Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
Complete remediation plan across all scored domains. The Priority Fixes section below highlights the five ranked starting points.
| Domain | Layer8 Service | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|
CQCustomer Quality✓ Quick Win | Contract Audit & CRM Implementation | $84,966 | ⏱ 8–10 wks | $5,000 – $9,000 | ~12x |
DRDiligence Risk✓ Quick Win | Security Hardening & Data Room Preparation | $72,828 | ⏱ 6–8 wks | $4,500 – $7,500 | ~12x |
OROwner Risk✓ Quick Win | Succession Planning & Knowledge Capture Sprint | $60,690 | ⏱ 8–10 wks | $6,000 – $10,000 | ~7.5x |
OSOperational Scalability✓ Quick Win | Process Documentation & Systems Audit | $52,598 | ⏱ 10+ wks | $6,500 – $11,000 | ~6x |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | $40,460 | ⏱ 8–12 wks | $5,000 – $9,000 | |
HCHuman Capital✓ Quick Win | Workforce Retention & Bench Depth Sprint | $40,460 | ⏱ 8–10 wks | $2,500 – $5,000 | ~11x |
FRFinancial Readiness✓ Quick Win | Books Cleanup & Add-Back Schedule | $28,322 | ⏱ 6–8 wks | $4,000 – $7,000 | ~5x |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | $24,276 | ⏱ 6–8 wks | $3,500 – $6,500 | |
| TOTAL | $404,600 | — | $37,000 – $65,000 | ~8x | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Layer8 Tech Group delivers each of these services for businesses preparing for acquisition. Engagements are scoped to your timeline and deal target.Schedule a Discovery Call →
MSP revenue infrastructure is evaluated on lead-to-contract automation, after-hours responsiveness, and client retention sequences — critical signals for buyers assessing whether ARR growth is system-driven or founder-dependent.
Automation maturity is scored separately from the overall readiness score. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not buyer discount risk.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv · ATS_CIM.txt · ATS_IT_Asset_Inventory.csv There is no evidence in any retrieved documents of AI voice agents, automated after-hours call handling, or even a basic auto-attendant system; the documents focus on cybersecurity gaps, HR metrics, and financial data with no mention of inbound call management infrastructure. After-hours calls would default to voicemail or unanswered, indicating no automation maturity in this function. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv · ATS_IT_Asset_Inventory.csv The retrieved documents contain no evidence of CRM presence or usage; the company relies on manual contact management with client relationships managed by two individuals ([PERSON] and [PERSON]) and operational data stored in spreadsheets and ServiceMax with shared credentials, indicating no systematic CRM infrastructure or workflow automation exists. | 0/2 | MANUAL | |
| R03 | 24/7 Lead Capture ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt · ATS_GL_Export.csv The retrieved documents contain no evidence of any lead capture system, contact form, chatbot, or after-hours inquiry handling capability; the company's business model relies entirely on direct client relationships managed by two account managers with no documented automated lead capture infrastructure. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv · ATS_CIM.txt The retrieved documents contain no evidence of automated SMS appointment reminders, confirmations, or follow-up workflows; the company appears to be a security systems integrator focused on field service delivery and monitoring rather than appointment-based client interactions that would require such automation. No references to SMS communication platforms, appointment scheduling systems, or client reminder workflows appear in any of the internal documents reviewed. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv · ATS_CIM.txt · ATS_IT_Asset_Inventory.csv There is no evidence of any automated post-service review solicitation system in the retrieved documents. The excerpts focus on cybersecurity gaps, HR retention, financial transactions, and IT assets, with no mention of review request processes, customer feedback collection, or any systematic or manual review solicitation workflows. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt · ATS_GL_Export.csv The retrieved documents contain no evidence of automated follow-up sequences for leads or dormant clients; they focus on cybersecurity posture, workforce retention, and financial metrics with no mention of CRM automation, email drip campaigns, or lead nurturing systems. The company appears to rely on manual relationship management by two individuals ([PERSON] and [PERSON]) who manage all client relationships. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
A low Automation Maturity score for an MSP signals that growth is relationship-driven rather than systematic. Buyers will apply a meaningful discount and may require remediation commitments as a condition of close.
