What IT should a Dallas startup set up first?
Set up six things in your first ninety days: a domain the company owns, business email and identity on Microsoft 365 or Google Workspace, a single device standard, a short written record of every account and who administers it, a basic security baseline of multi-factor authentication and backups, and a decision about what to postpone. Everything else can wait. I am Anthony Omini in Dallas, and that is the order I would do it in.
Answered by Anthony Omini, Cross River Tech, Dallas

Key takeaways
- Almost every expensive startup IT problem traces back to something free that was skipped in the first month, usually who owns the domain and the admin account.
- Pick one identity platform and put everything behind it, so adding and removing a person is a single action rather than a scavenger hunt.
- A device standard set before the first hire saves more time and money than any tool you could buy later.
- A startup under about five people usually does not need a provider on retainer, and I will say so rather than sell one.
- Postponing things on purpose is part of the plan; the point is to postpone them knowingly instead of discovering them during a customer security review.
What should a Dallas startup set up first?
Six things, in this order, and they can all be done in the first ninety days without a large budget. I am Anthony Omini, the owner of Cross River Tech in Dallas, and this is the list I give every founder who asks me where to start, whether or not they end up hiring me.
- A domain the company owns, registered in the company's name, in an account the founders control.
- Business email and identity on Microsoft 365 or Google Workspace, with the admin account owned by the company and protected with multi-factor authentication.
- A device standard: one or two laptop models, bought business-class, set up the same way every time.
- A written record of every account the company pays for, who administers it, where the recovery details are and when it renews.
- A security baseline: multi-factor authentication everywhere, endpoint protection, a password manager and a backup of the things you cannot recreate.
- A deliberate list of what you are postponing, so the gaps are choices rather than surprises.
What makes this list worth following is not that any item is difficult. It is that each one is nearly free at the start and genuinely painful to retrofit. Moving a domain out of a former contractor's personal account, migrating email a second time, or standardising thirty laptops that were all bought differently are the sort of jobs that cost a startup real money and a bad week.
If you would rather talk it through than work from a list, get in touch. A short conversation about what you are building and how many people you expect to hire this year is usually enough for me to tell you what to do, in what order, and what you can safely ignore.
Does a startup actually need an IT provider yet?
Often not, and I would rather say so than sell you a monthly plan you do not need. Two founders with two laptops and a Google Workspace account do not need a provider on retainer. They need about three hours of help setting things up correctly and then someone they can call when something breaks.
Roughly where the line falls, in my experience:
| Size | What usually makes sense |
|---|---|
| 1 to 4 people | A few hours of setup done properly, then hourly help when needed. No monthly plan. |
| 5 to 10 people | Still often hourly, but the documentation and onboarding checklist start to matter. Worth a yearly review. |
| 10 to 25 people | A monthly plan usually pays for itself, because onboarding, offboarding, updates and security stop fitting in someone's spare time. |
| Any size with customer data, regulated data or a security questionnaire from a customer | Get the baseline right immediately, regardless of headcount. |
The trigger is rarely headcount on its own. It is usually one of these: you hired someone whose first day went badly, a customer sent a security questionnaire, a founder is spending several hours a week on laptops, or something broke and nobody knew who to call. Any of those means the free-ride phase is over.
My hourly rate is published so you can do the arithmetic yourself: $100 an hour remote and $150 an hour onsite during business hours, one-hour minimum. If two hours a month covers you, pay for two hours a month. Hourly versus monthly IT support lays out where the crossover usually sits, and hourly IT support and break/fix is the no-contract option.
Who should own the domain, the email and the admin accounts?
The company, in accounts created for the company, with at least two founders able to get into them. This sounds obvious and it is the mistake I see most often, because at the start somebody just gets it done, quickly, with whatever account they were already signed in to.
The checklist:
- The domain is registered in the company's legal name at a mainstream registrar, in an account with a company email address on it, not a founder's personal address and not a contractor's account.
- Domain auto-renewal is on, with a card that will not expire quietly. A lapsed domain takes down email and the website at the same time.
- Registrar lock is enabled so the domain cannot be transferred away without deliberate action.
- DNS is somewhere you control, and the records are written down, because DNS is what breaks when a website is rebuilt by someone new.
- The email tenant admin account belongs to the company, with recovery details that at least two people can reach.
- There is a break-glass administrator account that is not any individual's daily login, with its credentials stored safely offline.
- No critical account is tied to a single founder's phone for its multi-factor codes. Store the codes in the shared password manager instead.
The reason to care is separation. Co-founders part ways, agencies get replaced, contractors move on. Every one of those is routine right up until the company discovers that the person leaving is the only one who can log in. Who owns your passwords, domain and equipment? covers the same ground from the point of view of a company changing providers, which is where this usually gets discovered the hard way.
Microsoft 365 or Google Workspace: how should you choose?
