Jones IT We’re Jones IT, your Bay Area tech team, making IT simple for 20+ years. Stress-free IT starts here. Let’s talk.

From daily support to top-notch security (SOC 2 & ISO 27001 certified), we keep businesses running smoothly.

A SaaS founder eighteen months from IPO sat down with two well-regarded Bay Area MSPs. Both gave him confident answers o...
08/13/2026

A SaaS founder eighteen months from IPO sat down with two well-regarded Bay Area MSPs. Both gave him confident answers on device management, help desk response times, and uptime.

Neither one asked about segregation of duties, audit logging retention, or who owns evidence collection once the auditors show up.

He hired the third firm; the one that asked what his auditors would actually test for.

That's the gap between managed IT for a typical small business and managed IT for a company heading toward an S-1. Once SOX auditors are involved, your MSP isn't just keeping the lights on, but building the evidence trail: timestamped change logs, standing quarterly access reviews, named approvers, available on request rather than assembled after the fact.

Two domains break generalist providers fastest: access management (access creep, segregation of duties) and change management (documented requests, tested in non-prod, named approvers, post-deployment records).

Before signing with any MSP, ask them to produce evidence, not describe a control. If they can't hand you a timestamped change log for an existing client right now, that's your answer.

Full breakdown of what to require: https://na2.hubs.ly/H079vmQ0

Six weeks. That's how long a Mission Bay healthcare startup had between signing a new lease and the day rent started acc...
08/11/2026

Six weeks. That's how long a Mission Bay healthcare startup had between signing a new lease and the day rent started accruing; ready or not.

They weren't unhappy with their IT provider. Nothing was broken. They were just opening a second office, onboarding 18 new hires, and demoing a new patient portal to their board; all in the same month their current setup wasn't built to support.

That's the shape of a deadline-driven IT transition. Not "our IT is failing us." Just: "we have a date, and it isn't moving."

If your IT transition is tied to a launch, a move, or a date someone else set, read how we structure kickoff, discovery, and stabilization for exactly that kind of pressure: https://na2.hubs.ly/H074z2B0

A Series A fintech client landed a clean SOC 2 Type 2 report last year. Zero exceptions. Auditor wrapped fieldwork in un...
08/06/2026

A Series A fintech client landed a clean SOC 2 Type 2 report last year. Zero exceptions. Auditor wrapped fieldwork in under three weeks.

Q1 and Q2, the quarterly access review ran like clockwork. Then reality set in. Q3 hit mid product launch and a hiring push, and the review slipped two weeks, then three. Someone eventually got to it, then backdated the ticket so it wouldn't look late.

The renewal auditor pulled the version history anyway. Timestamps didn't match the approval date. Not a control failure so much as a documentation integrity problem, but auditors read it exactly as what it looks like. That single exception followed the company into their renewal report, and it was the first thing flagged during their next enterprise prospect's procurement review.

We call this the Q3 Gap. Your observation window starts the moment your last report is issued, not six months before renewal. A control that goes dormant between audits doesn't cost the same to rebuild. It costs roughly double, because now you're reconstructing evidence for a period that's already passed.

The fix isn't scrambling harder in Q3. It's a standing owner for every control, quarterly access reviews with a hard 5-day sign-off window, and automated offboarding tied to your HRIS so revocation doesn't depend on someone remembering a Slack message.

Our latest blog post covers how to avoid the post-audit gap: https://na2.hubs.ly/H072q2c0

A 45-person SaaS startup ran security training for two years straight. Every employee, every module, all logged in a spr...
08/04/2026

A 45-person SaaS startup ran security training for two years straight. Every employee, every module, all logged in a spreadsheet.

Then their SOC 2 auditor asked about one engineer who started May 12th: could they produce a timestamp proving he finished training within the required 30-day window?

The spreadsheet had a checkmark. No timestamp. The ops manager had checked boxes from memory during audit prep week. The training happened, but the proof that it happened on time didn't exist.

That gap became a formal exception in the final report.

Auditors aren't grading your curriculum. They're testing whether you can draw a straight line from a written control to a specific record, for a specific person, on a specific date. A checkbox filled in after the fact isn't evidence; it's a reconstruction, and auditors are trained to spot the difference.

If your training program still lives in a spreadsheet someone updates by hand, that's worth fixing before fieldwork; not during it.

Here's what a security awareness training program looks like against SOC 2 requirements: https://na2.hubs.ly/H06-TnJ0

An AI startup closed their Series B in March. By June, headcount had gone from 18 to 51, mostly engineers, mostly new Ma...
07/30/2026

An AI startup closed their Series B in March. By June, headcount had gone from 18 to 51, mostly engineers, mostly new MacBooks and iPhones. The fleet that fit in a spreadsheet six months earlier now sprawled across three offices and a dozen home networks.

Then their SOC 2 Type II observation period started, and the auditor asked a question nobody had thought hard about: how do you control network access for company devices?

The honest answer was a shared Wi-Fi password rotated twice in two years, with zero segmentation between a laptop running production credentials and a guest's phone. That doesn't satisfy CC6.1 or CC6.6. A password everyone knows isn't an access control, it's a shared credential. There's no way to revoke one device without changing it for the whole company, and no way to prove who was authorized and when.

If your fleet has grown since your last raise and your network controls haven't caught up, that gap is worth closing before an evidence request finds it for you.

