Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
| Domain | Layer8 Service | Deal Impact | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|---|
DRDiligence Risk✓ Quick Win | Security Hardening & Data Room Preparation | +25% | $247,500 | ⏱ 4–6 wks | $2,500 – $4,500 | 20x+ |
OROwner Risk✓ Quick Win | Succession Planning & Knowledge Capture Sprint | +23% | $231,000 | ⏱ 6–8 wks | $3,500 – $6,000 | 20x+ |
CQCustomer Quality✓ Quick Win | Contract Audit & CRM Implementation | +23% | $231,000 | ⏱ 8–10 wks | $5,000 – $9,000 | 20x+ |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | +23% | $231,000 | ⏱ 6–8 wks | $3,000 – $5,500 | |
OSOperational Scalability✓ Quick Win | Process Documentation & Systems Audit | +21% | $214,500 | ⏱ 8–10 wks | $4,000 – $7,000 | 20x+ |
FRFinancial Readiness✓ Quick Win | Books Cleanup & Add-Back Schedule | +20% | $198,000 | ⏱ 4–6 wks | $2,000 – $4,000 | 20x+ |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | +17% | $165,000 | ⏱ 8–10 wks | $6,000 – $10,000 | |
HCHuman Capital & Key Employee Risk | Key Employee Retention & Documentation Sprint | +13% | $132,000 | ⏱ 6–8 wks | $3,000 – $5,500 | |
| TOTAL | — | $1,650,000 | — | $29,000 – $51,500 | 20x+ | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Valuation Impact Analysis
| Scenario | Score-Adjusted Range | Implied Value (EBITDA) |
|---|---|---|
| Current (as-is) | 4.1×–4.6× EBITDA | $4,100,000 – $4,600,000 |
| Post-Remediation (6.7/10 est.) | 4.7×–5.2× EBITDA | $4,700,000 – $5,200,000 |
Implementing the recommended priority fixes over 90 days could add an estimated $100,000–$1,100,000 to the transaction value — a potential 14% lift on the same underlying business.
↑ What drives higher multiples
- High MRR percentage >70%
- Documented service contracts
- NOC/helpdesk not owner-dependent
- Stack standardization across clients
↓ What buyers will flag
- Break-fix revenue dominant
- No formal service agreements
- Owner is primary engineer
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs README.md · PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated Peachtree has documented some key processes, including a structured onboarding program for technical staff (documented in Employee handbook with defined weeks 1-8 progression) and a Customer Onboarding SOP listed in the deal room contents, but documentation maturity remains inconsistent and incomplete. The Cybersecurity Assessment Report explicitly states "Documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the CIM notes that "incident response practices" remain informal rather than formally documented, indicating critical gaps in core operational procedures beyond onboarding. | 5/10 | NEEDS WORK | |
| fix_02 | Cybersecurity Posture PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated Peachtree's cybersecurity posture is incomplete and below buyer expectations for a healthcare-adjacent managed services firm. The assessment report identifies material gaps including inconsistent MFA enforcement (not yet rolled out to Microsoft 365, HubSpot, QuickBooks Online, ConnectWise, and remote admin tools), limited centralized monitoring with no formal SIEM deployed, and reliance on informal incident response practices lacking documented plans or testing. While endpoint protection is partially in place (Defender for Business on most endpoints with CrowdStrike in progress) and nightly backups are performed, the lack of MFA enforcement, absence of a formal IR plan, and incomplete endpoint coverage place the company squarely in the 5-6 range, with the assessment report itself assigning an overall "Medium" risk rating and noting that buyers will likely discount value pending remediation. | 5/10 | NEEDS WORK | |
| fix_03 | Owner Dependency PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The business demonstrates moderate owner dependency with some delegation in place but critical gaps in key relationships and formal succession planning. While the Operations Manager handles field scheduling and vendor relationships, and the company successfully operated without the owner for Q1 2026 with no SLA breaches, the CIM explicitly identifies "moderate owner dependence in late-stage sales, key client relationships, and vendor negotiations," and Northside Medical Group (16% of revenue) relies on the owner for executive relationship management with only operational contacts introduced to staff. No formal succession plan exists, with only a verbal commitment to a transition period post-close and no written agreement. | 6/10 | ADEQUATE | |
| fix_04 | Revenue Quality & Concentration README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated Peachtree's revenue base shows moderate quality with 42% recurring revenue (primarily MSP retainers and support agreements) and reasonable diversification across four service lines, but concentration risk is present with the top three customers representing 29.7% of total revenue. The largest single customer (Northside Medical Group) represents 11.4% of the $5.42M revenue base, and while no client exceeds the 15% threshold for a score of 7+, the company lacks formally documented renewal rates and relies on a mix of recurring, mixed, and project-based contract types rather than the multi-year contract stability expected at higher scores. | 6/10 | ADEQUATE | |