Vertical-specific operational automation gaps identified in MSP & Technology Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not a valuation adjustment. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Ticket Triage & Auto-Assignment | 0/2 | MANUAL | Ticket automation reduces mean time to first response — the metric buyers use most heavily to benchmark MSP operational maturity and client satisfaction. | |
| Patch Management & Compliance Reporting | 0/2 | MANUAL | Automated patch compliance reporting is a premium tier differentiator — it demonstrates systematic security management and supports cyber insurance requirements. | |
| Client Onboarding & Offboarding | 0/2 | MANUAL | Onboarding automation is the most visible quality signal to new clients — and the fastest way to surface the gap between an MSP that runs on people and one that runs on systems. | |
| Client Health Scoring & Churn Risk Alerts | 0/2 | MANUAL | Client health automation converts churn prevention from a reactive fire drill to a proactive managed process — directly protecting the MRR base that drives MSP valuation. | |
| QBR Scheduling & Preparation | 0/2 | MANUAL | QBR automation enables consistent executive engagement across the entire client base — not just the accounts that squeaky-wheel their way to attention. |
Layer8 runs 90-day Automation Sprints that close AMI gaps and systematize vertical-specific workflows. The ROI is measurable before you go to market.Schedule a Discovery Call →
Buyer Discount Risk
EBITDA (most recent FY): $476,000 (AI-extracted) · Exit Readiness: 3.9/10 — Material Gaps
| Score | Band | Buyer Discount Risk |
|---|---|---|
| 8.0 – 10.0 | Institutional Ready | Minimal — few gaps for buyers to exploit |
| 6.5 – 7.9 | Market Ready | Low — some negotiating leverage for buyers |
| 5.0 – 6.4 | Needs Preparation | Moderate — expect re-trade attempts |
| 3.5 – 4.9 | Material Gaps | High — significant discount likely |
| Below 3.5 | Not Ready | Very High — consider delaying go-to-market |
Scores reflect readiness relative to what buyers examine in diligence — not a valuation guarantee. For a specific valuation range, share your Exit Readiness Score with your broker or M&A advisor.
↑ What strengthens your position
- High MRR percentage >70%
- Documented service contracts
- NOC/helpdesk not owner-dependent
- Stack standardization across clients
↓ What buyers will flag
- Break-fix revenue dominant
- No formal service agreements
- Owner is primary engineer
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_CIM.txt — High confidence — multiple documents corroborated The company has minimal formal documentation with critical gaps in process ownership and consistency. While some documentation exists—Georgia POST certification requirements, unarmed officer onboarding orientation, and post orders manuals for all 22 active accounts—the documents reveal heavy reliance on individual knowledge holders, particularly the owner who "approves all supervisor-level and above hires" and holds "all major client relationships," and the Lead Technician who "holds most system design and integration knowledge." The absence of a formal supervisory development program, no documented backup and restore testing procedures, and informal compensation review processes indicate processes exist largely in people's heads rather than as standardized, version-controlled procedures accessible to staff. | 4/10 | NEEDS WORK | |
| fix_02 | Cybersecurity Posture ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Atlas Security Technologies has critical cybersecurity gaps that significantly impact exit readiness. While MFA is enforced for office staff and basic network security exists (Fortinet FortiGate, network segmentation), the company has no EDR solution, MFA is not enforced for 6 field technicians, and most critically, client system credentials are stored in an unvaulted shared spreadsheet with no formal access management—creating severe liability exposure that the external assessment identifies as requiring "immediate remediation regardless of sale timeline." Additionally, field iPads have no MDM enrollment or encryption, remote VPN access lacks MFA, and backup testing is undocumented, placing the company in the 3-4 range with significant known gaps that must be addressed before a credible exit process. | 4/10 | NEEDS WORK | |
| fix_03 | Owner Dependency ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The owner ([PERSON]) manages all client relationships directly, with only partial backup coverage—[PERSON] handles 9 of 22 accounts while the critical WellStar Health System account (18% of revenue) has no documented secondary contact and is at risk if the owner is unavailable. The Operations Manager can manage field issues but does not handle client escalations, and all CRM pipeline opportunities ($768K in deals) are owned by the same individual with no formal succession plan documented. | 3/10 | CRITICAL RISK | |
| fix_04 | Revenue Quality & Concentration ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company exhibits severe revenue concentration risk with WellStar Health System representing 18% of total revenue as a single client held directly by the owner, and no documented renewal rates or contract terms are provided in the available materials. The pipeline shown consists entirely of new business opportunities and upsells with no evidence of recurring revenue contracts, multi-year agreements, or formal renewal tracking, indicating a project-based revenue model with low predictability typical of contract security services. | 3/10 | CRITICAL RISK | |
