Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
| Domain | Layer8 Service | Deal Impact | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|---|
DRDiligence Risk✓ Quick Win | Security Hardening & Data Room Preparation | +29% | $246,240 | ⏱ 6–8 wks | $4,500 – $7,500 | 20x+ |
OROwner Risk✓ Quick Win | Succession Planning & Knowledge Capture Sprint | +27% | $229,824 | ⏱ 8–10 wks | $6,000 – $10,000 | 20x+ |
CQCustomer Quality✓ Quick Win | Contract Audit & CRM Implementation | +27% | $229,824 | ⏱ 8–10 wks | $5,000 – $9,000 | 20x+ |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | +27% | $229,824 | ⏱ 8–12 wks | $5,000 – $9,000 | |
OSOperational Scalability✓ Quick Win | Process Documentation & Systems Audit | +25% | $213,408 | ⏱ 10+ wks | $6,500 – $11,000 | 20x+ |
FRFinancial Readiness✓ Quick Win | Books Cleanup & Add-Back Schedule | +23% | $196,992 | ⏱ 4–6 wks | $2,000 – $4,000 | 20x+ |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | +19% | $164,160 | ⏱ 8–10 wks | $6,000 – $10,000 | |
HCHuman Capital & Key Employee Risk | Key Employee Retention & Documentation Sprint | +15% | $131,328 | ⏱ 8–10 wks | $5,000 – $9,000 | |
| TOTAL | — | $1,641,600 | — | $40,000 – $69,500 | 20x+ | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Valuation Impact Analysis
| Scenario | Score-Adjusted Range | Implied Value (EBITDA) |
|---|---|---|
| Current (as-is) | 4.0×–4.2× EBITDA | $3,456,000 – $3,628,800 |
| Post-Remediation (5.2/10 est.) | 4.3×–4.8× EBITDA | $3,715,200 – $4,147,200 |
Implementing the recommended priority fixes over 90 days could add an estimated $86,400–$691,200 to the transaction value — a potential 11% lift on the same underlying business.
↑ What drives higher multiples
- High MRR percentage >70%
- Documented service contracts
- NOC/helpdesk not owner-dependent
- Stack standardization across clients
↓ What buyers will flag
- Break-fix revenue dominant
- No formal service agreements
- Owner is primary engineer
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company has documented core processes (customer onboarding, material procurement, project execution) with assigned owners and target timelines, but significant gaps undermine operational maturity. The SOP explicitly acknowledges multiple "known gaps"—as-built documentation is inconsistent with many projects having no formal drawings, customer-specific alert protocols for monitoring clients are "largely undocumented" and managed from memory by a single person, and customer satisfaction follow-up is "not currently done"—placing this in the 3-4 range, elevated slightly by the existence of written SOPs with assigned owners rather than purely ad hoc operations. | 4/10 | NEEDS WORK | |
| fix_02 | Cybersecurity Posture company_dataset.json · PIS_company_dataset.json · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt — High confidence — multiple documents corroborated Pinnacle IS has a critically deficient cybersecurity posture with no MFA enforcement across any systems, exposed RDP on the public IP address, and an expired Cisco Meraki firewall license. The formal assessment explicitly rates the company's overall risk as "HIGH" and notes the complete absence of multi-factor authentication represents a "known attack vector that has been exploited in the majority of ransomware incidents targeting SMB businesses in 2023–2024," with no formal incident response plan, no endpoint detection and response (EDR), and ad hoc security management by a part-time de facto IT administrator. | 2/10 | CRITICAL RISK | |
| fix_03 | Owner Dependency PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · PIS_HC_Profile.txt · company_dataset.json — High confidence — multiple documents corroborated The owner is a critical single point of failure across sales, operations, financial management, and vendor relationships. Documentation explicitly identifies that "[PERSON] is required for all significant sales and customer decisions," "[PERSON] is the sole technically qualified field supervisor — no backup," the owner's spouse manages all financial operations, vendor accounts are held personally in the owner's name and not transferable, and the low-voltage license is tied to the owner personally. Additionally, the owner must personally orient all new hires, covered field service gaps during recent technician departures, and processes exist "in people's heads, particularly [PERSON]" with no formal SOPs documented—indicating the business cannot operate independently of the owner's direct involvement. | 3/10 | CRITICAL RISK | |
| fix_04 | Revenue Quality & Concentration PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · company_dataset.json · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The company exhibits moderate revenue quality with 40% recurring revenue ($1.92M annualized) from managed services and monitoring contracts across ~40 active accounts, but lacks documentation of renewal rates and customer concentration data that would substantiate predictability claims. While revenues are diversified across healthcare, commercial real estate, and multi-family verticals with preferred vendor status at Northside Hospital Affiliates and Paces Properties, the internal exit readiness assessment explicitly rates revenue quality at 6/10, and critical recurring revenue processes (alert protocols, monitoring enrollments) are undocumented and depend on single individuals, creating sustainability risk for an acquirer. | 5/10 | NEEDS WORK | |
