Growth Shuttle × DevriX · PE Research · No. 01 · July 2026

The PE Portfolio Cyber & Domain Exposure Deep-Dive

Security controls are widely published and rarely enforced.

A first-party study of the website security, email authentication, and domain hardening of 1,104 PE-backed and mid-market company websites, drawn from the disclosed portfolios of 31 software-focused private equity funds. Ninety-eight percent publish a DMARC record. Only forty-one percent actually enforce it. This report quantifies the gap between what portfolio companies say they do and what their DNS, mail, and web layers actually enforce, and what it will cost to close it.

A joint research report by
DevriX
Technology, data & revenue systems · 40-person engineering firm
Growth Shuttle
Advisory on the decisions that move EBITDA · PE & mid-market
Lead author: Mario Peshev. Founder of DevriX & Growth Shuttle; value-creation advisor to private equity and mid-market operators.
Companies
1,104
Funds
31
Signals / site
40+
Evidence
Level A
01Executive summary

Cyber diligence has moved from a box-ticking exercise to a line item that prices the deal. This report measures what that inherited risk actually looks like. Not in a survey of intentions, but in the reproducible public security posture of 1,104 PE-backed companies.

The headline is not that portfolio companies run ancient software. They do not. Only about 1% of detectable WordPress installs sit on an outdated core branch, and transport security is effectively solved. The exposure is governance, not software currency.

Security is the weakest of the five technical domains we score, at a median of 72/100. Within it the story is a single pattern: controls are near-universally published, and thinly enforced.

98%
Publish a DMARC record
41%
Enforce DMARC at p=reject
13%
Ship the complete 6-header stack
59%
Fronted by Cloudflare, mostly idle
94%
Negotiate TLS 1.3 on primary crawl
30%
Ship the four-header core baseline
14%
Domains with DNSSEC deployed
1%
Have completed all four hardening moves
02Part 1: The core finding

Security is the weakest of the five technical domains, and it's a governance gap.

Figure 1
Median score by technical domain (out of 100)
n = 1,104 companies. Security ranks last of the five domains scored. The same domain a cyber diligence team prices.
Figure 2
DMARC: near-universal adoption, minority enforcement
98% publish a DMARC record. Only 41% enforce it at p=reject, the setting that actually stops domain spoofing.
Figure 3
The governance funnel: from publishing to hardened
Read top-to-bottom, the population collapses at every stage. Exactly 1% of the universe has done all four.
Figure 4
Share of the set missing each individual security header
Most of the six headers are absent on a plurality or majority of the set.
The one line
"The edge control plane is bought and idle. 59% of the portfolio sits behind Cloudflare, yet Cloudflare-fronted sites are no more likely to ship the header baseline than sites with no CDN at all."
03Part 2: Where the floor is set

Platform choice is a security decision. Mail concentration is a shared-fate risk.

Figure 5
Mean security score by CMS platform
HubSpot CMS sets the highest default floor (75.1). Webflow the lowest (59.1), a 16-point spread.
Figure 6
Where portfolio mail lands: a near-duopoly
~3 in 4 companies depend on one of two vendors for email delivery and, increasingly, for identity.
Figure 7
Median security score by sector: regulation does not buy hygiene
Security-software vendors set the standard at 80. Insurance/Fintech and Education score below the set median despite handling regulated data.
The domain-hardening tail

The registrar-level controls are almost nobody's job.

DNSSEC is deployed on 14% of the domains we crawled. CAA, the record that pins which certificate authorities can issue for a domain, on 27%. Both are one-line DNS changes with no user-facing risk. Neither is anyone's KPI, and it shows.

27%
CAA records
14%
DNSSEC
04The operator playbook

The first 100 days of a portfolio security baseline.

  1. 01
    Enforce DMARC to reject on every domain.

    The first move by buyer-visibility-to-cost. Closes business-email-compromise exposure. It is a DNS change, and only 41% of the universe has done it.

  2. 02
    Ship the six-header stack at the CDN.

    59% of the portfolio already sits behind Cloudflare. The control is bought and idle. One edge configuration, applied as a standard, moves a company past the 13% frontier.

  3. 03
    Turn on DNSSEC and CAA at the registrar.

    Two one-line DNS changes. 86% of the market has not turned on DNSSEC; 73% lack CAA. Both are visible to the next buyer's diligence pass.

  4. 04
    Standardise on a platform with a higher default floor.

    HubSpot CMS: 75.1 mean security. Webflow: 59.1. Platform choice is a security decision disguised as an IT-consolidation move.

05Methodology
The dataset

1,104 PE-backed and mid-market company websites, compiled from public portfolio disclosures of 31 software-focused private-equity funds, including Thoma Bravo, Vista Equity Partners, Insight Partners, KKR, and Carlyle, cross-checked against acquisition news, with identified exits removed.

What we measured

40+ reproducible public signals per site in a single automated pass: performance, security, platform, instrumentation, and maintainability, plus keyless email, DNS, TLS, and certificate enrichment. None of this touches a non-public endpoint.

Evidence class

Level A: reproducible public data with a named source, date, and method. External benchmarks from Bain, McKinsey, EY, PwC, and Russell Reynolds are labelled as market context (Level B) and used only to frame the first-party crawl.

About the research

The operator behind the numbers.

Research and analysis by the Growth Shuttle × DevriX research program, with Mario Peshev as named operator. Mario is the founder of DevriX, a 40-person firm building technology, data, and revenue systems, and of Growth Shuttle, his value-creation advisory practice for private equity and mid-market operators. Six companies founded, two exited, more than 500 advised since 2010, 40+ acquisitions. Advisor to VMware, SAP, CERN, and Saudi Aramco. Featured in Forbes, BBC, Inc, and Entrepreneur. 30,000 operators and investors read the weekly briefing.

Cite as"The PE Portfolio Cyber & Domain Exposure Deep-Dive, DevriX and Growth Shuttle research program, 2026."