| fix_05 | Customer Contracts ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_Financials.csv — High confidence — multiple documents corroborated The retrieved documents provide no evidence of standardized customer contracts, centralized contract repository, change-of-control clauses, or formal renewal tracking processes. While the financial data shows 22 active accounts generating recurring revenue of $1.624M in FY2025, the documents indicate that only two individuals ([PERSON] and [PERSON]) manage all client relationships with no documented contract management system, and the CRM pipeline shows only new opportunities in various stages with no visibility into existing contract terms, renewal dates, or transferability language. | 3/10 | CRITICAL RISK | |
| fix_06 | IT Infrastructure & Asset Documentation ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_GL_Export.csv · ATS_IT_Asset_Inventory.csv — High confidence — multiple documents corroborated Atlas Security Technologies maintains a basic asset inventory (ATS_IT_Asset_Inventory.csv lists 20 assets with device types, users, and locations), but critical infrastructure documentation and maintenance gaps undermine readiness for exit. The cybersecurity assessment identifies multiple undocumented and unmanaged systems, including 5 field iPads with "no management, encryption, or remote wipe" and field technician laptops used for client system programming without endpoint detection and response (EDR) solutions. No backup testing is documented, and client credential management—a critical security function—relies on "a shared spreadsheet" rather than a secure vault, creating significant liability exposure that requires immediate remediation regardless of sale timeline. | 4/10 | NEEDS WORK | |
| fix_07 | CRM & Pipeline Documentation ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_CIM.txt — High confidence — multiple documents corroborated Atlas Security Technologies uses a CRM system with documented pipeline data showing 11 active opportunities across defined stages (Discovery, Qualified, Proposal, Negotiation) with assigned owners, probability percentages, and close dates totaling $620K in pipeline value with $298K weighted value. However, the human capital profile indicates that two individuals ([PERSON] and [PERSON]) manage all client relationships, suggesting potential concentration risk and limited pipeline diversification beyond key owners, though the pipeline itself appears reasonably current and systematically tracked. | 7/10 | ADEQUATE | |
| fix_08 | Key Employee Risks ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company has significant single points of failure in critical roles with minimal documentation or retention safeguards. Two individuals manage all 22 client relationships, with the Owner holding the direct relationship for WellStar Health System (18% of revenue) with no formal backup—the documents state "If [PERSON] were unavailable for [DATE_TIME], the WellStar account relationship would be at risk." There are no succession plans, no retention agreements, no formal supervisory development program, and no documented institutional knowledge capture beyond site-specific post orders manuals, creating substantial exit risk tied to key personnel continuity. | 3/10 | CRITICAL RISK | |
| fix_09 | Financial Trajectory & EBITDA Quality ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CIM.txt — High confidence — multiple documents corroborated The documents provided do not contain audited or reviewed financial statements, multi-year revenue/EBITDA trends, or documented add-backs required for exit readiness assessment. While the CIM references "$2.8M in [DATE_TIME] Revenue | 17% EBITDA Margin | ~$476K EBITDA" with "Normalized EBITDA of $524K after add-backs," there is no evidence of third-party financial review, clean accounting documentation, or multi-year growth trajectory. The owner draws $155,000 in S-corp distributions "not on payroll," which raises questions about financial clarity and suggests potential accounting irregularities that would concern acquirers. | 3/10 | CRITICAL RISK | |
| fix_10 | Data Room Readiness ATS_Cybersecurity_Assessment.txt · ATS_GL_Export.csv · ATS_IT_Asset_Inventory.csv · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents reveal a company in early stages of data organization rather than a prepared data room. While basic financial records (GL export), IT assets, and CRM pipeline data exist, critical due diligence documentation appears scattered across disconnected systems with no evidence of organized structure, version control, or centralized accessibility—the cybersecurity assessment and human capital profile are ad-hoc reports rather than systematized data room components. The documents themselves contain significant redactions ([PERSON], [LOCATION], [DATE_TIME]) and incomplete entries (truncated GL rows, missing asset details), suggesting the underlying data sources lack the standardization and completeness required for buyer review. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated No formal succession plan exists; the business lacks documented protocols for key role transitions and is heavily dependent on the owner for critical client relationships. The WellStar Health System account (18% of revenue) is held directly by the owner with only partial backup coverage, and the assessment notes "No succession planning" with the explicit risk that "If [PERSON] were unavailable for [DATE_TIME], the WellStar account relationship would be at risk." Operations Manager [PERSON] has no formal documented backup, and while the company has operated during owner vacation, the owner remains the primary decision-maker with no identified successor actively transitioning into an expanded role. | 2/10 | CRITICAL RISK | |
