory & EBITDA Quality AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Apex Managed Solutions reported $2.1M in revenue with an 18% EBITDA margin ($378K) and normalized EBITDA of $412K after add-backs, demonstrating reasonable profitability, but the documents provide no evidence of audited or reviewed financials, multi-year growth trajectory, or detailed documentation of add-back justifications. The CIM presents only a single-year financial snapshot with normalized adjustments, and no historical financial statements, audit reports, or detailed add-back schedules are included in the retrieved excerpts to assess EBITDA quality or growth consistency. | 6/10 | ADEQUATE | |
| fix_10 | Data Room Readiness AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents show critical gaps in data room preparation for a sale process. While a Confidential Information Memorandum and Cybersecurity Assessment exist, there is no evidence of a comprehensive, organized data room structure with version control, access management, or systematic documentation of key operational, financial, legal, and HR records. The documents reveal significant underlying business issues (key person dependencies, high turnover, compensation gaps, cybersecurity gaps) that require extensive remediation documentation, but no organized repository or checklist of due diligence materials is evident from the excerpts provided. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated No formal succession plan exists at Apex Managed Solutions. The documents explicitly state "No succession plan or cross-training program exists for any role," and the owner holds direct relationships with 11 of 14 managed services clients with no documented handoff protocols. Additionally, the owner is the sole decision-maker for all hires and is directly involved in technical onboarding, creating critical single-points-of-failure (particularly the owner's relationships and the Cisco/Network Architect role) that would destabilize the business if the owner departed unexpectedly. | 2/10 | CRITICAL RISK | |
| owr_02 | Institutional Knowledge Capture AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The company has minimal institutional knowledge documentation with critical expertise held by individual contributors rather than in accessible systems. The documents reveal that the owner holds direct relationships with 11 of 14 managed services clients with no succession plan, the only location-certified engineer has no backup, basic onboarding is "handled by [PERSON] (not documented)," and "no formal training program; learning is on-the-job." Additionally, there are no employment agreements for technical staff, creating significant flight risk for key personnel like the Senior Network Engineer who has raised compensation concerns twice and whose departure would eliminate the company's ability to service network-heavy clients without emergency hiring. | 2/10 | CRITICAL RISK | |
| owr_03 | Management Team Depth AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The business lacks formal management depth and cannot operate independently for 60+ days. The owner holds direct relationships with 11 of 14 managed services clients and is involved in all hiring decisions and technical orientations, while the only backup for critical technical roles (Cisco/Network Architecture, Tier-2 Lead) is either non-existent or informal, creating single points of failure. Additionally, no employment agreements exist for key technical staff, no succession plan or cross-training program is documented, and the 38% technical staff turnover rate (including the loss of the primary engineer for the largest client) demonstrates the organization cannot sustain operations without owner involvement during extended absences. | 3/10 | CRITICAL RISK | |
| owr_04 | Key Person Concentration Beyond Owner AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company has multiple critical single points of failure beyond the owner. Section 4 documents that the Cisco/Network Architect is a "single-point-of-failure" whose departure would eliminate the practice's ability to service network-heavy clients, and the Senior Network Engineer is significantly underpaid (7% below market) and has raised compensation concerns twice, creating high flight risk. Additionally, no employment agreements exist for technical staff, providing the buyer with no contractual retention protections, and there is no succession plan or cross-training program for any key role. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_Financials.csv — High confidence — multiple documents corroborated Apex Managed Solutions exhibits significant customer concentration risk with the largest client, Hendricks Medical Group, representing 18% of revenue according to the Human Capital Profile document. The top 7 customers shown in the Financials excerpt represent approximately 21% of total revenue, indicating heavy reliance on a small number of accounts, and the departure of the senior systems engineer who was "the primary engineer for the largest client" demonstrates vulnerability to key person dependencies that could further destabilize these critical relationships. | 3/10 | CRITICAL RISK | |
| cq_02 | Revenue Predictability & Recurring Mix AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated Apex generates 62% recurring revenue from managed services and monitoring contracts with 34 active clients averaging $3,200 per month and an average tenure documented in the files, providing a solid recurring base. However, predictability is moderately constrained by the absence of multi-year contract documentation, a 31% all-staff voluntary turnover rate with 38% technical staff turnover including loss of the primary engineer for the largest client (18% of revenue), and no formal renewal tracking or documented renewal rates in the materials provided. | 7/10 | ADEQUATE | |
