2026 State of Data Protection in Private Equity
Confidencial Research · 2026

2026 State of Data Protection in Private Equity

One Industry, One Attack Surface

A scored analysis of the 300 largest private equity firms. 82% of breaches in the cohort never touched the firm itself. This report explains why.

confidencial.io · June 2026
Executive Summary

Private equity does not have 300 separate security problems. It has one.

Most of the world's largest private equity firms share the same handful of law firms, fund administrators, and advisors. That concentration is efficient. It also turns each shared provider into a single point of failure for the industry. The incident data confirms attackers have worked this out. Of the firms in our index with documented cyber incidents, 82% were compromised through the network, not through the firm itself.

The consequences sharpened this year. In March 2026, a federal court allowed breach claims against a PE firm to proceed over a portfolio company's security failures. The most common breach path is now also a liability path. In June, amended Regulation S-P reached full effect, making incident response and 30-day notification a federal requirement. The same rule made encryption the practical dividing line between a reportable event and a documented non-event.

And the scored exposure is only the floor. Deal documents leave these firms through ordinary process. CIMs sit in losing bidders' inboxes forever. Diligence files are never retrieved after close. Associates paste deal terms into AI tools. No attacker required, and no mechanism to pull any of it back. This report scores the 300 largest private equity firms in the world across eight dimensions of data exposure, using public sources only.

82%

Of documented incidents entered through the network. Portfolio companies or third-party providers, not the firm itself.

Confidencial analysis: 39 firms with incident exposure
69%

Of the 300 largest firms show no visible security program. No named CISO, no certification, no published posture. These firms raised $3.2T in five years.

Confidencial analysis, public sources
$245M

Simultaneous breach exposure from a single event at one shared fund administrator — confirmed client relationships only.

Confidencial analysis × IBM 2025 sector average
32%

Of the 300 firms are served by a single law firm. The top five law firms collectively serve more than half the cohort.

Confidencial analysis, public records (floors, not ceilings)
1st

Time a US federal court allowed data breach claims against a PE firm to proceed over a portfolio company's security failures — including pre-close conduct.

Bain / PowerSchool, N.D. Cal., March 2026
Jun 3

Amended Reg S-P reached full effect for all registered advisers in 2026. Incident response, 30-day notification, vendor oversight now required.

SEC Final Rule 34-100155
Section 1 — The Structure

One industry, one attack surface

A private equity firm looks like a fortress: small headcount, controlled systems, limited public surface. The look is misleading. Every firm sits at the hub of a spoke network it does not control. Counsel holds the deal documents. Administrators hold LP records and wire instructions. Placement agents hold investor data. Consultants hold diligence files. Portfolio companies hold everything the firm knows about them. Mapped across 300 firms, those spokes converge on the same handful of providers.

The legal spine runs through five firms

A single law firm appears as counsel for 95 of the 300 firms analyzed across fund formation, deal advisory, or both — 32% of the world's largest private equity firms with deal documents, fund agreements, and transaction records on one provider's systems. The top five law firms collectively serve at least 153 firms, over half the cohort. These figures are floors, not ceilings: they count only relationships that surfaced in public announcements. A breach at any one of these providers is a private equity industry event, not a legal industry event.

Fund administration is a five-provider market

Five administrators were publicly identifiable as service providers across dozens of cohort firms. 44 are confirmed from public records alone. The true number is substantially higher, since administration relationships rarely appear in announcements. What an administrator holds is exactly what an attacker wants: limited partner identities, capital account balances, subscription documents, tax forms, and the wire instructions that move capital calls and distributions.

The wiring diagram — one firm's view
One PE Firm
the only perimeter it controls
only 7 of 39 incidents entered here
Outside Counsel
deal docs · fund agreements
one firm = 32% of the cohort
Fund Admin
LP records · wire instructions
five administrators serve the industry simultaneously
Placement Agents
investor data
Portfolio Companies
everything the firm knows
26 of 39 incidents entered here
Consultants & Advisors
diligence files
6 incidents via third parties

Data flows out — control does not return. The same five law firms and five administrators sit at the end of these spokes for most of the cohort. Concentration is efficient — and every shared provider is a correlated risk. The industry's risk model treats firms as independent. They are not.

