Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
| Domain | Layer8 Service | Deal Impact | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|---|
DRDiligence Risk✓ Quick Win | Security Hardening & Data Room Preparation | +13% | $60,690 | ⏱ 6–8 wks | $4,500 – $7,500 | ~10x |
OROwner Risk✓ Quick Win | Succession Planning & Knowledge Capture Sprint | +12% | $56,644 | ⏱ 8–10 wks | $6,000 – $10,000 | ~7x |
CQCustomer Quality✓ Quick Win | Contract Audit & CRM Implementation | +12% | $56,644 | ⏱ 6–8 wks | $5,000 – $9,000 | ~8x |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | +12% | $56,644 | ⏱ 8–12 wks | $5,000 – $9,000 | |
OSOperational Scalability✓ Quick Win | Process Documentation & Systems Audit | +11% | $52,598 | ⏱ 10+ wks | $6,500 – $11,000 | ~6x |
FRFinancial Readiness✓ Quick Win | Books Cleanup & Add-Back Schedule | +10% | $48,552 | ⏱ 6–8 wks | $4,000 – $7,000 | ~9x |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | +9% | $40,460 | ⏱ 8–10 wks | $6,000 – $10,000 | |
HCHuman Capital & Key Employee Risk | Key Employee Retention & Documentation Sprint | +7% | $32,368 | ⏱ 8–10 wks | $5,000 – $9,000 | |
| TOTAL | — | $404,600 | — | $42,000 – $72,500 | ~7x | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Valuation Impact Analysis
| Scenario | Score-Adjusted Range | Implied Value (SDE) |
|---|---|---|
| Current (as-is) | 2.5×–2.8× SDE | $1,190,000 – $1,332,800 |
| Post-Remediation (5.7/10 est.) | 2.6×–3.1× SDE | $1,237,600 – $1,475,600 |
Implementing the recommended priority fixes over 90 days could add an estimated ~$95,200 to the transaction value — a potential 8% lift on the same underlying business.
↑ What drives higher multiples
- High MRR percentage >70%
- Documented service contracts
- NOC/helpdesk not owner-dependent
- Stack standardization across clients
↓ What buyers will flag
- Break-fix revenue dominant
- No formal service agreements
- Owner is primary engineer
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_CIM.txt — High confidence — multiple documents corroborated The company has minimal documented processes with significant knowledge concentration in key individuals. While some documentation exists—including Georgia POST certification verification procedures, a post orders manual for all 22 active accounts, and an unarmed officer onboarding orientation—the documents reveal critical process gaps: client relationship management is entirely owned by two individuals ([PERSON] and [PERSON]), the owner approves all proposals over $25K with no formal approval workflow, compensation is set informally based on individual discretion with no formal review process, and the lead technician ([PERSON]) holds most system design and integration knowledge with no documented procedures. The cybersecurity assessment further indicates that critical processes like client credential management, backup testing, and access reviews lack formal documentation or standardized procedures. | 4/10 | NEEDS WORK | |
| fix_02 | Cybersecurity Posture ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Atlas Security Technologies exhibits significant cybersecurity gaps that fall below exit-readiness standards. While MFA is enforced for office staff and basic endpoint protection (Microsoft Defender) is deployed, critical vulnerabilities exist: MFA is not enforced for 6 field technicians, no EDR solution is deployed, client VPN credentials are stored in a shared spreadsheet without a password vault, field iPads lack MDM enrollment and encryption, and there is no documented formal incident response plan or backup testing. The external security assessment explicitly rates overall risk as "MEDIUM" and identifies the unvaulted client credential management as a "CRITICAL" gap that creates "severe liability exposure" and would be "reputationally devastating" if exploited—a particularly acute concern for a security systems integrator serving healthcare and schools. | 4/10 | NEEDS WORK | |
| fix_03 | Owner Dependency ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The owner ([PERSON]) is a critical single point of failure across client relationships and strategic decision-making. The documents explicitly state that "[PERSON] and [PERSON] manage all client relationships," with the owner holding the direct relationship for WellStar Health System (18% of revenue), and the assessment notes that "If [PERSON] were unavailable for [DATE_TIME], the WellStar account relationship would be at risk." Additionally, the owner approves all supervisor-level and above hires, sets compensation rates unilaterally, and the succession planning section confirms "No succession planning" and "no documented backup" for operations, with the business having operated without the owner only during brief vacations with limited scope. | 3/10 | CRITICAL RISK | |
| fix_04 | Revenue Quality & Concentration ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company exhibits severe revenue concentration risk with WellStar Health System representing 18% of revenue and held entirely by a single owner contact with no documented backup relationship. The pipeline shows early-stage, project-based opportunities (mostly in Discovery/Proposal stages with 20-75% close probability) rather than established recurring contracts, and the documents provide no evidence of multi-year agreements, renewal rates, or contract diversification across verticals—only a list of new client acquisitions and upsells indicating transactional rather than recurring revenue patterns. | 3/10 | CRITICAL RISK | |