Pick one, put every account behind it, and do not run both. Either platform will serve a startup well. What matters far more than the choice is that identity is centralized, so adding a person is one action and removing them closes every door at once.
| Consideration | Microsoft 365 | Google Workspace |
|---|---|---|
| Fits best when | Heavy Excel and Word use, Windows devices, customers or investors who expect Office files | Browser-first teams, heavy real-time collaboration, mostly Mac or mixed devices |
| Device management | Built in on the business plans, strong for Windows | Built in, strong for Chrome and Android, works for others |
| Desktop apps | Included on the mid-tier plans | Browser-based, desktop apps are separate |
| Security features | Conditional access and richer controls on higher plans | Solid baseline, advanced controls on higher tiers |
| Switching later | Possible but a real project | Possible but a real project |
Whichever you choose, do these five things on the first day: enforce multi-factor authentication for everyone including founders, create groups rather than sharing files with individuals, set up a shared drive structure instead of files living in personal accounts, turn on the basic email protections, and add a second administrator. That takes under an hour and prevents most of the mess I get called in to untangle later.
One more thing worth knowing: neither platform is a backup. Both protect you against a dead laptop and neither protects you against someone deleting a shared drive. That is a separate product, and it is cheap. The setup and administration side is on the Microsoft 365 and Google Workspace support page, and the security configuration is in Microsoft 365 security for a small business.
What device standard should you set before the first hire?
One or two business-class laptop models, bought new with a warranty, configured identically, and enrolled in management before they are handed over. Deciding this before you hire is worth more than any software you could buy afterwards, because a mixed pile of machines bought individually turns every support question into a research project.
What a device standard actually contains:
- One model for most people and one heavier model for anyone doing design, video or development work.
- Business lines rather than consumer, for the warranty, the parts availability and the manageability. I work with Dell and Lenovo most often.
- Specifications set once so nobody has to think: enough memory and storage that the machine is still comfortable in its third year.
- Company-owned, not reimbursed personal laptops. Reimbursing a personal machine feels flexible and creates a real problem when someone leaves with company data on their own property.
- Disk encryption on by default, enrolled in management, endpoint protection installed, before it ships to the person.
- A standard software set installed automatically, so a new machine is ready rather than assembled by hand.
- A spare or two once you pass ten people, so a failed laptop is a one-hour problem rather than a one-week one.
Phones are simpler: allow personal phones, but enroll the work profile so business email and files can be removed without touching personal data. That takes a few minutes per phone and solves the entire question of what happens when someone leaves. I go through the hardware choices in buying and supporting Dell and Lenovo business computers, and the day-one routine for a new person is in hiring your first employees: the IT onboarding checklist.
What security baseline is enough at the start?
Multi-factor authentication, a password manager, endpoint protection, backups and a rule about payments. That is genuinely most of it for an early-stage company, it costs very little, and it answers the majority of what a customer security questionnaire will ask.
The baseline, in the order I would do it:
- Multi-factor authentication on every account, enforced rather than encouraged, starting with email and the domain registrar. Email resets everything else, so it is the account that matters most.
- A business password manager from the first week, before the habit of sharing credentials in chat becomes normal.
- Endpoint protection on every machine, managed centrally so somebody knows it is actually running.
- Backups of what you cannot recreate: the email tenant and shared drives, plus any code or customer data not already backed up by the platform hosting it.
- A written rule about payment and bank detail changes, verified by phone on a known number. Small companies get hit by invoice fraud constantly, and this rule costs nothing.
- Least privilege as a habit: not everyone is an administrator, and access is granted per role.
- Automatic updates on for operating systems and browsers, checked rather than assumed.
What you can honestly skip early: a company-wide security awareness program, penetration testing, a formal compliance framework, and expensive monitoring tooling. Those become worth doing when you have staff, customer data at scale or a contractual reason. Doing them before the basics are in place is spending money in the wrong order. The wider picture for a company at this stage is in cybersecurity basics for a Dallas small business, and what I set up is on the cybersecurity, backup and disaster recovery page.
What should you write down, and where?
One document, kept somewhere two people can reach, listing every account, who administers it, how to recover it and what it costs. It takes an afternoon and it is the single highest-return hour of IT work a startup can do, because it is what makes the company independent of whoever set things up.
What belongs in it:
- Domain: registrar, account owner, renewal date, where DNS is hosted.
- Email and identity: platform, tenant name, administrators, the break-glass account and where its credentials live.
- Every paid service: what it is for, who administers it, the plan, the renewal date and the billing contact.
- Devices: who has what, serial numbers, purchase dates and warranty end dates.
- Network: internet provider, account number, equipment, and the Wi-Fi details.
- Backups: what is backed up, where it goes, how long it is kept and when a restore was last tested.
- Onboarding and offboarding checklists, so both are repeatable rather than remembered.
Two rules keep it useful. It lives in the company's own storage, not on a personal machine and not only in a provider's system. And it gets reviewed once a year, whether or not anything obvious has changed, because renewal dates and administrators drift. That review is worth putting in the calendar; the annual IT check-up every Dallas office should run is the agenda I use for it.