| owr_02 | Institutional Knowledge Capture ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Critical institutional knowledge remains concentrated in two individuals—[PERSON] and [PERSON] manage all 22 client relationships with no formal backup, and [PERSON] holds the direct relationship with WellStar Health System (18% of revenue) with only partial secondary coverage; the company explicitly lacks succession planning and has no documented standard operating procedures for core processes beyond basic site-specific post orders manuals and onboarding checklists. Field device knowledge (security system programming, network diagrams, configurations) is stored on unmanaged iPads with no credential vault or centralized documentation, meaning technical expertise cannot be readily transferred to new staff without direct mentoring from departing personnel. | 3/10 | CRITICAL RISK | |
| owr_03 | Management Team Depth ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company has a functional management layer with an Operations Manager, Account Supervisor, and Admin/Billing staff, but critical dependencies on the owner remain unresolved. The owner holds the direct relationship with WellStar Health System (18% of revenue) with no formal backup, and the documents explicitly state that "if [PERSON] were unavailable for [DATE_TIME], the WellStar account relationship would be at risk." While the business operated without the owner for up to [DATE_TIME] during vacation with the Operations Manager managing field issues, client escalations were not handled, indicating the team cannot fully operate independently for extended periods. | 5/10 | NEEDS WORK | |
| owr_04 | Key Person Concentration Beyond Owner ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Two employees represent critical single points of failure beyond the owner: [PERSON] holds the direct relationship with WellStar Health System (18% of revenue) with only partial backup coverage, and the Operations Manager has no formal documented backup despite managing all operations. Additionally, the document explicitly states that "[PERSON] and [PERSON] manage all client relationships" with [PERSON] handling 9 of 22 accounts directly, creating concentrated client relationship risk with limited succession planning in place. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_CIM.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated Atlas Security Technologies demonstrates moderate customer concentration risk with a well-diversified client base of 52 active monitoring and managed service clients, and no single customer identified as representing more than 10% of the $2.8M revenue base. The company's average recurring revenue per client of $31,200 across healthcare, retail, multifamily residential, and education verticals indicates a balanced portfolio without existential dependence on any single account, supporting a score in the 7-8 range for acceptable exit readiness. | 8/10 | STRONG | |
| cq_02 | Revenue Predictability & Recurring Mix ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_CIM.txt — High confidence — multiple documents corroborated Atlas demonstrates 58% recurring revenue in FY [DATE_TIME] ($1,624,000 of $2,800,000 total) with a documented upward trend from 50% in FY [DATE_TIME], indicating strong progress toward the 7-8 range threshold of 50-70% recurring revenue. The company maintains annual contracts with major clients across healthcare, education, and commercial segments (per CRM pipeline showing long-term managed services contracts), though the documents do not provide explicit renewal rates or 12-month forward revenue visibility beyond the current pipeline forecast. | 7/10 | ADEQUATE | |
| cq_03 | Contract Transferability ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The documents provide no evidence of formal assignment or change-of-control clauses in customer contracts, and reveal that client relationships are heavily personality-dependent and at significant risk in a transfer scenario. Specifically, two individuals ([PERSON] and [PERSON]) "manage all client relationships," with the owner holding a direct relationship with WellStar Health System (18% of revenue) where "[PERSON] is known to the WellStar security director but is not the primary contact," creating critical transferability risk. The absence of any contract management framework or centralized repository documentation, combined with the statement that "the WellStar account relationship would be at risk" if the primary contact were unavailable, indicates that customer consent and relationship continuity cannot be assured in an M&A transaction. | 3/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_Financials.csv — High confidence — multiple documents corroborated The company tracks security officer turnover at 48% annually, which is below the ASIS industry average of 55%+ and represents typical performance for contract security at this price point. However, the documents provide no evidence of customer/client churn rate metrics, net revenue retention tracking, root-cause analysis of client losses, or documented retention programs—only a sales pipeline showing new deal opportunities and a client list with contract values. The absence of client retention metrics, recovery playbooks, or proactive churn prevention initiatives