Peter Connolly at Toro Solutions explains why PE firms need to understand how cyber-security and business risk change from acquisition through to exit

A positive cyber-security due diligence process can give investors confidence at the point of acquisition. The controls may look good, the leadership team may understand the risks, and there may be no obvious warning signs. But over a three- to five-year holding period, the business can change significantly.
The real issue is what happens after completion. A company’s technology, suppliers, operating model and risk profile can all move on, while the level of scrutiny applied during the acquisition often does not continue at the same depth.
Cyber-security due diligence is now a routine part of private equity transactions. Before an acquisition, investors want to understand the cyber-risks within the business, whether there are material issues that could affect the transaction and what may need to be addressed after completion.
What is less well established is what happens after that point. A due diligence exercise captures a business at a single moment, and that picture can change considerably over time. Companies grow, make acquisitions of their own, enter new markets, switch suppliers and adopt new technology, often increasing their reliance on data and digital infrastructure along the way.
Some of this is difficult to predict. The rapid adoption of AI tools across businesses is a good example. A company reviewed three years ago is likely to now have staff using AI tools routinely, as well as AI capability embedded in systems that were never examined during the original assessment.
The scrutiny applied at acquisition is rarely repeated to the same extent afterwards. For PE firms managing sizeable portfolios, it can therefore become increasingly difficult to know where cyber-risk sits, where it is changing and where attention needs to be focused.
Most portfolio companies already provide some form of cyber-securityreporting, but they tend to measure and report security in different ways.
One business might have a dedicated security team, ISO 27001 certification and regular board-level reporting, while another has outsourced most of its IT and security to a managed service provider. Elsewhere in the same portfolio, assurance might rest on Cyber Essentials Plus, an annual penetration test, an internal risk register or an occasional questionnaire.
Each of these provides useful information about the company concerned, but they don’t necessarily make it easy to compare risk across the portfolio.
The volume of reported issues can be misleading. A business running a substantial remediation programme may have a far better understanding of its weaknesses than one reporting almost nothing. Equally, a company reporting a large number of findings may simply have greater visibility of its risks and a more mature approach to managing them.
For investment teams making decisions across multiple holdings, this inconsistency makes oversight more difficult. Identifying which companies carry the greatest risk, where that risk is increasing and whether previously identified issues are being resolved requires some consistency in how risk is assessed, even if the depth of that assessment varies from one company to the next.
Having a consistent view across the portfolio does not mean every company needs the same level of assessment.
A small professional services firm, a regulated financial services business and a technology company holding substantial volumes of sensitive customer data present very different risks.
Investment size will naturally influence the level of oversight, but it should not be the only factor. Sector, regulatory obligations, dependence on technology, sensitivity of data, reliance on critical suppliers and the likely impact of disruption all need to be considered.
A lower-risk business may only require a periodic review of key controls, governance arrangements and remediation progress. One with greater exposure may need regular technical testing, closer scrutiny of its supply chain or exercises to test how it would cope with disruption.
The level of assurance may also need to change over time. An acquisition, rapid growth, entry into a regulated market or a significant technology change could all alter the risk profile of the business.
Regular review does not mean repeating a detailed assessment every year. It means checking that the level of scrutiny remains appropriate for the business as it stands today.
There is a limit to what can be learned by looking at cyber-security controls in isolation. A technical assessment can confirm whether important controls are in place and identify weaknesses, but it will not necessarily show how much disruption an incident would cause or how well the company would cope with one.
A weakness in a peripheral system presents a very different risk to one affecting technology the business relies on to deliver its core service. The same applies to third parties. A supplier becomes a much greater concern if the company has no realistic way of operating without them. It is just as important to understand how dependent the business is on particular systems, suppliers or individuals, whether critical services could continue during an incident, how quickly key systems could be restored and whether crisis and incident response plans are current and have actually been tested, rather than simply written down.
The answers give investors a much clearer idea of how exposed the business would be if a serious incident occurred and how quickly it could recover. This matters because the cost of an incident is rarely confined to remediation. Lost revenue during downtime, damage to customer relationships and the management time diverted to handling a crisis can all affect performance in the period that follows, which in turn affects how the investment is viewed.
This is why the issue has become more material for investors. Recent research from Kroll found that cyber-security incidents are increasingly affecting portfolio value, with PE firms reporting an average financial impact of around $2.1 million where deals were disrupted by cyber-risk.
Looking at portfolio companies in a consistent way makes it easier to understand where the greater risks sit and where further attention or investment may be needed.
It can also bring out issues that are difficult to see when each company is considered separately. Several businesses may rely on the same technology provider, for example, or the same weaknesses in third-party risk management may be appearing across the portfolio. Companies that have grown or acquired quickly may also still be relying on the security arrangements they had when they were much smaller.
Patterns like these help investment teams decide where support is needed and where additional investment is justified. If the same issues are appearing in several businesses, there may also be an opportunity to address them across the portfolio rather than separately each time.
The aim is to be able to compare portfolio companies on a like-for-like basis, understand how their risk is changing and know where attention is needed, rather than simply collecting an annual assessment from each one.
There is another practical reason to keep reviewing cyber-risk throughout the holding period: the business is likely to face this scrutiny again.
When an exit approaches, a prospective buyer may examine much of the same ground covered at acquisition, including cyber-security, technology risk, third-party dependencies and operational resilience.
Issues that surface at that stage can be difficult to resolve quickly. Finding the same issue earlier in the holding period gives the business time to investigate it properly, fund the remediation and address the underlying problem.
There is also a meaningful difference, from a buyer’s perspective, between a business that has recently worked through a list of due diligence findings and one that can demonstrate how risk has been reviewed and managed throughout the investment period. That difference can show up directly in exit negotiations, whether through price, warranties or the time the process takes to complete.
Cyber-security due diligence provides a detailed view at acquisition, but that view becomes less reliable as the business changes.
For PE firms, regular review provides a way to keep that understanding current throughout the holding period and, importantly, to see how risk compares across the portfolio.
By the time the business reaches its next transaction, most of the ground a buyer will cover should already have been reviewed, understood and addressed.
Peter Connolly is CEO at Toro Solutions
Main image courtesy of iStockPhoto.com and deepblue4you
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543