The IT Checklist Every NYC Startup Needs Before Hiring Employee #5
Four people can run on chaos. The fifth hire is where chaos starts compounding, and where an afternoon of setup saves you a five-figure cleanup later.
There's a specific moment in every startup's life when IT debt comes due, and in our experience it lands somewhere between hire #5 and hire #10. Before that, the founders know every password and every file. After it, somebody asks "wait, whose Dropbox is the pitch deck in?" and nobody answers. We get called into NYC startups at both stages. The before-stage engagement takes an afternoon. The after-stage cleanup has cost clients $10,000-$30,000 in consulting hours, lost files, and one genuinely scary ex-contractor situation.
Here are the six things to have in place before employee #5 signs, each with the reason it can't wait.
1. One identity platform, with MFA, from day one
Do: Put every person on company-domain accounts in Microsoft 365 or Google Workspace. Enforce MFA tenant-wide. Connect every other SaaS tool (Slack, Notion, GitHub, QuickBooks) to that identity via SSO or at least "Sign in with", and stop creating standalone accounts.
Why before #5: Every standalone account you create now is an offboarding task later, and an account nobody remembers exists. The identity platform is the keyring for the whole company; pick it deliberately (our Microsoft 365 vs Google Workspace head-to-head exists for exactly this decision) and route everything through it. Retrofitting SSO onto 30 scattered SaaS accounts at 20 employees is a genuine project; doing it right at 4 employees is a checkbox. Setup help is what our Microsoft 365 support practice does weekly.
2. A written answer to "who owns this laptop?"
Do: Decide company-owned vs BYOD before the next hire, write it down, and enroll whatever you choose in basic device management (Intune comes free with M365 Business Premium; Google's endpoint management with Workspace). Minimum enforced settings: disk encryption, screen lock, OS updates, remote wipe.
Why before #5: The first four people are founders and near-founders; their personal MacBooks feel fine. Employee #5 is the first person who might leave on bad terms. If company data lives on a personal, unmanaged, unencrypted laptop, you have no remote wipe, no encryption guarantee, and no leverage. Our opinionated take: buy company laptops starting with hire #1 if you can afford it, a $1,200 machine is the cheapest control you'll ever purchase.
3. A file structure that doesn't live in anyone's head
Do: Create team-owned storage (SharePoint sites or Google Shared Drives) organized by function (Finance, Clients, Product, HR), with permissions set per area. Personal OneDrive/My Drive is for drafts only. Migrate the founder-Dropbox-and-desktop sprawl now, while it's small enough to move in a day.
Why before #5: Files shared person-to-person inherit the sharer's existence. When that person leaves, links break and ownership orphans. Team-owned storage survives any individual departure. At four people this migration is an afternoon; at fifteen it's a quarter-long archaeology dig.
4. Backup that nobody has to remember
Do: Automated third-party backup of your email and cloud files (yes, even though they're "in the cloud", Microsoft and Google protect against their failures, not your deletions), plus backup coverage for any device holding irreplaceable work. Then test a restore once a quarter.
Why before #5: The most common small-startup data loss isn't a hack, it's an admin deleting a departed user's account 31 days after they leave, which silently torches that user's entire drive past the recovery window. We've watched it happen. Day-one backup costs a few dollars per user per month; the full reasoning is on our cloud backup and disaster recovery page.
5. An offboarding script you've never needed yet
Do: Write the 10-line checklist now: disable identity account, revoke sessions, transfer file and email ownership, remove from SaaS tools (this is where the SSO from item 1 pays off, one switch instead of thirty), reclaim or wipe the device, rotate any shared credentials they touched, set mailbox forwarding.
Why before #5: Offboarding is always urgent when it happens and never urgent before. The teams that improvise it miss things, the GitHub account, the QuickBooks login, the Stripe key in someone's notes app. The first time you offboard someone in 20 minutes flat off a script, this checklist item retroactively justifies the whole article. The hiring-side mirror of this list is in our companion post on IT onboarding for new employees in NYC.
6. A security floor: EDR and someone watching
Do: Real endpoint detection and response on every machine (not the free antivirus that shipped with it) plus email filtering and a basic alert pipeline someone actually monitors. This is the small, boring core of our cybersecurity services, sized down for a five-person company.
Why before #5: Attackers don't check your headcount. NYC startups get phished in week one of having a public website, because the attacks are automated and your domain is new, which makes it cheap to spoof. The floor is inexpensive; the first incident without it is not.
The $0 Chaos Stack vs the ~$200/Month Foundation
For a 4-person NYC startup, here's what each path actually costs.
The $0 chaos stack
Personal Gmail forwarding, files split across two founders' Dropboxes, shared passwords in a group chat, personal laptops with no encryption, no backup, no offboarding plan. Monthly cost: $0. Eventual cost: the cleanup engagements we see run $10K-$30K, not counting the deal that stalled because nobody could find the signed contract, or the ex-contractor who still had access for eight months.
The ~$200/month foundation
Four Business Premium or Workspace licenses (~$88), third-party cloud backup (~$15), password manager (~$16), EDR on four machines (~$30), domain email security and a managed alert pipeline (~$50). Total: roughly $200/month (about what a Manhattan team spends on coffee) and every item on the checklist above is covered.
Do it yourself, or hand it off
A technical founder can implement this entire checklist solo in a focused weekend, the tools are not exotic, and we've just told you the order. The honest pitch for handing it to us instead: it's faster (we've run this exact playbook dozens of times), it stays maintained after the weekend ends, and founder hours have better uses. A managed IT plan for a sub-10-person startup costs less than most teams expect because the per-user economics work in your favor at NJ-based rates.
Either way: do it before the fifth offer letter goes out. Book a free IT assessment and we'll tell you which items you've already covered and which would bite first, in one call, no slide deck. More NYC-specific guides are on the Setnom blog.
Get your startup's IT foundation built before hire #5.
Book your free IT assessment. We'll review your systems, flag your biggest risks, and show you exactly what reliable, secure IT support looks like, no pressure, no obligation.
- (646) 719-0490
- info@setnomconsulting.com
- Response within one business day