Cybersecurity for private equity
Private Equity Cybersecurity and Portfolio Testing
Private equity cybersecurity has two halves: the firm, with its deal files, investor portal, and wire approvals, and the portfolio companies whose breaches land on the fund. Invadel tests both at published fixed prices, with a free retest and reports written for limited partners, boards, and operating partners.






The stakes
Why private equity firms get tested differently
Attackers want what a private equity firm moves and what it knows. Capital calls, distributions, and closing wires are large, scheduled, and announced by email, which is why business email compromise works so well against deal teams. The FBI’s 2025 Internet Crime Report counts 24,768 business email compromise complaints and more than $3 billion in reported losses, second only to investment fraud. Deal information is the other prize: data rooms, deal team mailboxes, and the investor portal that holds every limited partner’s details.
Limited partners ask first. The ILPA Due Diligence Questionnaire asks whether the firm carries out penetration testing and vulnerability testing, how often, and with which third parties. It asks whether the firm or any portfolio company had a breach in the last five years, and how the firm sets testing standards for the companies it controls. SEC-registered advisers also answer to Regulation S-P, amended in 2024 to require an incident response program, customer notice within 30 days, and service provider oversight. Venture advisers relying on the registration exemption fall outside the rule, but their limited partners ask the same questions.
A generic test of a fund finds very little, because a private equity firm is a small office wrapped in third parties: the fund administrator, law firms, placement agents, an outsourced IT provider, and a data room vendor. The exposure is identity, sharing, and approvals. The portfolio is the other half. Twelve companies tested by twelve vendors produce twelve report formats that nobody can compare. Operating partners need one method, one severity scale, and one price list across every company.
What we test
The systems attackers go after first
Deal team email and identity
Microsoft 365 or Google Workspace, tested for MFA gaps, mailbox forwarding rules, risky app consents, and conditional access that lets a stolen session read a live deal.
Data rooms and deal folders
The permissions, shared links, and external users on virtual data rooms and deal folders, reviewed for advisers and bidders who kept access after a process closed.
Investor portal and LP reporting
The portal where limited partners see capital accounts, notices, and tax documents, tested for authorization flaws between investors and weak onboarding and reset flows.
Capital calls, distributions, and closing wires
The people and callbacks behind payment instructions, tested with email and voice pretexts timed to real fund events, stopping at the request so no money moves.
Fund administrator and service provider access
Connections to the fund administrator, outsourced IT, and law firm file shares, reviewed for shared credentials, standing remote access, and accounts without a second factor.
Portfolio company estates
The external perimeter, Microsoft 365 tenant, internal network, and flagship application of each company, tested to one methodology and one report format across the portfolio.
Compliance
The frameworks that usually apply
- SEC Regulation S-P
For SEC-registered advisers: a written incident response program, customer notice within 30 days, and service providers that report breaches within 72 hours. Larger firms had to comply by December 3, 2025, smaller firms by June 3, 2026.
ILPA Due Diligence Questionnaire
The data security section asks about penetration testing and vulnerability testing, breaches at the firm and its portfolio companies, and the testing standards portfolio companies follow.
- NYDFS 23 NYCRR 500
Annual penetration testing for portfolio companies that hold a Department of Financial Services license, such as lenders, insurers, and money transmitters.
- SOC 2
The report enterprise customers ask software and services portfolio companies for, with an independent penetration test in the evidence set.
Services
What private equity firms usually buy
- From $4,200
Microsoft 365 Security Assessment
A manual review of your Microsoft 365 or Google Workspace tenant: identity and MFA, mail security, sharing, and OAuth apps, plus an optional attack simulation. From $4,200.
- From $4,200
External Network Penetration Testing
Testing of your internet-facing perimeter, from exposed services and VPN gateways to mail and cloud edges, with a free retest, from $4,200.
- From $3,600
Phishing Simulation & Social Engineering Testing
Phishing and social engineering campaigns that measure real-world human risk, with click and credential metrics by department, from $3,600.
- From $6,000
Internal Network Penetration Testing
Testing from an assumed foothold inside your network: Active Directory attack paths, lateral movement, and segmentation, from $6,000.
Penetration Testing as a Service
Recurring senior-led testing and validated scanning, run as one ongoing program with every finding tracked live on the platform.
LP due diligence
Private equity cybersecurity questions in the ILPA DDQ
Version 2.0 of the ILPA Due Diligence Questionnaire gives data security, technology, and third parties a section of their own. These are the questions in it that a testing program answers, and what an engagement puts in the file for each.
18.4 Independent audit
- What limited partners want to know
- Whether an independent third party audits the firm’s security policy and controls every year.
- What goes in the file
- A penetration test is not a policy audit, but it gives the audit independent evidence that the technical controls the policy describes actually hold.
18.5 Breaches
- What limited partners want to know
- Whether the firm or any portfolio company had a cyber breach in the last five years, and what was fixed afterward.
- What goes in the file
- Testing cannot change history, but retest results show that the weaknesses behind an incident were closed and stayed closed.
18.6 Penetration testing
- What limited partners want to know
- Whether the firm carries out penetration testing, how often, what type, and whether a third party does it.
- What goes in the file
- A dated report from an independent firm covering the email tenant, the investor portal, the external perimeter, and the office network, with an attestation letter that summarizes scope and outcome.