indicates retention tracking is informal at best. | 5/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Process documentation is minimal and heavily dependent on key individuals. While some documentation exists (Georgia POST certification requirements, unarmed officer onboarding orientation, post orders manuals for 22 accounts), the documents reveal critical operational gaps: there is "no formal supervisory development program," "no succession planning," and client relationships are managed by only two individuals ([PERSON] and [PERSON]) with [PERSON] holding the direct relationship for WellStar Health System (18% of revenue) with no documented backup. The business has demonstrated inability to function without the owner during client escalations, indicating processes cannot be executed repeatably without specific individuals. | 3/10 | CRITICAL RISK | |
| ops_02 | Technology & Systems Scalability ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_Financials.csv — High confidence — multiple documents corroborated Atlas Security Technologies relies on ServiceMax (cloud-hosted) and Microsoft 365 for core operations, but the company maintains significant technical debt and security gaps that would impede 3x growth. Critical issues include unvaulted client credentials stored in shared spreadsheets, field iPads without MDM or encryption holding client network diagrams, and no EDR solution on tech laptops used for client system programming—all of which represent architectural vulnerabilities requiring material remediation before scaling. The cybersecurity assessment identifies a "CRITICAL" credential management gap and rates overall risk as "MEDIUM," with an estimated $2,500 one-time remediation plus $300/month ongoing, indicating the current infrastructure is not audit-ready or resilient enough to support 3x growth without significant system hardening and architectural changes. | 4/10 | NEEDS WORK | |
| ops_03 | Vendor & Supplier Concentration ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt — High confidence — multiple documents corroborated Atlas Security Solutions exhibits critical single-source vendor dependencies, most notably a direct relationship with WellStar Health System that represents 18% of revenue and is held exclusively by the owner, with no documented backup contact or succession plan—creating existential risk if this relationship is disrupted. Additionally, the company relies on ServiceMax for field service management with shared credentials among technicians and no formal vendor agreements documented, and key operational functions (Operations Manager, client relations for 9 of 22 accounts) lack formal backup personnel, indicating owner-dependent relationships rather than vendor diversification with formal SLAs. | 3/10 | CRITICAL RISK | |
| ops_04 | Financial Controls & Reporting Cadence ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents contain no information about financial controls, reporting cadence, monthly close timelines, budget vs. actual reviews, or documented control procedures. The excerpts provided address cybersecurity posture, CRM pipeline, and human capital profile, but do not include any financial reporting documentation, accounting procedures, or evidence of a CFO/Controller oversight function necessary to assess this due diligence area. | 1/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents contain no information regarding financial statements, CPA relationships, audit/review/compilation status, or books quality. The excerpts provided are limited to CRM pipeline data, cybersecurity assessments, and human capital profiles, none of which address accounting records or financial statement preparation. Without evidence of any financial documentation or CPA engagement, exit readiness cannot be assessed in this critical area. | 1/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no formal add-back schedule, EBITDA normalization documentation, or supporting schedules that a buyer's accountant could verify. While Section 5 of the HC Profile identifies specific owner-related add-backs—vehicle ($720/mo), cell ($145/mo), and discretionary supervisor bonuses (~$4,000/yr)—these are mentioned only in passing without detailed documentation, accounting support, or a formal reconciliation to financial statements. The absence of any CPA-prepared or independently verified add-back documentation, combined with the lack of a clear normalized EBITDA presentation, means significant financial rework would be required during buyer due diligence. | 3/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no information regarding revenue recognition policies, GAAP compliance, deferred revenue tracking, or revenue consistency practices. The excerpts focus exclusively on cybersecurity assessments, human capital profiles, and CRM pipeline data, leaving the revenue recognition assessment completely unaddressable based on the provided materials. Without access to financial statements, accounting policies, or revenue documentation, this area presents significant due diligence risk and cannot be evaluated. | 1/10 | CRITICAL RISK | |