Section 2 — The Math

The price of correlation

The traditional model prices breaches one firm at a time: IBM's 2025 figures put the financial-sector average at $5.56 million per incident. The wiring diagram says that is the wrong unit of account. A single event at a shared provider is not one breach — it is dozens of simultaneous ones.

Both figures are conservative three times over: they use confirmed relationships only, an industry-average cost for firms holding far-above-average data, and exclude the cost private equity actually fears — the damage to limited partner trust, which never appears on an invoice and never fully recovers. It does not belong to any one firm. It belongs to the industry's structure.

$245M

Simultaneous breach exposure from one correlated event at a single shared fund administrator, applied only to its 44 publicly confirmed client relationships at the sector-average breach cost. Each dot is one of the largest firms in the world, breached in the same instant.

$500M+

Across the legal spine: 95 confirmed sponsor relationships at one law firm, at the same sector-average breach cost.

The precedent already happened

The 2023 MOVEit incident, a single vulnerability in one file-transfer product, cascaded into breaches at more than 2,700 organizations and exposed data on over 90 million individuals. Much of that exposure ran through third-party administrators and service providers rather than the named victims themselves. Private equity's administration layer has the same shape: shared providers, shared software, shared exposure.

The targeting is active

In May 2025 the FBI issued a private industry notification warning that the Silent Ransom Group was targeting US law firms through callback phishing and IT-support impersonation, specifically to exfiltrate client data for extortion. For private equity, the math is uncomfortable: a successful intrusion at any one of five law firms exposes deal and fund data belonging to dozens of the largest firms in the world at once.

Section 3 — The Attacker's View

Why attackers target the network, not the firm

If the firm is a fortress and the network is open ground, a rational attacker chooses the open ground. The incident record shows they do. Across the 300 firms, 39 had documented cyber incident exposure. 82% of those incidents entered through the network rather than the firm. The defended perimeter and the attacked perimeter are not the same perimeter.

The direct hits prove the value

Insight Partners, which manages over $90 billion and is itself an investor in some of the largest cybersecurity companies in the world, disclosed a ransomware attack that began with social engineering in October 2024. It ran undetected until servers were encrypted in January 2025. The stolen data included banking and tax information, employee records, and information on the firm's limited partners, funds, and portfolio companies. The entire network in one exfiltration, affecting 12,657 individuals. Class action investigations are now active.

The lesson is not that one firm was careless. It is that even a security-literate firm holds data worth months of patient effort, and that data implicates the entire network it sits in.

The economics favor the attacker

Private equity holds the most monetizable data in the economy: material non-public information on thousands of private companies, LP wire instructions, and the personal financial details of some of the wealthiest individuals and institutions in the world. IBM puts the financial-services breach average at $5.56M and the US average at an all-time high of $10.22M.

The target/defense mismatch

Set the value against the defense. 69% of these firms show no visible security program at all. The richest target in the economy, defended on average more lightly than a mid-market bank. Once there, the rational target is the portfolio company or the shared provider rather than the firm itself.

39 documented incidents — by entry point
26 — via portfolio company
7 direct
6 third-party

82% of incidents entered through the network rather than the firm. Two-thirds entered through portfolio companies specifically.

Section 4 — The Liability Chain

The most common breach path is now a liability path

26 of 39 documented incidents came through portfolio companies. Until this quarter, those were someone else's incidents — the portfolio company's problem, walled off from the fund by entity structure. As of March 2026, that wall has a crack in it. The most heavily trafficked path into a fund now carries legal consequences at the fund level.

Bain Capital / PowerSchool — N.D. California, March 2026

A federal court allowed negligence and aiding-and-abetting claims against Bain Capital to proceed in connection with a data breach at its portfolio company PowerSchool. It is the first time claims of this kind against a private equity firm have survived a motion to dismiss. The claims include conduct from before the acquisition closed. Liability has not been determined, but the theory is now live.