| fix_05 | Customer Contracts ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_Financials.csv — High confidence — multiple documents corroborated The documents provide no evidence of standardized customer contracts, centralized contract repository, change-of-control clauses, or formal renewal tracking. While the company manages 22 active accounts with post orders manuals and generates $2.8M in revenue (with 58% recurring), the retrieved documents contain no contract templates, assignment language, renewal dates, or documentation of contract terms—only sales pipeline data and client names. The company's reliance on two individuals ([PERSON] and [PERSON]) to manage "all client relationships" suggests informal, undocumented contract management practices typical of a small operator lacking formal legal infrastructure for M&A transferability. | 3/10 | CRITICAL RISK | |
| fix_06 | IT Infrastructure & Asset Documentation ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv · ATS_IT_Asset_Inventory.csv — High confidence — multiple documents corroborated Atlas Security Technologies maintains a basic IT asset inventory (ATS_IT_Asset_Inventory.csv) that documents 20 devices across desktops, laptops, mobile devices, and network equipment with purchase dates and status, but the inventory is incomplete—notably missing asset IDs for multiple iPads and lacking lifecycle tracking, maintenance records, and depreciation schedules. The cybersecurity assessment reveals significant infrastructure gaps including no MDM enrollment for 5 field iPads used for client system programming, no EDR solution deployed, unencrypted field devices, no documented backup testing, and no formal maintenance procedures, indicating that while systems exist, they are not systematically maintained or monitored. The absence of a disaster recovery plan testing record and deferred security remediation (estimated at $2,500 one-time plus $300/month ongoing) further demonstrates inconsistent infrastructure maintenance before exit readiness. | 4/10 | NEEDS WORK | |
| fix_07 | CRM & Pipeline Documentation ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_CIM.txt — High confidence — multiple documents corroborated Atlas Security Technologies uses a CRM system with documented sales pipeline showing 11 active opportunities totaling $620K in pipeline value ($298K weighted), tracked across defined stages (Discovery, Qualified, Proposal, Negotiation) with assigned owners and probability estimates. However, the pipeline documentation reveals concentration risk with multiple deals assigned to individual sales owners and no evidence of forecast validation against actuals or formal stage discipline enforcement processes. | 7/10 | ADEQUATE | |
| fix_08 | Key Employee Risks ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company has critical single points of failure in both client relationships and operations with no formal succession planning. Two individuals ([PERSON] and [PERSON]) manage all 22 client relationships, with [PERSON] holding the direct relationship for WellStar Health System representing 18% of revenue—if unavailable, this account relationship would be at risk. There are no documented backups for the Operations Manager role, no retention agreements, no formal supervisory development program, and no institutional knowledge captured beyond basic site-specific post orders manuals, creating severe exit readiness risk. | 3/10 | CRITICAL RISK | |
| fix_09 | Financial Trajectory & EBITDA Quality ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CIM.txt — High confidence — multiple documents corroborated The CIM shows $2.8M in revenue with a 17% EBITDA margin ($476K EBITDA) and normalized EBITDA of $524K after add-backs, but the documents provide no evidence of audited or reviewed financial statements, multi-year growth trajectory, or documentation of the add-backs themselves. The retrieved excerpts contain no historical financial data, audit reports, or clean accounting documentation necessary to assess financial quality and trajectory for M&A due diligence. | 4/10 | NEEDS WORK | |
| fix_10 | Data Room Readiness ATS_Cybersecurity_Assessment.txt · ATS_GL_Export.csv · ATS_IT_Asset_Inventory.csv · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents reveal significant data room disorganization and critical gaps that are not exit-ready. While basic financial records (GL export), IT asset inventory, and CRM pipeline data exist, there is no evidence of organized data room structure, version control, document categorization, or access management protocols. Most critically, the cybersecurity assessment identifies unresolved security vulnerabilities including client credentials stored in shared spreadsheets and unencrypted field devices, which would trigger immediate buyer concerns and require remediation before any responsible data room handoff. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated No formal succession plan exists, and the business is heavily dependent on the owner for critical client relationships and decision-making. The owner holds the direct relationship with WellStar Health System (18% of revenue), and while an Operations Manager exists, there is "no documented backup" for operations and "no succession planning" is acknowledged in the Human Capital Profile. The business has demonstrated it can operate without the owner for vacation periods, but client escalations and strategic decisions remain owner-dependent, creating significant continuity risk in an ownership transition. | 2/10 | CRITICAL RISK | |
