How to Read a Portfolio Company’s Security Budget

A security budget is not an IT expense report. For Private Equity firms, it serves as evidence of how well

How to Read a Portfolio Company's Security Budget

A security budget is not an IT expense report. For Private Equity firms, it serves as evidence of how well a portfolio company understands risk, protects revenue, supports the investment thesis, and prepares for an eventual exit.

Low spend is not always efficient, and high spend is not always mature. You must read the budget alongside growth plans, sensitive data, customer demands, insurance terms, compliance duties, technology debt, and the company’s risk appetite. Evaluating these expenditures should be a core component of your broader investment strategy when assessing technology assets.

Security gaps often become visible during acquisition diligence, leadership change, or a hard transition. That is why it helps to Prepare Technology for Diligence or Transition before the questions get more expensive.

Key Takeaways for Reading a Portfolio Company’s Security Budget

  • Judge spending against business exposure, not a fixed percentage of revenue.
  • Separate recurring operating costs, one-time remediation, technology debt, compliance work, insurance, and third-party risk.
  • Expect each major item to name an owner, outcome, timing, risk reduction, and consequence of delay.
  • Connect security investment to EBITDA, customer retention, uptime, deal readiness, and exit value.
  • Ask whether the company can show progress through performance metrics and reporting leaders can trust, rather than a long list of purchased tools.

A useful security budget should fit into board technology reporting that makes decisions and tradeoffs plain.

A minimalist scale holds abstract red growth charts on one side and protective shield icons on the other. This professional graphic displays the equilibrium between corporate development and cybersecurity investment strategies.

## Start With Exposure, Not the Security Spend Total

The same $500,000 can be sensible for one company and reckless for another. A regional manufacturer with limited customer data has different exposure than a software business holding payment data for enterprise customers.

Start with the business. How concentrated is revenue? Which customers demand security reviews? Does the company process regulated data? Would a system outage stop billing, production, fulfillment, or customer support? Is proprietary code part of the value story? These details define the broader security posture, which directly impacts long term Portfolio Performance and contributes to the accuracy of every Portfolio Report provided to sponsors.

Geographic reach matters. So does the exit plan. A buyer will look harder at weak controls when the company depends heavily on technology to produce revenue.

This is part of the broader technology risk oversight management and the board should expect, especially when assessing the company’s defined Risk Tolerance.

Ask What the Company Is Actually Protecting

You need a ranked list of assets, not a vague statement that everything is important. Start with customer data, payment systems, production platforms, proprietary code, employee records, cloud infrastructure, and operational technology.

Then ask which systems would stop revenue if they failed. Management should know recovery targets, backup test results, access control gaps, identity risks, endpoint coverage, and incident response readiness.

Security should protect the business outcomes that matter most. It does not need to treat every system as equally critical.

Translate Cyber Risk Into Expected Business Loss

We could get hacked is not a budget case. It is a fear.

A stronger case estimates event likelihood and business impact. That includes downtime, response costs, legal fees, lost sales, customer churn, insurance changes, and delayed deals. The figures will not be exact. They do make the tradeoff easier to judge.

If management estimates $10 million in expected annual loss from major cyber events, and a $2 million program could reduce that exposure to $5 million, you have a real decision to discuss.

The board can then decide whether the remaining exposure fits its Risk Tolerance.

Separate Maintenance, Remediation, and Strategic Security Investment

Do not read the budget as one large number. Instead, view the security budget as a form of asset allocation across different risk categories.

Maintenance keeps existing controls running. Remediation fixes known weaknesses, such as untested backups or weak privileged access. Strategic investment builds the capability needed for growth, acquisition integration, customer requirements, or a more demanding regulatory environment. Because these expenses hit the P&L statement, you must ensure they are classified accurately rather than being lumped into general IT spending.

Ask management to show spending across people, technology, services, training, insurance, compliance, and projects. Every line should connect to a named risk, a business outcome, an owner, and a measure of success.

A security tool does not prove maturity. It may only prove that someone signed a contract. Review each investment with the same discipline you would apply to technology spending ROI and the wider technology strategy.