The court found that Bain exercised "control over PowerSchool's key strategic decisions, including cybersecurity operations," and rejected contractual disclaimers of control as dispositive. GPs who direct cost decisions affecting portfolio security are building the factual record this theory runs on.

The shield that no longer holds

Entity separation, the principle that a portfolio company's breach stays the portfolio company's problem, has been the industry's structural defense against exactly this exposure. It was argued in the PowerSchool courtroom. It did not end the case. Where a sponsor exercises operational control over a portfolio company's security decisions, the separation may not survive contact with the negligence theory the court accepted.

Why this combination matters

Two-thirds of documented incidents enter through portfolio companies. A court has now allowed a fund to be sued for exactly that scenario, including for pre-close conduct. The exposure the fund treated as someone else's just became its own. The defense the theory turns on is the ability to show that protection traveled with the data, not just that a policy existed.

Section 5 — The Floor, Not the Ceiling

No attacker required

Everything scored in this report measures exposure visible in public records: incidents, posture, and provider concentration. Those figures are the floor. Above them sits an exposure no scoring framework can see from outside, because it isn't a breach at all: it is the ordinary lifecycle of a deal document, working exactly as designed.

A CIM goes to 40–80 prospective buyers during a sale process. Diligence files go to bankers, lawyers, and co-investors — 15 to 40 external parties per transaction. LP reports, K-1s, and capital calls go to every investor. Each document is downloaded, forwarded, and retained. The deal closes; the documents don't. And increasingly, those same files are pasted into AI tools on personal devices, invisible to the firm.

The deal document lifecycle
1 · CREATE

CIM, diligence pack, LP report

2 · DISTRIBUTE

40–80 parties via VDR or email

3 · CLOSE

VDR shuts. One buyer wins.

4 · …FOREVER

Every other party keeps everything. Indefinitely.

Sell-side

Losing bidders, including direct competitors of the target, retain the full CIM: financials, projections, customer lists, IP schedules. No mechanism exists to retrieve or expire any copy.

Post-close

Only 23% of executives manage cyber risk proactively after a deal closes (FTI, 2026). Diligence documents at advisors, bankers, and co-investors are almost never retrieved.

AI pipelines

Associates summarize CIMs in public LLMs on personal devices. No log, no alert, no policy that can technically prevent it.

A firm can score well on every dimension in this report and still have thousands of uncontrolled copies of its most sensitive documents sitting in other organizations' systems. The scored exposure requires an attacker. This one requires only business as usual.

Section 6 — Voice of the Market

What the industry is actually saying

PE Cybersecurity Adviser

"Cybersecurity is not appropriately accounted for in a deal or in a post-close strategy. Deal teams are still asking 'Is cybersecurity adequate?' instead of understanding what it will actually cost if it's not there."

— Anthony Catalano, PE Cybersecurity Leader, RSM US LLP · 2026
Deal Transition Risk

"As soon as deals are announced, attackers go after the organization. It's a 90-day window where everything is in flux and attention is not on security as it might need to be."

— Anthony Catalano, RSM US LLP · 2026
Portfolio Operations Research

"80% of firms experienced some form of disruption tied to cybersecurity risk during the hold period over the past year. Unexpected remediation costs, litigation, downtime, and integration failures."

— Kroll survey of 325 PE portfolio leaders · February 2026
PE Compliance Roundtable

"A recurring theme was the difficulty in evidencing governance historically. Consensus emerged around the importance of recordkeeping, controls, and board-level reporting."

— ACA Group Compliance Leaders Roundtable · December 2025
The transaction window: FTI Consulting, CISO Redefined III (March 2026, 278 senior leaders)
1 in 4
experienced a cyber incident during or shortly after a transaction
42%
of those saw significant deal value reduction
58%
said financial targets were impaired
23%
manage cyber risk proactively post-close
LP Operational Due Diligence · Adams Street Partners · January 2026

"For many allocators and institutional LPs, cybersecurity controls are now part of operational due diligence." Only 28% of managers under $1B AUM maintain active cyber insurance. The figure for managers above $1B is 52%. Smaller funds face the most LP scrutiny and have the least protection.