| fix_05 | Customer Contracts PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_HC_Profile.txt — High confidence — multiple documents corroborated Customer contracts lack standardization and transferability safeguards; the onboarding SOP documents project execution and invoicing procedures but contains no mention of change-of-control clauses, assignment language, or contract review processes. Contract renewal tracking is absent—while the company has 40 active accounts generating $1.92M in annualized recurring revenue (40% of total revenue), there is no documented system for monitoring renewal dates, and customer relationships for three healthcare facilities are undocumented regarding required HIPAA Business Associate Agreements. Additionally, critical customer data (monitoring protocols, alert configurations) are managed informally "from memory" by individual staff members rather than stored in a centralized, transferable repository. | 3/10 | CRITICAL RISK | |
| fix_06 | IT Infrastructure & Asset Documentation PIS_SOP_Customer_Onboarding_v1.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_company_dataset.json · company_dataset.json · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company maintains a basic asset inventory (documented in company_dataset.json with 20+ assets including servers, switches, and tools), but infrastructure documentation and maintenance are severely deficient. Critical systems show deferred maintenance—the UPS battery "last tested 2022" with "replacement due," the firewall license "expired in [DATE_TIME]," and the network switch is "end of sale" with "no redundancy"—while the cybersecurity assessment notes "no documentation of any restore test was located" for backups and confirms "no verified backup / no offsite backup" exists, with no DR plan evident. | 3/10 | CRITICAL RISK | |
| fix_07 | CRM & Pipeline Documentation PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · company_dataset.json — High confidence — multiple documents corroborated The company has low CRM maturity with HubSpot used only for active pipeline tracking by one person, while a second team member tracks deals "primarily in email and memory." The sales process relies on manual Excel-based proposals and QuickBooks for invoicing, with critical gaps including incomplete HubSpot logging at project closeout ("Not all projects logged at closeout. Reporting incomplete") and no formal forecast validation or pipeline discipline documented. | 3/10 | CRITICAL RISK | |
| fix_08 | Key Employee Risks PIS_company_dataset.json · company_dataset.json · PIS_HC_Profile.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The company exhibits severe key employee risks with multiple critical single points of failure and virtually no documentation or retention safeguards. The owner is "required for all significant sales and customer decisions," the owner's spouse "manages all financial operations," one individual is the "sole technically qualified field supervisor with no backup," and critical vendor accounts and the low-voltage license are personally tied to the owner—none of which have documented backups, retention agreements, or succession plans. Additionally, the overall documentation level is "LOW — No formal SOPs documented. Processes exist in people's heads," there is no formal onboarding or training program, and compensation is below market (6% below benchmark for senior technician, with 58% first-year attrition), creating high flight risk for remaining key personnel. | 2/10 | CRITICAL RISK | |
| fix_09 | Financial Trajectory & EBITDA Quality PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated The company demonstrates consistent revenue growth over three years ($4.05M to $4.8M) with stable and improving EBITDA margins (17.0% to 18.0%), and normalized 2024 EBITDA of $994,000 after documented add-backs totaling $130,400 (owner compensation, personal vehicle expense, and legal settlement). However, the financials appear to be compiled rather than audited, as evidenced by the internal dataset noting "revenue_quality_score": 6 and the absence of any third-party audit or review notation in the CIM; additionally, the company manages financial operations through the owner's spouse with key vendor accounts tied personally, raising control and sustainability concerns for a transaction. | 6/10 | ADEQUATE | |
| fix_10 | Data Room Readiness PIS_SOP_Customer_Onboarding_v1.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json — High confidence — multiple documents corroborated The company has prepared some key documents for the data room, including a Cybersecurity Assessment Report (marked "Internal Use / M&A Data Room"), a Confidential Information Memorandum, and operational SOPs, but critical gaps remain unaddressed. Multiple documents reference significant known gaps that have not been remediated: as-built documentation is "inconsistent" with "many projects" lacking formal drawings, customer satisfaction processes are "not currently done," alert protocols for monitoring clients are "undocumented," and HubSpot CRM closeout logging is incomplete. The cybersecurity assessment itself indicates "material risks" and "HIGH" overall risk rating that the company acknowledges are "likely to be identified by a sophisticated buyer's technical due diligence team," suggesting the data room contains problem documentation but lacks evidence of remediation or organized supporting materials needed for buyer review. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness PIS_company_dataset.json · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated There is no formal succession plan in place at Pinnacle IS. The company exhibits critical single-point-of-failure dependencies across all key functions: the owner is required for all significant sales and customer decisions, the owner's spouse manages all financial operations, the sole technically qualified field supervisor has no backup, and critical vendor accounts and the low-voltage license are tied personally to the owner. The internal assessment explicitly states "exit readiness is materially impaired" with an owner dependency score of only 3/10, and processes exist "in people's heads" with no formal succession documentation or identified successors prepared for transition. | 2/10 | CRITICAL RISK | |
