Every framework a private equity firm runs; counterparty exposure, operational resilience, third-party monitoring, assumes a consistent level of vigilance on the other side of the relationship. A portfolio company’s security team is watching. A target’s IT function is available to answer diligence questions. A vendor’s incident response desk is staffed.
For roughly eight weeks a year, that assumption weakens considerably, and almost nobody adjusts for it.
Summer doesn’t change the threat landscape. It changes the capacity to respond to it at exactly the moment deal activity, portfolio oversight, and vendor dependencies continue as normal. The gap between “risk level” and “coverage level” is where losses tend to originate, and it’s rarely visible in a standard risk register.
The scale of what’s at stake isn’t abstract. Independent research commissioned by the UK’s department for Science, Innovation and Technology puts the average cost of a significant cyber-attack to a UK business at almost £195,000, scaling to an estimated £14.7 billion a year across the economy, or 0,5% of GDP1. For a portfolio company already operating on thin margins, or a deal team relying on a clean diligence picture to underwrite valuation, that’s not a rounding error.
The Portfolio Company Problem: Reduced Security Coverage, Same Threat Level
Most portfolio companies are not run by security-first management teams. Cyber resilience typically depends on a small internal IT function, sometimes a single security lead (frequently viewed as a “side of desk activity”), and possibly an outsourced MSP. During summer, that already thin coverage gets thinner with annual leave rotations, reduced on-call capacity, and a reliance on seasonal or temporary staff who haven’t been through the same access and awareness controls as permanent employees.
None of this shows up in a quarterly board pack. Value creation teams reviewing portfolio company performance are typically looking at revenue, margin and operational KPIs and not whether the security function is fully staffed in August. The assumption that “it’s handled” is rarely tested and ultimately realised until it is confirmed by an incident.
This matters because attackers are not operating on the same assumption of a quiet season. Ransomware groups and phishing campaigns show consistent seasonal patterns, often timed deliberately around periods when organisations are known to be short-staffed and slower to detect or escalate. A portfolio company that looked adequately protected in Q1 can be a materially softer target in Q3, with no change to its actual security posture, only to who is watching it.
How increased risk manifests itself
Concretely, the summer risk window tends to show up in a few consistent forms:
- Phishing volume increases, often disguised as travel, delivery or IT helpdesk communications designed to catch employees who are moving faster and paying less attention.
- Detection and response times lengthen, simply because fewer people are monitoring alerts and escalation paths are slower to activate.
- Third-party and vendor risk goes unmonitored, as the personnel responsible for tracking vendor security posture are themselves on leave, creating a blind spot exactly where portfolio companies are often weakest.
- Temporary and seasonal hires expand the attack surface, particularly in portfolio companies with retail, hospitality, or logistics operations that scale up headcount for summer demand.
None of this requires a new category of threat. It’s the same risk, moving through a temporarily weaker set of defenses.
The pattern is well documented in sectors that track it closely. In hospitality, 90% of North American hotel IT and cybersecurity leaders reported at least one attempted cyber-attack during 2024 summer season with 66% saying attack frequency increases during summer and 50% reporting increased severity.2 Portfolio companies rarely track this metric at all, which is precisely the problem: the absence of data does not mean the absence of the pattern, only the absence of visibility into it.
The pattern held up again in 2025, closer to home. Jaguar Land Rover was hit by a major cyberattack beginning 31 August, right at the tail end of the UK summer holiday period, forcing the company to pause production the next day. The resulting disruption to its systems and supply chain ran for roughly five weeks, with knock-on effects across hundreds of suppliers and dealers dependent on JLR's operations. It's a useful case precisely because the target wasn't a niche or unprepared business, it was a major well-resourced manufacturer, and the disruption still cascaded for over a month.3 For a PE-backed business of any size, the lesson isn't “this only happens to careless companies.” It's that scale and resources don't remove the exposure that opens up when an incident lands during a low-coverage period.
A Framework for Assessing Portfolio Company Resilience Year-Round
