London, 10th September 2026
The investment funds sitting closest to Britain's most valuable early-stage intellectual property are, on average, the least equipped to protect it, according to a new study by the London-based risk intelligence and cybersecurity firm Thomas Murray.
The study, Out of Sight: The State of Cybersecurity in the Private Equity Industry, is an interim report analysing the external cybersecurity posture of 558 of the world's leading private equity and venture firms using entirely outside-in data. It found that the smallest managers have the weakest security of any group in the market: a quarter of UK growth and venture investors (below $1bn AUM) currently fall short of the "good" threshold which Thomas Murray advises its institutional clients to require of their managers.
This disproportionately affects the United Kingdom. The UK is home to the largest concentration of these smaller funds, more than a quarter of those analysed, reflecting the reality that Britain’s venture and growth capital ecosystem is the most active in Europe, particularly with university spin-outs from Oxford, Cambridge and London's "golden triangle."
These funds are not weaker, on average, than their European counterparts – they are, in fact, slightly stronger – but Britain’s exposure to the IP-intensive companies backed by these investors makes their weak average cybersecurity posture a more acute risk to the UK economy.
These are precisely the investors sitting on the boards of the earliest-stage companies in the sectors on which the UK’s industrial strategy depends: deep tech, life sciences, AI, quantum and semiconductors. In these companies, the entire value of the business is its research and its intellectual property, often before that IP is fully protected in law.
This is a concern for British growth, not just its investment industry
If the UK venture and growth capital industry has a cybersecurity problem, then it is a problem for the UK economy. IP-intensive industries account for between 25% and 40% of UK GDP, according to different measurements, and these are exactly the companies created and backed by early-stage capital.
The primary risk uncovered by this study is that the capital base closest to the UK's most valuable emerging technology might also be the least protected point in the chain. The threat actors most interested in Western early-stage IP are increasingly nation-state-backed or aligned and are among the most sophisticated and patient adversaries in the cyber landscape, interested not in cash but in the technology itself. The Five Eyes intelligence alliance has issued a joint public warning about a sharp rise in state-backed efforts to steal competitive advantage from emerging technology companies, singling out AI, quantum computing and synthetic biology.
There is a tension here for policy makers: the UK's growth strategy, like Europe's, depends on channelling further capital into companies that are being actively targeted by state-aligned threat actors and opportunistic cyber criminals. A growth strategy that fails to protect this innovation risks sacrificing at least a portion of its innovation to those who are willing and able to steal it. The investors who back and sit on the boards of these companies, often choosing and coaching their senior directors, are precisely the stakeholders who should understand and promote security governance. This, among other findings, is the gap identified in Thomas Murray’s study.
Comment from the Managing Director of Thomas Murray Cyber Risk
“I spent years as the Departmental Security Officer at the UK’s Intellectual Property Office arguing that cybersecurity had to be part of how we protect the UK's intellectual property, not an afterthought to the legal framework of patents and filings. This data is, in a sense, the evidence I did not have then. The fastest way to lose a breakthrough today is not to have it copied through the courts, it is to have it taken off a poorly defended server. Early-stage founders are rightly focused on proof of concept, and security is not on the list. What is harder to forgive is that the investors backing them, sitting on their boards and holding their most sensitive data, so often do not take even their own security seriously. These funds are custodians of national IP whether they realise it or not. The encouraging part is that the weaknesses we found are basic and fixable. This is not about defending against the impossible, it is about closing doors that should never have been left open.”
Ioan Peters, Managing Director, Thomas Murray Cyber Risk
Comments from the authors of the study
"Cybersecurity risk is often characterised as 'vulnerability × likelihood = risk'. Vulnerability is the thing most companies can control — security governance, controls, technical configuration, and the size of the external attack surface, among other variables. Likelihood, by contrast, is largely a function of a company's sector and geography: two firms with an identical technical profile can face radically different threat levels depending on whether one is a UK biotech firm developing novel IP and the other a Swiss farming conglomerate.
This study is our first attempt at a data-driven analysis of the vulnerability side of that equation across the global private equity market. What it has uncovered should interest —and perhaps worry — UK policy makers. The pattern is uncomfortable but consistent: the smaller the fund — venture and growth vehicles most acutely — the weaker the defences. If the growth of the UK economy depends on IP-intensive, innovative industries, then the venture and growth investors who fund them need to take their own security more seriously. Neither they nor their portfolio companies can rely on obscurity, and baseline or 'compliance-adequate' security is not enough. They are investing in the companies that global threat actors are most interested in; their security needs to be exceptional.”
Roland Thomas, Director and Edward Starkie, Director
About the study
Out of Sight is the first data-led cybersecurity analysis of the private equity and venture industry, covering 550+ of the largest firms globally. Each firm is scored from 0–1000 on external security posture using only publicly-observable data, combined with dark-web exposure monitoring. The study is anonymised: no firm is identified by name except where a breach has already been publicly disclosed. It forms the basis of the Thomas Murray Private Equity Cyber Index, a continuously maintained benchmark that the firm's LP clients use to assess where their managers sit relative to the industry. A future instalment will extend the analysis into the portfolio companies themselves.
About Thomas Murray
Thomas Murray is a risk-intelligence and cybersecurity firm serving the investment industry since 1994. Its cybersecurity services help limited partners assess and benchmark their managers, and general partners assess, benchmark and improve the security posture of their portfolios.
Media Contact
Amie Johnstone
Head of Marketing and Communications, Thomas Murray