| fix_05 | Customer Contracts README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated The documents reference "PIS_Customer_Contract_*.docx/pdf" sample contracts in the deal room but provide no evidence of standardization, change-of-control clauses, centralized repository, or renewal tracking. The CIM notes that "Documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the CRM pipeline shows renewal activity (e.g., "Q3 Service Agreement Renewal, Other SMB Accounts" at 0.75 probability) but lacks systematic renewal rate data or contract transferability assessment. No specific information is provided about assignment language, contract formats, or renewal dates being tracked centrally. | 4/10 | NEEDS WORK | |
| fix_06 | IT Infrastructure & Asset Documentation PIS_CIM.docx · README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated Peachtree maintains a basic IT asset inventory documented in the PIS_Financials_And_Operations.xlsx spreadsheet listing servers, network equipment, and mobile devices with locations and service status, and nightly backups are performed with cloud retention and local replication; however, the Cybersecurity Assessment Report explicitly notes that restore tests occur but are "not always documented," and the CIM acknowledges that "documentation maturity is improving but inconsistent across onboarding and engineering workflows," indicating incomplete lifecycle tracking and maintenance documentation. There is no evidence of a tested disaster recovery plan, formal asset lifecycle management, or consistent patching procedures beyond the basic backup regime. | 5/10 | NEEDS WORK | |
| fix_07 | CRM & Pipeline Documentation PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated Peachtree uses ConnectWise and HubSpot as part of its operational stack (referenced in cybersecurity assessment and onboarding documentation), and a CRM pipeline export file exists (`PIS_CRM_Pipeline_2025Q2.csv`), indicating some CRM adoption. However, the CIM explicitly identifies "moderate owner dependence in late-stage sales" and notes that Mark Ellis (Sales Director) "runs pipeline independently," suggesting the pipeline is not uniformly owned across the sales team and stage discipline may be inconsistent. The documents do not provide evidence of forecast validation against actuals or confirmation that the pipeline is current and accurate across all opportunities. | 5/10 | NEEDS WORK | |
| fix_08 | Key Employee Risks PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated Peachtree has identified most critical roles with documented backups (NOC operations has solid cross-training with 2 additional trained staff; billing/finance and sales pipeline have identified alternates; operations manager executes non-senior hiring independently), but key vulnerabilities remain: the owner holds the exclusive executive relationship with Northside Medical Group (16% of revenue), there is no formal succession plan despite verbal commitment to a post-close transition period, and Cisco networking architecture represents a single point of failure with only 2 of 3 senior engineers certified (CCNA level, no CCNP on staff). While the business successfully operated without the owner during Q1 2026 with no SLA breaches, the lack of written retention agreements and formalized succession documentation falls short of exit-ready standards. | 6/10 | ADEQUATE | |
| fix_09 | Financial Trajectory & EBITDA Quality README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The company reported $5.42M in [DATE_TIME] revenue with $1.00M EBITDA (18.5% margin) and demonstrates internally consistent financial data across multiple systems (P&L, customer revenue, and service-line views reconcile to the same total), but the documents indicate "compiled" rather than audited financials with no explicit third-party financial review mentioned. While the CIM highlights a growing recurring revenue base (~42% of revenue, ~$190K MRR) and the overall exit readiness score is noted as 6.5/10, the documents do not provide evidence of 2+ years of consistent audited growth, documented add-backs, or margin trajectory analysis needed for a higher rating. | 5/10 | NEEDS WORK | |
| fix_10 | Data Room Readiness README.md · PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The company has assembled core operational and financial documents in a structured format (master financials workbook, GL export, AR aging, employee roster, IT assets, customer contracts, and cybersecurity assessment), demonstrating basic data room organization. However, the CIM explicitly identifies "Documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the cybersecurity assessment notes that incident response practices are "informal" and backup restore tests are "not always documented," indicating gaps in secondary documentation that would require cleanup before buyer review. | 6/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt · PIS_CIM.docx · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated No formal succession plan has been documented; the owner has only "verbally committed to a [DATE_TIME] transition period post-close" with "no written agreement yet." While the business demonstrated operational resilience during the owner's absence in Q1 2026 with key managers managing client communications and technical escalations, a critical single point of failure exists in the Northside Medical Group relationship (16% of revenue), where "the owner holds the executive relationship" and the successor has "been introduced to operational contacts only." The company relies on informal verbal commitments rather than documented handoff protocols or a formalized succession plan. | 4/10 | NEEDS WORK | |
