Back to Blog

PE Portco Security Governance: The Quarterly Board Packet the Fund Actually Needs

Kroll's 2026 PE cyber survey puts the average portco incident at $2.1M and ACA's 2026 benchmark finds half of PE portcos at elevated or high cyber risk. This is the three-slide quarterly packet that replaces the folder of heat maps and lets the fund answer the LP's aggregate-exposure question before an incident forces the answer.

Quick Answer

Kroll's 2026 PE cyber survey puts the average portco incident at $2.1M and ACA's 2026 benchmark finds half of PE portcos at elevated or high cyber risk. This is the three-slide quarterly packet that replaces the folder of heat maps and lets the fund answer the LP's aggregate-exposure question before an incident forces the answer.

Every quarter, at every PE fund with a dozen portfolio companies, an operating partner opens a folder of portco-produced cyber updates and starts skimming. Half of them are heat maps. A quarter are training-completion percentages. The rest are certifications, framework logos, and screenshots of dashboards that the fund can't act on. The one number the LP is going to ask about next quarter — the aggregate cyber exposure across the portfolio, in dollars — is not on any of them.

The Kroll 2026 Cyber Risk to Value in Private Equity survey of 325 PE firm executives puts the average financial impact of a portfolio-company cyber incident at $2.1 million, and ACA's 2026 Vantage benchmark across 300+ portcos in 18 industries finds that half of PE portfolio companies face elevated or high cybersecurity risk. That's the exposure the packet is supposed to make visible. Most quarterly packets don't.

Here is what the fund actually needs to see, why most portco cyber updates default to theater, and the three-slide format that lets a fund answer the LP's question about aggregate exposure without waiting for an incident to force the answer.

$2.1M
average financial impact per portco cyber incident
Kroll 2026
50%
of PE portcos at elevated or high cyber risk
ACA Vantage 2026
54%
of PE risk leaders had a portco hit last year
Kroll 2026

Why most portco cyber packets default to theater

The default portco packet is built by the person at the portfolio company whose job depends on the fund not knowing anything is wrong. The IT lead at a $40M-revenue portco has one full-time security person, an MSP contract, and an auditor who visits once a year. The packet reflects the reports those three produce: MSP dashboards, auditor letters, training percentages. None of those numbers are wrong. None of them tell the fund whether the portco is going to lose a customer next quarter over a security failure or absorb a ransomware invoice in month eleven of the holding period.

The fund reads the packet with a different question: is anything in this portfolio company going to hit the P&L for a reason we didn't underwrite? Training-completion rates don't answer that. Vendor heatmaps don't answer that. What answers the question is a two-part frame — what's the exposure, and what changed since last quarter — with dollars attached to both.

Every fund running a functioning quarterly cyber governance loop uses some version of the same three-slide packet. The specifics differ. The format is the same.

The three slides that replace the folder

Slide 1 — Cyber exposure this quarter, in dollars

Two numbers. First: the FAIR-quantified annualized loss expectancy for this portco's top cyber scenarios, expressed as a range with a P50 and a P95. Not colors. A dollar range. Second: the delta from last quarter. The delta is the point — the absolute number gives context, the delta is what the fund reacts to.

Under the two numbers, three bullets naming the top three risk contributors driving the exposure and the delta. Three, not more. If it's the same three every quarter, the fund learns to skip them; the slide has to name what's actually on top of the stack right now, which moves.

Slide 2 — What actually changed this quarter

Two columns. Left: things that got better — three lines maximum, each with the material fact and a dollar impact. “Signed BAA and DPA with the new claims-processing vendor: $180K of contingent exposure removed.” Right: things that got worse — three lines maximum, same format. “Losing our second-largest customer's renewal because we can't answer their new AI-usage clauses: $1.4M contract at risk.”

Left column proves the portco is doing security work the fund funded. Right column makes risks visible in advance of an incident, not after one. A packet with only left-column entries is either lying or not paying attention; the fund should be suspicious of it.

Slide 3 — What we're asking the fund to do

One thing. Maybe two. Never three. “Approve $85K to close the CJIS gap our largest state-agency customer flagged in their September audit — deadline November 30.” Or: “Introduce us to the ops partner at PortcoX; they solved the same subprocessor governance problem last year and their playbook cuts our timeline in half.”

