Skip to main content

Private Equity has become much better at assessing cyber risk, but it may be looking in the wrong place. 

Cyber due diligence still tends to focus on individual portfolio companies: assess the business, identify weaknesses, remediate them and monitor progress. Whilst this matters, it misses a bigger risk. 

What happens when those individual cyber risks are aggregated across an entire portfolio?

As private markets become larger and more interconnected, the portfolio, not simply the portfolio company, needs to become a unit of cyber risk analysis.

The risk already exists

This is not a new risk created by secondaries, NAV financing or insurance capital, it occurs naturally within private equity, and is often the product of established playbooks and ways of working. Every acquisition adds another technology estate, another set of suppliers and another web of dependencies to the portfolio. Individually, those companies may look diversified. Collectively, they may not be, and the buy-and-build strategies and shared operating models central to private equity are likely to make that concentration more pronounced over time. Ten businesses might depend on the same cloud provider. Fifteen might use the same identity platform. Multiple funds may rely on the same administrator, payment provider or critical software. The result is simple: 

Financial diversification does not necessarily mean cyber diversification. 

50 acceptable companies do not necessarily make an acceptable portfolio

Consider a hypothetical portfolio of 50 companies, each assessed during due diligence. Each has been independently reviewed, each has reasonable cyber controls and none represents an unacceptable individual exposure. That sounds reassuring. However, the issues frequently lie beneath the individual asset. If 30 companies depend on the same cloud platform, 20 use the same identity provider, or businesses representing 40% of portfolio NAV rely on a small number of critical technology suppliers, a major incident affecting one of those dependencies could hit multiple investments simultaneously. The problem is no longer simply vulnerability; it is correlation. 

Private markets are making the issue harder to ignore

The rapid growth of the secondaries market makes this particularly relevant, and the implications extend beyond the private equity firm to the wider parties and industries connected to it. Secondaries vehicles can aggregate exposure across hundreds of funds and thousands of underlying companies. Structured financing and insurance capital increasingly sit above those portfolios. 

 

Financially, these structures can create diversification and liquidity. Operationally, however, the same underlying technology dependencies remain unmanaged, and may be growing. A cyber event originating deep within the portfolio, or at a provider shared across it, could have consequences much further up the investment structure. The more interconnected private markets become, the more important it is to understand the cyber risk sitting beneath them. 

The answer: Stop looking at cyber risk one company at a time

The answer is not to abandon company-level cyber assessment; it is to build on it. Where individual companies are already assessed against a consistent cybersecurity framework, their scores become the building blocks for understanding the portfolio. Those scores must, however, be supplemented and kept up to date.

Instead of asking only:

"What is the cyber risk of the company"

Investors can begin asking:

"What is the cyber risk of the portfolio"

That means combining cyber data with investment information to understand: 

  • How much NAV sits in weaker cyber-rated companies
  • Where the largest cyber exposures exist
  • Whether overall portfolio resilience is improving
  • Which companies share critical dependencies 
  • Where technology concentration is building
  • Which cyber scenarios could affect multiple investments simultaneously

The portfolio becomes the risk picture

A portfolio could have a strong average cyber resilience while remaining heavily dependent on one critical provider. Two dimensions therefore matter: 

  • Resilience: How well are individual companies managing cyber risk? 
  • Concentration: Where do those companies share common dependecies?

Private equity already understands portfolio risk. Investment teams monitor concentration by sector, geography, leverage, customer and currency. Cyber and technology dependency should join that list.

 

The next question for Private Equity 

Private equity did not deliberately create aggregated cyber risk. It emerged naturally as portfolios became larger, technology became more concentrated and investment structures became more interconnected. PE firms increasingly know a great deal about the cyber posture of individual portfolio companies. The next challenge is understanding what those companies look like together. The cyber event that matters most may not be the one that comprises the weakest company. It may be the one that compromises something 20 companies depend on at the same time. 

The question for investment committees is there for changing. 

Not simply: 

"Are our portfolio companies managing cyber risk?"

But:

"Do we understand the cyber risk of the portfolio?"

How Thomas Murray supports portfolio-level cyber risk oversight

Thomas Murray helps private equity firms manage cyber risk across the deal lifecycle, from pre-acquisition due diligence to portfolio-wide monitoring and exit readiness. By rating portfolio companies on a consistent basis and mapping the dependencies they share, we help investment teams see where resilience is building and where concentration is forming. Speak to our experts to discuss how a portfolio view of cyber risk could support your investment committee. 

Private Equity Cyber Risk Checklist

Private Equity Cyber Risk Checklist

Our PE Cyber Risk Checklist is a ten-step diagnostic for PE fund leadership, covering every stage from pre-deal surveillance to exit readiness. Work through it and know exactly where your gaps are.

  • 10 steps across five phases - deal, first 100 days, portfolio ownership, ESG, and exit.
  • Self-assessment at every step - rate your current position and walk away with a clear gap count.
  • Written for fund leadership, No jargon. Financial language throughout.
Download now