| owr_02 | Institutional Knowledge Capture README.md · PIS_CIM.docx · PIS_HC_Profile.txt · PIS_Cybersecurity_Assessment_Report.docx — High confidence — multiple documents corroborated Core operational knowledge is partially documented with structured onboarding for technical staff (Week 1–8 program detailed in Employee handbook) and documented SOPs for customer onboarding, but the CIM explicitly identifies "Documentation maturity is improving but inconsistent across onboarding and engineering workflows." Critical technical expertise remains concentrated in individuals: Cisco networking architecture depends on only 2 of 3 senior engineers with CCNA certification and no CCNP on staff, and the key account representing 16% of revenue is held exclusively by the owner with only operational contact introduction to backup staff, creating single points of failure despite successful [DATE_TIME] owner absence. | 5/10 | NEEDS WORK | |
| owr_03 | Management Team Depth PIS_HC_Profile.txt · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md — High confidence — multiple documents corroborated The business demonstrated independent operation during a 60+ day period in Q1 2026 when the owner was in surgery recovery, with [PERSON] and [PERSON] managing client communications without SLA breaches or escalations, and [PERSON] handling all technical escalations. Functional managers are in place across NOC Operations, Field Dispatch, Key Account Management, Billing/Finance, and Sales Pipeline with documented backup coverage and cross-training. However, two material weaknesses limit the score: the owner maintains the exclusive executive relationship with Northside Medical Group (16% of revenue) with no documented handoff plan, and no formal succession plan exists despite verbal commitment to a transition period post-close. | 7/10 | ADEQUATE | |
| owr_04 | Key Person Concentration Beyond Owner PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt · PIS_CIM.docx · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated The company has identified two material single points of failure beyond the owner: Cisco networking architecture relies on only 2 of 3 senior engineers with CCNA certification and no CCNP on staff, forcing escalation to vendor support for complex issues; additionally, the key account Northside Medical Group (16% of revenue) has the owner as the sole executive relationship holder, with [PERSON] introduced only to operational contacts. While the business successfully operated for [DATE_TIME] without the owner and the NOC lead has cross-trained others, the concentrated technical knowledge in Cisco systems and exclusive client relationship with a material revenue account represent limited backup coverage for critical functions. | 5/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated The top three customers represent 29.7% of total revenue, with the largest customer (Northside Medical Group) at 11.4% of revenue, placing the company in the moderate concentration range. The top five customers combined represent approximately 38.8% of revenue (Northside Medical Group 11.4%, Atlanta Property Holdings 9.4%, PeachState Clinics 8.9%, Cobb Retail Centers 7.6%, and Metro Office Parks 6.5%), demonstrating moderate diversification with manageable concentration risk across healthcare and commercial real estate segments. | 7/10 | ADEQUATE | |
| cq_02 | Revenue Predictability & Recurring Mix README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated Recurring revenue represents approximately 42% of 2024 total revenue ($5.42M), primarily through MSP retainers, network management, and support agreements with an estimated MRR of ~$190K, placing the company in the moderate predictability range. While the CIM identifies growth opportunities to "convert mixed and project-only accounts to recurring managed support contracts," the documents provide no evidence of documented renewal rates, formal renewal tracking mechanisms, or contract term lengths, limiting visibility into 12-month revenue predictability despite the established recurring base. | 6/10 | ADEQUATE | |
| cq_03 | Contract Transferability PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt · PIS_CIM.docx — High confidence — multiple documents corroborated The retrieved documents do not contain any substantive information about customer contract assignment clauses, change-of-control provisions, or transferability language. While the document index references "PIS_Customer_Contract_*.docx/pdf" files, the actual contract excerpts were not provided for review. The Cybersecurity Assessment and operational documents note "healthcare-adjacent customers" and identify a key account (Northside Medical Group, 16% of revenue) where "owner holds executive relationship," suggesting potential consent or relationship transfer risks, but no formal contract analysis is available to assess assignment clause coverage or consent requirements across the customer base. | 3/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated The documents provide no evidence of tracked customer churn rate, net revenue retention metrics, or formal retention programs. While the CIM notes that "recurring revenue represented approximately 42% of [DATE_TIME] revenue" and identifies a growth opportunity to "standardize [DATE_TIME] business reviews and lifecycle planning to improve retention," there is no documented measurement of customer attrition, root-cause analysis, or recovery playbooks. The company's approach to retention appears reactive and informal, lacking the systematic tracking and proactive churn prevention programs expected at this stage of maturity. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of audited, reviewed, or compiled financial statements prepared by a CPA firm, nor do they demonstrate an established CPA relationship. The only financial references are to internally-prepared workbooks (PIS_Financials_And_Operations.xlsx) and a QuickBooks export (PIS_GL_Export_2024Q4.csv), which appear to be operational reports rather than professionally-prepared financial statements, and the CIM notes that "documentation maturity is improving but inconsistent," suggesting financial records are not currently diligence-ready without significant rework. | 3/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The documents identify specific add-backs (owner vehicle at $740/mo, cell and personal expenses at ~$3,800/yr, and a discretionary bonus pool of $18,000 in [DATE_TIME]) but lack formal supporting documentation or a structured add-back schedule. The CIM states that the bonus pool "documentation limited but amounts have been consistent [DATE_TIME]; should be formalized," and there is no evidence of CPA review or independently verified normalized EBITDA calculations, indicating that a buyer's accountant would require substantial additional support and rework to validate the reported $1.00M EBITDA figure. | 4/10 | NEEDS WORK | |
| fr_03 | Revenue Recognition & Consistency PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents lack specific evidence of revenue recognition policies, GAAP compliance documentation, or deferred revenue tracking procedures. While the README notes that "2024 total revenue reconciles to $5.42M across P&L, customer revenue, and service-line views" and the CIM states that "recurring revenue represented approximately 42% of [DATE_TIME] revenue," there is no documentation of the underlying revenue recognition methodology, timing of recognition, or audit confirmation of GAAP adherence. The absence of explicit revenue recognition policy documentation and audit evidence indicates inconsistent formalization, placing the company in the "mostly consistent with some irregular practices" range. | 5/10 | NEEDS WORK | |
| fr_04 | Three-Year Financial Trend README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The CIM reports 2024 revenue of $5.42M with $1.00M EBITDA (18.5% margin) and describes a "growing recurring managed services base" with ~$190K MRR, but the retrieved documents provide no multi-year P&L data, CAGR calculations, or year-over-year comparability to assess the three-year trend. While the README references a master financials workbook ("PIS_Financials_And_Operations.xlsx"), the actual historical revenue and EBITDA figures for prior years are not included in the excerpts provided, preventing evaluation of growth consistency or margin stability over the required period. | 5/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability README.md · PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The company has documented several core operational processes, including a structured 8-week technical onboarding program (Week 1–2 systems access, Week 3–4 shadowing, Week 5–8 independent work) and administrative onboarding, with new-hire retention at 81%, indicating some repeatability. However, the CIM explicitly states "Documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the cybersecurity assessment notes reliance on "informal incident response practices," revealing significant gaps in formal process standardization. Key single points of failure remain—notably the owner holding the executive relationship with a 16% revenue customer and complex Cisco networking issues escalating to vendor TAC due to lack of senior certification—indicating moderate dependency on specific individuals despite documented onboarding. | 5/10 | NEEDS WORK | |
| ops_02 | Technology & Systems Scalability README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated Peachtree's technology stack shows moderate scalability constraints with inconsistent documentation and incomplete modernization. The cybersecurity assessment identifies "incomplete" controls, "limited centralized log monitoring," and "reliance on informal incident response practices," while the CIM notes "documentation maturity is improving but inconsistent across onboarding and engineering workflows." The company relies on a mix of cloud and on-premises tools (Microsoft Defender, CrowdStrike rollout in progress, Datto backups, ConnectWise) but lacks a unified monitoring stack, and critical Cisco networking architecture depends on only 2 of 3 senior engineers having CCNA certification with no CCNP-level expertise on staff—indicating that 3x growth would require meaningful systems modernization and skills investment. | 5/10 | NEEDS WORK | |