The fund can approve or decline. If there is nothing to ask, the slide reads “No action requested this quarter.” Portco leads who invent asks to fill the slide burn credibility faster than portco leads who ship one line and mean it.

How the portco actually produces slide one

Slide one — the FAIR-quantified P50 and P95 exposure number — is the slide most portcos have never built before. It is not the same thing as a risk register or a heat map. It is a dollar-denominated Annual Loss Expectancy for a small set of named scenarios, summed and reported with a confidence interval. If the portco security team has produced a SOC 2 report but has never produced this number, the first quarter under the new cadence is when they learn.

Five scenarios cover most of the exposure for a mid-market portfolio company. Each has a Loss Event Frequency (how often, per year) and a Loss Magnitude (how big, in dollars) that combine into ALE. Public benchmarks anchor the ranges; portco-specific inputs adjust them.

  1. Credential compromise into data exfiltration. Frequency anchor: the Verizon 2025 DBIR reports stolen credentials as the initial access vector in 22% of breaches — the single most common vector. Magnitude anchor: the IBM 2025 Cost of a Data Breach Report puts the global average breach at $4.44M, down 9% year over year. Portco-specific inputs that adjust the ALE: MFA coverage percentage, dormant account count, number of privileged accounts, and revenue-at-risk from customer notification.
  2. Ransomware on production systems. Frequency anchor: Verizon 2025 DBIR shows ransomware present in 44% of breaches. Magnitude anchor: median ransomware payment at $115,000 per the same report, and IBM 2025 puts the average total cost of an extortion or ransomware incident at $5.08M once recovery, downtime, and notification are added in. Portco inputs: EDR coverage percentage, unpatched CVE count, backup restore-test recency, revenue-per-day for downtime math.
  3. Regulatory or contractual violation. Frequency anchor: sector-specific — HIPAA-covered portcos price the OCR base rate; PCI-covered portcos price the PCI base rate; DORA-covered portcos price the Article 30 addendum failure rate. Magnitude anchor: the enforcement history for the specific regime, not a generic average. Portco inputs: data categories under regulation, contractual notification windows, current control coverage against the specific regime.
  4. Third-party vendor breach cascade. Frequency anchor: Verizon 2025 DBIR reports third-party involvement in 30% of breaches — a step change from prior years. Magnitude anchor: vendor-cascade breaches carry the same base cost as a direct breach plus real overhead in notification, forensics coordination, and customer outreach that a single-party incident doesn't. Portco inputs: vendor count with production access, vendor SOC 2 coverage, DPA/BAA coverage, and subprocessor chain depth.
  5. Slow-detection premium. Not a separate scenario — a multiplier on the four above. IBM 2025 puts the mean identification-and-containment window at 241 days, the lowest in nine years, but the distribution is wide and portcos with no SIEM, no IR retainer, and no tested tabletop sit well past the mean. When detection is slow, ALE per scenario grows because attackers dwell longer, notification obligations accumulate, and recovery costs compound. Apply the multiplier before summing.

The P50 is the point estimate. The P95 is the estimate at the 95th percentile of the calibrated probability distribution — a plausible worst case that the fund can defend against LP questioning as “the number if the year goes badly.” Portcos new to FAIR overshoot the P95 on the first pass and get it flagged by the fund's operating partner; the second-quarter packet usually calibrates correctly. That is expected. The point is to establish the cadence, not to nail the number on the first attempt.

The first-quarter kickoff for a new portco

When a new company enters the portfolio, the operating partner does not send the three-slide-packet template on day one. The first ninety days are cadence-setting, not reporting. Four moves in order.

Days 1-30: baseline exposure

The operating partner or the portco's contracted vCISO runs the first FAIR-quantified exposure calculation against the acquired entity's current state. This is a one-time exercise, not a quarterly one. Use the diligence-side Cyber Cost of Deal number from close as the anchor, then re-quantify against the portco's actual production stack — the diligence number is directional; the operating number is what the packet uses going forward.

Days 31-60: cadence design

The operating partner and the portco security lead agree on the quarter-end date, the packet-delivery date (typically two weeks after quarter-end), the review call date, and the escalation path if the packet is late or the exposure moves materially between quarters. This is the moment to fix the format: three slides, no template, feedback loop. Portcos that skip this step drift back to a 40-page monthly report by month four.

