TriVigil Free Consultation
Why TriVigilWhat actually makes us different Our ServicesTwelve domains, one agreement Education Small & Medium Business Investors & Portfolio Companies About UsOur story Leadership Team News & Resources Contact Schedule a Free Consultation
Home  /  Who We Serve  /  Investors & Portfolio Companies

Cyber and AI risk across a portfolio, from diligence to exit.

We work the four moments a fund already works: diligence before close, the first hundred days, the hold, and the run-up to exit. One firm across the portfolio, with a security leader assigned to each company that needs one and reporting in a single format. Most funds start with a five-company assessment, explained below.

The lifecycle

The four moments

A one-time assessment is a poor fit for how a fund holds a company, so the practice is structured around the timeline you already run.

BEFORE CLOSE

Cyber and AI diligence

Security liabilities, compliance gaps, AI exposure, data handling, technical debt, incident history, vendor risk. Written for an investment committee, delivered on your timeline, with a remediation cost estimate you can underwrite instead of a list of findings you can't price.

0–100 DAYS

Security transformation

The one window in which a management team will accept change. Governance, policy, MFA and identity, endpoint, backup, monitoring, a compliance roadmap, and AI governance stood up before the company gets busy again.

THE HOLD

Managed security and fractional CISO

Retained monthly, per company. Somebody named who knows the environment, attends the board meeting, answers the security questionnaires that are holding up enterprise deals, and calls you before you hear it from somewhere else.

BEFORE EXIT

Exit readiness

We run the company through the diligence a buyer will run, twelve months early, so the findings that would have become price adjustments get fixed while they're still cheap. This work is far cheaper a year out than during the sale process.

Why the framing matters

Where the spend shows up

Security budgets get re-argued every year because they only show up as cost. The table below maps the work to the lines a fund already measures.

Line
What we do
Where it shows up
Revenue
Get a company through enterprise security review and the certifications its buyers demand, and answer the questionnaires for the sales team.
Deals unstick in procurement. Usually the fastest return in the engagement, and the one a CEO notices first.
Multiple
Run the company clean through diligence so a buyer's technical review turns up nothing that becomes a negotiating lever.
Exit price. Kroll found 26% of firms saw a reduced valuation or exit price tied to cyber findings.
EBITDA
Prevent the incident. Then cut the duplicate tooling you're paying for three times across three companies.
Avoided cost. Average cyber impact during the hold period runs around $2.1 million.
Your time
One security leader per company, one control baseline, one reporting format across the fund.
Operating partner hours, and a board packet somebody else assembles.

Kroll surveyed 325 portfolio leaders across six countries in December 2025. The $2.1 million hold-period figure is from the same study. Every statistic on this site is cited to its source.

The wedge

Every company you back is an AI company now, whether or not that was the thesis.

Managed IT with a security line item is not the same thing as cyber readiness. What has changed underneath your companies in the last eighteen months is AI, and in most portfolios nobody is governing it. IBM's 2026 research put shadow AI in 43% of security incidents, roughly double the year before, with more than two thirds of organizations having nothing in place to limit unauthorized AI use.

IN YOUR OWN ROOM

The calls you're already on

Note-takers sit in board meetings, LP updates and diligence calls, keeping recordings nobody has reviewed. In 2024 a VC firm's assistant emailed a founder the transcript of what the partners said after he dropped off, and he walked away from the deal. Boards are getting formal legal advice on this now.

IN THE PORTFOLIO

What they're shipping

Companies building AI features inherit an attack surface that didn't exist when you invested. Prompt injection, agents holding credentials nobody can audit, model supply chain, MCP servers wired into production. We red team it and build the governance an enterprise buyer will ask to see.

AT EXIT

The new diligence question

Buyers have worked out that a vendor's SOC 2 says nothing about what downstream model providers do with data. Auditors are already asking for AI data-flow evidence, and an ISO 42001-aligned AI program is turning into a credential that unblocks enterprise sales rather than a compliance chore.

See the full AI security catalogue

Pricing

Published pricing.

Diligence is quoted per deal against your timeline. Everything after close is a monthly retainer per company, priced on size and risk, and it improves as more of the portfolio comes on.

Portfolio AI & Cyber Risk Assessment
The way most funds start. One company, or five at once.
$2,500–$5,000per companyBoard-ready report
  • AI tools in use, including shadow AI
  • Sensitive data exposure and AI vendor risk
  • Identity, MFA, endpoint, backup and recovery
  • Compliance exposure and cyber insurance gaps
  • Executive risk score and 90-day remediation plan
Most common
Portfolio AI + Cyber Secure
The managed program for a company through the hold period.
$3,000–$5,000/ month, per companyEverything in the assessment, run continuously
  • AI governance and employee AI policy
  • AI security and awareness training
  • Security monitoring and SOC coverage
  • Vulnerability management
  • Compliance support and vendor risk
  • Incident response planning
  • Quarterly executive review
Portfolio vCISO
For the larger or higher-risk companies, and anything heading toward a sale.
$5,000–$10,000/ month, per companyA named security executive
  • Fractional CISO and security strategy
  • Board reporting and compliance leadership
  • Security architecture, SOC and SIEM oversight
  • Penetration testing and incident response
  • Cyber insurance renewal and control validation
  • AI governance and M&A security assessments
Where most funds begin

The five-company portfolio assessment: $25,000

Five portfolio companies, assessed together. Each one gets a cyber and AI risk assessment, an executive scorecard and a 90-day roadmap. You get a heatmap across all five, which is usually the first time anyone has seen the portfolio's risk side by side. Companies that need ongoing work convert to a monthly retainer. Companies that come out clean are finished after the assessment.

Retainers run month to month after an initial term. ACA's 2026 benchmarking of 300+ portfolio companies found that those under structured monitoring for a year or more were twice as likely to reach a low-risk rating, which is the case for retaining somebody rather than buying a one-off project.

The part that changed

In March 2026, the exposure reached the sponsor.

In In re PowerSchool Holdings (S.D. Cal., March 18, 2026), a federal court allowed negligence and aiding-and-abetting claims to proceed against the private equity owner of a breached portfolio company. The court found it plausible that the sponsor had exercised control over the company's cybersecurity decisions, including cost cuts to the security team, and that some of the conduct at issue predated the closing.

It is a ruling on a motion to dismiss, not a finding of liability. It is also the first time a court has let a portfolio company's breach follow the money to the investor, and the company in question was the student information system used by thousands of school districts, including many in our client base. Most funds exercise that same kind of control through board seats and operating partners.

Start with the five that worry you most.

Assess five companies together, see the heatmap, and decide from there which ones need somebody retained. If none of them do, you still have the report.