| fr_04 | Three-Year Financial Trend ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents do not contain three-year historical financial statements, revenue trends, or EBITDA progression necessary to assess growth consistency or margin stability. While the CIM references $2.8M in revenue and $476K EBITDA for a single period with a 17% EBITDA margin, there is no year-over-year comparison, CAGR calculation, or documentation of trends across multiple years. The absence of comparative financial data across three periods prevents assessment of whether growth is consistent, margins are stable, or one-time items are distorting results. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt — High confidence — multiple documents corroborated The company holds two required Georgia licenses—a Low-Voltage Contractor license (LVA008821) and an Alarm Systems Contractor license (GA-ASC-41209)—both stated as current in the CIM. However, the retrieved documents do not provide evidence of transferability confirmation with legal counsel, formal documentation in a data room, or verification that these licenses are entity-held rather than individual-tied, which are critical for M&A completion in a regulated security services business. | 7/10 | ADEQUATE | |
| lc_02 | Contract Change-of-Control Provisions ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of legal review of key vendor, customer, or lease agreements for change-of-control provisions. The CIM identifies 52 active monitoring and managed service clients with recurring revenue contracts, but provides no documentation of assignment language or change-of-control clause analysis. The human capital profile notes that the owner [PERSON] holds the critical WellStar Health System account directly (18% of revenue) with no documented relationship transfer mechanism, creating material deal risk if this engagement cannot be assigned or requires client consent upon change of control. | 2/10 | CRITICAL RISK | |
| lc_03 | Employment Law Compliance ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt — High confidence — multiple documents corroborated The company maintains documented background checks, drug screens, and Georgia POST certification verification for security personnel, and compensation is benchmarked to ASIS industry standards; however, there are material gaps in employment documentation and compliance structure. The Human Capital Profile shows no formal non-compete or non-solicitation agreements documented for field technicians or management despite significant customer relationship concentration risk (one individual holds 18% of revenue through the WellStar account), and critical employee classifications lack explicit documentation—the distinction between the 28 FTE security officers and 14 PT officers, and their W-2 vs. 1099 status, is not addressed in the retrieved excerpts despite being essential for a security services business where technician departure risk is material. | 5/10 | NEEDS WORK | |
| lc_04 | Intellectual Property Ownership ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_CIM.txt — High confidence — multiple documents corroborated IP ownership is severely compromised by critical security and access control failures that create ambiguity over client data and system access rights. Client system credentials, network diagrams, and configurations are stored in unvaulted shared spreadsheets and on unmanaged field iPads without encryption or MDM, with no formal access review or revocation procedures documented following staff departures. The cybersecurity assessment identifies client credential management as "CRITICAL" risk, noting that "Client breach via compromised Atlas credentials would be reputationally devastating," and documents that "Some client system passwords not rotated after tech departures" and "Departed employee access revocation not formally tracked," creating material ambiguity over whether client data and access rights are cleanly owned and controlled at the entity level. | 3/10 | CRITICAL RISK | |
| lc_05 | Litigation & Contingent Liability ATS_Cybersecurity_Assessment.txt · ATS_CIM.txt · ATS_HC_Profile.txt — High confidence — multiple documents corroborated The company faces material cybersecurity vulnerabilities that create contingent liability exposure rather than active litigation. The cybersecurity assessment identifies a CRITICAL gap in client credential management—credentials are stored in a shared spreadsheet rather than a secure vault—and notes that "client breach via compromised Atlas credentials would be reputationally devastating," creating potential client claims and regulatory exposure given the company serves healthcare and education sectors. However, no open litigation, claims, or formal contingent liabilities are disclosed in the documents, and remediation costs are estimated at $2,500 one-time plus $300/month, which are manageable but should be resolved before close to eliminate buyer liability. | 6/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt — High confidence — multiple documents corroborated Core business systems exhibit significant documentation and ownership gaps that create material exit risk. The cybersecurity assessment identifies critical dependencies including client VPN credentials stored in a shared spreadsheet with no password vault, shared credentials among field technicians in ServiceMax, and no formal access review process for client system credentials. Additionally, key client relationships—particularly the WellStar Health System account representing 18% of revenue—are held directly by named individuals with no documented backup or succession plan, creating personal account dependencies that would impede a smooth transaction. | 3/10 | CRITICAL RISK | |