| owr_02 | Institutional Knowledge Capture ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Critical institutional knowledge remains concentrated in individual key personnel with minimal documentation. The company has no formal succession plan, and [PERSON] holds the direct relationship with WellStar Health System (18% of revenue) with only partial backup coverage; the documents state "If [PERSON] were unavailable for [DATE_TIME], the WellStar account relationship would be at risk." While site-specific post orders manuals exist for all 22 accounts and Georgia POST certification requirements are documented, there is no formal supervisory development program, no documented backup for operations management, and [PERSON] and [PERSON] manage all client relationships without documented handoff procedures or client relationship documentation accessible to other staff. | 3/10 | CRITICAL RISK | |
| owr_03 | Management Team Depth ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company has a functional management layer with an Operations Manager, Account Supervisor, and Admin/Billing staff who have maintained stable tenure (0% management turnover), and the team has operated for up to [DATE_TIME] without the owner during vacation. However, critical dependencies remain on the owner: [PERSON] holds the direct relationship with WellStar Health System (18% of revenue) with no documented backup, the Operations Manager has no formal backup for critical operations, and [PERSON] and [PERSON] manage all 22 client relationships with only partial coverage—indicating the business cannot safely operate independently for 60+ days without risking key account relationships and client escalations. | 5/10 | NEEDS WORK | |
| owr_04 | Key Person Concentration Beyond Owner ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Two employees—[PERSON] (Account Supervisor) and [PERSON] (Operations Manager)—represent critical single points of failure with limited documented backup coverage. [PERSON] holds the direct relationship with WellStar Health System, which represents 18% of revenue, with only partial backup coverage; the document explicitly states "If [PERSON] were unavailable for [DATE_TIME], the WellStar account relationship would be at risk." Additionally, [PERSON] has "no formal backup" for operations, and while [PERSON] and [PERSON] "manage all client relationships," [PERSON] handles only 9 of 22 accounts directly, indicating concentrated knowledge without documented succession planning or cross-training. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_CIM.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Atlas Security Solutions demonstrates excellent customer diversification with 52 active monitoring and managed service clients averaging $31,200 per client annually, and no single customer mentioned as representing a material concentration of the $2.8M total revenue. The CRM pipeline shows a well-distributed prospective customer base across multiple verticals (healthcare, retail, multifamily, education, government), with the largest pipeline opportunity being WellStar Health System at $192K—representing only 6.9% of current annual revenue and well below the 10% threshold for top-tier exit readiness. | 9/10 | STRONG | |
| cq_02 | Revenue Predictability & Recurring Mix ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_CIM.txt — High confidence — multiple documents corroborated Atlas Security Solutions demonstrates strong revenue predictability with 58% recurring revenue in FY [DATE_TIME] growing from 50% in FY [DATE_TIME], indicating a solid and improving recurring base under multi-year contracts. The company maintains 22 active accounts with documented site-specific training and post orders manuals, and the operations team actively manages client relationships; however, the pipeline shows primarily new deal opportunities rather than documented renewal rates or multi-year contract terms, preventing a higher score. While the recurring revenue percentage and growth trajectory align with the 7-8 band, the absence of explicitly documented renewal rates >90% or formal multi-year contract documentation limits confidence in 12-month predictability. | 7/10 | ADEQUATE | |
