A scored analysis of the 300 largest private equity firms. 82% of breaches in the cohort never touched the firm itself. This report explains why.
Most of the world's largest private equity firms share the same handful of law firms, fund administrators, and advisors. That concentration is efficient. It also turns each shared provider into a single point of failure for the industry. The incident data confirms attackers have worked this out. Of the firms in our index with documented cyber incidents, 82% were compromised through the network, not through the firm itself.
The consequences sharpened this year. In March 2026, a federal court allowed breach claims against a PE firm to proceed over a portfolio company's security failures. The most common breach path is now also a liability path. In June, amended Regulation S-P reached full effect, making incident response and 30-day notification a federal requirement. The same rule made encryption the practical dividing line between a reportable event and a documented non-event.
And the scored exposure is only the floor. Deal documents leave these firms through ordinary process. CIMs sit in losing bidders' inboxes forever. Diligence files are never retrieved after close. Associates paste deal terms into AI tools. No attacker required, and no mechanism to pull any of it back. This report scores the 300 largest private equity firms in the world across eight dimensions of data exposure, using public sources only.
Of documented incidents entered through the network. Portfolio companies or third-party providers, not the firm itself.
Of the 300 largest firms show no visible security program. No named CISO, no certification, no published posture. These firms raised $3.2T in five years.
Simultaneous breach exposure from a single event at one shared fund administrator — confirmed client relationships only.
Of the 300 firms are served by a single law firm. The top five law firms collectively serve more than half the cohort.
Time a US federal court allowed data breach claims against a PE firm to proceed over a portfolio company's security failures — including pre-close conduct.
Amended Reg S-P reached full effect for all registered advisers in 2026. Incident response, 30-day notification, vendor oversight now required.
A private equity firm looks like a fortress: small headcount, controlled systems, limited public surface. The look is misleading. Every firm sits at the hub of a spoke network it does not control. Counsel holds the deal documents. Administrators hold LP records and wire instructions. Placement agents hold investor data. Consultants hold diligence files. Portfolio companies hold everything the firm knows about them. Mapped across 300 firms, those spokes converge on the same handful of providers.
A single law firm appears as counsel for 95 of the 300 firms analyzed across fund formation, deal advisory, or both — 32% of the world's largest private equity firms with deal documents, fund agreements, and transaction records on one provider's systems. The top five law firms collectively serve at least 153 firms, over half the cohort. These figures are floors, not ceilings: they count only relationships that surfaced in public announcements. A breach at any one of these providers is a private equity industry event, not a legal industry event.
Five administrators were publicly identifiable as service providers across dozens of cohort firms. 44 are confirmed from public records alone. The true number is substantially higher, since administration relationships rarely appear in announcements. What an administrator holds is exactly what an attacker wants: limited partner identities, capital account balances, subscription documents, tax forms, and the wire instructions that move capital calls and distributions.
Data flows out — control does not return. The same five law firms and five administrators sit at the end of these spokes for most of the cohort. Concentration is efficient — and every shared provider is a correlated risk. The industry's risk model treats firms as independent. They are not.
The traditional model prices breaches one firm at a time: IBM's 2025 figures put the financial-sector average at $5.56 million per incident. The wiring diagram says that is the wrong unit of account. A single event at a shared provider is not one breach — it is dozens of simultaneous ones.
Both figures are conservative three times over: they use confirmed relationships only, an industry-average cost for firms holding far-above-average data, and exclude the cost private equity actually fears — the damage to limited partner trust, which never appears on an invoice and never fully recovers. It does not belong to any one firm. It belongs to the industry's structure.
Simultaneous breach exposure from one correlated event at a single shared fund administrator, applied only to its 44 publicly confirmed client relationships at the sector-average breach cost. Each dot is one of the largest firms in the world, breached in the same instant.
Across the legal spine: 95 confirmed sponsor relationships at one law firm, at the same sector-average breach cost.
The 2023 MOVEit incident, a single vulnerability in one file-transfer product, cascaded into breaches at more than 2,700 organizations and exposed data on over 90 million individuals. Much of that exposure ran through third-party administrators and service providers rather than the named victims themselves. Private equity's administration layer has the same shape: shared providers, shared software, shared exposure.
In May 2025 the FBI issued a private industry notification warning that the Silent Ransom Group was targeting US law firms through callback phishing and IT-support impersonation, specifically to exfiltrate client data for extortion. For private equity, the math is uncomfortable: a successful intrusion at any one of five law firms exposes deal and fund data belonging to dozens of the largest firms in the world at once.