| cq_03 | Contract Transferability AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The documents provide no evidence of formal customer contracts, assignment clauses, or change-of-control provisions. The CIM states that Apex serves "34 active clients under recurring contracts averaging $3,200 per month per client," but no contract templates, assignment language, or transferability terms are included in any retrieved documents. Most critically, the HC Profile reveals that the Owner "[PERSON] holds direct relationships with 11 of 14 managed services clients," indicating that a majority of the revenue base is personality-dependent and lacks institutional contract documentation, making transfer without individual customer consent highly unlikely. | 2/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_Financials.csv · AMS_CIM.txt — High confidence — multiple documents corroborated The company does not track customer churn rate or retention metrics—no documented gross churn percentage, net revenue retention figures, or formal retention programs appear in any of the provided documents. While the CIM references 34 active managed services clients with average tenure and 62% recurring revenue, there is no evidence of monthly or quarterly churn tracking, root-cause analysis, or retention playbooks. The internal focus appears reactive rather than proactive, with significant operational instability evidenced by 38% technical staff turnover and the recent departure of a senior engineer responsible for 18% of revenue from the largest client. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no information regarding financial statements, audit or review status, CPA relationships, or books quality. The available excerpts focus on cybersecurity assessment, HR profiles, CRM pipeline, and company overview, but do not address accounting practices, financial statement preparation, or auditor engagement. Without evidence of financial statement quality or CPA involvement, exit readiness in this critical area cannot be assessed from the provided documentation. | 2/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The documents provide no formal add-back schedule, supporting documentation, or CPA verification of EBITDA adjustments. While the CIM references "Normalized EBITDA of $412K after add-backs" compared to reported EBITDA of $378K, the specific add-backs are not detailed or supported. The only add-back items identified in the HC Profile are owner S-corp distributions ($180,000 requiring conversion to employment agreement), discretionary tech bonuses (paid via owner check, not payroll), and owner vehicle expense ($680/mo), but these lack formal documentation or buyer-ready support schedules that a buyer's accountant could independently verify. | 3/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents contain no information regarding revenue recognition policies, GAAP compliance, deferred revenue tracking, or revenue consistency practices. The available excerpts address cybersecurity posture, company overview, and human capital metrics, but provide no evidence to assess revenue recognition methodology or documentation. This absence of critical financial policy documentation represents a significant gap that would require immediate clarification during due diligence before any revenue-related assessment can be made. | 1/10 | CRITICAL RISK | |
| fr_04 | Three-Year Financial Trend AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated The company generated $2.1M in revenue with an 18% EBITDA margin ($378K EBITDA, normalized to $412K) as of the assessment date, demonstrating solid profitability. However, the documents provide only a single-year financial snapshot with no multi-year revenue or EBITDA trend data, making it impossible to assess consistency of growth, CAGR performance, or margin trajectory over three years. Without historical financial statements showing year-over-year comparability across 2023-2025, the assessment cannot confirm whether growth has been sustained or margins stable. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated Apex Managed Solutions has minimal formal process documentation with heavy reliance on key individuals. The onboarding section explicitly states "No formal training program; learning is on-the-job" with "Basic system access setup handled by [PERSON] (not documented)" and helpdesk onboarding consisting only of "[DATE_TIME] ticket shadowing; no documented playbook." Critical operational knowledge is person-dependent, as evidenced by single points of failure: the owner holds direct relationships with 11 of 14 managed services clients, the Senior Network Engineer is the only [LOCATION]-certified engineer with no backup, and "No succession plan or cross-training program exists for any role." | 3/10 | CRITICAL RISK | |
| ops_02 | Technology & Systems Scalability AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The company relies on undocumented systems and processes with critical knowledge concentrated in key individuals. The cybersecurity assessment identifies significant gaps including "No documented incident response plan exists. Informal procedures are followed but not written down" and credential management risks, while the HR profile shows the senior network engineer ([PERSON]) is a "single-point-of-failure" for Cisco/network architecture with "no succession plan or cross-training program." Scaling to 3x growth would require material documentation, formalization of undocumented onboarding procedures, and replacement of the owner-dependent hiring and approval processes currently described as "ad-hoc." | 4/10 | NEEDS WORK | |
| ops_03 | Vendor & Supplier Concentration AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated Apex has moderate vendor concentration with identified dependencies on key platforms (ConnectWise Manage, IT Glue, Huntress EDR, Microsoft 365, and Datto) but lacks documented formal SLAs or formal alternatives for critical services. The cybersecurity assessment identifies a specific single-source risk with IT Glue credentials and recommends migration to BeyondTrust/CyberArk as an alternative, and recommends evaluating Barracuda Message Archiver as an alternative to M365 retention—indicating some switching costs and alternatives are acknowledged but not yet formalized or contractually secured. | 6/10 | ADEQUATE | |
