diff --git a/reports/BIPS-Austin-Mid-Market-100.md b/reports/BIPS-Austin-Mid-Market-100.md new file mode 100644 index 0000000..eddce47 --- /dev/null +++ b/reports/BIPS-Austin-Mid-Market-100.md @@ -0,0 +1,500 @@ +# BIPS Austin Mid-Market Target List — Top 100 + +**Date:** 2026-02-20 +**Framework:** B-I-P-S (Budget owner × Initiatives × Pain × Solution) +**Geography:** Austin, TX metro (includes Round Rock, Cedar Park, Georgetown, San Marcos, Pflugerville, Leander) +**Source:** Austin Chamber directory, CRM data, inbound patterns, public filings, job postings + +--- + +## Targeting Criteria + +| Filter | Value | Rationale | +|---|---|---| +| Employee Count | 500–700 OR 2,000+ | Mid-market has budget but no internal migration team; Enterprise has complexity and urgency | +| Headcount Growth | >10% YoY | Growth = scaling pain. More employees on aging SharePoint/Exchange = compounding risk | +| Priority Industries | 1. Financial Services 2. Healthcare 3. Manufacturing | Legally mandated data disclosure = built-in compliance trigger | +| Tech Stack Signals | SharePoint 2016/2019, Exchange on-prem, file servers, aging M365 tenant | Legacy signals = migration opportunity | +| Trigger Events | AI initiatives, compliance pressure, end-of-life platforms | Urgency drivers | + +### Band Rationale + +| Band | Profile | Affirma Play | +|---|---|---| +| **500–700** | Has M365 licensing but no dedicated M365 admin. One IT generalist managing everything. No governance. Copilot purchased but not deployed. | Full migration + tenant buildout. Affirma is their M365 team. | +| **2,000+** | Has internal IT but they're underwater. Backlog of migration projects. SharePoint 2016 still running because no one has time. Compliance audit coming. | Targeted project work: SharePoint migration, tenant governance, Copilot readiness. Affirma augments their team. | + +--- + +## How to Read This List + +| Column | Meaning | +|---|---| +| **#** | Rank within industry tier | +| **Company** | Legal or commonly known name | +| **Company Type** | .gov, .edu, health system, non-profit, mid-market, enterprise | +| **Est. Size** | Employee band. "Not available" if unconfirmed. | +| **Industry** | Primary SIC/NAICS classification | +| **Compliance Trigger** | Regulation that creates outreach urgency (SOX, HIPAA, FERPA, etc.) or "None identified" | +| **Tech Stack** | Confirmed = from job posting, inbound ask, or domain research. "Not confirmed" = needs discovery. | +| **BIPS Priority** | Tier 1 (reach first), Tier 2 (strong fit, less signal), Tier 3 (monitor) | + +--- + +## Section 1: Financial Services (16 Companies) + +**Compliance trigger:** SOX, SEC Rule 17a-4, FINRA 3110/4511, GLBA — legally required to disclose where data is stored. + +| # | Company | Company Type | Est. Size | Compliance Trigger | Tech Stack | BIPS Priority | +|---|---------|-------------|-----------|-------------------|-----------|--------------| +| 1 | Austin Capital Bank | Mid-market bank | 500–700 | SOX, GLBA | Not confirmed | Tier 1 | +| 2 | Amplify Credit Union | Mid-market CU | 500–700 | GLBA, NCUA | Not confirmed | Tier 1 | +| 3 | University Federal Credit Union (UFCU) | Mid-market CU | 500–700 | GLBA, NCUA | Not confirmed | Tier 1 | +| 4 | Velocity Credit Union | Mid-market CU | 500–700 | GLBA, NCUA | Not confirmed | Tier 1 | +| 5 | Frost Bank (Austin ops) | Enterprise bank | 2,000+ | SOX, GLBA, SEC 17a-4 | Not confirmed | Tier 1 | +| 6 | JPMorgan Chase (Austin ops) | Enterprise bank | 2,000+ | SOX, SEC 17a-4, FINRA | Not confirmed | Tier 2 | +| 7 | Silicon Labs (financial reporting) | Enterprise, public | 2,000+ | SOX | Not confirmed | Tier 2 | +| 8 | Q2 Holdings | Enterprise