Section 7 — The Defense

The defense line is flat

The industry's exposure would matter less if its defenses scaled with its data. They do not. Of the 300 firms analyzed, 208 (69%) show no visible security program: no named CISO or head of information security, no published certification such as SOC 2 or ISO 27001, and no security or trust posture disclosed anywhere public. These are firms that collectively raised more than $3.2 trillion over the past five years.

208/300
firms with no visible security program of any kind
$3.2T
raised by those firms over the past five years
42%
of firms that have already been breached still show no visible program
The industry learns by being breached

Firms with documented incident history show measurably stronger security posture than untouched firms. Security investment in private equity is reactive, arriving after the breach rather than before it — the most expensive sequence available. Even among breached firms, 42% still show nothing.

Visibility is itself a control

A firm with no public security signal is not necessarily undefended. But in a network where counterparties increasingly demand security evidence before they transact, the absence of a posture is a commercial liability as well as a risk one. The firms scoring worst cannot prove they are not exposed.

Section 8 — The Timing

Four curves crossing in 2026

The danger is not any single number. It is timing. Four forces are converging on the same year, and the defense line is not rising to meet them. 2026 is the year the gap becomes legible to attackers, regulators, courts, and LPs at the same time.

AI data movement2022 → 2026
Externalization
Regulation
Liability
Visible defenseflat
01 · AI
AI is accelerating data movement

26% of the cohort (78 firms) show deep operational AI adoption. IBM found unsanctioned AI was a factor in 20% of all breaches in 2025, adding $670K to average cost and taking 247 days to detect. 63% of breached organizations lacked AI governance entirely.

02 · NETWORK
Externalization is accelerating

The spoke network is not static. As firms outsource more of the fund lifecycle and pursue more deals, the share of sensitive data living outside the firm's walls rises every year. Every new deal adds permanently to the stock of documents that never come home.

03 · REGULATION
Regulation arrived this month

The SEC's amended Regulation S-P reached its final compliance deadline on June 3, 2026. Written incident response, data mapping, and breach notification are now federal requirements. The SEC's 2026 exam priorities add AI governance and vendor oversight.

04 · LIABILITY
Liability joined them this quarter

The Bain / PowerSchool ruling converts the industry's most common breach path into a fund-level legal exposure, and it landed in the same quarter as the regulation above it.

Section 9 — The Regulatory Floor

Reg S-P and the encryption pivot

The amended Regulation S-P, the SEC's first revision in 24 years, is usually summarized as a notification rule: a written incident response program, 30-day notification, vendor oversight, and written documentation, in force for all registered advisers as of June 3, 2026. Read closely, the final rule (34-100155) does something more consequential: it draws a line through every firm's data, and encryption is the line.

Unencrypted data

An LP's inbox is compromised. The K-1s and capital account statements inside are plaintext PDFs. That is unauthorized access to sensitive customer information: the incident response program triggers, and the firm is notifying every affected individual within 30 days, with the investigation, costs, and LP-trust damage that follow.

Encrypted data

Same incident. But the documents carry file-level encryption meeting current industry standards, and the keys remain secure. Under the final rule, the firm may determine the encrypted data is not "sensitive customer information" at all. The breach becomes a documented non-event, provided the determination is recorded in writing.

The rule does not mandate encryption. It prices its absence. The SEC declined to write an explicit encryption safe harbor, but stated that encryption using industry-standard practices is a reasonable factor in the harm determination, and referenced FIPS 140-3 as the benchmark. Under the new rule, encryption is no longer a security preference. It is the difference between disclosure and a file note.

The service provider provisions regulate the spokes

The rule requires written policies for oversight of service providers, who must notify the firm within 72 hours of becoming aware of a breach. The definition covers fund administrators, placement agents, and data room providers. LP data sitting at an administrator is the adviser's obligation, not the administrator's alone.

Examination is active

The Division of Examinations' 2026 priorities name Reg S-P incident response, data loss prevention, and access controls as focus areas. The question examiners ask is not whether a policy exists. It is whether the firm can demonstrate the controls and produce the records.