| ops_03 | Vendor & Supplier Concentration PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated Peachtree demonstrates moderate vendor concentration risk across its technology stack, with multiple dependencies on Microsoft (365, Defender, Sentinel), ConnectWise, HubSpot, and QuickBooks Online, though the cybersecurity assessment recommends consolidating endpoint security and establishing a single SIEM solution rather than identifying existing alternatives. Critical single-point-of-failure risk exists in Cisco networking architecture where only 2 of 3 senior engineers hold CCNA certification and no CCNP expertise is on staff, forcing complex network issues to escalate to vendor TAC with no documented backup or formal SLA, and a key customer relationship (Northside Medical Group, 16% of revenue) is owner-dependent with limited documented alternatives. | 5/10 | NEEDS WORK | |
| ops_04 | Financial Controls & Reporting Cadence PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The company has a Controller on staff and uses QuickBooks Online for accounting, with general ledger exports and AR aging reports available, indicating basic financial infrastructure in place. However, the retrieved documents provide no evidence of monthly close timelines, formal budget vs. actual reviews, documented control procedures, or audit trail specifics—only that financial data exists in spreadsheet and export formats. Without documentation of close cadence, control formalization, or management review frequency, the company appears to operate at the lower end of the "basic controls" tier, requiring clarification on close speed and oversight practices during diligence. | 5/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_Financials_And_Operations.xlsx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated Core business systems including Microsoft 365, HubSpot, QuickBooks Online, and ConnectWise are in use and partially documented, but the Cybersecurity Assessment Report identifies incomplete MFA enforcement and privileged accounts that are "not fully separated from day-to-day identities," indicating personal account dependencies. The CIM notes that "documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the assessment recommends completing MFA rollout and documenting incident response procedures, suggesting current system ownership and access controls lack formalization and pose transfer risk to a buyer. | 5/10 | NEEDS WORK | |
| tm_02 | Cybersecurity & Data Protection Posture PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_Financials_And_Operations.xlsx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated Peachtree demonstrates partial endpoint protection with Defender for Business deployed to most endpoints and CrowdStrike rollout in progress for engineering/executive users only, but critical gaps remain across the security stack. The assessment explicitly identifies "inconsistent MFA enforcement, limited centralized log monitoring, and reliance on informal incident response practices" with no documented incident response plan, no cyber insurance mentioned, and vendor security reviews absent from the provided documentation. While backups occur nightly with restore tests, the overall risk rating is Medium, and buyers are expected to discount value until identity hardening, monitoring, and documentation are improved. | 5/10 | NEEDS WORK | |
| tm_03 | Data Integrity & Business Intelligence PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated Peachtree has foundational data systems in place (QuickBooks Online, ConnectWise, CRM pipeline, AR aging reports, and a master financial workbook documented in the README), and 2024 revenue reconciles across multiple views at $5.42M, indicating basic data consistency. However, the documents reveal significant gaps: the cybersecurity assessment identifies "limited centralized log monitoring" and "informal incident response practices," the CIM notes "documentation maturity is improving but inconsistent across onboarding and engineering workflows," and there is no mention of a mature business intelligence layer or BI tool beyond operational system exports. Data accessibility appears dependent on key individuals (Operations Manager for scheduling/vendor relationships, Controller for finance) without evidence of self-service BI or audit trail automation. | 5/10 | NEEDS WORK | |
| tm_04 | Technology Vendor & Subscription Management PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The documents provide no evidence of formalized vendor contract documentation, license tracking, or renewal date management. The Cybersecurity Assessment Report mentions reliance on tools including Microsoft 365, HubSpot, QuickBooks Online, ConnectWise, Datto, and SentinelOne, but contains no inventory of vendor agreements, ownership verification, or transferability status. The CIM notes that "documentation maturity is improving but inconsistent across onboarding and engineering workflows," indicating vendor and subscription management lacks formal documentation and poses significant transfer risk for a buyer. | 3/10 | CRITICAL RISK | |
