Skip to main content

We recently published ODD is More Than Questionnaires, making the case that operational due diligence has outgrown the traditional annual DDQ and needs to run on multiple, continuously updating signals: financial health, reputational monitoring, and cyber posture, read together rather than filed separately. Cyber was one of three risk categories in that piece. It deserves a closer look on its own, because of the three, it is the one most ODD teams still treat as somebody else’s job.

Somewhere along the way, cybersecurity oversight ended up stranded between two teams that each have a partial claim on it. IT or cybersecurity understands the technical risk but rarely engages with the due diligence process itself. They form a reactive role, not a proactive one. The ODD teams however own the due diligence process but typically lack the technical depth to interrogate what they're being told. So a questionnaire gets sent, the manager's IT or compliance function answers it, and the responses are filed alongside governance and operational risk sections. Job done. In the early years of formalised ODD, that arrangement made reasonable sense - most ODD professionals were never meant to be cybersecurity specialists, let alone specialists that have the time to devote to understanding threats at a granular level and being able to articulate risk to businesses. The end result is that no one actually owns the assessment end-to-end, and the gap between what that process captures and what allocators actually need to know has grown considerably. 

Cybercrime now costs more annually than the GDP of every country on earth except the United States and China, $9.5 trillion in 2024, according to Cybersecurity Ventures. Fund managers sit squarely in the crosshairs. They hold sensitive investor data, process significant financial flows, and frequently operate with IT infrastructure that is leaner, and more exposed, than the institutional allocators placing capital with them. When a manager suffers a serious cyber incident, the operational consequences do not stay contained within the manager's four walls. NAV calculations are disrupted, reporting fails and investor data is compromised. The allocator finds out about it in the worst possible way.

That is an operational risk. It belongs inside the operational due diligence process, not alongside it.

What Cyber Questionnaires Miss in Operational Due Diligence

The standard approach to cyber within ODD is a questionnaire section covering information security policies, incident response procedures, business continuity, and sometimes third-party vendor management. Managers complete it, ODD teams review it and the responses are usually accurate in the narrow sense that they describe what the manager says is in place. The problem, as we touched on in our last article, is that what a manager says about their cyber posture and what their external attack surface actually looks like are regularly two different things. It is worth setting out exactly what that gap looks like in practice, because it is more specific, and more common, than most allocators assume. Adopting a “trust but verify” mentality is possible in some cases.

Take email security. A manager's questionnaire will ask if email authentication controls are in place, and the compliance team believes that to be true. Independent checks of the manager's DNS (Domain Name System) records tell a different story more often than you would expect: no DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy enforced, or one set to “none” rather than “reject,” meaning spoofed emails from the manager's own domain would sail through a recipient's inbox. That is one attack vector used in business email compromise (BEC) attacks, one of the most common causes of fraudulent wire transfers in the asset management industry, and it is invisible to a questionnaire because nobody thought to ask the DNS servers instead of the compliance officer.

Take exposed infrastructure. A questionnaire response describes robust access controls, asset hardening and a proactive stance towards restricting the use of unauthorised technologies - fantastic. A technical scan reveals remote desktop protocols open directly to the internet, one of the most common entry points for threat actors who frequently seek to deploy ransomware or launch other types of attacks. In other cases, a manager has documented their own security framework in reasonable detail but has not mapped the security posture of the third-party technology providers their operations depend on, so the questionnaire is accurate about the manager and silent about the supply chain sitting underneath it. The M&S and Jaguar Land Rover incidents of last year both used weaknesses within trusted third parties.

None of this is necessarily the result of bad faith. Questionnaire responses reflect what compliance and IT teams believe to be true- at the moment they are asked. But belief and verified reality are different things, and the gap between them is precisely where operational risk lives in a cyber due diligence context.

As briefly touched upon, there is a timing problem. A questionnaire captures a point in time. A manager's external attack surface changes continuously; new services are constantly deployed, vulnerabilities are disclosed (currently we are seeing a deluge driven by new tooling and techniques), and suppliers are onboarded. An annual questionnaire cycle, or even a six-monthly one, cannot track that rate of change. 

The Regulatory Direction of Travel

Regulators have been watching this gap widen, and their response has become progressively more prescriptive. DORA, the EU's Digital Operational Resilience Act, came into force in January 2025. It explicitly requires financial entities to assess the digital operational resilience of their third-party service providers, not just ask them about it, but assess it. Fund managers are service providers. That assessment obligation sits with the allocator.

