What Private Equity Firms Learn When They Assess Every Portfolio Company the Same Way

The most useful thing a private equity firm can learn about cybersecurity in its portfolio is not how bad any single company is. It is how the companies compare.

That sounds like a small distinction. It changes everything about how the assessment gets built.

A deep, bespoke security assessment of one portfolio company produces a document that is accurate, thorough, and almost impossible to act on at the fund level. It tells an operating partner that Company A has gaps in identity management and vendor oversight. Fine. Is that worse than Company B? Is it worse than it was six months ago? Is it the sort of thing three other companies also have, which would make it a fund-level program rather than a company-level project? The bespoke report cannot answer any of those questions, because there is nothing to compare it to.

Comparability is the product. Depth is a means to it.

The one-off diligence assessment has a short half-life

Most PE firms already buy security assessments. They buy them during diligence, from whichever firm the deal team likes, scoped to whatever the deal timeline allows. The output lands in the data room, informs a purchase price adjustment or a rep and warranty position, and then it stops being read.

Two things go wrong after close.

The report ages badly. A security posture assessed in March describes a company that has since migrated a workload, onboarded 40 people, changed identity providers, and signed three new vendors. By the time anyone reopens the document it is describing an environment that no longer exists.

And it does not stack. Diligence assessments across a portfolio come from different providers, against different frameworks, with different scoring, at different depths. Twenty of them side by side produce a stack of paper, not a portfolio view. An operating partner cannot rank them, cannot spot the pattern that appears in six companies, and cannot show a limited partner a defensible fund-level picture.

The firms getting real value from this have stopped treating assessment as a diligence artifact and started treating it as an operating cadence.

PORTFOLIO SECURITY

One Read Across Every Portfolio Company

A Cybersecurity Strategy Assessment run the same way at every company, so the results compare.

Book a Consult Explore Fractional Services →

Pick one framework and do not negotiate it per company

The single highest-leverage decision is committing to one framework across every company in the portfolio, and holding that line when a portfolio company CTO argues for a different one.

For portfolio work, CIS Controls is usually the right choice, for reasons that have more to do with the portfolio than with security theory.

CIS Controls is prescriptive. It describes specific things a company either does or does not do, which produces a score that means the same thing at a 60-person software company and a 900-person healthcare services business. NIST CSF is a stronger framework for building a program, and it is what we use once a company has a security leader driving one, but its outcomes are written to be interpreted in context. Context is exactly what destroys comparability across twenty companies. SOC 2 has the opposite problem: it is an audit of the controls a company chose to describe, so two SOC 2 reports can attest to very different levels of security and look identical to a reader.

CIS Controls also maps cleanly onto NIST CSF, ISO 27001, and most regulatory obligations a portfolio company is going to face. Nobody has to redo the work later. Starting with CIS Controls is not a detour around the framework a company eventually needs. It is the on-ramp.

Separate what a machine can evidence from what needs a person

In a portfolio assessment run at scale, roughly 60 percent of the control set can be evidenced by read-only integrations into the systems a company already runs. Identity provider, cloud platform, endpoint tooling, MDM. Those integrations answer questions like whether MFA is genuinely enforced everywhere rather than configured and bypassed, how many privileged accounts exist, whether logging is on, and what the actual patch state is.

Those answers arrive without a workshop, without a questionnaire, and without a portfolio company employee estimating something from memory. That matters more than it sounds like it does. Self-attested questionnaires are the weakest input in this entire process, and they are what most portfolio assessment programs are built on.

The remaining 40 percent needs a human. Governance, incident response readiness, third-party risk management, whether the security budget survives contact with a bad quarter, whether anybody actually owns the program. No integration reads those. They need somebody experienced asking questions and knowing which answers are rehearsed.

The split matters for economics as well as accuracy. If the evidenced portion is automated, the expensive human hours go where they change the answer. That is what makes it viable to run the same assessment across a whole portfolio rather than the three companies the fund is most worried about.

EVIDENCE, NOT QUESTIONNAIRES

See What Your Controls Actually Do

Read-only integrations evidence most of the control set, and experienced advisors cover the rest.

Request a Cybersecurity Strategy Assessment Explore Fractional Services →

Six months is the cadence that works

Annual is too slow. It produces a document rather than a signal, and it means an operating partner is always looking at a picture of the portfolio as it was.

Continuous monitoring alone is too noisy for fund-level use. It is genuinely valuable at the company level, and every portfolio company should have it, but a fund does not need a stream. It needs a point-in-time score it can put on a page next to nineteen other scores.

Six months does both. The evidenced controls stay live in between, so drift is visible when it happens. The full re-assessment gives the fund a comparable snapshot twice a year, which lines up with how boards and LP reporting actually run. It is also long enough that a company that committed to a remediation roadmap has had a fair chance to execute against it, which turns the second assessment into an accountability conversation instead of a repeat of the first one.

What the fund does with the output

Four things, in practice.

Rank the portfolio and fund the bottom quartile first. Most firms discover the ranking does not match their intuition. The company everybody worried about has a competent director of IT quietly doing the work. The one nobody mentions has no MFA on a system holding customer data.

Find the shared gaps and solve them once. When six companies all lack formal third-party risk management, that is a fund-level program with a negotiated rate, not six separate projects at six separate prices.

Give each company a roadmap its own leadership will actually run. This is where the model earns its keep. An assessment that produces a fund-level score and nothing a company CTO can act on will be resented and quietly ignored. The same assessment that hands that CTO a prioritized roadmap, budget-ready, in a format their own board will accept, gets adopted.

Build the exit story early. Security posture shows up in diligence on the way out. A company that can show two years of assessment history against a recognized framework, with a documented improvement curve, is answering the buyer’s question before it is asked. A company that can show a report from the year it was acquired is not.

The part that is genuinely hard

None of this is technically difficult. The hard part is holding the standard.

Portfolio companies will push back on the framework. Timelines will slip because a CTO is mid-migration. The second assessment will show a company that made no progress at all, and somebody has to have that conversation with a CEO who has eleven other priorities and a number to hit.

That is a governance problem, not a security problem, and it is the reason portfolio security programs stall. The firms that get this right treat the assessment cadence the way they treat financial reporting. It happens on schedule, the format does not change to suit the company, and the results go to the same people every time.

Build the Cadence, Not Another Report

Experienced security leadership that meets each portfolio company where it is and builds from there.

Book a Consult