| ops_04 | Financial Controls & Reporting Cadence AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no information about financial controls, reporting cadence, monthly close timelines, budget vs. actual reviews, or documentation of accounting procedures. The only financial data present relates to compensation levels and owner distributions, which are insufficient to assess the company's financial reporting infrastructure. Without evidence of a CFO, Controller, or formal close process, this company appears to fall into the lowest tier of financial maturity for M&A readiness. | 2/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt — High confidence — multiple documents corroborated Core business systems are partially documented but have significant personal account dependencies and ownership gaps. The cybersecurity assessment identifies that "shared administrative credentials for client environments [are] stored in IT Glue without dedicated vaulting" (Gap 1, HIGH risk), and critical technical roles lack succession planning—notably, "[PERSON] is the only [LOCATION]-certified engineer" with "no succession plan or cross-training program" and the owner holds "direct relationships with 11 of 14 managed services clients" with no documented transfer mechanism. Additionally, basic system access setup and onboarding are "handled by [PERSON] (not documented)," indicating undocumented processes tied to individual staff members rather than formalized entity-owned procedures. | 4/10 | NEEDS WORK | |
| tm_02 | Cybersecurity & Data Protection Posture AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_Customer_Contract_Hendricks.txt · AMS_Financials.csv · AMS_Customer_Onboarding_SOP.txt — High confidence — multiple documents corroborated Apex Managed Solutions deploys EDR (Huntress) across client endpoints and maintains RMM monitoring with patch management as standard offerings, but significant gaps exist in internal security maturity. The internal cybersecurity assessment identifies critical missing controls including no documented incident response plan, no privileged access management vault (credential exposure risk via IT Glue), no recent penetration testing, and unenforced mobile device policies—with no evidence of cyber insurance or annual vendor security reviews in the retrieved documents. | 6/10 | ADEQUATE | |
| tm_03 | Data Integrity & Business Intelligence AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The company lacks reliable, accessible operational data and exhibits significant individual dependencies across critical functions. The cybersecurity assessment identifies "credential exposure on staff departure" with passwords managed through IT Glue without a dedicated privileged access management (PAM) system, and the human capital profile reveals that the owner holds "direct relationships with 11 of 14 managed services clients" with "no succession plan or cross-training program" and key technical staff (like the Senior Network Engineer) representing single points of failure. Additionally, compensation is set "ad-hoc" by the owner with "no formal benchmarking process," and the incident response plan is "informal" with "procedures followed but not written down," indicating scattered, undocumented operational data without reliable audit trails or systematic BI reporting. | 3/10 | CRITICAL RISK | |
| tm_04 | Technology Vendor & Subscription Management AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Core technology vendor relationships are partially known but lack formal documentation and transfer mechanisms. The cybersecurity assessment identifies critical gaps including shared administrative credentials stored in IT Glue without dedicated vaulting, no formal PAM solution, and credentials documented under individual IT staff rather than entity-owned systems—creating significant transfer risk on staff departure. Additionally, key technical personnel dependencies (e.g., the single CCNP-certified network engineer) suggest that access to vendor relationships and client system credentials may be concentrated with individuals rather than formally transferred to the entity. | 4/10 | NEEDS WORK | |
| tm_05 | Technical Debt & Modernization Risk AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company operates a mixed technology stack with modern cloud components (Microsoft 365 with Azure AD, Huntress EDR, Datto BCDR) but carries material technical debt in privileged access management and documentation. The cybersecurity assessment identifies a HIGH-priority gap where "shared administrative credentials for client environments stored in IT Glue without dedicated vaulting" create credential exposure risk, along with missing formal incident response documentation and no external penetration testing in the assessment period—issues requiring post-close remediation at modest cost ($8,000-12,000 for pen test alone) but nonetheless deferred from the current operation. | 6/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_Financials.csv — High confidence — multiple documents corroborated The retrieved documents contain no information regarding business licenses, permits, their current status, or transferability in a change-of-control event. While the company operates as a managed services provider and cybersecurity services firm, there is no documentation of required licenses (such as professional certifications, vendor certifications, or regulatory compliance licenses), their renewal status, or any legal review of transferability to a buyer, representing a material compliance gap for exit readiness. | 2/10 | CRITICAL RISK | |