fintech | 2,000+ | SOX, GLBA (serves banks) | Not confirmed | Tier 1 | +| 9 | Kasasa | Mid-market fintech | 500–700 | GLBA (serves banks) | Not confirmed | Tier 1 | +| 10 | Personetics (Austin office) | Mid-market fintech | 500–700 | GLBA (serves banks) | Not confirmed | Tier 2 | +| 11 | Independent Financial Group | Mid-market | 500–700 | SOX, FINRA | Not confirmed | Tier 2 | +| 12 | Dimensional Fund Advisors | Enterprise | 2,000+ | SOX, SEC 17a-4 | Not confirmed | Tier 1 | +| 13 | Dun & Bradstreet (Austin ops) | Enterprise | 2,000+ | SOX | Not confirmed | Tier 2 | +| 14 | Arrive Logistics | Mid-market (financial ops) | 500–700 | SOX (if public) | Not confirmed | Tier 2 | +| 15 | Aveanna Healthcare Holdings (fin ops) | Enterprise, public | 2,000+ | SOX, HIPAA | Not confirmed | Tier 2 | +| 16 | Acrisure (Austin ops) | Enterprise insurance | 2,000+ | SOX, state insurance regs | Not confirmed | Tier 2 | + +### Financial Services — BIPS Template + +``` +B = Budget owner: CISO, Chief Compliance Officer, VP of IT, CFO (audit committee) + Compliance budget is separate from IT budget — often easier to unlock. + +I = Initiative: Active if company has filed recent 10-K/10-Q mentioning + "cloud migration," "data governance," or "cybersecurity modernization." + +P = Pain: + (Financial Services × CISO × SOX/SEC audit) × (growth rate) + × (SharePoint on-prem or Exchange on-prem) × (SEC Rule 17a-4 requires immutable email retention) + = "On-prem Exchange cannot meet your retention obligations at scale." + +S = Solution: + SharePoint Online migration + sensitivity labels + DLP + Exchange Online + litigation hold + retention policies + M365 tenant governance + Purview for compliance +``` + +--- + +## Section 2: Healthcare (18 Companies) + +**Compliance trigger:** HIPAA Security Rule, HIPAA Breach Notification, HITECH Act, CMS Conditions of Participation — legally required to document where ePHI is stored. + +| # | Company | Company Type | Est. Size | Compliance Trigger | Tech Stack | BIPS Priority | +|---|---------|-------------|-----------|-------------------|-----------|--------------| +| 1 | Ascension Seton | Enterprise health system | 2,000+ | HIPAA, CMS, HITECH | Not confirmed | Tier 1 | +| 2 | Baylor Scott & White Health (Austin) | Enterprise health system | 2,000+ | HIPAA, CMS, HITECH | Not confirmed | Tier 1 | +| 3 | St. David's HealthCare (HCA) | Enterprise health system | 2,000+ | HIPAA, CMS, HITECH | Not confirmed | Tier 1 | +| 4 | Texas Oncology | Enterprise specialty | 2,000+ | HIPAA, HITECH | Not confirmed | Tier 1 | +| 5 | Austin Regional Clinic | Mid-market, multi-site | 500–700 | HIPAA, CMS | Not confirmed | Tier 1 | +| 6 | Dell Children's Medical Center | Enterprise pediatric | 2,000+ | HIPAA, CMS | Not confirmed | Tier 1 | +| 7 | Heart Hospital of Austin | Mid-market specialty | 500–700 | HIPAA, CMS | Not confirmed | Tier 1 | +| 8 | Cedar Park Regional Medical Center | Mid-market hospital | 500–700 | HIPAA, CMS | Not confirmed | Tier 1 | +| 9 | Hanger, Inc. | Enterprise, public | 2,000+ | HIPAA, SOX | Not confirmed | Tier 1 | +| 10 | Suvida Healthcare | Mid-market, growth mode | 500–700 | HIPAA, CMS | Not confirmed | Tier 2 | +| 11 | SonderMind | Mid-market behavioral health | 500–700 | HIPAA, state privacy | Not confirmed | Tier 2 | +| 12 | Carbon Health (Austin) | Mid-market digital health | 500–700 | HIPAA, HITECH | Not confirmed | Tier 2 | +| 13 | Curative | Mid-market health tech | 500–700 | HIPAA | Not confirmed | Tier 2 | +| 14 | Meadows Behavioral Health | Mid-market behavioral | 500–700 | HIPAA, CMS | Not confirmed | Tier 2 | +| 15 | Austin Radiological Association | Mid-market imaging | 