The PE Portfolio Cyber & Domain Exposure Deep-Dive
Security controls are widely published and rarely enforced.
A first-party study of the website security, email authentication, and domain hardening of 1,104 PE-backed and mid-market company websites, drawn from the disclosed portfolios of 31 software-focused private equity funds. Ninety-eight percent publish a DMARC record. Only forty-one percent actually enforce it. This report quantifies the gap between what portfolio companies say they do and what their DNS, mail, and web layers actually enforce, and what it will cost to close it.
Cyber diligence has moved from a box-ticking exercise to a line item that prices the deal. This report measures what that inherited risk actually looks like. Not in a survey of intentions, but in the reproducible public security posture of 1,104 PE-backed companies.
The headline is not that portfolio companies run ancient software. They do not. Only about 1% of detectable WordPress installs sit on an outdated core branch, and transport security is effectively solved. The exposure is governance, not software currency.
Security is the weakest of the five technical domains we score, at a median of 72/100. Within it the story is a single pattern: controls are near-universally published, and thinly enforced.
Security is the weakest of the five technical domains, and it's a governance gap.
"The edge control plane is bought and idle. 59% of the portfolio sits behind Cloudflare, yet Cloudflare-fronted sites are no more likely to ship the header baseline than sites with no CDN at all."
Platform choice is a security decision. Mail concentration is a shared-fate risk.
The registrar-level controls are almost nobody's job.
DNSSEC is deployed on 14% of the domains we crawled. CAA, the record that pins which certificate authorities can issue for a domain, on 27%. Both are one-line DNS changes with no user-facing risk. Neither is anyone's KPI, and it shows.
The first 100 days of a portfolio security baseline.
- 01Enforce DMARC to reject on every domain.
The first move by buyer-visibility-to-cost. Closes business-email-compromise exposure. It is a DNS change, and only 41% of the universe has done it.
- 02Ship the six-header stack at the CDN.
59% of the portfolio already sits behind Cloudflare. The control is bought and idle. One edge configuration, applied as a standard, moves a company past the 13% frontier.
- 03Turn on DNSSEC and CAA at the registrar.
Two one-line DNS changes. 86% of the market has not turned on DNSSEC; 73% lack CAA. Both are visible to the next buyer's diligence pass.
- 04Standardise on a platform with a higher default floor.
HubSpot CMS: 75.1 mean security. Webflow: 59.1. Platform choice is a security decision disguised as an IT-consolidation move.
1,104 PE-backed and mid-market company websites, compiled from public portfolio disclosures of 31 software-focused private-equity funds, including Thoma Bravo, Vista Equity Partners, Insight Partners, KKR, and Carlyle, cross-checked against acquisition news, with identified exits removed.
40+ reproducible public signals per site in a single automated pass: performance, security, platform, instrumentation, and maintainability, plus keyless email, DNS, TLS, and certificate enrichment. None of this touches a non-public endpoint.
Level A: reproducible public data with a named source, date, and method. External benchmarks from Bain, McKinsey, EY, PwC, and Russell Reynolds are labelled as market context (Level B) and used only to frame the first-party crawl.
The operator behind the numbers.
Research and analysis by the Growth Shuttle × DevriX research program, with Mario Peshev as named operator. Mario is the founder of DevriX, a 40-person firm building technology, data, and revenue systems, and of Growth Shuttle, his value-creation advisory practice for private equity and mid-market operators. Six companies founded, two exited, more than 500 advised since 2010, 40+ acquisitions. Advisor to VMware, SAP, CERN, and Saudi Aramco. Featured in Forbes, BBC, Inc, and Entrepreneur. 30,000 operators and investors read the weekly briefing.
Cite as"The PE Portfolio Cyber & Domain Exposure Deep-Dive, DevriX and Growth Shuttle research program, 2026."