| owr_02 | Institutional Knowledge Capture PIS_company_dataset.json · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company has virtually no formal institutional knowledge capture, with documentation explicitly rated as "LOW — No formal SOPs documented. Processes exist in people's heads, particularly [PERSON] and [PERSON]." Critical processes including alert response protocols remain undocumented, and as-built documentation is inconsistent with many projects having no formal records. The business is entirely dependent on key individuals with no documented backups: the owner holds all sales relationships and customer decisions, one technician is the sole field supervisor, and the owner's spouse manages all financial operations, creating severe single points of failure that would collapse without these individuals. | 2/10 | CRITICAL RISK | |
| owr_03 | Management Team Depth PIS_company_dataset.json · company_dataset.json · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The business cannot operate independently without the owner for 60+ days. The documents identify multiple critical single points of failure: the owner is "required for all significant sales and customer decisions," the owner's spouse "manages all financial operations," there is "no formal SOPs documented" with "processes exist in people's heads," and key vendor accounts (ADI, Anixter, bonding) are tied personally to the owner. The company's internal exit readiness assessment assigns an owner dependency score of 3 and operational maturity score of 4, explicitly stating the owner is "deeply embedded in sales, customer relationships, and operations." | 2/10 | CRITICAL RISK | |
| owr_04 | Key Person Concentration Beyond Owner PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json — High confidence — multiple documents corroborated The company has multiple employees beyond the owner who represent critical single points of failure with undocumented expertise and exclusive relationships. Specifically, a Senior Technician is described as "the sole technically qualified field supervisor — no backup," a dispatcher (Tanya Morris) whose "departure would create immediate operational disruption" with "no documented backup," and the owner's spouse manages "all financial operations — key person and succession risk." The documents explicitly state "No succession planning has been considered" and processes "exist in people's heads, particularly [PERSON] and [PERSON]," with only 58% new-hire retention indicating ongoing staff instability that would severely disrupt operations if any of these critical employees departed. | 2/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration PIS_Confidential_Information_Memorandum.txt · PIS_Financials_2024.csv · PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The largest customer (Northside Hospital Affiliates) represents 13.0% of total revenue ($624,000), and the top 5 customers combined represent 44.0% of revenue ($2,112,000), placing the company in the moderate concentration range with manageable risk. The company serves approximately 40 active accounts with 29.0% of revenue distributed across various small accounts (<$50K each), demonstrating reasonable diversification across healthcare, commercial real estate, and multi-family segments. | 7/10 | ADEQUATE | |
| cq_02 | Revenue Predictability & Recurring Mix PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated The company has 40% recurring revenue ($1.92M annualized MRR of $160K in FY2024), consisting of managed services retainers, 24/7 remote monitoring, and annual maintenance contracts. However, revenue predictability is moderate at best—while recurring revenue has remained stable at 40% across three fiscal years, the documents contain no documented renewal rates, churn analysis, or formal contract tracking mechanisms, and alert protocols for monitoring clients are "largely undocumented" and managed by a single person, creating concentration risk that undermines forecast reliability beyond 12 months. | 5/10 | NEEDS WORK | |
| cq_03 | Contract Transferability PIS_Confidential_Information_Memorandum.txt · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json — High confidence — multiple documents corroborated The company lacks formal assignment or change-of-control clauses in customer contracts, with no evidence of centralized contract documentation or transfer mechanisms. Critical vendor accounts (ADI Global, Anixter) and the Georgia Low-Voltage Contractor license are held personally by the owner and are explicitly "not transferable without vendor consent," while the company's top two revenue relationships ($624K and $480K) are described as personal relationships with the owner that pose material succession risk. The documents indicate "no formal preferred vendor agreements" with major GCs and note that relationships are personality-dependent, making transfer contingent on individual customer consent rather than contractual assignment rights. | 3/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · PIS_CRM_Pipeline_Q1_2025.csv — High confidence — multiple documents corroborated The company does not track or report churn rate, retention metrics, or net revenue retention in any of the provided documents. While the company maintains 40 active accounts and generates 40% recurring revenue ($1.92M annualized) from managed services and monitoring contracts, there is no documented churn analysis, root-cause tracking, or formal retention programs—only reactive customer management embedded within project closeout procedures. The company's known operational gaps (undocumented monitoring protocols, inconsistent project documentation, absence of post-project customer satisfaction surveys) indicate a reactive rather than proactive approach to customer retention. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated The documents provide no evidence of audited, reviewed, or compiled financial statements prepared by a CPA firm, nor is there any mention of a CPA relationship. While financial summary data is presented (showing $4.8M revenue and 18% EBITDA margin for FY 2024 with $130,400 in add-backs), the company's own exit readiness assessment explicitly states that "[PERSON] (owner spouse) manages all financial operations — key person and succession risk," indicating internally-prepared financials without professional accounting oversight. The absence of any CPA engagement letter, audit opinion, or reviewed statement documentation, combined with the company's self-identified operational maturity score of 4/10 and overall exit readiness score of 4/10, indicates the books are not diligence-ready and would require significant accounting rework prior to a transaction. | 3/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The company has not documented owner add-backs or EBITDA adjustments; the retrieved documents contain no formal add-back schedules, normalized EBITDA calculations, or CPA verification of adjustments. Financial operations are managed manually by the owner's spouse with significant process gaps ("billing is being handled manually by [PERSON] and [PERSON]"), and a billing specialist position remains vacant, making independent verification of normalized EBITDA extremely difficult for a buyer's accountant. The overall exit readiness assessment rates the company's operational maturity at 4/10 with "process documentation nearly absent," indicating that add-back documentation and financial normalization are not prepared for M&A scrutiny. | 2/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · PIS_Cybersecurity_Assessment_Report_2025.txt · company_dataset.json — High confidence — multiple documents corroborated Revenue recognition appears mostly consistent with 40% recurring revenue maintained uniformly across three fiscal years ($1.62M to $1.92M) and clearly delineated in financial summaries, suggesting standardized application of policies for service offerings like managed network services and 24/7 monitoring contracts. However, the company's internal documentation lacks evidence of formalized revenue recognition policies, GAAP audit trails, or deferred revenue tracking mechanisms—the financial summary provides no discussion of revenue recognition methodology, timing of recognition across service types (project-based vs. recurring), or audit verification, creating risk during buyer due diligence. | 5/10 | NEEDS WORK | |
| fr_04 | Three-Year Financial Trend PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated The company demonstrates solid three-year revenue growth with a CAGR of approximately 8.9% ($4.05M to $4.8M) and consistent EBITDA margin expansion from 17.0% to 18.0%, with normalized 2024 EBITDA of $994,000 after documented add-backs totaling $130,400. However, growth deceleration is evident—revenue growth declined from 9.6% (FY2 to FY3) to 8.1% (FY3 to 2024)—and the add-backs include material one-time items ($32,000 legal settlement) that must be excluded to assess underlying operational performance, preventing a higher score. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability PIS_company_dataset.json · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company has minimal formal process documentation with an explicit assessment stating "LOW — No formal SOPs documented. Processes exist in people's heads, particularly [PERSON] and [PERSON]." While a Customer Onboarding SOP exists, critical operational workflows remain undocumented, including alert response protocols, monitoring configuration procedures, and vendor account management—all of which are heavily dependent on specific individuals. The documented gaps (as-builts inconsistent, alert protocols "undocumented — [PERSON] manages from memory," and vendor accounts "held in [PERSON]'s name") demonstrate that the business cannot execute core workflows repeatably without key personnel, representing a severe exit readiness impediment. | 3/10 | CRITICAL RISK | |
| ops_02 | Technology & Systems Scalability company_dataset.json · PIS_company_dataset.json · PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt — High confidence — multiple documents corroborated The company's technology stack and core systems present critical scalability liabilities. Key infrastructure lacks redundancy (Cisco switch "end of sale. No redundancy," UPS battery "last tested 2022. Replacement due"), critical alert response protocols are undocumented, and the company has "minimal formal cybersecurity program" with "security controls ad hoc and rely largely on default configurations." Scaling to 3x growth would require material system replacement and architectural overhaul, as documented processes exist primarily "in people's heads" with no formal SOPs, and the internal assessment assigns a technology maturity score of only 3/10 with commentary noting "process documentation is nearly absent." | 2/10 | CRITICAL RISK | |