| cq_03 | Contract Transferability ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The documents provide no evidence of formal assignment or change-of-control clauses in customer contracts, and reveal that client relationships are heavily personality-dependent and concentrated with two individuals. The human capital profile explicitly states that "[PERSON] and [PERSON] manage all client relationships," with the WellStar Health System account (18% of revenue) held as a direct relationship by a single owner whose unavailability would put the account "at risk," indicating that contracts lack transferability mechanisms and would require individual customer consent to transition to a new owner. | 3/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_Financials.csv — High confidence — multiple documents corroborated Atlas Security Solutions tracks security officer turnover at 48% annually (below the 55%+ industry average for contract security), with post supervisor turnover at 12%, but there is no documented customer churn rate or net revenue retention metrics provided in the materials. The company manages customer relationships through two account owners ([PERSON] and [PERSON]) with site-specific training and post order manuals for 22 active accounts, but no formal retention programs, proactive churn prevention strategies, or root-cause analysis processes are described in the available documentation. | 5/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt — High confidence — multiple documents corroborated No financial statements, audited or otherwise, are present in the retrieved documents. The only financial information provided is compensation data and expense line items (vehicle $720/mo, cell $145/mo) embedded in human capital and operational profiles, which do not constitute formal accounting records or CPA engagement. There is no evidence of a CPA relationship, financial statement preparation, or any accounting framework necessary for M&A due diligence. | 1/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no add-back schedules, EBITDA adjustments, or normalized earnings documentation. While one document identifies owner-specific expenses ("Vehicle ($720/mo) — add-back" and "Cell ($145/mo) — add-back"), these are mentioned only in passing within a human capital profile with no supporting schedules, calculations, or verification. A buyer's accountant would have no formal documentation to verify normalized EBITDA, and significant rework would be required to reconstruct add-backs and separates personal from business expenses. | 2/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents do not contain any information regarding revenue recognition policies, GAAP compliance, deferred revenue tracking, or revenue recognition documentation. The excerpts provided address cybersecurity posture, human capital, compensation structure, and sales pipeline, but contain no evidence of accounting policies or financial reporting practices necessary to assess this area. Without access to financial statements, accounting policies, or audit documentation, revenue recognition consistency cannot be evaluated. | 1/10 | CRITICAL RISK | |
| fr_04 | Three-Year Financial Trend ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_CIM.txt — High confidence — multiple documents corroborated The documents provided contain no three-year historical financial data (revenue, EBITDA, or margin trends) necessary to assess financial trajectory. While the CIM references "$2.8M in [DATE_TIME] Revenue | 17% EBITDA Margin," only a single point-in-time snapshot is provided with no prior-year comparisons or year-over-year growth rates documented. Without multi-year comparable financials, exit readiness cannot be assessed against the scoring rubric's growth and trend requirements. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Process documentation is minimal and heavily dependent on key individuals. While some documentation exists (Georgia POST certification requirements, unarmed officer onboarding procedures, site-specific post orders manuals for 22 accounts, and background check/drug screen policies), the company relies entirely on two individuals ([PERSON] and [PERSON]) to manage all 22 client relationships, with no formal backup or succession planning documented. Critical operational functions like client escalation management lack documented procedures—when the owner was unavailable for an extended period, the Operations Manager could only handle field issues but was unable to manage client escalations, demonstrating significant process dependency on specific individuals rather than documented, repeatable workflows. | 3/10 | CRITICAL RISK | |
| ops_02 | Technology & Systems Scalability ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_Financials.csv — High confidence — multiple documents corroborated The company's technology infrastructure shows critical scalability limitations rooted in security and operational gaps rather than documented architectural constraints. The cybersecurity assessment identifies unvaulted client credentials stored in shared spreadsheets, unmanaged field iPads without MDM, and lack of EDR deployment—indicating systems built without enterprise-grade architecture or documentation. While the company operates cloud-based platforms (Microsoft 365, ServiceMax), the absence of formal system documentation, the reliance on shared credentials and manual access management, and the dependency on the owner for key operational decisions suggest that 3x growth would require material rework of core access, credential, and field management infrastructure beyond simple scaling. | 3/10 | CRITICAL RISK | |
