Business model · Private equity

Portfolio risk, in one view.

Every portfolio company is a different size, with a different stack and different obligations. TruOps gives each its own program and gives the fund one view: this company versus its industry on a control maturity scale, and the gap that is the value-creation plan.

Fund view · this company vs. industrycomparable, not identical
2.4this company · CSF
2.8industry average
−0.4gap to industry
3.5fund target
PortCo · 40-person SaaS · NIST CSF 2.0 · this company vs. industry vs. fund target
Govern2.4vs 2.8 · -0.4
Identify3.1vs 2.9 · +0.2
Protect2.9vs 3.1 · -0.2
Detect1.8vs 2.7 · -0.9
Respond2.2vs 2.6 · -0.4
Recover2.0vs 2.5 · -0.5
Detect −0.9vs. industryIdentify +0.2ahead of peersone questionnairescored the same way across the fund
Illustrative example · fictional company. The industry line is a sector reference you load. TruOps does not publish an industry ranking.
In short

TruOps helps private equity firms oversee cybersecurity and compliance across a portfolio: each company gets an isolated environment set up from its own documents, the fund runs a consistent assessment across companies, and a parent-level view shows posture, risk, and deadlines portfolio-wide. Operating partners see this company on a 0–5 scale next to a sector reference and a fund target — not a heatmap that cannot be compared. The same engine runs pre-acquisition due diligence questionnaires.

This page is for you if
  • You cannot put this portco next to its industry on a maturity scale
  • Diligence questionnaires are unchecked, and findings die after close
  • Each portco is a different size, stack, and obligation

The actual challenge

Funds get board slides from portcos that cannot be compared. Diligence is a PDF in the VDR. Value creation is a year of standing up a program from zero — instead of a 0–5 gap versus industry that is the plan.

  • Each client or entity is a new implementation.
  • The view above is a spreadsheet of exports.
  • Playbooks do not transfer.

What you are probably using today

This is what the book of business, the fund, or the holding company is usually running today.

What you use nowWhere it breaksWith TruOps
Quarterly cyber questionnaires in ExcelIncomparable, unchecked, optimistic.A consistent assessment across companies, scored the same way, with a parent-level view.
Pass/fail cyber scorecardsEvery portco is “green,” or on a private scale nobody else uses.0–5 maturity by control function, plotted against a sector reference and a fund target.
Diligence in the VDR onlyFindings do not become the day-one register.Checked questionnaires before close; environment and findings after close.

Bring one real document. Watch the program get set up from it.

From diligence to value creation

  1. DiligenceRun a security and compliance questionnaire on a target; answers are checked against the documents provided.
  2. After closeSet up the company's environment from its documents; a baseline assessment pre-fills.
  3. HoldRun the fund's standard assessment on a cadence; track findings and risk.
  4. ExitHand over a dated, evidence-backed record of the program.

Industry average, then this company

The conversation that moves an operating partner is not “controls are green.” It is: this portco is behind on Detect, peers in the same industry sit higher, and the fund has a target on the same scale. TruOps scores each company on the framework's own 0–5 scale (NIST CSF, CIS, or yours). The industry line is a sector reference you load, or the rest of the fund in that vertical. Pass/fail scorecards cannot do this. A 40-person SaaS company and a regulated insurer keep their own control libraries; they are still comparable on the questions the fund actually asks.

Consistent, not identical

Each company keeps the frameworks that apply to it, while the fund compares companies on a common assessment and a common risk scale.

What operating partners are usually fighting

  • Quarterly cyber questionnaires that cannot be compared or checked.
  • A mandated GRC tool the portco never adopted.
  • Diligence findings that die in the VDR between signing and day one.
  • Value-creation plans that start with "stand up a program" for a year.

If this is your situation

Bring one client, portco, or subsidiary's documents to a demo. TruOps will stand up an isolated environment from them and show the parent-level view.

How TruOps helps

Per-company environments
Isolated data, frameworks, and access.
Fund-wide view
Posture, risk, and deadlines across the portfolio.
This company vs. industry
0–5 maturity by function, plotted against a sector reference and a fund target.
Diligence questionnaires
Pre-deal reviews on the same engine.
Day-one program
Stand the company up from its own documents, with diligence findings already in the register.
Sized to the portco
Defaults work for a small company; depth is there when the company is regulated.

Questions

Can a fund see all portfolio companies at once?

Yes. The parent-level view aggregates posture, risk, and deadlines across companies, with a drill-down into each.

Can we compare a portco to its industry?

Yes, on the same 0–5 maturity scale the fund uses everywhere. The industry line is a sector reference you load, or the rest of the fund in that vertical. TruOps does not publish an industry ranking.

Can TruOps support M&A due diligence?

Yes. See M&A due diligence.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.