General Partners in UK private equity firms are under increasing pressure to mitigate the business risks associated with the exponential growth in cyber crime. They also face the burden of complying to strict data security requirements of European regulations which include the General Data Protection Regulation (GDPR) and the Alternative Investment Fund Managers Directive (AIFMD).
The risks are high for private equity firms
Successful cyber attacks use complex, and constantly changing technology to deliver targeted email phishing, viruses and ransomware. Criminals with industry knowledge apply this technology to deliver highly effective campaigns that include ‘fake CEO’ email and drawdown scams. The latter break into internal systems and extract lists of investors and drawdown notices. New notices are forged and easily used to defraud investors.
With responsibility for the investment and management of high value funds, private equity firms have many stakeholders who store and exchange confidential information assets. Limited Partners, portfolio companies, staff, lawyers, advisors – all part of the lifeblood of a PE business but all potential ‘weak points’ that can be exploited in a cyber attack.
Protection for Portfolio Companies
To protect revenue and preserve the value of an investment portfolio, it is essential for PE firms to ensure that their portfolio companies are applying the best practice for cyber security and regulatory compliance.
Investor Relationships
Larger institutional investors are also very aware of the risk of cyber attack. The Coller Private Equity Barometer 2016 Report confirmed that 55% of Limited Partners expected a serious cyber attack on their firms in the next five years. A greater portion will now require fund managers to assess cyber risks in the future. During fund raising, it is essential to demonstrate to your investors that cyber security is your highest priority.
Lack of Cyber Security Expertise
Private equity firms are often smaller organisations (fewer than 50 users) and may have limited in-house cyber security expertise. Qualified cyber security managers are an expensive and rare commodity.
Cyber security compliance for private equity firms
Cyber security is a regulatory burden of the Alternative Investment Fund Managers Directive (AIFMD) and the strict legal requirements of the General Data Protection Regulation (GDPR). Although the May 2018 deadline for compliance to GDPR has now passed, many companies are still struggling to ensure they meet the requirements of Article 30 (Security of Personal Information) and Articles 33/4 (Notification of Data Breach).
——————–
Wizard Cyber a specialist cyber security provider to private equity firms and their partners in the UK. We are a trusted supplier to many of the leading PE firms and deliver 24/7 outsourced cyber security via our flagship range of CYBERSHIELD MDR services.