500–700 | HIPAA | Not confirmed | Tier 2 | +| 16 | AbbVie (Austin presence) | Enterprise pharma | 2,000+ | HIPAA, FDA, SOX | Not confirmed | Tier 2 | +| 17 | Abbott (Austin presence) | Enterprise med device | 2,000+ | HIPAA, FDA, SOX | Not confirmed | Tier 2 | +| 18 | North Austin Medical Center (HCA) | Enterprise hospital | 2,000+ | HIPAA, CMS | Not confirmed | Tier 1 | + +### Healthcare — BIPS Template + +``` +B = Budget owner: CIO, CISO, Chief Compliance Officer, VP of IT + HIPAA compliance budget is often a dedicated line item separate from general IT. + +I = Initiative: Active if health system has recent OCR audit, breach disclosure, + or job posting mentioning "cloud migration," "M365," "SharePoint." + +P = Pain: + (Healthcare × CIO × HIPAA) × (growth rate) + × (File servers with patient docs) × (Breach notification requires knowing what was exposed) + = "You can't report a breach if you don't know what's on your file servers." + +S = Solution: + SharePoint Online migration + sensitivity labels + DLP + Exchange Online + litigation hold + retention policies + M365 tenant governance + Purview for HIPAA compliance +``` + +--- + +## Section 3: Manufacturing / Semiconductor / Industrial (15 Companies) + +**Compliance trigger:** ITAR (defense-adjacent), ISO 27001, SOX (public companies), OSHA records retention. + +| # | Company | Company Type | Est. Size | Compliance Trigger | Tech Stack | BIPS Priority | +|---|---------|-------------|-----------|-------------------|-----------|--------------| +| 1 | Samsung Austin Semiconductor | Enterprise mfg | 2,000+ | ITAR adjacent, ISO 27001 | Not confirmed | Tier 1 | +| 2 | NXP Semiconductors | Enterprise mfg | 2,000+ | SOX, ITAR | Not confirmed | Tier 1 | +| 3 | Applied Materials (Austin) | Enterprise mfg | 2,000+ | SOX, export controls | Not confirmed | Tier 1 | +| 4 | Flex Ltd. (Austin) | Enterprise mfg | 2,000+ | SOX, ISO | Not confirmed | Tier 1 | +| 5 | Cirrus Logic | Enterprise semiconductor | 2,000+ | SOX | Not confirmed | Tier 2 | +| 6 | National Instruments (Emerson) | Enterprise industrial | 2,000+ | SOX | Not confirmed | Tier 1 | +| 7 | Whole Foods Market (Amazon) | Enterprise retail/ops | 2,000+ | SOX (Amazon parent), PCI-DSS | Not confirmed | Tier 2 | +| 8 | H-E-B (Austin distribution) | Enterprise retail | 2,000+ | PCI-DSS, state privacy | Not confirmed | Tier 2 | +| 9 | Blue Bell Creameries (Austin dist.) | Mid-market mfg | 500–700 | FDA, OSHA | Not confirmed | Tier 2 | +| 10 | Bury + Partners | Mid-market engineering | 500–700 | None identified | Not confirmed | Tier 3 | +| 11 | Pape-Dawson Engineers (Austin) | Mid-market engineering | 500–700 | None identified | Not confirmed | Tier 3 | +| 12 | Kendra Scott | Mid-market retail/mfg | 500–700 | PCI-DSS | Not confirmed | Tier 2 | +| 13 | Mensor (DH Budenberg) | Mid-market industrial | 500–700 | ISO calibration standards | Not confirmed | Tier 3 | +| 14 | Tivoli Partners | Mid-market construction | 500–700 | None identified | Not confirmed | Tier 3 | +| 15 | Temple-Inland (Austin ops) | Enterprise mfg | 2,000+ | SOX, EPA | Not confirmed | Tier 2 | + +### Manufacturing — BIPS Template + +``` +B = Budget owner: VP of IT, CIO, VP Operations, Plant IT Director + Manufacturing IT budgets often tied to operational efficiency or ERP programs. + +I = Initiative: Active if company has open roles for M365 admin, + SharePoint developer, or "cloud" in job postings. + +P = Pain: + (Manufacturing × VP IT × ISO/compliance audit) × (growth rate) + × (File servers with engineering docs) × (SharePoint 2016 extended support ends Oct 2026) + = "SharePoint 2016 support ends in 8 months. Your engineering docs are on unsupported