Find the Hidden Costs Behind the Headline Number

Security costs often sit outside the stated security budget. Engineering work, audit preparation, legal review, employee training, incident-response retainers, penetration tests, backup storage, and recovery exercises may be assigned elsewhere.

Capitalized development can also make a program look cheaper than it is. Shared IT costs can hide the labor required to operate new controls after implementation. A disciplined budgeting process is essential here, as management should track internal labor and hidden costs to get a true picture of the program.

Ask two direct questions: Is internal labor included? And can the company afford to run this control after the project closes?

Spot Tool Sprawl and Vendor-Driven Spending

A long product list can mean duplicated features, weak ownership, and vendor-led decisions. It can also mean unused licenses that directly reduce EBITDA without improving protection.

For each major platform, ask about adoption, coverage, alert quality, response time, and accountable ownership. If no one can answer, the company may have bought technology instead of solving risk. Rebalancing assets is often necessary to shift funds away from this vendor-driven tool sprawl toward more effective, measurable controls.

Tool sprawl is a governance problem, especially when vendors begin setting the roadmap. Management needs a clear way to stop vendors from driving the roadmap.

Test Whether the Budget Reduces Real Portfolio Company Risk

You are not trying to eliminate every possible threat. Instead, you are testing whether the plan reduces the specific risks that could materially hurt the business. Your review process should begin with robust target setting, ensuring every security initiative is clearly aligned with reducing the organization’s most pressing exposures.

Review current control maturity, known incidents, open audit findings, overdue remediation, recovery test results, customer requirements, and regulatory obligations. Then, compare those facts with what the budget actually funds. A professional portfolio report should clearly illustrate the risk before the spend, the expected exposure after the investment, and the contingency plans if delivery slips. A board-ready cybersecurity reporting template can help keep the discussion focused on these strategic priorities.

Look for Clear Owners, Measures, and Deadlines

Every major initiative needs a business owner, a technology or security lead, a budget, a delivery date, and a measurable result. To ensure true accountability, these results should follow SMART goals. By aligning security projects with specific, measurable, achievable, relevant, and time-bound objectives, you ensure that the security program remains disciplined.

Useful performance metrics include the number of critical vulnerabilities closed, privileged accounts reviewed, backup recovery time, high-risk findings past due, phishing failure rates, and mean time to detect or contain an incident.

Activity is not proof of risk reduction. A training session, a new tool, or a completed meeting does not tell you whether the company is safer.

Ask the questions boards should hear about cyber risk: what changed, what remains exposed, who owns the response, and what decision is needed? Effective board cyber reporting should answer those questions in plain language, helping to mitigate the volatility introduced by frequent or unexpected cyber incidents that threaten business operations.

Review Third-Party and Cloud Risk Separately

A company may have decent internal controls and still be exposed through cloud providers, payment processors, managed service providers, software vendors, and outsourced developers.

Review vendor concentration, data access, breach notice terms, audit rights, recovery commitments, data ownership, and exit support. A vendor failure can become a customer problem fast. Because vendor exposure directly affects downside protection and exit readiness, third-party risk reporting for the board deserves its own dedicated view within your regular oversight process.

Use the Security Budget to Protect EBITDA and Exit Value

Underfunded security can create downtime, lost customers, delayed sales, higher insurance premiums, missed acquisitions, and ugly remediation work during diligence. When assessing these costs, consider how they impact your EBITDA and Free Cash Flow to Firm.

Overfunding creates a different problem. The company buys controls it cannot operate, does not need, or cannot explain. That also hurts EBITDA.

Read the budget against margin targets, customer commitments, integration plans, and exit timing. Security maturity directly protects your valuation during an exit, as strong readiness builds buyer confidence and streamlines valuation discussions. Strong technical due diligence does not replace good operating discipline; rather, it exposes the absence of it.

Ask What Happens If You Delay the Spend

Every security request should include a delay test. What risk remains? Which business objective could be affected? How long can the company wait? What temporary control reduces exposure?

When security projects are ignored, unexpected downtime can jeopardize your sales forecasting and make it difficult to meet quarterly financial goals. Management should clarify the tradeoff between immediate cash flow and the long-term cost of remediation. Delaying a backup project, identity improvement, segmentation effort, or critical patch program may be reasonable, but it can also create a significant future liability. Not every request is urgent, but every delay should be clearly understood.