| tm_05 | Technical Debt & Modernization Risk PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The company operates a mixed technology stack with some aging components and deferred modernization work. The Cybersecurity Assessment Report identifies incomplete MFA rollout, duplicate endpoint security tooling (Defender for Business and in-progress CrowdStrike), lack of centralized log monitoring, and reliance on informal incident response practices—all flagged as gaps requiring remediation. While core business systems (ConnectWise, Datto, SentinelOne, Microsoft 365, HubSpot, QuickBooks Online) are in use, the assessment rates overall security risk as "Medium" and explicitly notes that "buyers will likely discount value or require a remediation plan" until identity hardening, monitoring, and documentation improvements are completed. | 5/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits PIS_HC_Profile.txt · PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md — High confidence — multiple documents corroborated The retrieved documents contain no information regarding business licenses, permits, their current status, documentation, or transferability in a change-of-control event. While the CIM mentions the company provides "structured cabling, access control, CCTV, and managed IT services," which typically require licenses in regulated sectors like healthcare, there is no evidence in the provided excerpts that licenses have been inventoried, are current, or that transferability has been assessed with counsel. | 1/10 | CRITICAL RISK | |
| lc_02 | Contract Change-of-Control Provisions PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of a systematic review of key vendor, customer, or lease agreements for change-of-control provisions or assignment clauses. While the CIM identifies customer concentration risk (top three customers = 29.7% of revenue) and notes owner dependence in "late-stage sales, key client relationships, and vendor negotiations," there is no documentation of legal review of these critical contracts or their transferability. The one identified key customer relationship risk—Northside Medical Group (16% of revenue)—explicitly states that "owner holds executive relationship" with no formal succession plan in place, presenting material deal risk upon change of control. | 2/10 | CRITICAL RISK | |
| lc_03 | Employment Law Compliance PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The documents reveal inconsistent employment compliance documentation and compensation structure gaps that create moderate exit risk. While the company maintains a structured onboarding program (documented in Employee Handbook) and portable benefits (Cigna health/dental, Fidelity Simple IRA, Travelers workers comp), critical compliance issues include: (1) a compensation review cycle addressing senior engineer market-rate gaps with no documented adjustment timeline, (2) an undocumented discretionary bonus pool ($18,000 in [DATE_TIME]) that is "currently owner-discretionary" with "limited documentation," and (3) owner compensation arrangements requiring formalization at close with no written employment agreement yet in place. The retrieved excerpts contain no evidence of I-9 verification status, non-compete documentation, EEOC/DOL clearance, or formal job classification review, leaving material gaps relative to buyer expectations. | 5/10 | NEEDS WORK | |
| lc_04 | Intellectual Property Ownership PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The documents contain no evidence of formal IP ownership documentation, assignment agreements, or an IP schedule in the data room. While the CIM mentions the company provides software and managed services, there is no discussion of trademark registration, software licensing agreements, or formal assignment of intellectual property from founders or contractors to the entity. The cybersecurity assessment and HR profile reference tools and processes (ConnectWise, Datto, SentinelOne, internal SOPs) but do not establish clear ownership or documentation of proprietary systems, methodologies, or customer data handling protocols that would survive buyer diligence. | 3/10 | CRITICAL RISK | |
| lc_05 | Litigation & Contingent Liability PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The documents contain no disclosure of open litigation, material claims, or undisclosed contingent liabilities against Peachtree Integrated Systems. The cybersecurity assessment identifies control gaps and operational risks (incomplete MFA enforcement, limited monitoring, informal incident response practices) rated as "Medium" overall risk, but these are operational/compliance deficiencies rather than litigation or contingent liabilities. The identified contingent liabilities—PTO accrual of $28,000 and a discretionary bonus pool of $18,000—are disclosed on the balance sheet and in the human capital profile, falling within standard commercial risk for a mid-market services firm. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Employee Documentation & Compensation PIS_CIM.docx · README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The company maintains a structured employee roster with documented onboarding programs (5-8 week technical track with defined milestones) and clear reporting lines across 22 FTE staff, but compensation documentation is incomplete and inconsistent. A senior engineer compensation gap was identified in a recent review with two senior engineers expressing interest in market-rate adjustments planned for an upcoming cycle, and the CIM notes "documentation maturity is improving but inconsistent across onboarding and engineering workflows," indicating partial rather than comprehensive formalization of roles and compensation structures. | 6/10 | ADEQUATE | |