Section 10 — What Changes

What changes when protection travels with the file

The CIM in a sell-side process
Today

Goes to 40 to 80 bidders. The losers, which include competitors of the target, keep the full document forever. No expiry, no revocation, no record of who still holds it.

With protection on the file

Access is scoped per recipient and expires automatically at close. Revoke a losing bidder and every copy they hold, whether downloaded or forwarded, stops opening.

The compromised LP inbox
Today

K-1s and capital account statements sit in the inbox as plaintext. The compromise is unauthorized access to sensitive customer information: a 30-day Reg S-P notification event.

With protection on the file

The same documents are encrypted with secure keys. The firm can document a determination that the data is not usable to cause harm: a non-event, with the written record the rule requires.

The breach in the network (counsel, administrator, portfolio company)
Today

A breach at a shared provider exposes deal and fund data the firm sent there. The firm has no control over the provider's perimeter and no way to make the stolen files unreadable after the fact.

With protection on the file

The file left the firm already encrypted. Exfiltrated from any spoke, it stays inaccessible without authorization. The blast radius shrinks to nothing.

None of these require the firm to control the perimeter, retrieve a document, or trust a counterparty's security. The protection is in the file, so it holds wherever the file goes.

Section 11 — The Conclusion

What holds in a network you don't control

This report has described two failure modes that look different and are the same. Where data sits — at counsel, with administrators, inside portfolio companies — it waits for someone else's breach. How data moves — in CIMs that outlive auctions, diligence files that outlive deals, AI tools that retain what they are fed — it leaks with no breach at all. Defending the firm's perimeter addresses neither, because in both cases the data has already left. The perimeter the data actually lives behind is the file.

Field-level encryption that travels with the document changes the unit of defense. If the file is exfiltrated in a breach at the firm, a law firm, or an administrator, the data inside stays inaccessible to anyone without authorization. The blast radius of every breach in the network shrinks, because the stolen file is unreadable. And under amended Reg S-P, that same property is what separates a 30-day notification event from a documented non-event.

Persists

Encryption embedded in the document survives download, forward, and every hop through the network.

Expires

Access ends when the process does: at close, at engagement end, at LP exit. No retrieval chase.

Revocable

Revoke once and every copy stops opening, including copies already sitting in other organizations' systems.

Audited

Who opened what, when, from where. The written record Reg S-P determinations and examinations require.

This is the only model that matches the wiring diagram. Perimeter tools defend a boundary that the industry's own structure renders irrelevant. Discovery and classification tools tell a firm where its sensitive data is without stopping it from leaving. Protection that travels with the file defends the data at the one location it never leaves, across every spoke the firm cannot control. Fund documents and LP records stay sensitive for decades — well inside the window where data harvested now is decrypted later. Protection built on post-quantum-ready cryptography is built to outlast that window.

Private equity is one connected surface. The data confirms attackers treat it that way. The defensible response is to stop trying to wall off 300 firms and thousands of providers, and to protect the asset that moves through all of them.

Methodology

How this report was built

Cohort

The 300 largest private equity firms in the world by capital raised over the trailing five years, per the 2026 PEI 300 ranking. 206 are headquartered in the United States; 94 internationally. A majority across both groups are SEC-registered investment advisers and therefore subject to the regulations referenced in this report.

Scoring framework

Each firm was scored 0–5 across eight exposure dimensions, producing a 40-point composite aligned with Confidencial's prior sector analyses of the legal and pharmaceutical industries to allow cross-vertical comparison. The dimensions: fund scale and limited partner surface; deal velocity; regulated-portfolio exposure; portfolio breadth and control model; third-party sprawl; AI adoption depth; incident history; and security posture (inverse-scored). Composites were banded: Critical (30–40), High (24–29), Moderate (17–23), Low (≤16).

Sources

All scoring relied on publicly available information: firm websites, portfolio and team pages, public deal and fundraising announcements, regulatory filings, careers pages, and reported cyber incident records. No confidential or non-public information was used. Provider-concentration figures were derived from named relationships in public deal announcements and filings; because many such relationships are never publicly disclosed, all concentration figures stated in this report are floors and understate true concentration.