| ops_03 | Vendor & Supplier Concentration ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt — High confidence — multiple documents corroborated Atlas Security Technologies exhibits significant vendor concentration risk, particularly with Microsoft 365 and ServiceMax, which are critical to operations but lack documented alternatives or formal SLAs. The cybersecurity assessment identifies that "ServiceMax (field service) — shared credentials among techs" and reliance on Microsoft 365 for client access management represent moderate-to-high switching costs, while the company's IT infrastructure lacks redundancy with no EDR solution deployed and local files having no cloud backup. Additionally, the business is heavily dependent on two key client relationships—WellStar Health System represents 18% of revenue with an owner-held relationship lacking formal backup—creating additional concentration risk beyond traditional vendor dependencies. | 4/10 | NEEDS WORK | |
| ops_04 | Financial Controls & Reporting Cadence ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents contain no information about financial controls, reporting cadence, monthly close timelines, budget vs. actual reviews, or documentation of accounting procedures. The excerpts provided cover cybersecurity assessment, CRM pipeline, and human capital profile, but do not address the financial controls and reporting structure necessary to evaluate exit readiness in this area. | 1/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt — High confidence — multiple documents corroborated Critical business systems show significant documentation and ownership gaps that create exit risk. Client VPN credentials and system passwords are stored in a shared spreadsheet with no password vault, no formal access review process, and credentials not rotated after employee departures; additionally, ServiceMax field service uses shared credentials among technicians, and the WellStar Health System account (18% of revenue) is held directly by a single individual with no documented backup, creating a key-person dependency that would jeopardize the account if that person became unavailable. | 3/10 | CRITICAL RISK | |
| tm_02 | Cybersecurity & Data Protection Posture ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_Financials.csv — High confidence — multiple documents corroborated The company has MFA enforced for office staff but critically lacks endpoint detection and response (EDR) deployment—only basic Microsoft Defender is in place—and field technicians operate without MFA protection. The cybersecurity assessment identifies no formal incident response plan, no documented cyber insurance, and no vendor security review process, while documenting a "CRITICAL" gap in client credential management stored in unvaulted shared spreadsheets that poses severe reputational and liability exposure. | 4/10 | NEEDS WORK | |
| tm_03 | Data Integrity & Business Intelligence ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Atlas Security Solutions lacks reliable, accessible operational data infrastructure with significant individual dependencies and security gaps that undermine data integrity. The CRM pipeline data exists in a basic CSV format with limited structure, while critical operational information—including client credentials—is stored in "a shared spreadsheet" without a password vault, creating both access control and audit trail failures. Additionally, departed employee access is "not formally tracked," field devices lack encryption or MDM enrollment, and the company relies on two individuals ([PERSON] and [PERSON]) to manage all client relationships with no documented backup systems or formal data governance processes. | 4/10 | NEEDS WORK | |
| tm_04 | Technology Vendor & Subscription Management ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt — High confidence — multiple documents corroborated The documents provide no evidence of formal vendor contract documentation, renewal date tracking, or license transfer procedures. Multiple critical tools show personal or shared credential dependencies: ServiceMax uses "shared credentials among techs," client VPN credentials are "stored in a shared spreadsheet," and the cybersecurity assessment identifies no password vault or formal access management, creating significant transfer risk for an acquirer. | 3/10 | CRITICAL RISK | |
| tm_05 | Technical Debt & Modernization Risk ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt — High confidence — multiple documents corroborated The company operates a mixed technology environment with significant cybersecurity gaps that constitute material technical debt requiring post-close investment. Critical issues include client credentials stored in unvaulted shared spreadsheets (Gap 1—CRITICAL), field devices (5 iPads) without MDM enrollment or encryption management, and missing MFA for 6 field technicians accessing Microsoft 365 and VPN (Gaps 2, 3, 5). The external cybersecurity assessment estimates $2,500 one-time remediation plus $300/month ongoing costs, and explicitly states "The client credential management gap is the most critical finding and requires immediate remediation regardless of sale timeline," indicating these are not deferred but actively unresolved security vulnerabilities that expose both the company and its clients to breach risk. