A typical mid-cap Private Equity fund may be tracking up to 100 potential acquisition targets at any one time. Monitoring these companies early provides visibility of long-term cyber security trends and helps identify critical risks that could affect a transaction (e.g. a database compromise) or undermine value (e.g. intellectual property loss).
Thomas Murray’s Orbit Security platform offers non-intrusive, continuous monitoring - without alerting the target company.

External Attack Surface Monitoring
- Automated, external monitoring of companies to detect breaches, vulnerabilities and misconfigurations that could be exploited by threat actors
- 0–1000 ratings
- Long-term trend analysis
- Benchmarking against sector peers
Dark and Deep Web Monitoring
- Gain a competitive edge by examining areas most others do not
- Continuous monitoring of dark and deep web sources to identify exposed company data — including client information, employee credentials and intellectual property — as well as emerging threats
- Monitor domains, sub-domains and named individuals


Cybersecurity Checklist for Private Equity
For private equity partners and portfolio managers focused on value creation, understanding and mitigating cyber security risk is critical. This 10-step checklist demonstrates how to identify and quantify cyber risk at both portfolio and company levels—turning an intangible threat into measurable financial value.
Find out more
Our experts


Insights

Beneath the Asset – Out of Sight: The State of Cybersecurity in the Private Equity Industry
The UK’s smallest investment funds are weak security link in protecting the IP needed for national growth, new Thomas Murray study finds.

Fool me once: What the Apollo breach tells private equity about the threats it now faces
Apollo’s August breach was one data point in a five-week campaign mapping 200+ private capital firms. What it means for fund-level cyber risk.

From Red Flag to Redline: How Cyber Findings Actually Change Deal Terms
A cyber finding rarely kills a deal, it can and does, however what it does far more often, is move it: from a line in a due diligence report to a redline in the SPA.

Why Summer is a Blind Spot in Private Equity Risk Oversight
Threat levels don't take annual leave. Why PE firms need continuous cyber oversight of portfolio companies, not seasonal assessment.
