---
titel: "IT for scale-ups: from ten employees · SACOSI"
url: https://sacosi.ch/en/scale-ups
seite: /en/scale-ups
stand: 2026-09-24
beschreibung: "From around ten employees, IT is no longer a laptop: regulations, risks, scaling and costs. IT processes for start-ups and scale-ups in Switzerland."
---

> Knowledge version of the page https://sacosi.ch/en/scale-ups. It contains the full text, including what is shortened or collapsible on the page itself. Publisher: SACOSI, Situational Awareness Consulting by Ivo Schönberner, Zürich.

# From ten employees, IT is no longer a laptop.

**Short answer:** It is about regulations, risks and the criticality of the business. And about whether the IT can carry the growth that executive management and investors are planning. I bring in the IT processes a growing company needs, and explain to executive management why it pays to know its situation before a customer, an investor or a regulator asks about it.

## What changes at around ten employees?

IT no longer fits in one person's head. Devices turn into obligations, risks and costs.

### Access

Who may see what? With every new hire and every departure, this becomes a security question.

### Customer data

Data protection applies from the very first customer. In Switzerland, the FADP; with EU customers, also the GDPR.

### Customer requirements

Larger customers send security questionnaires and ask about standards such as ISO 27001.

### Costs

Subscriptions, licences and services grow unnoticed. No one has the overview.

## Why does IT become a regulatory question as a company grows?

Because every new market, every corporate customer and every industry brings its own rules, which are met through IT.

A Swiss scale-up with customers in Germany operates under the Swiss Data Protection Act and the GDPR at the same time. Anyone offering AI features in the EU falls under the EU AI Act. Anyone supplying vehicle manufacturers needs TISAX. Anyone building medical devices operates under the MedDO and the EU MDR. Which rule applies when is shown on the [Regulation](https://sacosi.ch/en/regulation) page.

## How do you build IT that can carry growth?

With modern technology and no legacy baggage, documented from the outset, and with a cost logic that fits the funding.

- **Identity first:** a central sign-on for everyone, with roles instead of individual rights.
- **Centrally managed devices:** Mac and Windows with the same rules.
- **Processes before tools:** clarify the workflows first, then choose the software.
- **Environments separated from the outset:** dedicated development, test and production systems, plus a clean separation of customer tenants. Retrofitting this means rebuilding existing workflows and paying dearly for it.
- **CAPEX and OPEX by design:** ongoing expense protects liquidity, while investments can be cheaper over time. The decision is made based on exit horizon, investor type and funding stage, not a fixed rule.
- **Documented and auditable:** so that the next funding round, the first audit or the first corporate customer does not trigger a rebuild.
- **Playbooks (documented procedures, SOPs):** operating and emergency procedures documented and auditable from the outset.

## Why should executive management know its situation?

Because decisions made without a situation picture save or invest in the wrong place.

Situational Awareness means being aware of the situation. The term comes from aviation, where errors rarely arise from a lack of technology but from an incorrect picture of the situation. It is the same in a growing company. That is why every engagement includes executive management being able, at the end, to explain for themselves which IT serves which goal. More on the [method from a founder's perspective](https://sacosi.ch/en/situational-awareness?rolle=gruender#gruender) and on the [films](https://sacosi.ch/en/concept).

## Questions from scale-ups.

### From what point does a company need an IT strategy?

At the latest when IT no longer fits in one person's head. This is often the case around ten employees: roles, access, customer data, contracts and the first customer security requirements can no longer be managed on the side.

### What is different about IT for scale-ups?

The pace. What is built today for twenty people must carry a hundred within a year, across several countries and under new regulations. Modern technology without legacy baggage makes this possible, if it is documented and built to scale from the outset.

### CAPEX or OPEX: how should IT be financed?

That depends on the exit horizon, the valuation logic and the investor type, not on a fixed rule. Subscriptions and cloud services are ongoing expense (OPEX) and protect liquidity; with an exit approaching, this also avoids investments that a buyer often will not pay for. Owned hardware or locally operated systems are investments (CAPEX), which can be cheaper over time and are negotiable with a long-term investor. The decision belongs to financial planning and is set out in the decision log.

### Why separate development and production systems from the outset?

Because otherwise errors, test data and experiments have a direct effect on live operations, and because customers, investors and auditors increasingly ask about it. Retrofitting development, test and production systems, along with the separation of customer tenants, means rebuilding existing workflows and paying considerably more than if the separation is planned in from the start.

### Which regulations come with growth?

That depends on the industry and markets. With customers in the EU comes the GDPR, with corporate customers come security evidence requirements such as ISO 27001 or TISAX, with AI products the EU AI Act, and in critical sectors reporting obligations. An overview is on the Regulation page.

## Is your IT growing with your company?

Thirty minutes, no pitch. You describe the situation, I ask questions. Afterwards, we both know whether a situation picture is worthwhile.

CH +41 78 251 09 69 DE +49 152 27602667 ZRH 47.3769°N · FRA 50.1109°N · German, English
