A private equity firm, with $45 billion in assets under management, seeks to evaluate the maturity of their Cybersecurity Incident Response (IR) capabilities within the firm, as well as the IR capabilities and practices implemented by their portfolio companies.
Brief
HKA’s cybersecurity and privacy team was commissioned to provide expert support to a global private equity firm / hedge fund, and 40 of its portfolio companies, to gather relevant information, conduct an analysis, produce maturity ratings, and provide recommendations across each companies IR program.
What we did
HKA is performing a cybersecurity IR capability assessment for the firm. Subject matter experts are measuring against guidelines on best practices in IR from the National Institute of Standards and Technology (NIST) and the International Organization for Standardization (ISO). The assessment will evaluate key areas of people, processes, data management, and technology to determine the maturity level of the IR capabilities.
Areas of focus for the IR review include organizational oversight and governance; IR capabilities; detection and analysis; containment, eradication, and recovery; and post-incident activities.
At the conclusion of the assessment, reporting will be provided in the form of a board-level readout regarding IR processes and capabilities, identified program gaps and other weaknesses, and high-level recommendations for maturity improvements.
Outcomes
HKA conducted high-level assessments on the client’s IR capabilities and provided remediation to the identified gaps.
HKA will provide updates as the portfolio companies continue to be consulted.

-
ClientPrivate Equity Firm
-
Year2021 - Ongoing
-
ValueUS $175,000
-
ServicesThird-Party & Vendor Risk Management
-
SectorsCybersecurity & Privacy Risk Management
RELATED PROJECTS
RELATED PROJECTS

Securities and Exchange Commission (SEC) Cybersecurity Mock Exam
Americas

Cybersecurity Dispute Resolution
Europe

Department of Defense Cybersecurity Compliance (CMMC)
Americas

Business Email Compromise Response
Americas

Data Duplication
Americas

Email Environment Investigation
Americas