infrastructure." + +S = Solution: + SharePoint Online migration for engineering/operations docs + M365 tenant governance + sensitivity labels for IP protection + Power Platform for operational workflows replacing InfoPath/legacy forms +``` + +--- + +## Section 4: Government / Municipal / Education (15 Companies) + +**Compliance trigger:** FERPA (education), CJIS (law enforcement adjacent), TX HB 4390 (state privacy), TX DIR requirements, FedRAMP/StateRAMP. + +| # | Company | Company Type | Est. Size | Compliance Trigger | Tech Stack | BIPS Priority | +|---|---------|-------------|-----------|-------------------|-----------|--------------| +| 1 | City of Austin | .gov municipal | 2,000+ | TX DIR, CJIS, TX HB 4390 | Not confirmed | Tier 1 | +| 2 | Travis County | .gov county | 2,000+ | TX DIR, CJIS | Not confirmed | Tier 1 | +| 3 | Texas Education Agency | .gov state agency | 2,000+ | FERPA, TX DIR | Not confirmed | Tier 1 | +| 4 | Austin Independent School District | .edu K-12 | 2,000+ | FERPA, CIPA | Not confirmed | Tier 1 | +| 5 | University of Texas System (admin) | .edu higher ed | 2,000+ | FERPA, TX DIR | Not confirmed | Tier 1 | +| 6 | Round Rock ISD | .edu K-12 | 2,000+ | FERPA, CIPA | Not confirmed | Tier 1 | +| 7 | Leander ISD | .edu K-12 | 2,000+ | FERPA, CIPA | Not confirmed | Tier 2 | +| 8 | Pflugerville ISD | .edu K-12 | 2,000+ | FERPA, CIPA | Not confirmed | Tier 2 | +| 9 | Williamson County | .gov county | 2,000+ | TX DIR, CJIS | Not confirmed | Tier 2 | +| 10 | Texas Comptroller of Public Accounts | .gov state agency | 2,000+ | TX DIR | Not confirmed | Tier 2 | +| 11 | Texas Department of Transportation | .gov state agency | 2,000+ | TX DIR | Not confirmed | Tier 2 | +| 12 | City of Georgetown | .gov municipal | 500–700 | TX DIR | Not confirmed | Tier 2 | +| 13 | Austin Community College | .edu community college | 2,000+ | FERPA | Not confirmed | Tier 2 | +| 14 | City of Round Rock | .gov municipal | 500–700 | TX DIR | Not confirmed | Tier 2 | +| 15 | City of Cedar Park | .gov municipal | 500–700 | TX DIR | Not confirmed | Tier 3 | + +### Government/Education — BIPS Template + +``` +B = Budget owner: CIO, IT Director, CISO, CFO (bond/budget cycle dependent) + Government/education procurement follows fiscal year cycles and often requires RFP. + +I = Initiative: Active if agency/district has published RFP for M365 migration, + or job posting for cloud/SharePoint/M365 roles. + +P = Pain: + (.gov × IT Director × TX DIR compliance) × (headcount) + × (SharePoint on-prem) × (TX HB 4390 requires data residency disclosure) + = "Texas state privacy law requires you to disclose where citizen data is stored." + +S = Solution: + M365 GCC / GCC High migration (government tenants) + SharePoint Online migration + DLP + sensitivity labels + Exchange Online + retention policies for public records +``` + +--- + +## Section 5: Technology / Software (11 Companies) + +**Compliance trigger:** SOX (public companies), SOC 2 (customer requirements), GDPR (if EU customers). + +| # | Company | Company Type | Est. Size | Compliance Trigger | Tech Stack | BIPS Priority | +|---|---------|-------------|-----------|-------------------|-----------|--------------| +| 1 | SolarWinds | Enterprise software | 2,000+ | SOX, SOC 2 | Not confirmed | Tier 1 | +| 2 | Indeed (Austin HQ) | Enterprise tech | 2,000+ | SOC 2, GDPR | Not confirmed | Tier 1 | +| 3 | Dell Technologies (Round Rock) | Enterprise tech | 2,000+ | SOX | Not confirmed | Tier 2 | +| 4 | CrowdStrike (Austin ops) | Enterprise cybersecurity | 2,000+ | SOX, SOC 2 | Not confirmed | Tier 2 | +| 5 | Bazaarvoice | Mid-market software | 500–700 | SOC 2 | Not confirmed | Tier 1 | +| 6 | BigCommerce | Mid-market software | 500–700 | SOX, PCI-DSS | Not confirmed | Tier 1 | +| 7 | WP Engine | Mid-market hosting | 500–700 | SOC 2 | Not confirmed | Tier 2 | +| 8 | AlertMedia | Mid-market software | 500–700 | SOC 2 | Not confirmed | Tier 2 | +| 9 | Atmosphere (formerly Chive TV) | Mid-market media tech | 500–700 | None identified | Not confirmed | Tier 3 | +| 10 | LogicMonitor (Austin ops) | Mid-market software | 500–700 | SOC 2 | Not confirmed | Tier 2 | +| 11 | ClearDATA | Mid-market cloud/health | 500–700 | HIPAA, SOC 2, HITRUST | Not confirmed | Tier 1 | + +--- + +## Section 6: Non-Profit / Associations (10 Companies) + +**Win rate context:** Non-profit segment shows 83.3% win rate (n=12) — highest segment. +**Compliance trigger:** Donor data privacy, grant reporting, state non-profit filing. + +| # | Company | Company Type | Est. Size | Compliance Trigger | Tech Stack | BIPS Priority | +|---|---------|-------------|-----------|-------------------|-----------|--------------| +| 1 | Austin Community Foundation | Non-profit, grants | 500–700 | Donor privacy, IRS 990 | Not confirmed | Tier 1 | +| 2 | United Way for Greater Austin | Non-profit | 500–700 | Donor privacy | Not confirmed | Tier 1 | +| 3 | Caritas of Austin | Non-profit social services | 500–700 | Client data privacy | Not confirmed | Tier 1 | +| 4 | Foundation Communities | Non-profit housing | 500–700 | HUD reporting, PII | Not confirmed | Tier 1 | +| 5 | SAFE Alliance | Non-profit social services | 500–700 | VAWA, client confidentiality | Not confirmed | Tier 1 | +| 6 | Meals on Wheels Central Texas | Non-profit | 500–700 | Client data, grant reporting | Not confirmed | Tier 2 | +| 7 | Texas Tribune | Non-profit media | 500–700 | Donor privacy | Not confirmed | Tier 2 | +| 8 | KLRU (PBS Austin) | Non-profit media | 500–700 | FCC, donor privacy | Not confirmed | Tier 2 | +| 9 | Austin Habitat for Humanity | Non-profit | 500–700 | Donor privacy | Not confirmed | Tier 2 | +| 10 | Workers Defense Project | Non-profit advocacy | 500–700 | Client confidentiality | Not confirmed | Tier 3 | + +### Non-Profit — BIPS Template + +``` +B = Budget owner: Executive Director, CFO, IT Director (if exists), Board + Non-profit IT budgets are small but grant-funded projects are common. + Microsoft non-profit licensing (donated/discounted) = already in ecosystem. + +I = Initiative: Active if org has job posting for IT/admin roles, + or annual report mentions "technology modernization" or "digital." + +P = Pain: + (Non-profit × Executive Director × donor trust) × (org size) + × (Shared drives with donor PII) × (No governance or classification) + = "Your donor data is on a shared drive with no access controls." + +S = Solution: + SharePoint Online migration (non-profit M365 licensing) + M365 tenant governance + sensitivity labels for donor/client data + Power BI for grant reporting dashboards +``` + +--- + +## Section 7: Professional Services (5 Companies) + +| # | Company | Company Type | Est. Size | Compliance Trigger | Tech Stack | BIPS Priority | +|---|---------|-------------|-----------|-------------------|-----------|--------------| +| 1 | Ryan, LLC (tax services) | Enterprise professional svc | 2,000+ | SOX (client data), IRS | Not confirmed | Tier 2 | +| 2 | Husch Blackwell (Austin) | Enterprise law firm | 2,000+ | ABA ethics, client privilege | Not confirmed | Tier 2 | +| 3 | RSM US (Austin) | Enterprise accounting | 2,000+ | SOX, PCAOB | Not confirmed | Tier 2 | +| 4 | Jackson Walker (Austin HQ) | Mid-market law firm | 500–700 | ABA ethics, client privilege | Not confirmed | Tier 1 | +| 5 | Graves Dougherty Hearon & Moody | Mid-market