| ops_03 | Vendor & Supplier Concentration PIS_company_dataset.json · company_dataset.json · PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The company has critical single-source vendor dependencies that create existential risk to operations and exit readiness. Key vendor accounts for procurement (ADI Global and Anixter) are held personally in one individual's name and personal credit, explicitly documented as "not transferable without vendor consent," and the company's low-voltage license is also personally tied to this individual. Additionally, the company relies on a single cloud phone system provider (RingCentral) with no documented alternative, and critical infrastructure components like the Cisco network switch are end-of-sale with no redundancy noted. | 3/10 | CRITICAL RISK | |
| ops_04 | Financial Controls & Reporting Cadence PIS_company_dataset.json · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The retrieved documents contain no information about financial controls, monthly close timelines, budget vs. actual reviews, or documentation of accounting procedures. The only financial system mentioned is QuickBooks Online, which is referenced in operational workflows (PO creation, invoice generation) but with no detail on close cadence, oversight structure, or control documentation. Without evidence of CFO/Controller oversight, formal close processes, or regular financial reporting cadence, the company appears to lack basic financial control infrastructure required for M&A exit readiness. | 2/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership PIS_company_dataset.json · company_dataset.json · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_SOP_Customer_Onboarding_v1.txt — High confidence — multiple documents corroborated Core business systems (Milestone VMS, Lenel S2 access control, QuickBooks) are in use but lack formal documentation of ownership and access controls, with critical dependencies on individual staff members managing systems ad hoc. The cybersecurity assessment identifies that [PERSON] serves as "de facto IT administrator in addition to his field technician responsibilities" with no dedicated IT management function, and customer monitoring alert protocols are "largely undocumented — [PERSON] manages from memory," creating significant personal account and knowledge dependencies that would impede transferability to an acquirer. | 3/10 | CRITICAL RISK | |
| tm_02 | Cybersecurity & Data Protection Posture PIS_Cybersecurity_Assessment_Report_2025.txt · company_dataset.json · PIS_company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company exhibits critical cybersecurity deficiencies across all assessed domains. The internal assessment report explicitly states "complete absence of multi-factor authentication (MFA) across all critical business systems" and identifies an "exposed Remote Desktop Protocol (RDP) port on the Company's public IP address" as known attack vectors, while company documentation confirms "Pinnacle IS has minimal formal cybersecurity program" with "security controls are ad hoc" and notes "the company has not undergone a formal security assessment." There is no evidence of endpoint detection and response (EDR), data classification, incident response planning, cyber insurance, or vendor security reviews in any retrieved documents. | 2/10 | CRITICAL RISK | |
| tm_03 | Data Integrity & Business Intelligence PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated The company lacks reliable, accessible operational data with significant dependencies on individuals. The cybersecurity assessment reveals that "Internal staff manage the technology environment on an ad hoc basis" with one person ([PERSON]) serving as "de facto IT administrator," while the onboarding SOP documents that "alert protocols for monitoring clients" are "largely undocumented — [PERSON] manages from memory" and HubSpot CRM reporting is "incomplete" with "not all projects logged at closeout." Critical business data is scattered across multiple systems (QuickBooks, ServiceTitan, SharePoint, HubSpot) with no integrated BI platform, and key operational knowledge—particularly customer monitoring protocols and project documentation—exists primarily in individual heads rather than accessible, auditable systems. | 3/10 | CRITICAL RISK | |
| tm_04 | Technology Vendor & Subscription Management PIS_SOP_Customer_Onboarding_v1.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json — High confidence — multiple documents corroborated Core vendor relationships for critical systems (ADI Global, Anixter/Wesco, QuickBooks Online, ServiceTitan, RingCentral) are operationally known but lack formal documented contracts or renewal tracking; the Cisco Meraki firewall license has already expired as of the assessment date, indicating no systematic renewal management. Additionally, the Georgia Low-Voltage Contractor license is held personally by the owner rather than by the entity, creating a significant transfer barrier, and the company lacks documented Business Associate Agreements with three HIPAA-regulated healthcare clients, creating compliance and transferability risk. | 3/10 | CRITICAL RISK | |