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no information regarding business licenses, permits, their current status, transferability, or documentation in a data room. While the documents reference Georgia POST certification requirements for armed security officers and verify that "Georgia POST certification [is] required for all armed posts" with verification occurring "before armed post assignment," there is no evidence that business operating licenses, regulatory permits, or their change-of-control transferability have been reviewed by counsel or formally documented. The absence of any licenses and permits section in the due diligence materials represents a material gap in exit readiness assessment. | 3/10 | CRITICAL RISK | |
| lc_02 | Contract Change-of-Control Provisions ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Customer_Contract_WellStar.txt — High confidence — multiple documents corroborated No evidence exists in the retrieved documents that key vendor, customer, or lease agreements have been reviewed by counsel for change-of-control provisions or assignment language. While the WellStar contract (18% of revenue) contains a permissive assignment clause allowing transfer "in connection with acquisition or merger," there is no documentation indicating a systematic legal review of the company's other material contracts, and the cybersecurity assessment identifies critical credential management gaps that would likely trigger customer concerns during any change-of-control scenario. The absence of any contract review documentation, combined with the identified security vulnerabilities that could affect client relationships, creates material deal risk. | 3/10 | CRITICAL RISK | |
| lc_03 | Employment Law Compliance ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The documents provided focus primarily on cybersecurity posture and human capital metrics but contain minimal specific evidence regarding I-9 compliance, non-compete documentation, or formal compensation benchmarking processes. While compensation data is presented (with some roles benchmarked against ASIS standards), the HC Profile explicitly states "No formal comp review or benchmarking process" and notes that owner compensation "has not been reviewed since [DATE_TIME]." The documents contain no evidence of I-9 audits, non-compete agreements, or open EEOC/DOL matters, creating material documentation gaps typical of a 5-6 score range. | 5/10 | NEEDS WORK | |
| lc_04 | Intellectual Property Ownership ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The documents provided contain no evidence of formal IP ownership documentation, assignment agreements, or IP schedules. The cybersecurity assessment reveals that critical client system access credentials and configurations are stored in unvaulted shared spreadsheets and on unencrypted field devices without formal access controls, creating ambiguity around data ownership and security. There is no mention of trademark registration, software IP assignments, process documentation ownership, or any formalized IP transfer mechanism that would be required for a clean exit. | 3/10 | CRITICAL RISK | |
| lc_05 | Litigation & Contingent Liability ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_CIM.txt — High confidence — multiple documents corroborated The documents reveal no active litigation or disclosed legal claims against the company; however, a critical cybersecurity vulnerability creates material contingent liability exposure. Specifically, the Cybersecurity Assessment identifies that "client breach via compromised Atlas credentials would be reputationally devastating," noting that client system credentials are stored in an unvaulted shared spreadsheet rather than a secure vault, creating severe liability if a breach occurs and affects healthcare facilities and schools that are among the company's major clients (WellStar Health System, Marietta City Schools, Northside Ortho). While this represents a remediable vulnerability rather than existing litigation, the potential for client lawsuits stemming from a credential compromise and resulting system breach constitutes a material undisclosed contingent liability that must be remediated before exit. | 6/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Employee Documentation & Compensation ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated While core management roles and compensation benchmarks are documented (Operations Manager at $72,000 aligned to ASIS standards, Account Supervisor at $58,000 slightly below median), critical gaps exist in role formalization and compensation governance. There is no formal compensation review process—rates are set informally by the owner based on contract terms rather than systematic benchmarking—and the owner's compensation of $155,000 in S-corp distributions has not been reviewed since an unspecified prior date. Additionally, succession planning is absent; the WellStar account (18% of revenue) is owner-dependent with no documented backup, and no formal supervisory development program exists despite the company employing 28 full-time security officers across 22 active accounts. | 5/10 | NEEDS WORK | |