Incident classification

Cyber incidents were classified by the entity actually breached (firm-level, portfolio-company-level, or third-party-vendor-level) rather than by headline attribution. Incidents at portfolio companies were counted against the sponsor where the portfolio relationship was confirmed for the relevant period.

Anonymization

Service providers (law firms, fund administrators, and placement agents) are not named in this report. All concentration counts and derived figures are retained in full; only the identities are withheld. This report is intended as industry-level analysis of structural exposure, not as an assessment of any individual provider or firm.

Limitations

Public-source scoring captures visible posture, not internal reality: a firm with no public security signal may maintain strong internal controls. The document-lifecycle exposure described in Section 5 is, by its nature, not visible to public scoring and is presented as analysis rather than scored data. The cohort is a point-in-time snapshot; rankings, portfolios, and provider relationships change continuously.

References

Sources & citations

[1]BleepingComputer / TechCrunch / Maine Attorney General notification, "Insight Partners ransomware breach," 2025. The breach affected 12,657 individuals and exposed banking and tax data, employee records, and limited partner, fund, and portfolio company information.
[2]IBM, "Cost of a Data Breach Report 2025." Financial-services average breach cost $5.56M; United States average $10.22M; shadow-AI-related breaches added up to $670K to average cost.
[3]U.S. Securities and Exchange Commission, "Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information — Final Amendments" (Final Rule 34-100155). Compliance deadlines December 3, 2025 (larger entities) and June 3, 2026 (smaller entities).
[4]U.S. Securities and Exchange Commission, Division of Examinations, "2026 Examination Priorities," naming AI governance, data loss prevention, access controls, and third-party vendor oversight as focus areas.
[5]Private Equity International, "PEI 300, 2026 ranking," published June 2026.
[6]Kroll, "State of Portfolio Cybersecurity in Private Equity," February 2026 (n=325 PE executives).
[7]FTI Consulting, "CISO Redefined III: Navigating Cybersecurity Risks in Transactions," March 2026 (n=278 senior leaders). Confidencial, "2026 State of Data Protection in the Legal Sector" and "2026 State of Data Protection in Pharma," prior sector analyses establishing the comparative scoring framework.
[8]Federal Bureau of Investigation, Private Industry Notification, "Silent Ransom Group targeting U.S. law firms," May 2025.
[9]Emsisoft / public MOVEit incident tracking, 2023–2024: the MOVEit file-transfer vulnerability cascaded to 2,700+ organizations and 90M+ individuals, predominantly through third-party service providers.
[10]In re PowerSchool Holdings Data Breach Litigation, S.D. Cal., order of March 18, 2026, granting in part and denying in part Bain Capital's motion to dismiss; analysis per Womble Bond Dickinson client alert, "Unprecedented: Private Equity Firm Potentially on Hook for Portfolio Company's Data Breach," April 2026.
[11]Adams Street Partners, "Private Markets Outlook," January 2026. Operational due diligence and cyber-insurance coverage figures (28% of sub-$1B managers vs. 52% above $1B).

This report is provided for informational purposes and reflects analysis of publicly available information as of June 2026. It does not constitute legal, financial, or security advice, and is not an assessment of the security practices of any individual firm named or referenced. Confidencial makes no representation as to the completeness of public records relied upon.

Next Steps

See where your firm sits on this map.

The exposure described in this report is structural. It is also measurable, firm by firm. Confidencial offers a data risk assessment that maps one live process — a sell-side deal, LP reporting, or a diligence room — and shows exactly where your most sensitive documents are exposed today. No agents to install. No disruption to the deal.

Deal document lifecycle management, from first distribution through close and beyond
LP document protection with the audit trail Reg S-P determinations and examinations require
Protection that persists across the provider network: counsel, administrators, data rooms, AI pipelines
Portfolio-level deployment that reduces fund aggregation risk and the liability surface the Bain theory runs on
confidencial.io/contact
Protection that travels with the data.
2026 State of Data Protection in Private Equity · © 2026 Confidencial, Inc. All rights reserved.