A global investment firm standardized security assessments across 400+ portfolio companies.
A global alternative investment firm used TruOps to run CIS Controls v8 assessments and track risk across more than 400 portfolio companies.
A global alternative investment firm with more than 400 portfolio companies needed a consistent way to assess security and compliance across industries and regions. With a dedicated TruOps tenant for each portfolio company, it standardized CIS Controls v8 assessments, centralized risk tracking, and gave its team one view across the portfolio.
- Customer
- Global alternative investment firm, 20+ years investing
- Portfolio
- 400+ companies across industries and regions
- Framework
- CIS Controls v8, plus portfolio-specific frameworks
- Results
- Standardized assessments across the portfolio. One view of risk.
The challenge
- Different rules for every company. Portfolio companies faced different regulations by industry and country.
- Scale. With more than 400 companies, manual processes could not keep up and gaps were easy to miss.
- CIS v8 assessments. Assessing each company against CIS Controls v8 was slow and labor-intensive.
- No single view of risk. Risks were documented in different ways, so the firm could not compare or prioritize them.
What they did
- A dedicated tenant for each portfolio company, keeping each company's data confidential.
- Compliance, vendor, and risk management for every company on one platform.
- Standard CIS v8 assessments, automated to cut the time each one took.
- A framework library plus custom frameworks for companies with extra requirements.
- Configurable dashboards showing compliance status, risk, and maturity across the portfolio.
- Support for several identity providers, so deal teams and portfolio company staff could sign in easily.
Results
- Consistent assessments against CIS v8 and other frameworks across the portfolio.
- Less administrative work for the firm and each portfolio company.
- Better risk visibility, with risks identified, prioritized, and documented in one place.
- Time and cost savings on assessments and reporting.
- Portfolio-wide alignment across industries and regions.
How this works in TruOps 2.0
In TruOps 2.0, each portfolio company gets its own isolated environment. Agents pre-fill the CIS Controls or any other assessment from the company's own documents, and the firm can compare every company on the same 0 to 5 maturity scale. The same platform runs security due diligence on targets and day-one programs after close. See TruOps for acquisitive companies and PE portfolios.
About this story
This customer ran its program on the TruOps platform before TruOps 2.0. The results are as the customer reported them at the time.
Questions
Which framework did the firm standardize on?
CIS Controls v8, with other frameworks added for portfolio companies that needed them.
Related
Assess every deal and bring each new company into the program from its own documents.
→FrameworksCIS Controls18 prioritized safeguards with implementation groups.
→Use casesM&A due diligenceSecurity and compliance diligence on targets, then a working program from day one.
→LearnMulti-tenant GRCOne platform, many isolated clients or entities.
→See it run on your own data.
Book 30 minutes with a GRC specialist. Bring a real document, like a SOC 2 report, risk register, or vendor list (redacted is fine), and we'll show TruOps 2.0 working on it.