Intelligent Issue 05 | Page 53



BlueVoyant , an industry-leading cyberdefence company that combines internal and external cybersecurity , has released a new report highlighting cyber-risks impacting private equity portfolio companies .

The study , Private Equity : A Look at Portfolio Company Cyber-risk , found IT management was a top concern , with many portfolio companies struggling with IT hygiene , potentially leaving them susceptible to costly breaches .
“ When it comes to private equity portfolio companies , we see a wide range of cyberdefence postures ,” said Dan Vasile , Vice President of Strategic Development , BlueVoyant . “ Cybersecurity as a subset of risks is sometimes overlooked . This analysis confirms the need to prioritise cyberdefence to protect portfolio company value . The private equity space is beginning to get on track . However , we must button up the entire process to protect those vulnerable entities and ramp up cyberdefence against less easily exploitable but equally damaging threats .”
BlueVoyant analysed 780 portfolio companies from private equity-backed firms , with the majority headquartered in the US but including companies across Europe and around the globe . Key survey findings include :
• 19 % of the examined portfolio companies are exposed via ‘ zero tolerance findings ’ discovered in their Internet-facing , publicly accessible footprints . BlueVoyant defines zero tolerance as critical known findings easily exploitable by malicious actors and commonly associated with successful ransomware attacks . Should these vulnerabilities be exploited , it could lead to loss of data and service availability , translating into customer distrust and financial loss
• More than 70 % of the critical Internetfacing findings are related to IT hygiene
“ It is imperative that private equity firms effectively oversee their digital ecosystems by continuously monitoring their portfolio companies to quickly remediate issues and minimise the financial impacts of any cyberattacks ,” added James Tamblin , Vice Chairman of Strategic Development , BlueVoyant . “ Without proper cyber-risk management , these companies can face costly repercussions , especially if improvements in IT hygiene are not made .”
At a recent private equity roundtable held by BlueVoyant in the UK and attended by 20 private equity firms , there was widespread recognition that cyber-risk is important . But at the same time , it was felt that due diligence can slow the acquisition process down . Private equity firms competing to buy portfolio companies say that the speed of the deal is key and that too much compliance can be a negative . Therefore , they recognise that there is a trade-off between managing cybersecurity risk and securing the deal .
“ This is where BlueVoyant can help private equity firms have that necessary level of due diligence in their processes without compromising the deal ,” said Tamblin .
To maintain cybervigilance within private equity firms , BlueVoyant recommends proactively working within portfolio companies to reduce cybersecurity risk and avoid the costs associated with breaches . Working with portfolio companies to improve IT management practices to current standards is key , as well as establishing a prioritised risk reduction programme and continually assessing for any weaknesses in their realtime risk posture .
BlueVoyant ’ s study used digital ‘ footprints ’, the mapping of an organisation ’ s external-facing network assets , registered IP addresses and Internet hosting presence , to gain comprehensive visibility into any given organisation ’ s attack surface using a combination of Artificial Intelligence and Machine Learning . � www . intelligentfin . tech