If the firm is a fortress and the network is open ground, a rational attacker chooses the open ground. The incident record shows they do. Across the 300 firms, 39 had documented cyber incident exposure. 82% of those incidents entered through the network rather than the firm. The defended perimeter and the attacked perimeter are not the same perimeter.
Insight Partners, which manages over $90 billion and is itself an investor in some of the largest cybersecurity companies in the world, disclosed a ransomware attack that began with social engineering in October 2024. It ran undetected until servers were encrypted in January 2025. The stolen data included banking and tax information, employee records, and information on the firm's limited partners, funds, and portfolio companies. The entire network in one exfiltration, affecting 12,657 individuals. Class action investigations are now active.
The lesson is not that one firm was careless. It is that even a security-literate firm holds data worth months of patient effort, and that data implicates the entire network it sits in.
Private equity holds the most monetizable data in the economy: material non-public information on thousands of private companies, LP wire instructions, and the personal financial details of some of the wealthiest individuals and institutions in the world. IBM puts the financial-services breach average at $5.56M and the US average at an all-time high of $10.22M.
Set the value against the defense. 69% of these firms show no visible security program at all. The richest target in the economy, defended on average more lightly than a mid-market bank. Once there, the rational target is the portfolio company or the shared provider rather than the firm itself.
82% of incidents entered through the network rather than the firm. Two-thirds entered through portfolio companies specifically.
26 of 39 documented incidents came through portfolio companies. Until this quarter, those were someone else's incidents — the portfolio company's problem, walled off from the fund by entity structure. As of March 2026, that wall has a crack in it. The most heavily trafficked path into a fund now carries legal consequences at the fund level.
A federal court allowed negligence and aiding-and-abetting claims against Bain Capital to proceed in connection with a data breach at its portfolio company PowerSchool. It is the first time claims of this kind against a private equity firm have survived a motion to dismiss. The claims include conduct from before the acquisition closed. Liability has not been determined, but the theory is now live.
The court found that Bain exercised "control over PowerSchool's key strategic decisions, including cybersecurity operations," and rejected contractual disclaimers of control as dispositive. GPs who direct cost decisions affecting portfolio security are building the factual record this theory runs on.
Entity separation, the principle that a portfolio company's breach stays the portfolio company's problem, has been the industry's structural defense against exactly this exposure. It was argued in the PowerSchool courtroom. It did not end the case. Where a sponsor exercises operational control over a portfolio company's security decisions, the separation may not survive contact with the negligence theory the court accepted.
Two-thirds of documented incidents enter through portfolio companies. A court has now allowed a fund to be sued for exactly that scenario, including for pre-close conduct. The exposure the fund treated as someone else's just became its own. The defense the theory turns on is the ability to show that protection traveled with the data, not just that a policy existed.
Everything scored in this report measures exposure visible in public records: incidents, posture, and provider concentration. Those figures are the floor. Above them sits an exposure no scoring framework can see from outside, because it isn't a breach at all: it is the ordinary lifecycle of a deal document, working exactly as designed.
A CIM goes to 40–80 prospective buyers during a sale process. Diligence files go to bankers, lawyers, and co-investors — 15 to 40 external parties per transaction. LP reports, K-1s, and capital calls go to every investor. Each document is downloaded, forwarded, and retained. The deal closes; the documents don't. And increasingly, those same files are pasted into AI tools on personal devices, invisible to the firm.
CIM, diligence pack, LP report
40–80 parties via VDR or email
VDR shuts. One buyer wins.
Every other party keeps everything. Indefinitely.
Losing bidders, including direct competitors of the target, retain the full CIM: financials, projections, customer lists, IP schedules. No mechanism exists to retrieve or expire any copy.
Only 23% of executives manage cyber risk proactively after a deal closes (FTI, 2026). Diligence documents at advisors, bankers, and co-investors are almost never retrieved.
Associates summarize CIMs in public LLMs on personal devices. No log, no alert, no policy that can technically prevent it.
A firm can score well on every dimension in this report and still have thousands of uncontrolled copies of its most sensitive documents sitting in other organizations' systems. The scored exposure requires an attacker. This one requires only business as usual.
"Cybersecurity is not appropriately accounted for in a deal or in a post-close strategy. Deal teams are still asking 'Is cybersecurity adequate?' instead of understanding what it will actually cost if it's not there."