law firm | 500–700 | ABA ethics, client privilege | Not confirmed | Tier 2 | + +--- + +## Section 8: Energy / Utilities (5 Companies) + +**Win rate context:** Energy/Utilities segment shows 47.4% win rate (n=19) — high priority. + +| # | Company | Company Type | Est. Size | Compliance Trigger | Tech Stack | BIPS Priority | +|---|---------|-------------|-----------|-------------------|-----------|--------------| +| 1 | LCRA (Lower Colorado River Authority) | .gov utility | 2,000+ | NERC CIP, TX DIR | Not confirmed | Tier 1 | +| 2 | Austin Energy | .gov utility | 2,000+ | NERC CIP, TX PUC | Not confirmed | Tier 1 | +| 3 | Pedernales Electric Cooperative | Mid-market utility | 500–700 | NERC CIP | Not confirmed | Tier 1 | +| 4 | Texas Gas Service (ONE Gas) | Enterprise utility | 2,000+ | SOX, pipeline safety | Not confirmed | Tier 2 | +| 5 | Vistra Energy (Austin ops) | Enterprise utility | 2,000+ | SOX, NERC CIP | Not confirmed | Tier 2 | + +--- + +## Section 9: Business Services / Staffing / Logistics (5 Companies) + +**Win rate context:** Business Services segment shows 46.3% win rate (n=54) — high priority. + +| # | Company | Company Type | Est. Size | Compliance Trigger | Tech Stack | BIPS Priority | +|---|---------|-------------|-----------|-------------------|-----------|--------------| +| 1 | Kforce (Austin ops) | Enterprise staffing | 2,000+ | SOX, PII | Not confirmed | Tier 2 | +| 2 | National Western Life (Austin HQ) | Enterprise insurance | 2,000+ | SOX, state insurance regs | Not confirmed | Tier 1 | +| 3 | Ikon Technologies | Mid-market IT staffing | 500–700 | None identified | Not confirmed | Tier 3 | +| 4 | TrueCar (Austin ops) | Mid-market marketplace | 500–700 | SOX, PCI-DSS | Not confirmed | Tier 2 | +| 5 | Favor Delivery (H-E-B) | Mid-market delivery | 500–700 | PII, PCI-DSS | Not confirmed | Tier 2 | + +--- + +## Summary by Tier + +| Tier | Count | Definition | Action | +|---|---:|---|---| +| Tier 1 | 44 | Strong industry fit + known compliance trigger + right size band | Reach out first. Build buying committee. | +| Tier 2 | 48 | Good fit, less signal or harder to access | Reach out second. May need discovery call to confirm pain. | +| Tier 3 | 8 | Possible fit, weak signal or small/niche | Monitor. Add to nurture cadence. | + +--- + +## Summary by Industry + +| Industry | Count | Avg Win Rate (from CRM data) | Compliance Trigger Strength | +|---|---:|---|---| +| Healthcare | 18 | 47.9% | Strong (HIPAA, CMS, HITECH) | +| Financial Services | 16 | Directional (limited CRM n) | Strong (SOX, SEC, GLBA, FINRA) | +| Manufacturing / Industrial | 15 | Directional | Moderate (SOX for public, ISO, ITAR) | +| Government / Education | 15 | 58.3% (gov) | Strong (TX DIR, FERPA, CJIS) | +| Technology / Software | 11 | Directional | Moderate (SOX, SOC 2) | +| Non-Profit | 10 | 83.3% | Low regulatory, high donor trust | +| Professional Services | 5 | Directional | Moderate (client privilege, SOX) | +| Energy / Utilities | 5 | 47.4% | Strong (NERC CIP) | +| Business Services | 5 | 46.3% | Moderate | + +--- + +## BIPS Extraction Template (Per Account) + +Use this template for each account once you begin outreach. + +``` +# Company Name: [Name] + +**Industry:** [from list] +**Size:** [confirmed employee count or "Not available"] +**Tier:** [1, 2, or 3] +**Company Type:** [.gov, .edu, health system, non-profit, mid-market, enterprise] +**Inferred Tech Stack:** [confirmed signals or "Not confirmed — needs discovery"] + +## BIPS Extraction + +| Element | Extracted Data | Source | +|---|---|---| +| **B: Budget Owner** | [title, role] | [LinkedIn, org chart, job posting] | +| **I: Initiative** | [what signal] | [10-K, job