| hc_02 | Retention Agreements & Non-Competes PIS_CIM.docx · README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The documents reveal minimal retention agreements and no evidence of non-compete or retention bonus structures for key employees. While the Human Capital Profile notes "Owner has verbally committed to a [DATE_TIME] transition period post-close; no written agreement yet," this is insufficient protection, and there is explicit acknowledgment of flight risk for senior technical staff, including a notation that "two senior engineers have expressed interest in market rate adjustment" and a critical client relationship (Northside Medical Group, 16% of revenue) where "owner holds executive relationship" with no formal succession plan documented. | 3/10 | CRITICAL RISK | |
| hc_03 | Bench Depth & Succession PIS_HC_Profile.txt · PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md — High confidence — multiple documents corroborated The company demonstrates moderate bench depth with documented backups for most operational roles—NOC operations has three cross-trained staff, billing/finance and sales pipeline each have identified backups, and the business operated successfully for a full quarter (Q1 2026) without the owner with no SLA breaches or client escalations. However, two critical single points of failure remain: Cisco networking architecture expertise is concentrated among only 2 of 3 senior engineers (neither holding CCNP), and the key account representing 16% of revenue (Northside Medical Group) has the owner as the sole executive relationship holder, with [PERSON] introduced only to operational contacts. No formal succession plan exists despite the owner's verbal commitment to a post-close transition period. | 6/10 | ADEQUATE |
MSP revenue infrastructure is evaluated on lead-to-contract automation, after-hours responsiveness, and client retention sequences — critical signals for buyers assessing whether ARR growth is system-driven or founder-dependent.
Automation maturity is scored separately from the valuation composite. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not valuation discounts.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md No evidence of AI voice agent or automated after-hours call handling exists in the retrieved documents; the company's technology stack (ConnectWise, Datto, SentinelOne, Microsoft 365) and operational descriptions focus on manual ticketing and human-staffed support with no mention of 24/7 voice automation or lead qualification capabilities. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md Peachtree has a CRM system in place (HubSpot is referenced in security recommendations and a CRM pipeline export exists), but automation maturity is partial and inconsistent. The company relies on manual processes for key workflows—sales pipeline is owner-dependent with Mark Ellis as primary manager, and there is no evidence of automated follow-up sequences, triggered notifications, or systematized pipeline management beyond the export artifact. | 1/2 | PARTIAL | |
| R03 | 24/7 Lead Capture PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md The retrieved documents contain no evidence of a contact form, chatbot, or any after-hours lead capture mechanism; the company's sales process relies on owner-dependent late-stage involvement and traditional outbound prospecting through LinkedIn and referral networks with no mention of automated 24/7 lead routing or capture infrastructure. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md No evidence of automated SMS appointment reminders or confirmation workflows exists in the retrieved documents; the company relies on manual scheduling through ConnectWise and field staff coordination without any documented SMS automation capability. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md The retrieved documents contain no evidence of automated post-service review solicitation; there is no mention of review request workflows, triggers, or systematic review collection in any operational, CRM, or process documentation. Review generation appears to be either organic or entirely absent from the company's documented revenue operations practices. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md No evidence of automated follow-up sequences exists in the retrieved documents; the company relies on manual processes for lead and client engagement, with no mention of drip campaigns, automated email sequences, or dormant client re-engagement workflows in the CRM pipeline, onboarding procedures, or operations documentation. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
A low Automation Maturity score for an MSP signals that growth is relationship-driven rather than systematic. Buyers will apply a meaningful discount and may require remediation commitments as a condition of close.