The FCA has signaled equivalent expectations for UK-regulated firms. APRA's CPS 230, which took effect in Australia in 2024, requires material service providers to be subject to ongoing monitoring, with documented processes for identifying and responding to operational risk. Cyber risk is specifically within scope.

The direction is consistent across jurisdictions, and it is the same direction we flagged across financial and reputational monitoring in our previous piece: passive, point-in-time assessment is being replaced by an expectation of active, evidenced oversight. Allocators who rely on a completed DDQ section to satisfy this requirement are likely to find that position increasingly difficult to defend to regulators, investment committees, and eventually to beneficiaries.

It is worth being direct here: many allocators are behind where they need to be. The questionnaire approach has been the industry norm for long enough that change is slow, and ODD teams are already stretched. But the regulatory timeline does not accommodate the pace of institutional inertia.

What Continuous Cyber Monitoring Actually Looks Like

External attack surface assessment works differently from a questionnaire. Rather than asking a manager what controls they have in place, it involves independent technical scanning of what is actually visible and accessible from outside the organisation. This covers exposed services and open ports, certificate validity and configuration, email security standards such as DMARC and SPF (Sender Policy Framework), known software vulnerabilities mapped to public databases, and dark web monitoring for compromised credentials associated with the organisation.

The output is a risk score, generated from observed evidence rather than self-reported responses. Crucially, because the underlying data changes as the attack surface changes, the score updates continuously. A manager who scores well in January may have a materially different profile in March, following a new system deployment or a supplier breach. Continuous monitoring means that deterioration is visible as it happens, not twelve months later at the next annual review.

This is where the managed service model becomes relevant. Operational Due Diligence teams are not expected to run technical security assessments themselves. Thomas Murray's Orbit Security module, for instance, generates independent cyber risk scores based on external scanning and surfaces the outputs in risk terms that an ODD analyst can act on directly, no cybersecurity expertise required. The specialist work is done; the ODD team receives the findings in the same format as the rest of their monitoring programme, and, as we discussed in relation to financial and media signals, it slots into a single monitoring view rather than sitting apart from it.

That matters because the practical barrier to integrating cyber into ODD is rarely a question of willingness. It is a question of capacity and expertise, and a managed approach removes both constraints.

Building Cyber Risk into the Operational Due Diligence Process

What this means in practice is a shift from treating cyber as a section of a periodic questionnaire to treating it as a continuous monitoring signal alongside financial health, governance, and operational risk, the multi-signal model we set out in our previous article. An Operational Due Diligence process fit for the current environment monitors manager cyber posture on an ongoing basis, flags material deterioration between review cycles, and provides documented evidence of independent assessment that satisfies regulatory expectations. The reality is that there are so many variables, that mean the threat landscape and risk profile of an organisation is constantly changing. 

Investment committees are asking harder questions about operational oversight than they were five years ago. Trustees are being held to a higher standard of documented diligence. The allocators who will find the transition easiest are those who have already embedded cyber into their fund manager risk frameworks, not as a quarterly box-tick but as a live data feed with clear escalation protocols.

The questionnaire will not disappear, it remains a useful baseline and a documented record of manager representations, a line in the sand, a starting point. To use a nautical analogy the questionnaire is the initial forecast the captain would consult before setting sail- but for a long journey of many miles across an unpredictable ocean you would hope, (expect and possibly pray) that the captain is conducting ongoing checks and not relying on the initial weather forecast. On cyber specifically the landscape is not only changing at speed, influenced by both geopolitics and the pace of technological advancement, it is also the least reliable part of the ODD toolkit. The gap between what is reported and what is real is verifiable within minutes, by anyone running the right scan, the results understandable when presented in the correct platform, and the implications of it understood when shaped by industry experts.

We haven’t even discussed what is expected or even reasonable to expect of the organisations you are assessing, or to put it another way, how much security is required, and in what form- this is a huge question, and is one that we will tackle in a separate article.

For a fuller view of how cyber sits alongside financial and reputational monitoring in a modern ODD framework, Thomas Murray's Playbook for Asset Owners and Allocators covers the fundamentals in full. 

Operational Due Diligence

Operational Due Diligence

Automate your operational due diligence with Orbit Risk technology. 

Get ongoing monitoring of your investment managers, track adverse media, and receive cyber risk alerts as they happen.

Learn more