What should a startup deliberately postpone?
Almost all infrastructure. The most common way an early-stage company wastes money on IT is buying things that made sense for the last company somebody worked at. Postpone these on purpose, and write down that you have postponed them so they are decisions rather than gaps.
- An office server. Cloud storage covers a small team fully. A server becomes worth discussing when file sizes or specific software force it, not before.
- An enterprise phone system. A cloud phone service per user is enough until you have a real front desk and call flow.
- A long office lease with a big build-out before you know your headcount. Coworking first is often the cheaper mistake to make; when the move comes, moving from coworking to your own Dallas office covers what changes.
- Expensive security tooling ahead of the baseline. Buy the fundamentals first and the tools when something requires them.
- A formal compliance program before a customer or a regulation actually asks. Keep good records so you are ready to start when it happens.
- Custom internal software for a process that a spreadsheet still handles.
- A full-time IT hire. At under about twenty-five people that role is not a full week of work, which is why hourly help or a monthly plan usually costs less and covers more.
Postponement is only safe when it is written down. A gap you chose is manageable; a gap you did not know about is what turns into a bad afternoon when a customer sends a security questionnaire and asks how you handle backups.
What does the first ninety days look like, and what does it cost?
Three short phases, most of them a few hours of work rather than a project. Here is how I would sequence it for a company that has just started hiring.
| Phase | What gets done |
|---|---|
| First 30 days | Domain ownership sorted and locked, email and identity platform chosen and set up, multi-factor authentication enforced, password manager rolled out, second administrator created |
| Days 30 to 60 | Device standard chosen, machines bought and enrolled, endpoint protection deployed, shared drive structure created, backup of the email tenant and shared drives turned on |
| Days 60 to 90 | Documentation written, onboarding and offboarding checklists agreed, payment-change rule circulated, a restore tested once, the postponed list recorded and a yearly review put in the calendar |
On cost, the honest answer is that the setup is mostly time rather than equipment. A founder can do a good deal of it alone with this list. If you want help, I work hourly with no contract at $100 an hour remote and $150 an hour onsite during business hours, one-hour minimum, and most early-stage setups are a small number of hours rather than a project. Software costs are per user per month for the identity platform, the password manager, endpoint protection and backup, and they are modest at small headcounts.
When you grow past the point where hourly makes sense, managed IT services is quoted per user or per device per month, month to month with no lock-in. For reference, small-business managed IT in the Dallas market is commonly quoted somewhere around $100 to $175 per user per month depending on what is included; that is a typical market range, not my price. What a small business should budget for IT each year puts the whole picture together.
I work with companies across Dallas and the metroplex onsite, and support businesses remotely anywhere in Texas. Tell me what you are building, how many people you expect to hire this year and what you have set up so far, and I will tell you what to do next, including the parts you do not need me for.
Questions people ask
What technology does a new startup need first?
A domain the company owns, business email and identity on Microsoft 365 or Google Workspace, one device standard, a written record of every account and who administers it, and a security baseline of multi-factor authentication, a password manager, endpoint protection and backups. Everything else, including servers, phone systems and compliance programs, can wait until something specific forces the decision.
At what point does a Dallas startup need an IT provider?
Usually somewhere between ten and twenty-five people, or earlier if a customer sends a security questionnaire, a new hire's first day goes badly, or a founder is losing hours each week to laptops. Under about five people, a few hours of setup done properly plus hourly help when something breaks is normally enough. I would rather tell you that than sell a monthly plan too early.
Should a startup buy laptops or reimburse people for their own?
Buy them. A company-owned, business-class laptop can be encrypted, enrolled in management, protected and wiped, and it comes back when the person leaves. Reimbursing a personal machine feels flexible and leaves company data on property you do not own. Standardise on one or two models so a replacement is a shelf item rather than a research project.
Is Microsoft 365 or Google Workspace better for a startup?
Either works well; running both is the mistake. Microsoft 365 suits teams living in Excel and Word or on Windows devices, and Google Workspace suits browser-first teams doing heavy real-time collaboration. What matters more is centralizing identity behind one platform, enforcing multi-factor authentication from day one and having a second administrator, so adding or removing a person is a single action.
Are backups needed if everything is already in the cloud?
Yes. Microsoft 365 and Google Workspace protect against a dead laptop or a failed server on their side. Neither protects you against someone deleting a shared drive, a compromised account wiping mailboxes, or a mistake noticed months later. A separate backup of your email tenant and shared drives costs a few dollars per user per month and is worth every cent.
How much should a startup budget for IT?
At the very start it is mostly per-user software rather than equipment: the identity platform, a password manager, endpoint protection and backup, plus laptops as you hire. Setup help is hourly, at $100 remote and $150 onsite during business hours with a one-hour minimum. A monthly managed plan becomes worth considering as you approach twenty-five people.