Vertical-specific operational automation gaps identified in MSP & Technology Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not valuation buyer discount risk reduction. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Ticket Triage & Auto-Assignment | 0/2 | MANUAL | Ticket automation reduces mean time to first response — the metric buyers use most heavily to benchmark MSP operational maturity and client satisfaction. | |
| Patch Management & Compliance Reporting | 0/2 | MANUAL | Automated patch compliance reporting is a premium tier differentiator — it demonstrates systematic security management and supports cyber insurance requirements. | |
| Client Onboarding & Offboarding | 1/2 | PARTIAL | Onboarding automation is the most visible quality signal to new clients — and the fastest way to surface the gap between an MSP that runs on people and one that runs on systems. | |
| Client Health Scoring & Churn Risk Alerts | 0/2 | MANUAL | Client health automation converts churn prevention from a reactive fire drill to a proactive managed process — directly protecting the MRR base that drives MSP valuation. | |
| QBR Scheduling & Preparation | 0/2 | MANUAL | QBR automation enables consistent executive engagement across the entire client base — not just the accounts that squeaky-wheel their way to attention. |
Top 3 Strengths
- Demonstrated Operational Resilience and Recurring Revenue Base: Peachtree successfully operated without the owner during Q1 2026 with no SLA breaches, and has built a 42% recurring revenue base (~$190K MRR) across MSP retainers and support agreements, providing a stable foundation for post-close transition and buyer confidence in cash flow predictability.
- Core Financial Consistency and Internal Alignment: The company's $5.42M revenue and $1.00M EBITDA (18.5% margin) are internally consistent across multiple systems (P&L, customer revenue, and service-line views), with financial data reconciling across spreadsheets and demonstrating the baseline operational discipline required for exit readiness.
- Foundational Technical Controls and Backup Infrastructure: Nightly backups with cloud retention and local replication are in place, and endpoint protection is partially deployed (Defender for Business on most endpoints with CrowdStrike in progress), establishing a baseline infrastructure that buyers in the managed services space will recognize as industry-standard, even if incomplete.
Top 3 Risks
- Critical Cybersecurity Gaps Below Buyer Expectations: The 5/10 cybersecurity posture includes material gaps that healthcare-adjacent buyers will not overlook—inconsistent MFA enforcement across Microsoft 365, HubSpot, QuickBooks Online, ConnectWise, and remote admin tools, no formal SIEM deployment, and informal incident response practices lacking documented plans or testing—with the assessment report itself assigning "Medium" risk and noting that buyers will likely discount value pending remediation.
- Owner Dependency in Revenue-Critical Relationships: Northside Medical Group (11.4% of revenue, 16% when excluding other segments) relies exclusively on the owner for executive relationship management, and the CIM explicitly identifies "moderate owner dependence in late-stage sales, key client relationships, and vendor negotiations"; without documented transition plans or introduced executive contacts, this concentration creates both transition risk and potential revenue loss post-close.
- Incomplete and Inconsistent Documentation Across Core Operations: The Cybersecurity Assessment Report and CIM both flag "documentation maturity is improving but inconsistent across onboarding and engineering workflows," with incident response practices informal rather than formally documented, backup restore tests "not always documented," and no evidence of a tested disaster recovery plan or formalized asset lifecycle management—creating material risk for buyer diligence and post-close integration.
Recommended Priority Fixes
Actions the company should take in the next 90 days to maximise exit readiness:
Compliance Notes
No PII was detected in the ingested documents.