| hc_02 | Retention Agreements & Non-Competes ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company has no documented non-compete or retention agreements in place for key employees. The human capital profile explicitly states "No retention bonuses" and identifies critical single-person dependencies, including the WellStar Health System account (18% of revenue) held solely by the owner with only partial backup coverage, creating significant flight risk for key client relationships post-close. Management turnover is currently 0% and field staff turnover (48%) is below industry average, but the absence of formal agreements and succession planning leaves the business vulnerable to key employee departures during and after transaction. | 3/10 | CRITICAL RISK | |
| hc_03 | Bench Depth & Succession ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_CIM.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Atlas Security Solutions exhibits critical single points of failure across its management structure, with the owner holding all major client relationships and approving all proposals over $25K, and the WellStar Health System account (18% of revenue) having no documented backup contact. The company lacks formal succession planning, with the Operations Manager having "no formal backup" and the business only tested to operate without the owner for short vacation periods during which client escalations were not handled, creating substantial risk in a sale or transition scenario. | 3/10 | CRITICAL RISK |
MSP revenue infrastructure is evaluated on lead-to-contract automation, after-hours responsiveness, and client retention sequences — critical signals for buyers assessing whether ARR growth is system-driven or founder-dependent.
Automation maturity is scored separately from the valuation composite. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not valuation discounts.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv · ATS_CIM.txt · ATS_IT_Asset_Inventory.csv No evidence of AI voice agents or automated after-hours call handling exists in the retrieved documents; the company's IT infrastructure focuses on cybersecurity gaps and field service management with no mention of inbound call automation or lead qualification systems. After-hours calls would route to voicemail or answering service at best, representing a missed opportunity for lead capture and qualification. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv · ATS_IT_Asset_Inventory.csv There is no evidence of a CRM system in any of the retrieved documents; client relationships and credentials are managed manually through spreadsheets (client VPN credentials stored in shared spreadsheet) and owner/account supervisor direct management with no documented pipeline tracking or workflow automation. The company relies entirely on manual processes with no systematized contact management or automated follow-up workflows. | 0/2 | MANUAL | |
| R03 | 24/7 Lead Capture ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt · ATS_GL_Export.csv No evidence of after-hours or 24/7 lead capture capability exists in the retrieved documents; the company documents focus on operations, cybersecurity, and HR matters with no mention of website forms, chatbots, or automated lead routing systems. Lead generation and capture processes are entirely absent from the available materials. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv · ATS_CIM.txt The retrieved documents contain no evidence of automated SMS appointment reminders, confirmations, or follow-up workflows; the company's operations focus on security systems integration and monitoring services rather than appointment-based scheduling that would require such automation. This criterion is not applicable to the company's business model and therefore scores as not present. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv · ATS_CIM.txt · ATS_IT_Asset_Inventory.csv There is no evidence in the retrieved documents of any automated post-service review solicitation system; the documents focus on cybersecurity gaps, HR metrics, financial records, and IT assets with no mention of review request automation, trigger-based email/SMS systems, or customer feedback collection processes. Review solicitation appears to be entirely absent from the company's operations. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt · ATS_GL_Export.csv The retrieved documents contain no evidence of automated follow-up sequences for leads or dormant clients; there is no mention of email automation, CRM drip campaigns, or any systematic re-engagement process for unconverted prospects or inactive accounts. Client relationship management appears to be entirely manual, managed by two individuals ([PERSON] and [PERSON]), with no documented workflow or automation capability. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
A low Automation Maturity score for an MSP signals that growth is relationship-driven rather than systematic. Buyers will apply a meaningful discount and may require remediation commitments as a condition of close.
