
Artemis x Sentant Warrior Guide: Your CTO Shouldn't Be Resetting Passwords
May 12, 2026

By The Artemis Fund & Sentant
The Artemis Fund believes technology can create prosperity for all. With offices in New York, Texas, Massachusetts, and Nevada, Artemis leads seed rounds for companies creating resilient families, individuals, and businesses across the US.
Sentant is a full-service IT, Cybersecurity, and vCISO/ Compliance Managed Service Provider specializing in startups and VC/PE firms. From day-to-day support — onboarding, offboarding, help desk — to high-level advisory on your IT, security, and compliance roadmap, Sentant operates as your internal IT department, embedded in your Slack and built around your growth.
The startups that get into trouble with IT and security aren't the ones that ignored it, they're the ones that planned to get around to it. That's a different problem, and a harder one to solve.
And "later" doesn't work for IT infrastructure because the cost of later compounds: in the engineering time spent on tasks that have no business being there, in the scramble to answer a vendor questionnaire before a deal closes, in the bill to unwind a year of misconfigured systems. The right time to build this foundation is before you need it. For most startups, that means now.
Get The Artemis Fund’s stories in your inbox.
Get The Artemis Fund’s stories in your inbox.
Sign up for our newsletter
The Two Forcing Functions
The Two Forcing Functions
Most startups don't wake up one day and decide to invest in IT and security infrastructure. Something forces the conversation, and it typically comes from one of two directions.
The internal forcing function is role corruption. In the earliest stages, IT falls on whoever is available: the founder, the CTO, or a chief of staff. That's fine when the company is three people, but it becomes expensive fast. A CTO onboarding a new employee manually might spend two hours on a task that a proper IT process handles in 30 minutes. Multiply that by the velocity of hiring that comes post-funding, and you're pulling one of your most expensive employees away from product development to reset passwords and ship laptops.
The external forcing function is a questionnaire. Either a prospective enterprise client sends a vendor risk assessment before signing a contract, or an investor sends due diligence questions during a fundraise. Founders look at it and realize they can't answer it. At that point, they're scrambling to build months of infrastructure in weeks, usually at a much higher cost than if they had started earlier.
Both trace back to the same friction point: treating IT and security as something to figure out later. When IT and security are reactive, they cost more: in engineering time, in emergency project hours, and sometimes in deals that stall or collapse because you can't pass a vendor questionnaire. Companies that build the right foundation early avoid crises, and they walk into enterprise sales conversations and due diligence with an answer ready.
Where to Start: The IT Cleanup Sequence
Where to Start: The IT Cleanup Sequence
When a company first centralizes its IT, the instinct is to tackle everything at once. The right approach is to understand which areas have different timing triggers, and start moving on all of them in parallel.
- Email Infrastructure: Most early-stage companies have never formally set up their email infrastructure. This is how the domain connects to the email system, DNS settings that affect deliverability (if your marketing emails are landing in spam folders, this is usually why), password policies, and email security configurations. These can be addressed quickly and create an immediate baseline of protection.
- Cybersecurity Controls: This isn't a "later" investment. Endpoint management and MDM (mobile device management) are relevant from day one, as soon as you have employees on devices accessing company data. These tools give you the ability to remotely manage, secure, or wipe a device if it's compromised. Without them, a containable incident becomes an open-ended one.
- Onboarding and Offboarding: This is the most commonly neglected area. A chaotic onboarding process means someone senior is spending hours on a task that should take 30 minutes. A chaotic offboarding process is a direct security risk: former employees retaining access to company systems is one of the most common and most preventable vulnerabilities.
- Help Desk Access: Once a company grows past 20 to 30 employees, ad hoc IT support stops working. Dedicated help desk access means employees have a clear place to go when something breaks, and it keeps IT tasks off the plates of people who should not be handling them.
