Skip to content

Cybersecurity for private equity

Private Equity Cybersecurity and Portfolio Testing

Private equity cybersecurity has two halves: the firm, with its deal files, investor portal, and wire approvals, and the portfolio companies whose breaches land on the fund. Invadel tests both at published fixed prices, with a free retest and reports written for limited partners, boards, and operating partners.

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology
LatentPerygeeCity National BankAubaDesteiaDTCC

The stakes

Why private equity firms get tested differently

Attackers want what a private equity firm moves and what it knows. Capital calls, distributions, and closing wires are large, scheduled, and announced by email, which is why business email compromise works so well against deal teams. The FBI’s 2025 Internet Crime Report counts 24,768 business email compromise complaints and more than $3 billion in reported losses, second only to investment fraud. Deal information is the other prize: data rooms, deal team mailboxes, and the investor portal that holds every limited partner’s details.

Limited partners ask first. The ILPA Due Diligence Questionnaire asks whether the firm carries out penetration testing and vulnerability testing, how often, and with which third parties. It asks whether the firm or any portfolio company had a breach in the last five years, and how the firm sets testing standards for the companies it controls. SEC-registered advisers also answer to Regulation S-P, amended in 2024 to require an incident response program, customer notice within 30 days, and service provider oversight. Venture advisers relying on the registration exemption fall outside the rule, but their limited partners ask the same questions.

A generic test of a fund finds very little, because a private equity firm is a small office wrapped in third parties: the fund administrator, law firms, placement agents, an outsourced IT provider, and a data room vendor. The exposure is identity, sharing, and approvals. The portfolio is the other half. Twelve companies tested by twelve vendors produce twelve report formats that nobody can compare. Operating partners need one method, one severity scale, and one price list across every company.

What we test

The systems attackers go after first

01

Deal team email and identity

Microsoft 365 or Google Workspace, tested for MFA gaps, mailbox forwarding rules, risky app consents, and conditional access that lets a stolen session read a live deal.

02

Data rooms and deal folders

The permissions, shared links, and external users on virtual data rooms and deal folders, reviewed for advisers and bidders who kept access after a process closed.

03

Investor portal and LP reporting

The portal where limited partners see capital accounts, notices, and tax documents, tested for authorization flaws between investors and weak onboarding and reset flows.

04

Capital calls, distributions, and closing wires

The people and callbacks behind payment instructions, tested with email and voice pretexts timed to real fund events, stopping at the request so no money moves.

05

Fund administrator and service provider access

Connections to the fund administrator, outsourced IT, and law firm file shares, reviewed for shared credentials, standing remote access, and accounts without a second factor.

06

Portfolio company estates

The external perimeter, Microsoft 365 tenant, internal network, and flagship application of each company, tested to one methodology and one report format across the portfolio.

Compliance

The frameworks that usually apply

  • SEC Regulation S-P

    For SEC-registered advisers: a written incident response program, customer notice within 30 days, and service providers that report breaches within 72 hours. Larger firms had to comply by December 3, 2025, smaller firms by June 3, 2026.

  • ILPA Due Diligence Questionnaire

    The data security section asks about penetration testing and vulnerability testing, breaches at the firm and its portfolio companies, and the testing standards portfolio companies follow.

  • NYDFS 23 NYCRR 500

    Annual penetration testing for portfolio companies that hold a Department of Financial Services license, such as lenders, insurers, and money transmitters.

  • SOC 2

    The report enterprise customers ask software and services portfolio companies for, with an independent penetration test in the evidence set.

Services

What private equity firms usually buy

LP due diligence

Private equity cybersecurity questions in the ILPA DDQ

Version 2.0 of the ILPA Due Diligence Questionnaire gives data security, technology, and third parties a section of their own. These are the questions in it that a testing program answers, and what an engagement puts in the file for each.

18.4 Independent audit

What limited partners want to know
Whether an independent third party audits the firm’s security policy and controls every year.
What goes in the file
A penetration test is not a policy audit, but it gives the audit independent evidence that the technical controls the policy describes actually hold.

18.5 Breaches

What limited partners want to know
Whether the firm or any portfolio company had a cyber breach in the last five years, and what was fixed afterward.
What goes in the file
Testing cannot change history, but retest results show that the weaknesses behind an incident were closed and stayed closed.

18.6 Penetration testing

What limited partners want to know
Whether the firm carries out penetration testing, how often, what type, and whether a third party does it.
What goes in the file
A dated report from an independent firm covering the email tenant, the investor portal, the external perimeter, and the office network, with an attestation letter that summarizes scope and outcome.

18.7 Vulnerability testing

What limited partners want to know
Whether the firm runs vulnerability testing, how often, and with whom.
What goes in the file
Analyst-validated vulnerability scans on a quarterly or monthly cadence between annual tests, with false positives removed and findings ranked by risk.