Vertical-specific operational automation gaps identified in MSP & Technology Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not valuation buyer discount risk reduction. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Ticket Triage & Auto-Assignment | 0/2 | MANUAL | Ticket automation reduces mean time to first response — the metric buyers use most heavily to benchmark MSP operational maturity and client satisfaction. | |
| Patch Management & Compliance Reporting | 0/2 | MANUAL | Automated patch compliance reporting is a premium tier differentiator — it demonstrates systematic security management and supports cyber insurance requirements. | |
| Client Onboarding & Offboarding | 0/2 | MANUAL | Onboarding automation is the most visible quality signal to new clients — and the fastest way to surface the gap between an MSP that runs on people and one that runs on systems. | |
| Client Health Scoring & Churn Risk Alerts | 0/2 | MANUAL | Client health automation converts churn prevention from a reactive fire drill to a proactive managed process — directly protecting the MRR base that drives MSP valuation. | |
| QBR Scheduling & Preparation | 0/2 | MANUAL | QBR automation enables consistent executive engagement across the entire client base — not just the accounts that squeaky-wheel their way to attention. |
Top 3 Strengths
- Functional CRM Pipeline with Documented Sales Tracking (7/10): Atlas maintains an active CRM system with 11 documented opportunities totaling $620K in pipeline value, tracked across defined stages with assigned owners and probability estimates, providing a foundation for acquirer confidence in revenue forecasting and sales process discipline.
- Established Service Delivery Model with Recurring Revenue Base: The company demonstrates $2.8M in revenue with 58% recurring revenue and manages 22 active accounts with documented post orders manuals and Georgia POST certification procedures, indicating a scalable service delivery framework that has achieved customer retention and operational consistency.
- Basic IT Infrastructure Inventory Exists: Atlas maintains a documented IT asset inventory across 20 devices with purchase dates and status tracking, and has deployed baseline security controls including MFA for office staff and Microsoft Defender endpoint protection, providing a starting point for infrastructure governance.
Top 3 Risks
- Critical Single Point of Failure in Revenue and Client Relationships (3/10 Owner Dependency, 3/10 Key Employee Risks): Two individuals manage all 22 client relationships, with the owner holding the exclusive direct relationship for WellStar Health System representing 18% of revenue; documented assessment explicitly notes this account would be "at risk" if the owner were unavailable, creating unacceptable deal completion risk and immediate valuation discount in M&A scenarios.
- Severe Cybersecurity Vulnerabilities with Reputationally Devastating Exposure (4/10 Cybersecurity Posture): Client VPN credentials are stored in a shared spreadsheet without a password vault, field iPads lack MDM enrollment and encryption, and MFA is not enforced for 6 field technicians; the external security assessment explicitly rates this as a "CRITICAL" gap creating "severe liability exposure" and "reputationally devastating" risk—particularly acute for a security systems integrator serving healthcare and schools, and this exposure would likely trigger deal termination by sophisticated acquirers.
- Severe Revenue Concentration with No Contract Infrastructure (3/10 Revenue Quality & Concentration, 3/10 Customer Contracts): WellStar Health System represents 18% of revenue with no documented backup relationship, the pipeline is project-based rather than recurring, and there is no evidence of standardized customer contracts, centralized contract repository, change-of-control clauses, or formal renewal tracking—meaning an acquirer cannot confirm customer retention post-acquisition or enforce contractual continuity.
Recommended Priority Fixes
Actions the company should take in the next 90 days to maximise exit readiness:
Compliance Notes
No PII was detected in the ingested documents.