The Three Buckets
The Three Buckets
When founders think about IT and security, it helps to separate the work into three distinct areas:
- IT is your operational infrastructure. It’s how you manage employees, provision devices, run onboarding and offboarding, and keep day-to-day systems running. It is the foundation everything else depends on.
- Cybersecurity is the tooling layer, i.e., what you’ve deployed and actively manage to protect the company. Think: endpoint protection, MDM, and security monitoring. These are what determine how quickly you can respond when something goes wrong.
- Compliance is the regime layer: the formal frameworks (SOC 2, HIPAA, PCI, ISO 27001) that enterprise clients and investors will ask about. Compliance programs require that IT and cybersecurity are already in place. Attempting to get compliant without that foundation takes significantly longer and costs significantly more.
Most founders approach these in the wrong order, investing in compliance before addressing basic IT hygiene. The right sequence is IT first, then cybersecurity, then compliance.
How to Think About Timing
How to Think About Timing
The most common IT and security mistake is timing. For example, a SOC 2 certification takes roughly 12 months from start to finish. If you're planning to close your first enterprise accounts next year, you need to be thinking about it today. Most compliance regimes work the same way: the lead time is long, and questionnaires don't wait for you to be ready.
A useful rule: if you expect to be entering enterprise sales cycles or due diligence within the next three to six months, your IT and security posture should already be in motion. The other timing mistake is waiting for something to break. Unwinding poorly configured IT infrastructure routinely costs $10,000 or more in project hours before any ongoing service even begins. Building it right from the start is almost always cheaper.
Underestimated Threats
Underestimated Threats
Ask any managed service provider what threats they're seeing in 2026 and you'll hear the same answer: phishing. The threat landscape has grown more sophisticated. For example, finance department impersonation is one of the most effective attacks right now. A bad actor mimics a known vendor's email domain and sends an invoice for $50,000. Someone in accounts payable doesn’t double check the sender's domain and pays it.
The exposure doesn't stop with the payment. When attackers get into an email domain, they often use it to send phishing attempts to the company's own clients, instantly creating a legal liability. With endpoint management and security tooling in place, a phishing event can be contained fast: the device is isolated from the network, 2FA is reset, the investigation starts. Without those tools, an attacker might spend hours inside company systems before anyone realizes something is wrong.
The Shadow IT Problem
The Shadow IT Problem
Every company is figuring out how to use AI tools, but many aren’t yet thinking seriously about governance. Employees are adopting AI tools faster than companies establish policies around them. That means someone on your team may be using a personal ChatGPT account instead of the company's enterprise license, and putting client data, financial information, or proprietary company information into a model that doesn't carry the same data protections as an enterprise agreement.
The starting point is practical: make sure every employee is on the right seat, in the right product, with the correct data-sharing settings turned on. Beyond tooling, companies should have written AI policies that cover how AI is used internally and disclose to clients when and how AI is being leveraged. If something goes wrong, you want to demonstrate that you had a policy and that clients were informed.
Start Small, Now
Start Small, Now
One of the most persistent misconceptions about IT and security is that it's all-or-nothing. Most companies put it off because the perceived cost of a full program feels too high for where they are. The right partner lets you build incrementally. Rather than waiting until you can afford a full package, you can start with a few hours a month, enough to begin building the right foundation in the right sequence, and scale from there.
When you’re assessing an IT & security service, look for:
- Month-to-month contracts that keep the relationship accountable and scale with your needs
- Block-hour pricing that grows more efficiently than per-user-per-month models as headcount grows
- Slack integration so that IT support feels like an internal team member rather than a vendor ticket queue
IT and security infrastructure won't be the reason your company succeeds. But weak infrastructure can slow a deal, derail a fundraise, or turn a phishing click into a client crisis. The companies that get ahead of this treat it as an operational foundation, the same way they'd approach finance or legal. Build it incrementally, build it before you need it, and build it with a partner who knows how to sequence it for your stage.
We believe once in a generation companies will be built by unexpected founders. If that sounds like you, pitch us here!


Newsletter Signup
