Cyber risk has moved from an IT footnote to a value-creation and value-protection issue at the fund level. A single incident at one portfolio company can erase a year of operating gains, complicate an exit, or trigger an investor question a sponsor cannot answer. Yet most firms still manage portfolio cyber risk the way they manage a single company, one assessment at a time, and it does not scale. Here is a clearer way to think about it.
Why portfolio cyber risk is a different problem
Managing cyber risk across a portfolio is not the same job as managing it inside one company, for three reasons. First, scale: a sponsor may hold ten, thirty, or a hundred companies, each with its own systems and its own risks. Second, uneven maturity: one company has a full security team, the next has an office manager handling IT. Third, data reluctance: portfolio companies are often wary of sending operational detail up to the sponsor. Any approach that ignores these realities produces work, not insight.
Thirty assessments are not a portfolio view
The common instinct is to run the same single-company assessment across every holding. The result is thirty or a hundred separate reports, each in its own format, that the sponsor cannot line up against one another. You cannot tell which company carries the most risk, where the next dollar of attention should go, or whether the book is getting safer or riskier over time. A stack of assessments answers "did we look at each company." It does not answer "how much risk are we carrying, and where," which is the question a sponsor actually needs to govern.
What a sponsor actually needs
The goal is one model applied consistently across every company, rolling up into one operating view. In practice that means:
- Comparable numbers. Every company measured the same way, so exposure at one is directly comparable to exposure at another, and the whole portfolio adds up to a single figure.
- Direction of travel. Whether exposure is rising or falling over time, per company and across the book, so the sponsor sees momentum rather than a one-time snapshot.
- Priorities the sponsor sets. The ability to pin what matters most, whether multi-factor authentication, asset management, or board reporting, and track it across every company at once.
- A view each company can use too. Every company sees where it stands and its own ranked list of next actions, which is what earns their cooperation instead of resistance.
This is the sponsor operating view Core3 builds on its portfolio page: the whole book on one page, sortable by fund, industry, or region, with the biggest gaps first, and every company measured on the same quantified model.
Due diligence and ongoing oversight are one system
Cyber due diligence at acquisition and cyber oversight during the hold are usually treated as separate exercises run by different providers. They should be the same system. A quantified baseline taken during diligence becomes the day-one exposure figure for the hold, so nothing is thrown away and the clock starts immediately. Instead of a diligence report that goes in a drawer, the sponsor gets a living number that carries through the whole ownership period and into the exit story.
Meet each company where it is
Because maturity varies so widely, the model has to run at whatever depth each company can support today. A company with an existing assessment can be loaded into the model with no new work, just enough to rank it against the book. A company that warrants deeper attention gets its controls validated against real evidence. The portfolio view is useful at every stage and sharpens as companies engage more deeply, so the sponsor never has to wait for uniform data that will never exist.
How to roll it out
The practical path is a pilot cohort rather than a big-bang rollout. Start with five to ten companies across a range of maturities, prove the model and the operating view on that cohort, then extend it in waves. This keeps the early effort small, produces a visible result the sponsor can react to quickly, and builds the track record that eventually goes in front of fund investors. Over several quarters, the reduction in exposure across the book becomes a value-creation story with numbers behind it.
Cyber risk done this way stops being a defensive checkbox and becomes part of the value-creation thesis: a measurable reduction in risk across the portfolio, reported the same way every quarter, that a sponsor can stand behind with an LP, a buyer, or a board.