Categories
The Sekhmet Scribe

Fourteen Companies, Fourteen Front Doors: The Portfolio Risk Nobody Owns

The Sekhmet Scribe | Team Sekhmet

THE BREACH HAPPENED AT THE SMALLEST COMPANY YOU OWN.

Not the platform. Not the one with a CTO and a security budget. The bolt-on acquired eighteen months ago, still running the stack it had on completion, still supported by the local IT firm the founder has used since 2011.

It cost considerably more than the acquisition multiple suggested it could.

This edition of The Sekhmet Scribe is about portfolio cyber risk: why it concentrates precisely where nobody is looking, and why the answer is standardisation rather than surveillance.

Protect • Empower • Evolve


WHAT’S HOT 🔥

Risk Doesn’t Respect the Org Chart

Private equity portfolios accumulate technology the way they accumulate companies: unevenly, and at speed. Every acquisition arrives with its own identity provider, its own backup regime, its own incumbent supplier and its own undocumented exceptions. Governance is set at fund level. Risk sits at asset level. The gap between the two is where incidents live.

The uncomfortable arithmetic is this: a portfolio’s exposure is not the average of its companies’ security postures. It is much closer to the worst one — particularly where shared services, common suppliers or a single lender relationship connect them.

You are not managing fourteen risks. You are managing one risk, fourteen times over, at the standard of the weakest.


WHAT’S HOT 🔥

Standardisation Is a Value Lever, Not a Cost Line

Operating partners are increasingly treating cyber the way they already treat procurement or finance systems: as something to harmonise for margin, not merely for safety.

A common baseline across the portfolio — identity, endpoint protection, backup and recovery, patching, incident response — lowers cost per company, shortens diligence on the way out, and removes the discount a buyer applies to risk they cannot quantify. It also makes reporting possible for the first time. A single view across assets moves the board conversation from anecdote to evidence.

Cyber maturity is now a genuine line item in exit readiness. Portfolios that can evidence it defend valuation. Portfolios that can’t, negotiate.


WHAT’S NOT ❄️

Treating cyber as a portfolio company problem and nothing more. Diligence that ends at completion. Annual questionnaires answered by whoever happened to be free that week. Fourteen different providers working to fourteen different definitions of “managed”. Discovering during a breach at one company that three others share the same supplier and the same weakness.

A portfolio without a baseline doesn’t have a security posture. It has a collection of opinions.


THE SEKHMET STANCE

Portfolio cyber resilience is an ownership discipline, not an IT purchase.

At Sekhmet we work with private equity firms to set a baseline that is proportionate to each asset, deploy it consistently, and report it in a form an investment committee can actually act on. From day-one integration through to exit-ready evidence, we make the portfolio legible — so cyber risk becomes something you manage deliberately rather than something you discover.

The lioness hunts as a pride. The pride is only as fast as the one at the back.

Stop asking fourteen companies how they’re doing. Start knowing.

Protect • Empower • Evolve

Team Sekhmet

Leave a Reply

Your email address will not be published. Required fields are marked *