Build a Board View That Shows Tradeoffs, Not Technical Noise

A useful board view shows the top risks, current exposure, risk appetite, spending by outcome, major changes, overdue actions, incident trends, and decisions needed.

Use business language: expected loss, customer impact, recovery time, and investment payback. The board oversees priorities and risk, while management retains ownership of execution. That clear division of responsibility is a hallmark of effective executive technology leadership.

A Practical Security Budget Review for PE Sponsors

Conducting a thorough budget review is a critical component of strategic management for Private Equity sponsors. Before approving a budget, request the current plan, prior-year actual spend, risk register, incident history, insurance requirements, customer demands, audit findings, vendor list, recovery-test results, and a 12-month security roadmap that directly supports your overarching Portfolio Performance objectives.

You are looking for a business-aligned plan, not a technical wish list. The best budget fits the operating plan and the company’s business-aligned technology strategy.

Use Five Questions to Challenge the Plan

The budgeting process acts as the primary mechanism for verifying that your security spend is truly effective. Ask management:

  1. What business risk does each major item address?
  2. What evidence shows that risk is real?
  3. Who owns the result?
  4. What happens if you delay it?
  5. How will you know the investment worked?

Weak answers usually point to a reporting, ownership, or leadership gap. They do not automatically mean the company needs more tools. A clear technology roadmap can sequence remediation, growth work, and integration priorities effectively.

Know When You Need Outside Executive Technology Oversight

Outside support can help when management cannot produce a reliable risk picture, the budget is disconnected from business priorities, or no one clearly owns technology decisions.

A managed service provider can operate systems. A consultant can assess a narrow issue. A fractional leader can connect security, spend, vendors, delivery, and board reporting into one operating picture.

If the decisions feel scattered or too dependent on the wrong people, Get an Executive Technology Clarity Check.

FAQs About Reviewing a Portfolio Company’s Security Budget

What percentage of revenue should a portfolio company spend on security?

There is no reliable universal percentage. While some organizations look to market benchmarks to gauge their spending, the right amount ultimately depends on your specific industry, data sensitivity, customer commitments, technology dependence, compliance duties, maturity, and risk appetite. A percentage can serve as a helpful comparison point, but it should never replace a thorough, risk-based review of your actual requirements.

What should a PE firm request before approving a security budget?

Request current and prior-year spend, the risk register, critical asset list, incident history, open findings, control coverage, recovery-test results, vendor exposure, insurance requirements, customer commitments, owners, milestones, and expected outcomes.

How can you tell whether a security budget is too low?

Look for repeated incidents, untested backups, overdue critical vulnerabilities, weak identity controls, failed audits, rising customer objections, missing ownership, and unfunded remediation. Low spend becomes dangerous when management cannot show how it manages known exposure.

When should a PE firm use a fractional CTO or security leader?

Outside leadership may fit when you have technical staff but lack executive ownership, credible reporting, a workable roadmap, or a clear connection between security decisions and revenue, margin, and exit readiness. Private Equity firms often find that fractional CTO services can help bridge the leadership gap when the need for strategic oversight reaches beyond a single security project. Fractional CTO services provide the professional guidance necessary to align technology investments with long-term value creation.

The Budget Should Make Risk Easier to Govern

A security budget tells you how the company perceives risk, accountability, and the future. The strongest budget is not necessarily the largest one. Instead, an effective budget protects the assets that matter, funds the right controls, establishes clear ownership, measures progress, and makes necessary tradeoffs visible.

Ultimately, your security spending must connect directly to improved portfolio performance and the protection of EBITDA. By transforming technical security details into a clear strategic investment decision, you ensure that the company remains resilient, maintains customer trust, and stays prepared for future diligence. This level of transparency in risk governance is essential for maintaining a strong valuation at the time of exit. If management needs help building this oversight, you can Build a Board-Ready Technology Risk View.

Search Leadership Insights

Type a keyword or question to scan our library of CEO-level articles and guides so you can movefaster on your next technology or security decision.

Request Personalized Insights

Share with us the decision, risk, or growth challenge you are facing, and we will use it to shape upcoming articles and, where possible, point you to existing resources that speak directly to your situation.