Registered office
20 Wenlock Road
London N1 7GU
Registered office
20 Wenlock Road
London N1 7GU

Follow a UK startup IT setup checklist from the company domain and cloud accounts through devices, backups, support and onboarding your first hire.
A UK startup should set up company-owned identity, collaboration, devices, access, backups and support before the first hire needs them. The chronological checklist below takes a founder from incorporation and domain ownership through onboarding the first employee without turning the stack into an enterprise project.
Reviewed: 18 August 2026
Record whether the team is office-based, remote or hybrid; which data it handles; expected headcount for the next year; and any customer, investor or regulatory requirements. A five-person consultancy, an ecommerce startup and a health product should not inherit the same default stack.
Name one founder as the business owner for IT decisions even if a supplier performs the technical work. Ownership means approving risk, spend and access—not fixing every laptop.
List the domain registrar, email platform, banking, accounting, source-code hosting, website, CRM and any product infrastructure. Record the company owner, technical administrator, renewal date and exit/export route. Keep passwords in a business password manager, not in the register.

Register the domain in a company-controlled account, enable MFA and ensure renewal details are current. Record who can change DNS and how the account can be recovered. The domain controls website and email trust, so it should never be left solely in an agency or former founder’s account.
Microsoft 365 and Google Workspace are both credible foundations. Choose based on customer requirements, file formats, meeting and collaboration preferences, device management needs and internal familiarity. Avoid splitting email and files across several overlapping services without a reason.
Every person should use an individual login. Addresses such as hello@, accounts@ and support@ should be shared mailboxes, groups or delegated accounts rather than passwords known by several people. Use groups to grant access to shared resources.
Set up SPF and DKIM, then introduce DMARC in monitoring mode before increasing enforcement. Add legitimate senders methodically. The staged process is covered in SPF, DKIM and DMARC explained.
Choose a supported laptop model or specification, operating system and warranty. Decide who orders it, configures it and holds the asset record. Include disk encryption, screen locking, supported security software and automatic updates.
Define what a typical employee, contractor, manager, finance user and administrator receives. Start with the minimum access required and add exceptions deliberately. Separate administrator accounts from ordinary email and web use.
Explain approved devices and storage, software installation, password management, MFA, confidential data, lost-device reporting and the route for suspicious messages. Keep it readable enough that a new starter will actually use it.
Use structured shared locations rather than personal drives for company records. Define who owns each team area and how access changes. Avoid making the founder’s personal folder the permanent home for contracts, finance or product documentation.
Do not send a permanent password through the same channel as the username. Prefer a temporary credential and forced change, or the platform’s secure invitation and recovery process.
Identify data the company cannot recreate and determine whether the SaaS provider’s retention meets the need. Consider independent protection for email, files, website and product data. Set realistic recovery objectives and test that authorised people can restore useful information.
Keep domain, cloud and banking recovery routes available if the normal email account is unavailable. Store emergency contacts for suppliers and insurers outside the primary tenant.
Decide whether a founder, internal hire or external provider will handle accounts, laptops, permissions, renewals and incidents. A very small team may use on-demand IT support; a growing team may benefit from a managed helpdesk and monitoring.
Document the path for urgent incidents and normal requests. A new hire should not need to message every founder to find out who can reset an account.
Compare cost per user and per server, then add one-off setup and project costs. Cheap tools become expensive when they duplicate each other or cannot be administered consistently.
After the first few hires, review active accounts, devices, shared folders, licences, external guests and supplier access. Test a backup restore and a leaver scenario. Check that the real workflow still matches the original access template.
Use the separate startup IT security checklist for a deeper control review. The NCSC’s Small Business Guide is also a useful UK baseline for backups, devices, passwords and phishing.
ACA Tech Solutions can configure Microsoft 365 or Google Workspace, devices, permissions, onboarding and practical security for founders and first hires. Explore startup IT setup or use an IT health check to assess an existing stack.
Consider it when IT work is continuous, product knowledge is strategic or supplier coordination needs a permanent owner. External support can still provide cover and specialist depth.
Sometimes, but set supported versions, encryption, separation of work data, access expiry and incident reporting. Use company devices for higher-risk roles or sensitive data.
Company-controlled domain and tenant, named account, MFA, secured device, shared-file structure, password manager, backup decision and a documented support and leaver route.