18.7 Vulnerability testing
- What limited partners want to know
- Whether the firm runs vulnerability testing, how often, and with whom.
- What goes in the file
- Analyst-validated vulnerability scans on a quarterly or monthly cadence between annual tests, with false positives removed and findings ranked by risk.
18.13 and 18.14 Cloud and third-party data
- What limited partners want to know
- Whether data held in the cloud, and data held by service providers, gets independent security review.
- What goes in the file
- A Microsoft 365 or Google Workspace security assessment of sharing, guest access, and identity controls, and a cloud penetration test where the firm runs its own cloud accounts.
18.16 Portfolio companies
- What limited partners want to know
- How the firm works with the portfolio companies it controls on security policy, testing standards, and third-party assessments.
- What goes in the file
- One testing standard across the portfolio: the same methodology, severity scale, and report format for every company, each priced from the published list.
Question numbers follow ILPA DDQ 2.0, section 18.0. Limited partners often send their own questionnaires as well, and the same evidence answers them.
How it runs
Typical engagements
Illustrative scopes for this industry, written to show what a test covers and what you walk away with.
They are not client stories; our anonymized engagements are on the case studies page.
Typical engagement
Buyout firm answering a fundraise questionnaire
A mid-market buyout firm raising its next fund gets an LP questionnaire asking when it last ran a penetration test and who ran it. We test the Microsoft 365 tenant, the investor portal across LP roles, and the external perimeter, and run a phishing campaign against the finance team timed to a capital call notice. The CFO receives an executive summary and attestation letter for the questionnaire response, the technical report for the IT provider, and retest results.
Typical engagement
Operating partner setting one standard across the portfolio
An operating partner wants every portfolio company tested the same way before the annual board cycle. Each company gets an external test and a Microsoft 365 review from the published price list, scheduled around its own calendar, under rules of engagement signed by its own management. Findings land on one severity scale and in one report format, so the operating partner compares companies side by side and tracks each company’s fixes to the retest.
Typical engagement
Platform company before connecting an add-on
A platform company in a buy-and-build strategy is about to connect a newly acquired add-on to its network and domain. Before the link goes live, we run an internal test of the add-on from a standard user workstation and map every path to domain admin, including a service account reused across both companies. The integration waits for the fixes, the retest confirms them, and the connection goes live on evidence rather than hope.
FAQ
What deal teams and operating partners ask
01Does the SEC require private equity firms to run penetration tests?
Not by name. Regulation S-P requires SEC-registered advisers to keep written safeguards for customer information, and the 2024 amendments add an incident response program, customer notice within 30 days, and oversight of service providers. Larger firms had to comply by December 3, 2025 and smaller firms by June 3, 2026. The SEC withdrew its 2022 proposal for a separate adviser cybersecurity rule in June 2025, and its 2026 examination priorities list the Regulation S-P amendments. An independent test is the clearest evidence that the safeguards were tested. See what Regulation S-P requires.
02What do limited partners ask about cybersecurity?
Most start from the ILPA Due Diligence Questionnaire, whose data security section asks whether the firm carries out penetration testing and vulnerability testing, how often, and who does it. It also asks about breaches at the firm or its portfolio companies in the last five years, and how the firm sets testing standards for the companies it controls. An executive summary and an attestation letter answer the testing questions without handing over the technical report. You can see the format in our sample penetration testing report.
03Can you test a company we are about to buy?
Yes, with the target’s written authorization, which the target signs rather than the buyer. We scope a test that fits the deal clock, usually the external perimeter and the flagship application before close and the internal network after it. Our cybersecurity due diligence guide covers scope menus, deal terms, and the first 100 days after close.
04How does a portfolio testing program work?
We agree one methodology, one severity scale, and one report format for every company, then price each company from the published list, so the total is known before the first call. Each company signs its own authorization and schedules its own windows, and every company’s findings are tracked to closure in our findings platform and reported in the same format. Companies that ship software every week often move to a recurring penetration testing as a service program instead of one annual test.
05Which test shows whether ransomware could spread through a portfolio company?
An internal network test from a standard user workstation, which follows the paths ransomware operators use through Active Directory to the servers and backups that matter. Our ransomware readiness assessment, from $6,000, is built around that question. It is often the first test an operating partner buys for a company that has never had one.
06A portfolio company needs a pentest report before its next round. How fast can you move?
Onboarding starts within 24 hours of a signed proposal, and testing typically begins within a week. A focused test of the product investors care about, usually a web application penetration test from $5,200, produces a dated report and an attestation letter the company can share in its data room. A free retest of remediated findings is included, so the report shows fixes as well as findings.
07How much does penetration testing cost for a private equity firm?
For the firm itself, a Microsoft 365 or Google Workspace security assessment starts at $4,200, external network testing at $4,200, and a phishing campaign at $3,600. Investor portal testing starts at $5,200 as a web application test, and internal network testing at $6,000. Each price is fixed in writing before work starts, and penetration tests include a free retest of remediated findings. Portfolio programs are priced per company from the same list, shown on our pricing page.
Get a fixed price for your firm or portfolio
Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.
Prefer the full scoping questionnaire?Get a Fixed-Scope Quote
Tell us what you need tested. We reply within one business day.
Thanks, we've received your message.
We'll be in touch shortly.