We work the four moments a fund already works: diligence before close, the first hundred days, the hold, and the run-up to exit. One firm across the portfolio, with a security leader assigned to each company that needs one and reporting in a single format. Most funds start with a five-company assessment, explained below.
A one-time assessment is a poor fit for how a fund holds a company, so the practice is structured around the timeline you already run.
Security liabilities, compliance gaps, AI exposure, data handling, technical debt, incident history, vendor risk. Written for an investment committee, delivered on your timeline, with a remediation cost estimate you can underwrite instead of a list of findings you can't price.
The one window in which a management team will accept change. Governance, policy, MFA and identity, endpoint, backup, monitoring, a compliance roadmap, and AI governance stood up before the company gets busy again.
Retained monthly, per company. Somebody named who knows the environment, attends the board meeting, answers the security questionnaires that are holding up enterprise deals, and calls you before you hear it from somewhere else.
We run the company through the diligence a buyer will run, twelve months early, so the findings that would have become price adjustments get fixed while they're still cheap. This work is far cheaper a year out than during the sale process.
Security budgets get re-argued every year because they only show up as cost. The table below maps the work to the lines a fund already measures.
Kroll surveyed 325 portfolio leaders across six countries in December 2025. The $2.1 million hold-period figure is from the same study. Every statistic on this site is cited to its source.
Managed IT with a security line item is not the same thing as cyber readiness. What has changed underneath your companies in the last eighteen months is AI, and in most portfolios nobody is governing it. IBM's 2026 research put shadow AI in 43% of security incidents, roughly double the year before, with more than two thirds of organizations having nothing in place to limit unauthorized AI use.
Note-takers sit in board meetings, LP updates and diligence calls, keeping recordings nobody has reviewed. In 2024 a VC firm's assistant emailed a founder the transcript of what the partners said after he dropped off, and he walked away from the deal. Boards are getting formal legal advice on this now.
Companies building AI features inherit an attack surface that didn't exist when you invested. Prompt injection, agents holding credentials nobody can audit, model supply chain, MCP servers wired into production. We red team it and build the governance an enterprise buyer will ask to see.
Buyers have worked out that a vendor's SOC 2 says nothing about what downstream model providers do with data. Auditors are already asking for AI data-flow evidence, and an ISO 42001-aligned AI program is turning into a credential that unblocks enterprise sales rather than a compliance chore.
Diligence is quoted per deal against your timeline. Everything after close is a monthly retainer per company, priced on size and risk, and it improves as more of the portfolio comes on.
Five portfolio companies, assessed together. Each one gets a cyber and AI risk assessment, an executive scorecard and a 90-day roadmap. You get a heatmap across all five, which is usually the first time anyone has seen the portfolio's risk side by side. Companies that need ongoing work convert to a monthly retainer. Companies that come out clean are finished after the assessment.
Retainers run month to month after an initial term. ACA's 2026 benchmarking of 300+ portfolio companies found that those under structured monitoring for a year or more were twice as likely to reach a low-risk rating, which is the case for retaining somebody rather than buying a one-off project.
In In re PowerSchool Holdings (S.D. Cal., March 18, 2026), a federal court allowed negligence and aiding-and-abetting claims to proceed against the private equity owner of a breached portfolio company. The court found it plausible that the sponsor had exercised control over the company's cybersecurity decisions, including cost cuts to the security team, and that some of the conduct at issue predated the closing.
It is a ruling on a motion to dismiss, not a finding of liability. It is also the first time a court has let a portfolio company's breach follow the money to the investor, and the company in question was the student information system used by thousands of school districts, including many in our client base. Most funds exercise that same kind of control through board seats and operating partners.
Assess five companies together, see the heatmap, and decide from there which ones need somebody retained. If none of them do, you still have the report.