18.13 and 18.14 Cloud and third-party data

What limited partners want to know
Whether data held in the cloud, and data held by service providers, gets independent security review.
What goes in the file
A Microsoft 365 or Google Workspace security assessment of sharing, guest access, and identity controls, and a cloud penetration test where the firm runs its own cloud accounts.

18.16 Portfolio companies

What limited partners want to know
How the firm works with the portfolio companies it controls on security policy, testing standards, and third-party assessments.
What goes in the file
One testing standard across the portfolio: the same methodology, severity scale, and report format for every company, each priced from the published list.

Question numbers follow ILPA DDQ 2.0, section 18.0. Limited partners often send their own questionnaires as well, and the same evidence answers them.

How it runs

Typical engagements

Illustrative scopes for this industry, written to show what a test covers and what you walk away with. They are not client stories; our anonymized engagements are on the case studies page.

Typical engagement

Buyout firm answering a fundraise questionnaire

A mid-market buyout firm raising its next fund gets an LP questionnaire asking when it last ran a penetration test and who ran it. We test the Microsoft 365 tenant, the investor portal across LP roles, and the external perimeter, and run a phishing campaign against the finance team timed to a capital call notice. The CFO receives an executive summary and attestation letter for the questionnaire response, the technical report for the IT provider, and retest results.

Typical engagement

Operating partner setting one standard across the portfolio

An operating partner wants every portfolio company tested the same way before the annual board cycle. Each company gets an external test and a Microsoft 365 review from the published price list, scheduled around its own calendar, under rules of engagement signed by its own management. Findings land on one severity scale and in one report format, so the operating partner compares companies side by side and tracks each company’s fixes to the retest.

Typical engagement

Platform company before connecting an add-on

A platform company in a buy-and-build strategy is about to connect a newly acquired add-on to its network and domain. Before the link goes live, we run an internal test of the add-on from a standard user workstation and map every path to domain admin, including a service account reused across both companies. The integration waits for the fixes, the retest confirms them, and the connection goes live on evidence rather than hope.

FAQ

What deal teams and operating partners ask

01Does the SEC require private equity firms to run penetration tests?

Not by name. Regulation S-P requires SEC-registered advisers to keep written safeguards for customer information, and the 2024 amendments add an incident response program, customer notice within 30 days, and oversight of service providers. Larger firms had to comply by December 3, 2025 and smaller firms by June 3, 2026. The SEC withdrew its 2022 proposal for a separate adviser cybersecurity rule in June 2025, and its 2026 examination priorities list the Regulation S-P amendments. An independent test is the clearest evidence that the safeguards were tested. See what Regulation S-P requires.

02What do limited partners ask about cybersecurity?

Most start from the ILPA Due Diligence Questionnaire, whose data security section asks whether the firm carries out penetration testing and vulnerability testing, how often, and who does it. It also asks about breaches at the firm or its portfolio companies in the last five years, and how the firm sets testing standards for the companies it controls. An executive summary and an attestation letter answer the testing questions without handing over the technical report. You can see the format in our sample penetration testing report.

03Can you test a company we are about to buy?

Yes, with the target’s written authorization, which the target signs rather than the buyer. We scope a test that fits the deal clock, usually the external perimeter and the flagship application before close and the internal network after it. Our cybersecurity due diligence guide covers scope menus, deal terms, and the first 100 days after close.

04How does a portfolio testing program work?

We agree one methodology, one severity scale, and one report format for every company, then price each company from the published list, so the total is known before the first call. Each company signs its own authorization and schedules its own windows, and every company’s findings are tracked to closure in our findings platform and reported in the same format. Companies that ship software every week often move to a recurring penetration testing as a service program instead of one annual test.

05Which test shows whether ransomware could spread through a portfolio company?

An internal network test from a standard user workstation, which follows the paths ransomware operators use through Active Directory to the servers and backups that matter. Our ransomware readiness assessment, from $6,000, is built around that question. It is often the first test an operating partner buys for a company that has never had one.

06A portfolio company needs a pentest report before its next round. How fast can you move?

Onboarding starts within 24 hours of a signed proposal, and testing typically begins within a week. A focused test of the product investors care about, usually a web application penetration test from $5,200, produces a dated report and an attestation letter the company can share in its data room. A free retest of remediated findings is included, so the report shows fixes as well as findings.

07How much does penetration testing cost for a private equity firm?

For the firm itself, a Microsoft 365 or Google Workspace security assessment starts at $4,200, external network testing at $4,200, and a phishing campaign at $3,600. Investor portal testing starts at $5,200 as a web application test, and internal network testing at $6,000. Each price is fixed in writing before work starts, and penetration tests include a free retest of remediated findings. Portfolio programs are priced per company from the same list, shown on our pricing page.

Get a fixed price for your firm or portfolio

Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.