| tm_02 | Cybersecurity & Data Protection Posture ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt · ATS_Financials.csv — High confidence — multiple documents corroborated The company has MFA partially deployed for office staff but lacks enforcement for 6 field technicians accessing Microsoft 365 and company systems, and has no EDR solution deployed beyond basic Microsoft Defender. Critical gaps include unvaulted client credentials stored in shared spreadsheets, unmanaged field iPads with no encryption or remote wipe capability, no formal incident response plan, and no documented cyber insurance or vendor security review program. The external cybersecurity assessment rates overall risk as MEDIUM and identifies the client credential management gap as "the most critical finding" requiring immediate remediation, with estimated remediation costs of $2,500 one-time plus $300/month ongoing. | 4/10 | NEEDS WORK | |
| tm_03 | Data Integrity & Business Intelligence ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Atlas Security Solutions lacks reliable, accessible data infrastructure with significant manual processes and individual dependencies. The company manages client relationships and operations through a basic CRM pipeline and human memory—two key employees ([PERSON] and [PERSON]) hold direct relationships with 9 of 22 accounts, with the WellStar Health System account (18% of revenue) entirely dependent on one person whose unavailability would put the relationship "at risk." Additionally, critical operational data including client system credentials are stored in "a shared spreadsheet" rather than a secure vault, client VPN credentials lack formal access review, and departed employee access revocation is "not formally tracked"—indicating no reliable audit trail or centralized data governance. | 4/10 | NEEDS WORK | |
| tm_04 | Technology Vendor & Subscription Management ATS_Cybersecurity_Assessment.txt · ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt — High confidence — multiple documents corroborated The documents reveal critical gaps in technology vendor and subscription management with no formal documentation of vendor relationships, licenses, or renewal tracking. Multiple tools are identified (Microsoft 365, Fortinet FortiGate, ServiceMax, Microsoft Defender) but the assessment notes "shared credentials among techs" for ServiceMax and lacks any evidence of entity ownership verification or transferability documentation. Additionally, client system access credentials are stored in "a shared spreadsheet" rather than a centralized vault, creating significant transfer risk and indicating that subscription and vendor management dependencies are not properly formalized for a change of control. | 3/10 | CRITICAL RISK | |
| tm_05 | Technical Debt & Modernization Risk ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_HC_Profile.txt — High confidence — multiple documents corroborated The company operates a mixed technology environment with significant cybersecurity gaps that constitute material technical debt. The Cybersecurity Assessment identifies five documented gaps including critical client credential management stored in shared spreadsheets (Gap 1), unmanaged field iPads with no MDM or encryption (Gap 2), and missing MFA for field technician VPN access (Gap 5), with an overall MEDIUM risk rating and estimated remediation cost of $2,500 one-time plus $300/month ongoing. While core systems (Microsoft 365, Fortinet FortiGate, ServiceMax) are cloud-hosted and current, the absence of EDR solutions, privileged access management, and formal backup testing on local files, combined with critical security vulnerabilities in client credential handling, represents deferred remediation that a buyer would likely need to address post-close. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Workforce Retention & Tenure ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt · ATS_Financials.csv — High confidence — multiple documents corroborated Atlas Security Solutions exhibits concerning workforce retention dynamics with security officer turnover at 48% over the rolling 24-month period, approaching the 40%+ threshold for significant buyer risk, though this is acknowledged as below the industry average of 55%+ for contract security at this price point. Management retention is stable at 0% turnover, but the lack of a formal compensation review process (owner compensation not reviewed since a prior date), absence of retention bonuses, and slightly below-market compensation for armed officers ($19-$21/hr versus union rates) suggest limited structural retention strategy. The company's reliance on two key individuals ([PERSON] and [PERSON]) to manage all client relationships creates additional concentration risk that is not mitigated by documented succession or retention planning. | 4/10 | NEEDS WORK | |
| hc_02 | Compensation Competitiveness ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company has documented compensation data benchmarked to ASIS standards for some roles (Operations Manager at benchmark, Account Supervisor 6% below median), but lacks a formal comp review or benchmarking process—rates are set ad-hoc by the owner based on contract terms rather than systematic market analysis. Critical retention risks exist: armed security officers are paid "slightly below union rates," the owner's compensation has not been reviewed since an unspecified past date, and there are no retention bonuses or succession planning for key client-relationship holders, creating material risk of departures under new ownership without offsetting payroll savings. | 4/10 | NEEDS WORK | |
| hc_03 | Recruiting & Training Capability ATS_HC_Profile.txt · ATS_CRM_Pipeline.csv · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company has documented hiring processes (background checks, drug screens, job board sourcing) and Georgia POST certification verification for armed officers, with site-specific training manuals for all 22 active accounts, but critical gaps limit scalability. Owner approval is required for all supervisor-level and above hires, there is no formal supervisory development program (promotion based on owner observation only), and new-hire one-year retention of 61% for officers falls below the 7+ score threshold; additionally, the documents explicitly state that "[PERSON] and [PERSON] manage all client relationships" with no formal backup for recruiting and training functions, indicating these capabilities remain concentrated rather than distributed across multiple staff members. | 5/10 | NEEDS WORK | |
| hc_04 | Bench Depth & Succession Beyond Owner ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company has critical single-points-of-failure in key non-owner roles with no documented succession planning. The WellStar Health System account represents 18% of revenue and is held directly by one person with only partial backup coverage; the document explicitly states "If [PERSON] were unavailable for [DATE_TIME], the WellStar account relationship would be at risk." Operations Manager has "no documented backup," and while the business operated during owner vacation, the Operations Manager "did not handle client escalations," indicating insufficient cross-training for critical functions. | 3/10 | CRITICAL RISK | |
| hc_05 | Compensation/Benefits Structure Transferability ATS_CRM_Pipeline.csv · ATS_HC_Profile.txt · ATS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company maintains portable group health (UnitedHealthcare) and dental (MetLife) benefits with documented PTO policy, but has several owner-specific arrangements requiring cleanup: the owner draws $155,000 in S-corp distributions rather than payroll, vehicle and cell allowances totaling ~$865/month are add-backs, and discretionary supervisor bonuses (~$4,000/yr) flow through the owner's account. Additionally, there is no group retirement plan, requiring the buyer to establish one post-close to retain the management layer—a gap that will require restructuring despite otherwise portable benefits. | 5/10 | NEEDS WORK |
Top 3 Strengths
- Customer Quality at 5.8/10 presents an adequate foundation that will reduce buyer concern over revenue concentration and churn risk during diligence. While not exceptional, this adequate customer profile demonstrates enough stability to preempt aggressive working capital or escrow provisions tied to customer retention post-close. A buyer will face lower re-trade risk on this dimension compared to peers in the MSP vertical with weaker customer stickiness.
- Legal & Regulatory Compliance at 4.2/10, while still needing work, avoids the critical-risk category and signals that Atlas has not accumulated material regulatory violations or compliance liabilities that would trigger substantial buyer discounts. This adequate-to-needs-work posture means diligence on compliance will likely confirm manageable remediation costs rather than discovered violations that could cascade into price reductions or deal termination risk.
- Human Capital at 4.2/10 reflects a needs-work profile that, despite its modest score, demonstrates the company retains identifiable talent and organizational structure rather than facing a critical talent exodus. This positioning limits buyer concern over immediate key-person risk or the need for emergency retention packages post-acquisition, thereby reducing one vector of post-close cost surprises that typically drive material discounts in technology services transactions.
Top 3 Risks
- Financial Readiness at 2.0/10 (CRITICAL RISK) represents the most acute deal-blocking gap in Atlas's exit posture. Buyers will demand extensive forensic accounting, tax compliance review, and working-capital analysis during diligence, and material accounting gaps or tax exposure will trigger a substantial buyer discount and likely require escrow holdbacks or purchase-price adjustment mechanisms to close. This critical gap also increases re-trade risk substantially—buyers discovering post-LOI financial irregularities routinely renegotiate deal terms downward or impose material earn-out clawbacks.
- Operational Scalability at 2.8/10 (CRITICAL RISK) signals to buyers that Atlas lacks the infrastructure, process repeatability, and management depth required to grow efficiently post-acquisition. Buyers will underwrite significant integration and restructuring costs, apply a material haircut to valuation to offset operational drag, and likely impose earn-out penalties if revenue-per-headcount or margin targets are not met within the first 24 months post-close, creating deal-risk friction and negotiating leverage for the buyer.
- Owner Risk at 3.5/10 (NEEDS WORK) creates a critical gap in buyer confidence regarding founder transition, knowledge concentration, and post-close governance. Buyers will flag key-person dependencies, demand founder retention agreements with substantial clawback provisions, and apply a discount to account for integration friction and the cost of backfilling owner-held functions, thereby reducing the final offer price and requiring the owner to co-invest in escrow to bridge buyer concerns.
Recommended Priority Fixes
The five highest-priority actions for the next 90 days, ranked by deal impact. For the complete domain-by-domain remediation plan and cost estimates, see the Value Recovery Roadmap above.
Compliance Notes
No PII was detected in the ingested documents.