| tm_05 | Technical Debt & Modernization Risk company_dataset.json · PIS_company_dataset.json · PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The company operates aging on-premises infrastructure with critical security gaps and no formal IT management function. Specifically, the environment includes two aging Dell PowerEdge servers running Milestone VMS and Lenel S2 systems, an expired Cisco Meraki firewall license, exposed RDP ports, complete absence of multi-factor authentication across critical systems, and a UPS battery last tested in 2022 with replacement due—all managed ad hoc by a network technician with dual field responsibilities. The cybersecurity assessment rates overall risk as HIGH and notes that "without remediation, these findings are likely to reduce buyer confidence, result in price reduction demands, and/or require escrow holdbacks pending remediation," indicating material post-close investment will be required. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · company_dataset.json — High confidence — multiple documents corroborated The company holds two required licenses—Georgia Low-Voltage Contractor (LVA003847) and Alarm Systems Contractor (GA-ASC-28841)—that are current, but transferability is severely compromised. The Low-Voltage Contractor license is held personally by [PERSON], requiring a buyer to either obtain a new license pre-close through a qualifying individual or negotiate a transitional post-close arrangement. Additionally, vendor accounts critical to operations (ADI Global, Anixter, bonding) are tied to [PERSON] personally and are not transferable without vendor consent, creating material change-of-control obstacles that have not been formally addressed with legal counsel or vendors. | 4/10 | NEEDS WORK | |
| lc_02 | Contract Change-of-Control Provisions PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_SOP_Customer_Onboarding_v1.txt — High confidence — multiple documents corroborated The documents reveal no evidence that key vendor, customer, or lease agreements have been reviewed by counsel for assignment clauses or change-of-control provisions. While the company maintains relationships with general contractors (Hardin Construction, [PERSON]) and customers (WinnCompanies, Post Apartment Homes, Northside, Paces Properties), these are described as informal "preferred vendor agreements" and "personal relationships" with no formal master agreements executed. Critical material risks are identified elsewhere—including undocumented HIPAA Business Associate Agreements with three healthcare clients and a Georgia Low-Voltage Contractor license held personally by [PERSON] requiring post-close transitional arrangements—but no contractual review addressing assignability or change-of-control triggers is documented in the materials provided. | 3/10 | CRITICAL RISK | |
| lc_03 | Employment Law Compliance PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_HC_Profile.txt · company_dataset.json · PIS_company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt — High confidence — multiple documents corroborated The documents reveal material employment compliance gaps with no evidence of I-9 verification, non-compete documentation, or formal compensation benchmarking. The Human Capital Profile explicitly states "No formal compensation benchmarking process" and that "[PERSON] sets all compensation at his discretion based on informal market awareness and employee requests," creating compensation structure risk; additionally, the 36% voluntary turnover rate and multiple recent departures suggest potential retention and classification concerns that warrant pre-close employment law review. | 4/10 | NEEDS WORK | |
| lc_04 | Intellectual Property Ownership PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_company_dataset.json · company_dataset.json — High confidence — multiple documents corroborated IP ownership is materially ambiguous and undocumented. Critical business systems and processes are managed by individuals without formal assignment — the low-voltage license is "tied to [PERSON] personally" and "must be replaced pre-close or post-close," vendor accounts (ADI, Anixter) are "held in [PERSON]'s name and personal credit — not transferable without vendor consent," and monitoring alert protocols are "undocumented — [PERSON] manages from memory." No IP schedule, trademark registrations, or formal assignment documentation to the entity is evident in the data room materials. | 3/10 | CRITICAL RISK | |
| lc_05 | Litigation & Contingent Liability PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt — High confidence — multiple documents corroborated The company faces undisclosed HIPAA Business Associate Agreement documentation gaps across three healthcare clients (Northside Hospital Affiliates, Emory Hillandale Medical Center, and Resurgens Orthopaedics), which represents a material compliance and contingent liability risk. Additionally, the cybersecurity assessment identifies three HIGH-risk findings including expired firewall security licenses, lack of network segmentation, and no verified offsite backup—conditions that could expose the company to ransomware liability and cascading data loss affecting customer monitoring infrastructure. While no active litigation is disclosed and a prior legal dispute settlement ($32,000) has been resolved, these unaddressed compliance and operational security gaps constitute material open matters requiring remediation before exit. | 5/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Employee Documentation & Compensation PIS_HC_Profile.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated Employee Documentation & Compensation is minimal and largely informal. The Human Capital Profile lists staff names and tenures but provides no formal role descriptions, responsibilities matrices, or documented compensation structures—the document explicitly states "No formal compensation benchmarking process. [PERSON] sets all compensation at his discretion based on informal market awareness and employee requests." Additionally, critical operational knowledge is undocumented and owner-dependent: the Cybersecurity Assessment notes that [PERSON] serves as "de facto IT administrator" with "no dedicated IT management function," and the Customer Onboarding SOP reveals that "Customer-specific alert protocols configured (largely undocumented — [PERSON] manages)" and monitoring protocols are managed "from memory" rather than in formal documentation. | 3/10 | CRITICAL RISK | |
