In the early days, the founder is also the IT department. The choices you make in the first few months are easy to get right and expensive to undo later, so a little deliberate setup now saves you a painful cleanup at twenty people. You do not need to build something elaborate. You need to get a short list of foundations right, in the right order, and sidestep the traps that cost growing companies the most.
Here is what to set up first, and why each one matters more than it looks.
One rule before you start: build for the company you are becoming
Almost every expensive IT mess in a small business traces back to setting things up for "just me" and never revisiting it: the personal email that became the company login, the laptop nobody else can manage, the subscription tied to one person's credit card. Set things up as if you will be twenty people, even when you are two, and the cost is a few extra minutes now instead of a migration later. Every step below follows from that one idea.
Start with identity: one place everyone signs in
Your first real decision is the platform that holds your email, files, and accounts: Microsoft 365 or Google Workspace. Pick one, on a paid business plan tied to your own domain, not a free personal account, and put everyone on it. That single sign-in becomes the keystone for everything else, security, sharing, adding and removing people, because it is the one identity you control centrally. Which one to choose comes down to how your team works (our Microsoft 365 vs Google Workspace guide compares them), and why the business tier is worth it is covered in consumer vs business plans.
Turn on the security basics on day one
Before you have anything obviously worth stealing, automated attacks are already trying your logins. The basics take an afternoon and protect you from the most common ways small businesses get hit:
- Multi-factor authentication (MFA) on everything, email, banking, and every important account. It is the single highest-value thing you can do.
- A password manager for the whole team, so people use strong, unique passwords without sticky notes or reused logins.
- Device encryption and screen locks on every laptop and phone, so a lost device is not a data breach.
- Automatic updates turned on, so security fixes install themselves instead of waiting on someone to remember.
Our cybersecurity basics guide walks through the full short list, and since most attacks start with a convincing email, it pays to teach the team to spot phishing early.
Set up devices the same way every time
Decide how a new laptop gets set up and stick to it, so your fifth hire is not configured by guesswork. Standardize on one platform where you can, Windows or Mac rather than a mix, since running both quietly doubles the work (we explain why in Windows vs Mac). Use a simple onboarding checklist, and make sure the company, not the employee, owns each device and its accounts. Once you are past a handful of people, basic device management (unified endpoint management) lets you push settings, updates, and a remote wipe from one place.
Back up what you cannot afford to lose
The most common and most dangerous assumption a founder makes is that the cloud is a backup. It is not. If a file is deleted, hit by ransomware, or walks out the door with a departing employee's account, "it was in Microsoft 365" will not bring it back. From the start, make sure your email, files, and any business-critical app are backed up somewhere separate, and that you have actually tested restoring something. The 3-2-1 backup rule is the simple standard to aim for.
Own your accounts and your data
This is the one founders thank themselves for later. Register your domain name and your key accounts under the company, not a personal Gmail or one co-founder's name, and keep the admin and recovery access somewhere the business controls. Store every important login in the shared password manager, not in someone's head. It feels like overkill at two people, but a domain registered to a contractor who disappears, or an app locked to a co-founder who leaves, is exactly the avoidable mess that stalls a growing company.
Keep the stack small and portable
Two early habits cause most later pain: tool sprawl (a new subscription for every problem until nobody knows what you pay for or where data lives) and lock-in (building on something you cannot easily leave). Keep your toolset small, prefer tools that let you export your own data, and review your subscriptions every few months. You can always add a tool; removing one, or escaping it, is the hard part.
Know when to stop doing it yourself
Being your own IT department works right up until it doesn't. The signal to get help is usually one of these: you are spending real time on IT instead of the business, a new hire's setup is a scramble, or a client or insurer starts asking security questions you cannot confidently answer. That is the point to bring in a managed provider, and our guide on how to choose one covers what to look for.