| lc_02 | Contract Change-of-Control Provisions AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no evidence of contract review, assignment clause analysis, or change-of-control provision assessment for any vendor, customer, or lease agreements. While the CRM pipeline lists 14 active customer opportunities and the compensation section references a portable Cigna health plan and entity-owned retirement benefits, there is no documentation of legal review of material customer MSAs, vendor contracts, or lease agreements for assignability or change-of-control triggers—creating material deal risk for a potential acquirer. | 2/10 | CRITICAL RISK | |
| lc_03 | Employment Law Compliance AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The company lacks critical employment law compliance documentation and controls. No employment agreements exist for technical staff, creating no contractual retention protections for key personnel; compensation is set ad-hoc without formal benchmarking, with technical staff earning 6-10% below market rates and at least one key engineer ([PERSON], Senior Network Engineer) having raised compensation concerns twice; and the documents show no evidence of I-9 verification processes, non-compete agreements, or formal classification documentation. Additionally, the owner's compensation structure ($180,000 S-corp distributions plus discretionary bonuses paid via owner check rather than payroll) requires formalization and cleanup before a transaction. | 4/10 | NEEDS WORK | |
| lc_04 | Intellectual Property Ownership AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The documents do not contain evidence of formal IP ownership documentation, assignment agreements, or an IP schedule. While the CIM references the company's Microsoft Gold Partner designation and vendor relationships (Dell, Datto), and the cybersecurity assessment mentions tools like ConnectWise Manage, IT Glue, and Huntress EDR, there is no explicit statement that all software, processes, or IP are formally assigned to the entity or free from founder/personal overlap. The absence of IP ownership documentation, trademark registration status, or a data room IP schedule places this assessment in the "assumed but not formally documented" range. | 5/10 | NEEDS WORK | |
| lc_05 | Litigation & Contingent Liability AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_CIM.txt · AMS_Customer_Contract_Hendricks.txt — High confidence — multiple documents corroborated The documents reveal no active material litigation or undisclosed contingent liabilities threatening the business. However, there are several operational and compliance gaps that create moderate legal exposure: the cybersecurity assessment identifies missing incident response documentation and no external penetration testing performed (creating "regulatory exposure with healthcare-adjacent clients"), and the HC profile notes $18,000 in accrued PTO liability and informal owner compensation arrangements requiring formalization before close. These are disclosed, addressable issues rather than hidden claims, placing the company in the "minor open matters" category with standard commercial risk. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Employee Documentation & Compensation AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Employee roles lack formal documentation and succession planning, with critical single points of failure across technical functions. The company has no employment agreements for technical staff, ad-hoc compensation setting by the owner with no formal benchmarking process, and acknowledged compensation gaps of 6–10% below market for technical roles, creating retention risk—particularly for the Senior Network Engineer who has "raised this concern twice" and is identified as the "highest flight risk." Onboarding is undocumented (basic system access setup "not documented," helpdesk training has "no documented playbook"), and no formal roles matrix exists beyond an informal bench depth table showing multiple single-point-of-failure positions with "no succession plan or cross-training program." | 3/10 | CRITICAL RISK | |
| hc_02 | Retention Agreements & Non-Competes AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated No employment agreements exist for technical staff, creating significant post-close retention risk. The documents explicitly state "No employment agreements for technical staff — buyer has no contractual retention protections for [PERSON] or other key engineers," and there are no retention bonuses or equity incentives in place. With 38% technical staff turnover, compensation 6-10% below market for key roles (particularly the Senior Network Engineer at $88,000 vs. $95,000 market), and the critical Senior Network Engineer identified as "the highest flight risk given his compensation gap and market value," the company presents minimal contractual safeguards for key personnel retention through a transition. | 2/10 | CRITICAL RISK | |
| hc_03 | Bench Depth & Succession AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The company has severe bench depth deficiencies with multiple critical single points of failure. The Senior Network Engineer [PERSON] is the only [LOCATION]-certified engineer and holds exclusive responsibility for Cisco/Network Architecture with "None" documented backup, creating a single-point-of-failure that would eliminate the company's ability to service network-heavy clients without emergency hiring. Additionally, the Owner [PERSON] holds direct relationships with 11 of 14 managed services clients (78% of the client base) with no succession plan or cross-training program in place, and no employment agreements exist for technical staff to provide contractual retention protections. | 3/10 | CRITICAL RISK |
MSP revenue infrastructure is evaluated on lead-to-contract automation, after-hours responsiveness, and client retention sequences — critical signals for buyers assessing whether ARR growth is system-driven or founder-dependent.