| hc_02 | Retention Agreements & Non-Competes PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Financials_2024.csv · PIS_HC_Profile.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of non-compete agreements, retention agreements, or retention bonuses for any key employees at Pinnacle Integrated Systems. The company experienced a 36% voluntary turnover rate with 40% technical staff turnover, including two technician departures in the past year that created service delivery gaps requiring the owner to personally cover field service, indicating significant flight risk among key personnel with no contractual retention mechanisms in place. | 2/10 | CRITICAL RISK | |
| hc_03 | Bench Depth & Succession PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_HC_Profile.txt · PIS_company_dataset.json · company_dataset.json — High confidence — multiple documents corroborated The company has critical single points of failure across all major functions with no documented succession planning. The owner holds all sales relationships and key account management with no backup, the dispatcher [PERSON] has no documented replacement, the sole technically qualified field supervisor has no backup, and financial operations are managed by the owner's spouse with no succession plan in place. The internal assessment explicitly states "The business has not operated without [PERSON] for more than 3 business days" and notes that "no succession planning has been considered," creating material operational risk in the event of owner or key employee departure. | 2/10 | CRITICAL RISK |
MSP revenue infrastructure is evaluated on lead-to-contract automation, after-hours responsiveness, and client retention sequences — critical signals for buyers assessing whether ARR growth is system-driven or founder-dependent.
Automation maturity is scored separately from the valuation composite. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not valuation discounts.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · PIS_company_dataset.json · PIS_Confidential_Information_Memorandum.txt · company_dataset.json The company uses RingCentral cloud phone system with 4 lines for office operations, but there is no evidence of AI voice agent capability or automated after-hours call handling; calls are not addressed by any documented after-hours automation mechanism. This represents a gap in revenue operations automation maturity, as inbound calls during non-business hours are unhandled. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · company_dataset.json · PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt The company uses ServiceTitan for work order and job management with some pipeline tracking, but CRM adoption is incomplete—HubSpot CRM exists but projects are not consistently logged at closeout, resulting in incomplete reporting. Critical follow-up workflows such as customer satisfaction surveys are entirely absent, and monitoring protocols for recurring clients are managed manually from memory rather than through automated systems. | 1/2 | PARTIAL | |
| R03 | 24/7 Lead Capture PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · company_dataset.json · PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt The retrieved documents contain no evidence of any lead capture system, chatbot, or after-hours contact mechanism; the company's sales process appears entirely manual and person-dependent, with no reference to website forms or automated lead routing infrastructure. The documents focus on project delivery and operations, not lead generation or capture automation. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json There is no evidence of automated SMS appointment reminders or confirmations in the retrieved documents; the company relies on manual email communication and phone calls for customer contact, as evidenced by the onboarding SOP which references "[PERSON] communicates [DATE_TIME] status to customer" and "Monitoring confirmation email sent to customer by [PERSON]" with no mention of SMS automation workflows. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · company_dataset.json · PIS_HC_Profile.txt · PIS_IT_Asset_Inventory_2025.csv The company has no automated review solicitation process; the SOP explicitly states "Customer satisfaction survey: Not currently conducted" and identifies this as a known gap with a goal to implement by Q2 2025, indicating reviews are currently organic only with no systematic post-service requests. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json The retrieved documents contain no evidence of automated follow-up sequences for unconverted leads or dormant clients; the onboarding SOP mentions a post-project customer satisfaction survey as a planned future initiative ("not currently done") but provides no mechanism for automated re-engagement or lead nurturing. Follow-up activity is entirely manual and person-dependent, with no systematized drip campaigns or CRM-driven automation in place. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
A low Automation Maturity score for an MSP signals that growth is relationship-driven rather than systematic. Buyers will apply a meaningful discount and may require remediation commitments as a condition of close.