"As soon as deals are announced, attackers go after the organization. It's a 90-day window where everything is in flux and attention is not on security as it might need to be."
"80% of firms experienced some form of disruption tied to cybersecurity risk during the hold period over the past year. Unexpected remediation costs, litigation, downtime, and integration failures."
"A recurring theme was the difficulty in evidencing governance historically. Consensus emerged around the importance of recordkeeping, controls, and board-level reporting."
"For many allocators and institutional LPs, cybersecurity controls are now part of operational due diligence." Only 28% of managers under $1B AUM maintain active cyber insurance. The figure for managers above $1B is 52%. Smaller funds face the most LP scrutiny and have the least protection.
The industry's exposure would matter less if its defenses scaled with its data. They do not. Of the 300 firms analyzed, 208 (69%) show no visible security program: no named CISO or head of information security, no published certification such as SOC 2 or ISO 27001, and no security or trust posture disclosed anywhere public. These are firms that collectively raised more than $3.2 trillion over the past five years.
Firms with documented incident history show measurably stronger security posture than untouched firms. Security investment in private equity is reactive, arriving after the breach rather than before it — the most expensive sequence available. Even among breached firms, 42% still show nothing.
A firm with no public security signal is not necessarily undefended. But in a network where counterparties increasingly demand security evidence before they transact, the absence of a posture is a commercial liability as well as a risk one. The firms scoring worst cannot prove they are not exposed.
The danger is not any single number. It is timing. Four forces are converging on the same year, and the defense line is not rising to meet them. 2026 is the year the gap becomes legible to attackers, regulators, courts, and LPs at the same time.
26% of the cohort (78 firms) show deep operational AI adoption. IBM found unsanctioned AI was a factor in 20% of all breaches in 2025, adding $670K to average cost and taking 247 days to detect. 63% of breached organizations lacked AI governance entirely.
The spoke network is not static. As firms outsource more of the fund lifecycle and pursue more deals, the share of sensitive data living outside the firm's walls rises every year. Every new deal adds permanently to the stock of documents that never come home.
The SEC's amended Regulation S-P reached its final compliance deadline on June 3, 2026. Written incident response, data mapping, and breach notification are now federal requirements. The SEC's 2026 exam priorities add AI governance and vendor oversight.
The Bain / PowerSchool ruling converts the industry's most common breach path into a fund-level legal exposure, and it landed in the same quarter as the regulation above it.
The amended Regulation S-P, the SEC's first revision in 24 years, is usually summarized as a notification rule: a written incident response program, 30-day notification, vendor oversight, and written documentation, in force for all registered advisers as of June 3, 2026. Read closely, the final rule (34-100155) does something more consequential: it draws a line through every firm's data, and encryption is the line.
An LP's inbox is compromised. The K-1s and capital account statements inside are plaintext PDFs. That is unauthorized access to sensitive customer information: the incident response program triggers, and the firm is notifying every affected individual within 30 days, with the investigation, costs, and LP-trust damage that follow.
Same incident. But the documents carry file-level encryption meeting current industry standards, and the keys remain secure. Under the final rule, the firm may determine the encrypted data is not "sensitive customer information" at all. The breach becomes a documented non-event, provided the determination is recorded in writing.
The rule does not mandate encryption. It prices its absence. The SEC declined to write an explicit encryption safe harbor, but stated that encryption using industry-standard practices is a reasonable factor in the harm determination, and referenced FIPS 140-3 as the benchmark. Under the new rule, encryption is no longer a security preference. It is the difference between disclosure and a file note.
The rule requires written policies for oversight of service providers, who must notify the firm within 72 hours of becoming aware of a breach. The definition covers fund administrators, placement agents, and data room providers. LP data sitting at an administrator is the adviser's obligation, not the administrator's alone.
The Division of Examinations' 2026 priorities name Reg S-P incident response, data loss prevention, and access controls as focus areas. The question examiners ask is not whether a policy exists. It is whether the firm can demonstrate the controls and produce the records.
Goes to 40 to 80 bidders. The losers, which include competitors of the target, keep the full document forever. No expiry, no revocation, no record of who still holds it.
Access is scoped per recipient and expires automatically at close. Revoke a losing bidder and every copy they hold, whether downloaded or forwarded, stops opening.
K-1s and capital account statements sit in the inbox as plaintext. The compromise is unauthorized access to sensitive customer information: a 30-day Reg S-P notification event.
The same documents are encrypted with secure keys. The firm can document a determination that the data is not usable to cause harm: a non-event, with the written record the rule requires.
