










Acquiring targets with active threat actors inside. Compromise spreads on network connection. Historical breaches transferring ICO successor liability. Shadow IT with undocumented legacy systems.
Attackers monitoring M365 to intercept completion wire transfers. Capital call details altered. Deal announcements triggering targeted BEC. Leadership distracted by transaction.
Attackers striking during first 100 days. AD trust exploitation from compromised target. Email consolidation exposure. Relaxed firewalls and unfamiliar policies.
Secured platform connected to poorly secured bolt-ons. Each acquisition is a potential entry point. Inconsistent maturity across holdings. Weakest entity targeted.
VDR compromise exposing valuations and LOIs. Confidential deal information leaked. UK Takeover Code breach. Share price manipulation risk.
Ransomware during hold period. Revenue and customer loss. Exit multiple destroyed. Buyer using cyber risk to reduce offer price.
Acquirer inherits target breach liability and ICO enforcement
Operational resilience for regulated portfolio companies
Confidentiality where deal document leakage breaches requirements
Baseline for portfolio companies bidding on public sector contracts
Comprehensive resilience for portfolio baselining
Portfolio companies not exempt regardless of size
Quarterly portfolio cyber risk reporting for institutional investors
Upcoming legislation expanding portfolio obligations
Where portfolio companies are designated OES
Where portfolio companies process payments
Rapid 2-3 week assessments within exclusivity. Active threat hunting. Dark web exposure. Shadow IT discovery. Inherited breach identification. Financial risk reporting.
First 100 days oversight. AD trust assessment. M365 consolidation. ERP migration security. Co-existence phase access controls.
Standardised assessments across holdings. CE+ and ICA certification programme. Consistent scoring. LP-ready quarterly reporting.
Portfolio SaaS product testing. Cloud configuration reviews. API security for fintech and healthtech. Product validation for enterprise sales.
M365 assessments for PE and portfolio. BEC prevention on completion payments. DMARC, DKIM, SPF. VDR access reviews.
Pre-sale audit for buyer diligence. CE+ and ICA certification. UK GDPR successor liability. FCA compliance. Exit multiple protection.
Assess target and portfolio networks for inherited vulnerabilities and lateral movement paths before or after close.
View serviceValidate portfolio SaaS products and client portals before enterprise customer acquisition.
View serviceAssess portfolio AWS or Azure environments for misconfigurations exposing customer data and IP.
View serviceAudit VDR platforms, deal flow CRMs, and third-party SaaS across your portfolio.
View serviceAddress successor liability, FCA obligations, and LP governance across portfolio companies.
View servicePortfolio-wide CE+ enabling public sector contracts and demonstrating baseline at exit.
View servicePhishing simulations for portfolio staff and dark web monitoring for deal communication credentials.
View serviceTest portfolio mobile applications and fintech tools for vulnerabilities affecting valuation.
View serviceHarden M365 against BEC targeting completion payments and capital calls.
View service
Most SMBs and mid-market firms have “silent” gaps in their people, process and tech controls implementation. Take the 90-second maturity audit to see your percentile rank.