Full breakdown of the certificate setup, segmentation, and the iPhone/iPad checklist auditors actually check: https://na2.hubs.ly/H06Yp-00

A growing SaaS startup had just signed their new lease. TI budget locked. Move date on the calendar. The IDF closet on t...
07/28/2026

A growing SaaS startup had just signed their new lease. TI budget locked. Move date on the calendar. The IDF closet on the floor plan was a converted janitor closet. No dedicated circuit, no cooling, a mop sink still bolted to the wall.

That closet became their server room, and we spent six weeks retrofitting a space that was never built to hold networking equipment.

We now walk the space with founders before they sign, not after. A few questions catch most of what goes wrong:

➡️ Which ISPs actually have infrastructure in the building (not just "the neighborhood has fiber")
➡️ What category of cabling is really in the walls, and whether it terminates at a patch panel or dead-ends somewhere undocumented
➡️ Whether the server room has its own circuit and cooling, separate from the break room fridge
➡️ What's directly above it, in case a pipe fails
➡️ Whether your TI allowance can actually be applied to IT buildout, since landlords default it to paint and carpet

A walkthrough contingency costs a few hours before you sign. Skipping it costs six weeks after.

Get the full checklist: https://na2.hubs.ly/H06T0w80

An AI startup filled five engineering roles in one month. Great problem to have, until the laptops started shipping.By t...
07/23/2026

An AI startup filled five engineering roles in one month. Great problem to have, until the laptops started shipping.

By the end of the week 20 hours were burned on setup calls, every machine configured slightly differently, and the CTO was quietly wondering if the hiring surge had just created a security liability.

The fix wasn't more IT headcount. It was zero-touch onboarding: laptops that arrive pre-enrolled, so a new hire powers on, logs in, and is working by 9 a.m. with zero tickets.

Getting there means the real work happens before any device ships:
→ An active MDM platform with role-based configuration profiles
→ Apple Business Manager or Windows Autopilot connected to that MDM
→ Devices purchased through channels that support automatic registration
→ A dedicated service account managing it all; not tied to one employee

The teams that get this right build the prerequisites before the hiring wave, not during it. Skip the foundation and zero-touch fails in ways that don't announce themselves.

Our latest blog post walks through what a zero-touch deployment looks like. Check it out here: https://na2.hubs.ly/H06QyGf0

A Series A digital health startup, PHI already flowing through their platform, came to us six weeks before launch.Their ...
07/22/2026

A Series A digital health startup, PHI already flowing through their platform, came to us six weeks before launch.

Their MSP had done the basics well: devices set up, onboarding smooth, helpdesk responsive. But when the privacy officer mapped their environment against HIPAA's Security Rule, the gaps showed up fast. Encryption inconsistent. Audit logging incomplete. And when she asked for a BAA, what came back a week later showed the provider didn't fully understand what they were agreeing to.

This isn't really an MSP failure story. It's a mismatch problem. General MSPs are genuinely good at device management, provisioning, and patch cycles; that's plenty for most SaaS companies. But PHI raises the bar. HIPAA doesn't tell you which tools to use; it tells you which categories of safeguards to implement, and that flexibility means an environment can look fine on the surface and fail an audit underneath.

Three things we check first with healthcare startups:

→ Does the MSP's BAA actually hold up, or is it a generic NDA wearing a different label?
→ Is encryption enforced by default, not just "addressable" on paper?
→ Can they show you the audit trail — who accessed what, when, and who's reviewing it?

We took that Series A team through a full environment audit against the Security Rule, rebuilt their BAA library, and centralized their logging. They launched on schedule and have since passed two rounds of investor due diligence without a single IT finding.

If you're building in digital health, here's what you need from your MSP: https://na2.hubs.ly/H06P7Wh0

Most Series A/B fintech companies hit SOC 2 requirements within 18 months of raising. If your MSP isn't mapping IT contr...
07/16/2026

Most Series A/B fintech companies hit SOC 2 requirements within 18 months of raising. If your MSP isn't mapping IT controls to Trust Service Criteria from day one, you're rebuilding under audit pressure instead of staying ahead of it.

What fintech-ready IT actually requires:
✅ SOC 2/PCI DSS controls mapped from the start,
✅ IAM with SSO/MFA/RBAC and reviewed privileged access,
✅ MDM + actively monitored EDR, and
✅ an MSP that shows up to the compliance planning meeting; not just the helpdesk queue.

Full breakdown: https://na2.hubs.ly/H06Jc8M0

A founder called us the week his Series A was supposed to close. Great company, real revenue, term sheet on the table. T...
07/14/2026

A founder called us the week his Series A was supposed to close. Great company, real revenue, term sheet on the table. Then diligence found that a contractor who'd written most of the core backend years earlier had never signed an IP assignment. On paper, the company didn't clearly own the code its valuation rested on.

IT due diligence rarely kills deals on the merits. It kills them on preparation. The unsigned document. The undocumented system. The security gap nobody got around to closing.

The companies that move through diligence fastest aren't the ones with the flashiest stack. They're the ones who had their answers ready before anyone asked.

If you're heading toward a raise in the next year, now is the time to find your gaps, not during the term sheet week.

Get the full insights here: https://na2.hubs.ly/H06CfJm0

Address

1370 Harrison Street
San Francisco, CA
94103

Opening Hours

Monday 8:30am - 6:30pm
Tuesday 8:30am - 6:30pm
Wednesday 8:30am - 6:30pm
Thursday 8:30am - 6:30pm
Friday 8:30am - 6:30pm

Telephone

(415) 578-7111

Alerts

Be the first to know and let us send you an email when Jones IT posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share