A breach at a shared provider exposes deal and fund data the firm sent there. The firm has no control over the provider's perimeter and no way to make the stolen files unreadable after the fact.
The file left the firm already encrypted. Exfiltrated from any spoke, it stays inaccessible without authorization. The blast radius shrinks to nothing.
None of these require the firm to control the perimeter, retrieve a document, or trust a counterparty's security. The protection is in the file, so it holds wherever the file goes.
This report has described two failure modes that look different and are the same. Where data sits — at counsel, with administrators, inside portfolio companies — it waits for someone else's breach. How data moves — in CIMs that outlive auctions, diligence files that outlive deals, AI tools that retain what they are fed — it leaks with no breach at all. Defending the firm's perimeter addresses neither, because in both cases the data has already left. The perimeter the data actually lives behind is the file.
Field-level encryption that travels with the document changes the unit of defense. If the file is exfiltrated in a breach at the firm, a law firm, or an administrator, the data inside stays inaccessible to anyone without authorization. The blast radius of every breach in the network shrinks, because the stolen file is unreadable. And under amended Reg S-P, that same property is what separates a 30-day notification event from a documented non-event.
Encryption embedded in the document survives download, forward, and every hop through the network.
Access ends when the process does: at close, at engagement end, at LP exit. No retrieval chase.
Revoke once and every copy stops opening, including copies already sitting in other organizations' systems.
Who opened what, when, from where. The written record Reg S-P determinations and examinations require.
This is the only model that matches the wiring diagram. Perimeter tools defend a boundary that the industry's own structure renders irrelevant. Discovery and classification tools tell a firm where its sensitive data is without stopping it from leaving. Protection that travels with the file defends the data at the one location it never leaves, across every spoke the firm cannot control. Fund documents and LP records stay sensitive for decades — well inside the window where data harvested now is decrypted later. Protection built on post-quantum-ready cryptography is built to outlast that window.
Private equity is one connected surface. The data confirms attackers treat it that way. The defensible response is to stop trying to wall off 300 firms and thousands of providers, and to protect the asset that moves through all of them.
The 300 largest private equity firms in the world by capital raised over the trailing five years, per the 2026 PEI 300 ranking. 206 are headquartered in the United States; 94 internationally. A majority across both groups are SEC-registered investment advisers and therefore subject to the regulations referenced in this report.
Each firm was scored 0–5 across eight exposure dimensions, producing a 40-point composite aligned with Confidencial's prior sector analyses of the legal and pharmaceutical industries to allow cross-vertical comparison. The dimensions: fund scale and limited partner surface; deal velocity; regulated-portfolio exposure; portfolio breadth and control model; third-party sprawl; AI adoption depth; incident history; and security posture (inverse-scored). Composites were banded: Critical (30–40), High (24–29), Moderate (17–23), Low (≤16).
All scoring relied on publicly available information: firm websites, portfolio and team pages, public deal and fundraising announcements, regulatory filings, careers pages, and reported cyber incident records. No confidential or non-public information was used. Provider-concentration figures were derived from named relationships in public deal announcements and filings; because many such relationships are never publicly disclosed, all concentration figures stated in this report are floors and understate true concentration.
Cyber incidents were classified by the entity actually breached (firm-level, portfolio-company-level, or third-party-vendor-level) rather than by headline attribution. Incidents at portfolio companies were counted against the sponsor where the portfolio relationship was confirmed for the relevant period.
Service providers (law firms, fund administrators, and placement agents) are not named in this report. All concentration counts and derived figures are retained in full; only the identities are withheld. This report is intended as industry-level analysis of structural exposure, not as an assessment of any individual provider or firm.
Public-source scoring captures visible posture, not internal reality: a firm with no public security signal may maintain strong internal controls. The document-lifecycle exposure described in Section 5 is, by its nature, not visible to public scoring and is presented as analysis rather than scored data. The cohort is a point-in-time snapshot; rankings, portfolios, and provider relationships change continuously.
This report is provided for informational purposes and reflects analysis of publicly available information as of June 2026. It does not constitute legal, financial, or security advice, and is not an assessment of the security practices of any individual firm named or referenced. Confidencial makes no representation as to the completeness of public records relied upon.
The exposure described in this report is structural. It is also measurable, firm by firm. Confidencial offers a data risk assessment that maps one live process — a sell-side deal, LP reporting, or a diligence room — and shows exactly where your most sensitive documents are exposed today. No agents to install. No disruption to the deal.