Days 61-90: first packet dry run

The portco security lead produces a “dry-run” packet for a month that hasn't formally been reported. The fund reads it, gives specific feedback on what's missing and what's redundant, and the portco produces the corrected version. The first real quarterly packet at end of quarter one is what emerges from this loop — not the first draft the portco submits blind.

Portcos that get the ninety-day loop right ship a signal-heavy packet from quarter one. Portcos that skip it produce a heat-map packet at quarter one, get feedback, produce a marginally-improved heat-map packet at quarter two, and by quarter three the operating partner has stopped reading. The ninety-day loop is what prevents that trajectory.

What never goes in the packet

Phishing training completion percentages. Number of security tools deployed. Framework certification logos. Screenshots of dashboards. Photos of the SOC. Slides titled “Our approach to defense in depth.” Slides that explain what ransomware is. Any statistic that isn't specifically about this portfolio company. Anything that would still have been in the packet if the portfolio company had never had a security team at all.

The pattern for cutting is easy: does removing this slide change what the fund knows? If not, cut it.

The template mistake

Most funds try to solve the packet problem by shipping every portco a template and asking them to fill it in. Two quarters later, the templates come back with the same numbers in the same slots, and the fund still doesn't know which portco is a cyber problem waiting to hit the P&L. The template didn't fix anything because the template was the problem.

What works is inverting the loop. The fund tells each portco: give me your three slides on your schedule, in your format. If the fund reads them and doesn't know what to do, we iterate together on the next one. If the fund reads them and does know what to do, the packet is right. Don't ship templates. Ship feedback.

The quarterly loop the fund actually runs

The packet is not the loop. The loop is what the fund does with the packet. Reading and archiving is not a loop. The loop is: read the three slides, ask the portco lead one follow-up question, decide whether the ask on slide three moves forward, and log the delta from slide two into the fund's own portfolio-level cyber risk aggregate for the LP report. If the fund doesn't close the loop, the portco stops caring what's on the packet, and the packet drifts back to a folder of heatmaps and training percentages.

The LP question this rolls up to

The LP conversation about cyber is one question: is the fund managing cyber risk as a portfolio, or is the fund pretending each portco's cyber posture is the portco's problem alone. The three-slide packet is what makes the answer tractable. Twelve packets each quarter, aggregated at the fund level — sum the P50 exposure line across portcos, watch it move quarter over quarter, put the aggregate in the LP letter with the delta.

A fund that ships that to LPs quarterly earns three things a fund without a governance loop doesn't. First, the ability to price cyber risk into the next acquisition's underwriting rather than backing into it. Second, credibility on the exit conversation when the acquirer's cyber diligence team arrives and starts asking about aggregate exposure. Third, a real answer when the LP asks. The alternative — waiting until an incident forces the answer — is more expensive every year, and the frequency numbers are moving in the wrong direction: 54% of PE risk leaders in the Kroll 2026 survey reported at least a quarter of their portfolio hit by a cyber incident in the last twelve months. The question isn't if. It's whether the fund knew before the incident that this portco was the most likely one.

The bottom line

Three slides. Thirty minutes to write, ninety seconds to read, and one action the fund can approve or decline. That is the entire mechanic. The alternative — the fifty-page folder assembled from vendor dashboards and screenshots — costs the portco a full sprint of security-team time to produce, gets archived unread by the operating partner, and answers none of the questions the fund actually holds the portco accountable to. Portcos that ship the three-slide packet earn the ability to make an ask on slide three that the fund will act on. Portcos that ship the folder get their questions answered on the fund's timeline instead of theirs, usually after the incident forces the timing.

Put the playbook to work

The three-slide quarterly packet ships as the standing portfolio-company output on vCISO Lite's PE surface at diligence.vcisolite.com — FAIR-quantified dollar exposure with a P50 and P95, the delta-driven change log, and the one-ask slide, generated from the same continuous evidence pipeline that runs the portco's compliance program. The fund gets a consistent format across every portco. The portco gets the security work done under one subscription instead of stitching together an MSP, an auditor, and a spreadsheet.

If the fund runs the same format across every portco, the operating partner can compare cyber exposure across the portfolio in the same terms, and the LP letter's aggregate number is defensible on methodology. For the founder-side view of the same methodology at pre-close, see the Quantitative Cyber Diligence overview. Visit diligence.vcisolite.com to see how it works and enroll your fund.

Where this matters next

Share this article:

Ready to build your security program?

See how easy it can be.