
All the engineering in house, and still no IT
A software company is full of people who know how systems work, and almost never has anyone whose job is the corporate IT. Laptops, access, passwords and the evidence a customer will ask for land on the senior engineer least able to say no. This page is about that part, and about where we stay away from your product.
The product is sorted, the organisation around it is not
That is not sloppiness. It is the logical outcome of a company where everyone works on the product.
In a technology company the product infrastructure is usually excellent: there is version control, there are environments, there is a release process and there are people who understand it. The corporate IT beside it almost never is. New hires get their laptop from whoever happens to have time, access rights grow with the people requesting them, and nobody knows how many subscriptions are running until the quarterly figures point at it.
While the company is small that works. It breaks at two moments: at growth, when people join every month and the first day goes wrong structurally, and at the first large customer, when a questionnaire arrives about your own security.
Your customer’s questionnaire
The moment you sell to larger organisations, your own setup becomes part of their purchasing process. A list of questions arrives about access management, device management, leavers, backup and incident reporting, and the answers have to be demonstrable rather than plausible. Whoever starts setting up at that point loses weeks in a sales cycle where they do not have them.
What we do there is build the corporate side so those questions can be answered with a fact: role-based access with multi-factor verification, devices under management and encrypted, a demonstrable leaver procedure and a backup whose restore has been rehearsed. Whether you then want ISO 27001 or SOC 2 is your call and that route runs through an auditor; we supply the setup and the records such a judgement rests on.
A mixed fleet is the rule here
Developers on macOS or Linux, sales and finance on Windows, and everyone with their own tooling. That is not disorder to be tidied away but a reality management has to fit: device management that handles all three platforms without squeezing developers out of their work. A policy that does squeeze gets worked around within a month, and then it is worse than no policy.
What we take on at a technology company
You choose what you need. It all falls under one contract, one report and one point of contact.
- Access by role, with leavers handledAccounts follow the job, with multi-factor verification and immediate closure on departure. That last one is on every customer questionnaire and is the thing most often left undone internally.
- Device management across three platformsmacOS, Windows and Linux in the same management, with encryption and updates demonstrably on, without a developer losing the use of their machine.
- A first day that is not improvisedDuring growth, onboarding is the process that breaks first. Device, accounts and access are ready on the start date rather than the week after.
- Subscriptions and licences in viewWhat is running, in whose name and when it renews. In this sector that grows faster than anywhere else, because everyone can create an account.
- Backup of the corporate sideNot your production environment but what sits beside it: documents, mail, the administration and the source files that exist nowhere else.
- An answer to the questionnaireThe setup and the records that let a customer’s security questions be answered with a fact rather than an explanation.
How we start at a technology company
In this order, because here the risk is not that nothing exists but that nobody knows what does.
Establish what runs and in whose name
Which services are used, who owns them and who pays for them. This step almost always surfaces a service sitting on a former employee’s personal account.
Fix access and leavers
Rights back to the role and a departure procedure that actually runs. This is the cheapest step and the one that removes the most risk.
Record the boundary with the product
What we manage and what your own people keep, in writing. Without that line a grey area forms around the production environment, and nobody wants to work in it.
Adjust on what we see
The reporting shows tickets, turnaround times and recurring causes. During growth that is the signal a process is about to break before it does.
The services that come up most here
These building blocks come up most at a technology company.
Looking further
Recognise the picture but work in another industry? Then look at the other sectors.
Questions we get about this
The ones that come up most, answered briefly.
Do you build software for us as well?
No. We do not touch your product and we do not touch your production environment. What we do is the corporate IT beside it: laptops, access, subscriptions, backup of the office side and the evidence your customers ask for.
Can you get us to ISO 27001 or SOC 2?
We supply the setup and the records such a judgement rests on: role-based access, device management, a demonstrable leaver procedure and a rehearsed recovery. The certificate itself comes from an auditor and is in your name; we do not run that route for you.
Our developers work on Linux and macOS, is that a problem?
No, and here it is the rule rather than the exception. Management has to handle all three platforms without squeezing anyone out of their work. A policy that does gets worked around within a month, and is then worse than no policy.
We stay away from your product
We do not build software and we do not touch your production environment. Tell us what sits beside the product: the laptops, the access, the subscriptions and the questionnaire that arrived. We build around that.