The fix isn't a seasonal campaign, it's treating cyber resilience the way PE firms already treat other forms of operational and counterparty risk: continuously monitored, not periodically assessed.
A useful starting framework for risk and portfolio teams:
- Baseline every portfolio company's security coverage model, not just its tools, but who is actually responsible for monitoring and response, and what happens when they're unavailable.
- Understand portfolio company cyber security reporting. Performance of strategic initiatives is vital to the long-term success of cyber security within an organization, but operational control performance is vital to ensuring boards have visibility of cyber security risk within their business- the second is frequently overlooked.
- Ask for continuity plans, not just policies. A security policy that assumes full staffing isn't a plan. Request specifics on coverage during leave periods, especially for detection and incident response.
- Extend diligence rigor into the hold period. The scrutiny applied pre-deal shouldn't disappear post-close; portfolio companies benefit from the same standard of assessment applied consistently, not just at acquisition.
- Develop support mechanisms for portfolio companies. PE firms are excellently placed to provide the necessary mechanisms to support their portcos. Specialist cyber security knowledge is required during an incident and it’s in everybody’s best interest to know who to use, PE firms can ensure trusted providers are vetted, known and used during incidents.
- Flag low-staffing periods as a scheduling input for diligence, not an obstacle to work around. If a deal timeline runs through a known low-availability period, build in verification steps rather than defaulting to assurances.
- Track vendor and third-party coverage separately from internal coverage. A portfolio company's own team may be fully staffed while its critical vendors are not. Ensure the third party risk management process within portfolio captures these nuances both from a contractual and operational perspective.
Questions PE Risk Teams Should Be Asking Right Now
- Which portfolio companies rely on a single person, or a very small team, for their cyber security and what's their coverage plan for the next six weeks?
- For any live deals in diligence, has the target's security assessment been based on verified evidence, or largely on management assurance?
- Do we have visibility into critical vendor security posture across the portfolio, independent of any single portfolio company's internal reporting?
- When did we last request evidence, rather than a policy document of incident response readiness during reduced-staffing periods?
How Thomas Murray Supports Cyber and Operational Risk Intelligence for PE
Thomas Murray helps private equity firms manage cyber risk across the deal lifecycle, from pre-acquisition due diligence to portfolio-wide monitoring and exit readiness, turning a hidden liability into a source of value protection and creation. Speak to one of our experts today to understand how we help you turn your approach to cyber security into a competitive advantage.
1 VikingCloud (2026) 225 cybersecurity stats and facts for 2026. Available at: https://www.vikingcloud.com/blog/cybersecurity-statistics (Accessed: 24 July 2026).
2 Department for Science, Innovation and Technology (2025) Summary of research on the economic impact of cyber attacks. Available at: https://www.gov.uk/government/publications/independent-research-on-the-economic-impact-of-cyber-attacks-on-the-uk/summary-of-research-on-the-economic-impact-of-cyber-attacks (Accessed: 24 July 2026).
3 Sarah Young (2025) 'UK's Jaguar Land Rover cyberattack shutdown to hit four weeks', Reuters, 23 September. Available at: https://www.reuters.com/business/retail-consumer/ (Accessed: 24 July 2026).

Private Equity Cyber Risk Checklist
Our PE Cyber Risk Checklist is a ten-step diagnostic for PE fund leadership, covering every stage from pre-deal surveillance to exit readiness. Work through it and know exactly where your gaps are.
- 10 steps across five phases - deal, first 100 days, portfolio ownership, ESG, and exit.
- Self-assessment at every step - rate your current position and walk away with a clear gap count.
- Written for fund leadership, No jargon. Financial language throughout.
Insights

Why Summer is a Blind Spot in Private Equity Risk Oversight
Threat levels don't take annual leave. Why PE firms need continuous cyber oversight of portfolio companies, not seasonal assessment.

Private Equity Cyber Risk Checklist
The PE Cyber Risk Checklist is a ten-step diagnostic for PE fund leadership, covering every stage from pre-deal surveillance to exit readiness.

Why Private Equity Has Underinvested in Asset Safety, and Why the Window Is Closing
Half of PE portfolio companies carry elevated cybersecurity risk. Here's why asset safety has been underinvested, and why that's changing fast.

5 Ways Cybersecurity Reduces Exit Valuations
Cyber weaknesses quietly erode deal value. Discover five ways they reduce exit valuations and how to increase exit valuations across your portfolio.