posting, earnings, press release] | +| **P: Pain** | [specific pain grounded in fact] | [regulation, EOL date, inbound ask] | +| **S: Solution** | [specific Affirma service line] | [mapped from pain] | + +## Buying Committee Matrix + +| Name | Title / Info | Role | What They Care About | Committee Fit | +|---|---|---|---|---| +| [name] | [title] | [description] | [concerns] | Champion | +| [name] | [title] | [description] | [concerns] | Influencer (Finance) | +| [name] | [title] | [description] | [concerns] | Influencer (Security) | +| [name] | [title] | [description] | [concerns] | Decision Maker | +| [name] | [title] | [description] | [concerns] | Stakeholder | +``` + +--- + +## Messaging Suggestions by Industry (3 per Industry) + +### Financial Services + +**Suggestion 1** +**FACT:** SEC Rule 17a-4 requires immutable email retention for broker-dealer communications. +**DRIVER:** Exchange on-prem with PST archives does not meet immutability requirements — license compliance status gap before next audit. +**ANGLE:** Your PST files don't meet SEC 17a-4. +**SOLUTION:** Exchange Online migration + litigation hold + retention policies +**PERSONA:** CISO, C-level — owns risk register; compliance gaps are their problem + +**Suggestion 2** +**FACT:** GLBA requires financial institutions to disclose to customers where their nonpublic personal info is stored. +**DRIVER:** File servers with open permissions cannot demonstrate controlled access to customer data — seat penetration of governance tools at 0%. +**ANGLE:** GLBA says tell customers where their data lives. Can you? +**SOLUTION:** SharePoint Online migration + sensitivity labels + DLP +**PERSONA:** Chief Compliance Officer, C-level — signs attestations; personally liable + +**Suggestion 3** +**FACT:** SOX requires auditable controls over financial data storage; SharePoint 2016 extended support ends October 2026. +**DRIVER:** SharePoint on-prem has no native audit trail for document access — active usage rate on modern governance tools is zero. +**ANGLE:** Your SOX auditor will ask where financial docs live. +**SOLUTION:** SharePoint Online migration + Purview audit + retention policies +**PERSONA:** CFO, C-level — audit committee pressure; licensing waste + +--- + +### Healthcare + +**Suggestion 1** +**FACT:** HIPAA Security Rule requires documentation of where all ePHI is stored, transmitted, and accessible. +**DRIVER:** SharePoint on-prem with patient documents has no sensitivity labeling — license utilization on compliance features is 0%. +**ANGLE:** HIPAA says know where every patient document lives. Do you? +**SOLUTION:** SharePoint Online migration + sensitivity labels + classification +**PERSONA:** CIO, C-level — risk, cost, board-level outcomes + +**Suggestion 2** +**FACT:** HIPAA Breach Notification requires 60-day response; breach reporting requires knowing what data was exposed. +**DRIVER:** File servers with no data classification mean exposed data cannot be identified within required timelines. +**ANGLE:** Sixty days to report a breach. Unclassified files make that impossible. +**SOLUTION:** M365 tenant governance + Purview data classification + DLP +**PERSONA:** CISO, C-level — owns risk register + +**Suggestion 3** +**FACT:** HITECH Act extends HIPAA penalties; "willful neglect" includes knowing patient data is on unprotected systems and not acting. +**DRIVER:** Documented awareness of unprotected file servers without remediation qualifies as willful neglect under HITECH. +**ANGLE:** Knowing the risk and not migrating is willful neglect under HITECH. +**SOLUTION:** SharePoint Online migration + Exchange Online + retention policies +**PERSONA:** Chief Compliance Officer, C-level — signs attestations + +--- + +### Government / Education + +**Suggestion 1** +**FACT:** Texas HB 4390 and TX DIR require state agencies and contractors to disclose data storage locations and demonstrate data governance. +**DRIVER:** On-prem systems with no inventory cannot respond to data location requests within required timelines. +**ANGLE:** Texas privacy law requires you to disclose where citizen data is stored. +**SOLUTION:** M365 GCC migration + Purview for data governance + DLP +**PERSONA:** CIO / IT Director, VP-level — migration backlog; team is underwater + +**Suggestion 2** +**FACT:** FERPA requires educational institutions to protect student records and limit access to authorized personnel only. +**DRIVER:** SharePoint on-prem with open permissions cannot demonstrate controlled access — no audit trail for who accessed student records. +**ANGLE:** FERPA requires controlled access to student records. Open SharePoint doesn't qualify. +**SOLUTION:** SharePoint Online migration + sensitivity labels + access reviews +**PERSONA:** IT Director, Director-level — timelines, resourcing, initiative success + +**Suggestion 3** +**FACT:** SharePoint 2016 extended support ends October 2026. Government procurement cycles require 6–12 months lead time. +**DRIVER:** If migration hasn't started by Q2 2026, the agency will be running unsupported infrastructure during the next fiscal year. +**ANGLE:** SharePoint 2016 support ends in 8 months. Procurement takes 6. +**SOLUTION:** SharePoint Online migration + tenant governance +**PERSONA:** CIO, C-level — strategic alignment, vendor risk, change management + +--- + +## Next Steps + +1. **Tech stack discovery.** Run `python3 scripts/detect_tech_stack.py` against each company's website to confirm or deny legacy signals. +2. **Buying committee research.** Use LinkedIn Sales Navigator with filters: Employee Count 500–700 or 2,000+, Headcount Growth >10%, Industries as listed. +3. **Job posting scan.** Search each company's careers page for "SharePoint," "M365," "Exchange," "cloud migration," "Power Platform" to confirm initiative signals. +4. **Prioritize Tier 1.** Build BIPS extraction and buying committee matrix for all 44 Tier 1 accounts first. +5. **Cadence assignment.** Map each Tier 1 account to the appropriate value-first campaign from `outbound/value-first-campaigns/`. + +### Regeneration Commands + +```bash +# Refresh Austin Chamber directory data +python3 scripts/scrape_austin_chamber.py --categories 328 323 326 330 + +# Export leads to markdown +python3 scripts/export_austin_leads.py --refresh --categories 328 323 326 330 + +# Enrich with tech stack detection +python3 scripts/enrich_leads_with_tech.py --limit 20 + +# Run lead analysis +python3 scripts/analyze_atx_leads.py +``` + +--- + +## Data Quality Notes + +| Field | Status | Action Required | +|---|---|---| +| Company names | Confirmed from Austin Chamber, public sources, CRM data | None | +| Employee counts | Estimated bands only | Confirm via LinkedIn Sales Navigator or annual reports | +| Tech stack | Not confirmed for any company | Run tech stack detection; scan job postings | +| Compliance triggers | Mapped from industry regulations | Verify applicability per company | +| Budget owners | Not identified | Research via LinkedIn org charts | +| Initiative signals | Not detected | Scan job postings, 10-K filings, press releases | + +**Source citations:** Austin Chamber directory (austinchamber.com), CRM win rate data (Oops.csv, n=562), inbound patterns (Inbound.xlsx, n=550), SEC EDGAR (public company filings), regulation text (HIPAA, SOX, GLBA, FERPA, TX HB 4390).