Automation maturity is scored separately from the valuation composite. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not valuation discounts.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt The retrieved documents contain no evidence of AI voice agents or automated after-hours call handling capabilities at Apex Managed Solutions. The company uses ConnectWise Manage for service delivery but there is no mention of any call handling automation, voicemail systems, or after-hours telephony infrastructure in the provided excerpts. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt Apex uses ConnectWise Manage as its CRM platform with documented client contracts and a tracked pipeline ($380K active with $195K weighted value), but the documents provide no evidence of automated workflows—follow-up activities, escalations, and client communication appear to be manually managed, particularly given the owner's direct involvement in 11 of 14 client relationships and ad-hoc operational processes throughout the organization. | 1/2 | PARTIAL | |
| R03 | 24/7 Lead Capture AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt No evidence of after-hours or 24/7 lead capture capability exists in the retrieved documents; the company operates with manual, owner-dependent processes and no mention of contact forms, chatbots, or automated lead routing systems. As an MSP with a remote-first service delivery model, lead capture infrastructure is entirely absent from the operational documentation. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt The retrieved documents contain no evidence of automated SMS appointment reminders, confirmations, or follow-up workflows. The company uses ConnectWise Manage for service delivery and IT Glue for documentation, but there is no mention of SMS automation capabilities, appointment reminder systems, or confirmation workflows in any of the operational or technical assessments provided. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt There is no evidence of any automated or manual post-service review solicitation process in the retrieved documents. The company uses ConnectWise Manage and IT Glue for service delivery but no review automation or systematic follow-up mechanism is mentioned, indicating reviews are organic only. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt No evidence of automated follow-up sequences exists in the retrieved documents; the company operates with manual sales processes dependent on owner relationships, as evidenced by the owner holding direct relationships with 11 of 14 managed services clients and no documented sales automation or CRM-driven nurture workflows mentioned in any operational materials. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
A low Automation Maturity score for an MSP signals that growth is relationship-driven rather than systematic. Buyers will apply a meaningful discount and may require remediation commitments as a condition of close.
Vertical-specific operational automation gaps identified in MSP & Technology Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not valuation buyer discount risk reduction. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Ticket Triage & Auto-Assignment | 0/2 | MANUAL | Ticket automation reduces mean time to first response — the metric buyers use most heavily to benchmark MSP operational maturity and client satisfaction. | |
| Patch Management & Compliance Reporting | 0/2 | MANUAL | Automated patch compliance reporting is a premium tier differentiator — it demonstrates systematic security management and supports cyber insurance requirements. | |
| Client Onboarding & Offboarding | 0/2 | MANUAL | Onboarding automation is the most visible quality signal to new clients — and the fastest way to surface the gap between an MSP that runs on people and one that runs on systems. | |
| Client Health Scoring & Churn Risk Alerts | 0/2 | MANUAL | Client health automation converts churn prevention from a reactive fire drill to a proactive managed process — directly protecting the MRR base that drives MSP valuation. | |
| QBR Scheduling & Preparation | 0/2 | MANUAL | QBR automation enables consistent executive engagement across the entire client base — not just the accounts that squeaky-wheel their way to attention. |
Top 3 Strengths
- Solid recurring revenue base with 62% of revenue from managed services contracts across 34 active clients averaging $3,200/month, demonstrating predictable cash flow and a recurring business model attractive to acquirers (Revenue Quality & Concentration: 7/10).
- Adequate baseline cybersecurity posture for an MSP, including MFA enforcement across Microsoft 365/Azure AD, Huntress EDR deployed across all 11 endpoints, and Datto BCDR with tested restores, providing a foundation that meets industry standards for service delivery (Cybersecurity Posture: 7/10).
- Active CRM implementation with ConnectWise Manage tracking a documented sales pipeline of 15 opportunities across defined stages with assigned probabilities and close dates, demonstrating forward revenue visibility and basic sales discipline (CRM & Pipeline Documentation: 7/10).
Top 3 Risks
- Extreme key-person dependency creates material valuation and closing risk: the owner maintains direct relationships with 11 of 14 managed services clients with no documented succession plan, no formal retention agreements exist for technical staff, and the only [LOCATION]-certified engineer represents a single point of failure whose departure would eliminate the company's ability to service network-heavy clients (Owner Dependency: 3/10; Key Employee Risks: 3/10).
- Critical customer contract documentation is absent, with no evidence of contract terms, transferability provisions, change-of-control clauses, renewal tracking mechanisms, or centralized contract repository—preventing buyer assessment of revenue quality and creating post-close retention risk (Customer Contracts: 2/10).
- Documented processes and operational procedures exist primarily in people's heads rather than in standardized, documented SOPs, with the cybersecurity assessment explicitly identifying "documentation formality" as a HIGH-priority remediation gap before sale, compounding key-person dependency risk and limiting buyer confidence in operational continuity (Documented Processes & SOPs: 4/10).
Recommended Priority Fixes
Actions the company should take in the next 90 days to maximise exit readiness:
Compliance Notes
No PII was detected in the ingested documents.