eSentire · Private Equity

How much cyber exposure is sitting in your portfolio?

Four in five PE firms had a portfolio company disrupted last year. Model what that looks like across your holdings.

START THE CALCULATOR

Questions to evaluate exposure risk across your portfolio

2Typical portfolio company size
3Assets under management
Someone watching and able to contain at 3am. Owning the tooling is not the same thing.
35%
5Do you mandate a minimum set of security controls across the portfolio?
6Is cyber diligence standard in every transaction?
7Can you compare cyber risk across companies on the same basis?
One view your committee can read without translation.
8Has an incident response plan been tested with the deal team in the last 12 months?
A tabletop with deal leads, portfolio ops, counsel and security.
Your risk level
Elevated

Loading

— Chance of a security incident sometime this year
— Chance cyber losses top $5M this year
— Companies without 24/7 MDR coverage
— Of addressable cyber risk already removed
$0.00M

This figure is your expected annual cost of a serious incident: the likelihood of one in a given year (drawn from Kroll, IBM, and DBIR data, adjusted for your 24/7 MDR coverage) multiplied by what one costs. It's an average across many years. Most years cost less, and a bad one costs far more. It excludes reputational damage, LP confidence, and exit value, so treat it as an estimate, not a forecast.

Where the numbers come from

Kroll, February 2026Portfolio cybersecurity in private equity. Sapio Research, 325 PE portfolio leaders, seven countries.
IBM and Ponemon, July 2026Cost of a Data Breach 2026. 602 breached organisations, 17 countries.
Verizon DBIR, May 2026Data Breach Investigations Report. Roughly 22,000 confirmed breaches.

*Risk exposure estimates.

Where to start

In priority order. Start with 24/7 MDR and get to a full view of every portfolio company you sponsor.

Resources - Go Deeper on Private Equity Cyber Risk

Browse the Full Private Equity Library