Somebody described us that way recently and it stuck, because it's the honest version of what we do. We work the same four moments your operating partners already work: diligence, the first hundred days, the hold, and the run-up to exit.
Most security firms show up once, hand over a report, and leave. That's a poor fit for how a fund actually holds a company, so we structured the whole practice around the timeline you already run.
Security liabilities, compliance gaps, AI exposure, data handling, technical debt, incident history, vendor risk. Written for an investment committee, delivered on your timeline, with a remediation cost estimate you can underwrite rather than a list of findings you can't price.
The only window where a management team will genuinely accept change. Governance, policy, MFA and identity, endpoint, backup, monitoring, a compliance roadmap, and AI governance stood up before the company gets busy again.
Retained monthly, per company. Somebody named who knows the environment, attends the board meeting, answers the security questionnaires that are holding up enterprise deals, and calls you before you hear it from somewhere else.
We run the company through the diligence a buyer will run, twelve months early, so the findings that would have become price adjustments get fixed while they're still cheap. This is the piece nobody thinks about until the data room is already open.
Protection is a cost line, and a cost line is an argument you have to win again every year. We'd rather be measured the way your operating partners are measured. Here is where the money actually moves.
Kroll surveyed 325 portfolio leaders across six countries in December 2025. Every figure on this site carries its source, because there's a great deal of unsourced noise in our industry and we'd rather you check us.
Plenty of firms will sell a portfolio managed IT and call it cyber. The thing that's actually changed underneath your companies in the last eighteen months is AI, and almost nobody is governing it. IBM's 2026 research put shadow AI in 43% of security incidents, roughly double the year before, with more than two thirds of organizations having nothing in place to limit unauthorized AI use.
Note-takers sit in board meetings, LP updates and diligence calls, keeping recordings nobody has reviewed. In 2024 a VC firm's assistant emailed a founder the transcript of what the partners said after he dropped off, and he walked away from the deal. Boards are getting formal legal advice on this now.
Companies building AI features inherit an attack surface that didn't exist when you invested. Prompt injection, agents holding credentials nobody can audit, model supply chain, MCP servers wired into production. We red team it and build the governance an enterprise buyer will ask to see.
Buyers have worked out that a vendor's SOC 2 says nothing about what downstream model providers do with data. Auditors are already asking for AI data-flow evidence, and an ISO 42001-aligned AI program is turning into a credential that unblocks enterprise sales rather than a compliance chore.
Diligence is quoted per deal against your timeline. Everything after close is a monthly retainer per company, priced on size and risk, and it improves as more of the portfolio comes on.
Five portfolio companies, assessed together. Each one gets a cyber and AI risk assessment, an executive scorecard and a 90-day roadmap. You get a heatmap across all five, which is usually the first time anyone has seen the portfolio's risk side by side. Companies that need ongoing work convert to a monthly retainer. The ones that don't, don't.
Retainers run month to month after an initial term. A security firm that needs a long lock-in to keep you is telling you something. ACA's 2026 benchmarking of 300+ portfolio companies found that those under structured monitoring for a year or more were twice as likely to reach low risk, which is the only honest argument for retaining anybody rather than buying a one-off project.
A federal court allowed negligence and aiding-and-abetting claims to proceed against a private equity firm over a portfolio company's breach. The reasoning was that the sponsor exercised control over that company's cybersecurity decisions, so agency applied, and some of what was at issue predated the closing.
Board seats and operating partners are the model. It now appears they're also how liability travels, and we don't think most funds have worked out what to do about that yet.
Assess five companies together, see the heatmap, and decide from there which ones need somebody retained. If the answer is none of them, that's a good outcome and you'll have the report either way.