Vertical-specific operational automation gaps identified in MSP & Technology Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not valuation buyer discount risk reduction. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Ticket Triage & Auto-Assignment | 0/2 | MANUAL | Ticket automation reduces mean time to first response — the metric buyers use most heavily to benchmark MSP operational maturity and client satisfaction. | |
| Patch Management & Compliance Reporting | 0/2 | MANUAL | Automated patch compliance reporting is a premium tier differentiator — it demonstrates systematic security management and supports cyber insurance requirements. | |
| Client Onboarding & Offboarding | 1/2 | PARTIAL | Onboarding automation is the most visible quality signal to new clients — and the fastest way to surface the gap between an MSP that runs on people and one that runs on systems. | |
| Client Health Scoring & Churn Risk Alerts | 0/2 | MANUAL | Client health automation converts churn prevention from a reactive fire drill to a proactive managed process — directly protecting the MRR base that drives MSP valuation. | |
| QBR Scheduling & Preparation | 0/2 | MANUAL | QBR automation enables consistent executive engagement across the entire client base — not just the accounts that squeaky-wheel their way to attention. |
Top 3 Strengths
- Stable Financial Performance: Pinnacle demonstrates consistent revenue growth from $4.05M to $4.8M over three years with improving EBITDA margins (17.0% to 18.0%), yielding normalized 2024 EBITDA of $994,000—providing a solid financial foundation for valuation despite operational risks.
- Recurring Revenue Base with Vertical Diversification: The company generates $1.92M (40% of revenue) from managed services and monitoring contracts across ~40 active accounts spanning healthcare, commercial real estate, and multi-family verticals, including preferred vendor status at Northside Hospital Affiliates and Paces Properties.
- Core Processes Documented with Assigned Ownership: Customer onboarding, material procurement, and project execution SOPs exist with assigned owners and target timelines, providing a foundation for operational continuity that exceeds purely ad hoc management.
Top 3 Risks
- Critical Owner Dependency Across All Functions (3/10): The owner is the sole point of failure for all significant sales decisions, field operations, vendor relationships, and financial oversight (managed by spouse), with the low-voltage license, vendor accounts, and key customer relationships tied personally and non-transferable—making the business non-viable post-acquisition without the owner's continued involvement.
- Material Cybersecurity Deficiencies with HIGH Risk Rating (2/10): Pinnacle has no MFA enforcement, exposed RDP on public IP, an expired firewall license, no EDR, and no incident response plan, with the formal assessment explicitly rating overall risk as HIGH and identifying the absence of multi-factor authentication as "a known attack vector exploited in the majority of ransomware incidents targeting SMBs in 2023–2024."
- Undocumented Customer Contracts and Renewal Risk (3/10): Customer contracts lack change-of-control clauses, assignment language, and standardization; no documented renewal tracking exists for the 40 active recurring revenue accounts; and critical monitoring protocols, alert configurations, and HIPAA Business Associate Agreements are managed informally "from memory" rather than in a centralized, transferable repository.
Recommended Priority Fixes
Actions the company should take in the next 90 days to maximise exit readiness:
Compliance Notes
No PII was detected in the ingested documents.