Private Equity Firms Must Measure Their Portfolio Cyber Security Posture

12 September 2018by Abdallah Alhajeid

Cyber security is increasingly on the agenda of board meetings for successful investment management and private equity companies in the UK. General Partners must ensure they have effective cyber security measures in place in their own firm. They must also have visibility of the security measures implemented in their portfolio companies. To protect revenue and preserve the value of an investment portfolio, it is essential for PE firms to ensure that their portfolio companies are applying the best practice for cyber security and regulatory compliance.

 

Cyber security due diligence

Whatever the investment strategy, the business health of a potential portfolio company has always been evaluated prior to any investment. Chief Financial Officers and auditors spend long hours analysing and preparing risk assessments related to financial viability. The increasing frequency and potentially high cost of a cyber attack are ensuring that cyber security assessment is now an essential part of the technical due diligence process. Many in the PE industry argue that cyber security should be included in the Environmental, Social and Governance (ESG) group of issues. This is reinforced by the wide-ranging influence of GDPR and its associated cyber security requirements.

 

What is cyber security assessment?

One of the basic principles of cyber security management is the use of ‘before, during and after’ security assessments or audits. The cyber security assessment provides an independent and in-depth review of the ability of an organisation to protect its information assets from the impact of cyber threats. An initial assessment provides the baseline data and defines the current cyber security posture. Cyber risks are then identified and security measures (controls) are applied to mitigate the risks consistent with the objectives of the organisation. Subsequent assessments are performed at intervals to ensure that security measures are performing as required. This PDCA cycle (Plan, Do, Check, Act) is at the heart of the best practice as recommended by ISO 27001, the international standard for information security management.

.

Not all assessments are equal

A comprehensive cyber security assessment involves the evaluation of the people, processes and technology involved in an IT system. Audits of such complex frameworks require the use of many kinds of tests ranging from an inspection by an experienced cyber security professional to automated vulnerability assessment and penetration testing.

To evaluate the security posture of portfolio companies, we always recommend that our private equity clients use industry-standard criteria to provide quantitative and comparative audit reports. This is particularly important for an investment portfolio where the companies may have very different products or services. Consistent and reliable cyber security benchmarking of portfolio customers provides comparative data which can be added to an overall risk management process.

 

CIS Controls deliver a consistent benchmark

The Center for Internet Security (CIS) Controls feature twenty groups of ‘must have’ counter measures that businesses around the world already depend upon to stay cyber secure. Benchmarking against the availability of these controls delivers a quantitative and comparable measure of the cyber security profile of any organisation. Approved by the UK National Cyber Security Centre, the CIS Controls are compiled from the contributions of over 300 cyber security professionals who are global leaders in academia, industry and government organisations.

 

Unlike many similar cyber security recommendations, CIS Controls are highly regarded as they are regularly updated, technically very accurate and published with free availability. They also have the advantage of being internationally recognised particularly in North America and Europe. For the security assessment of prospective portfolio companies in the US, I can also recommend the use of the NIST Cybersecurity Framework as a complementary or alternative solution.

 

——————–

Wizard Cyber a specialist cyber security provider to private equity firms and their partners in the UK. We are a trusted supplier to many of the leading PE firms and deliver 24/7 outsourced cyber security via our flagship range of CYBERSHIELD-MDR services. We also deliver cyber security assessment services based on the use of the CIS Controls V7.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation