Cyberattacks rank as the top 2026 threat for 54% of US CEOs

One portfolio breach reprices insurance, credit, and exit diligence, which makes cybersecurity due diligence a portfolio standard

Operators and investors,

54% of US CEOs rank cyberattacks as their top geopolitical threat for 2026, ahead of every other external risk, according to The Conference Board's C-Suite Outlook, a survey of more than 1,700 executives including over 750 CEOs. Globally, the figure sits at 47%, so the US reading runs 7 points hotter than the rest of the world.

The concern has a specific shape in 2026. The WEF's Global Cybersecurity Outlook found 65% of large companies citing third-party and supply chain vulnerabilities as their greatest obstacle to cyber resilience, up from 54% a year earlier, while only 27% simulate incidents with their supply chain partners. CEOs now rank cyber-enabled fraud above ransomware, which had held the top spot the year before.

This issue covers 5 topics:

  • Cyber risk is now priced at the platform level

  • Why cyber moved to the top of the CEO threat list

  • How 1 breach reprices the whole platform

  • The third-party gap operators control least and pay for most

  • The portfolio baseline that catches exposure before diligence does

1. Cyber risk is now priced at the platform level

What I see in PE-backed companies is that cyber has moved from an IT budget line into deal economics. A breach at one portco surfaces in the next insurance renewal for the platform, in lender conversations where covenant terms and pricing get revisited, and in buyer diligence at exit, where an incident history and a weak control environment get priced as risk. The exposure is portfolio-wide while the controls remain company-by-company, and that mismatch sits with the operating partner.

We measure part of this directly. In our security audit of 1,104 PE-backed and mid-market company websites this year, fewer than half ran a complete set of baseline security headers, and only 47% ran a consent-management tool over their tracking stack, an immediate GDPR and CCPA exposure sitting on the public-facing layer any diligence scan reads first. This is the cheapest layer to fix and the first one a buyer's technical advisor looks at.

It is also written for operating partners and portco executives who own the risk conversation with lenders, insurers, and eventually buyers.

The spread between the first bar and the last two carries the operational lesson: CEOs rank the threat first while only 1 in 4 companies rehearses an incident with the partners most likely to cause it. In the portfolios we work with, that gap is normal rather than exceptional: the risk gets named at the board and managed nowhere in particular, which is exactly the condition a platform-wide standard fixes.

2. Why cyber tops the CEO threat list

The ranking reflects a change in who absorbs the damage. Ransomware taught boards that operations stop; the 2026 pattern adds fraud, identity abuse, and vendor-chain compromise, where the loss arrives through a wire transfer or a partner's stolen credential rather than a locked server. 73% of respondents in the WEF survey said they or someone in their network was personally affected by fraud in the past year, and 87% identified AI-related vulnerabilities as the fastest-growing risk of 2025.

The Conference Board's chief economist Dana Peterson reads the broader survey as CEOs "navigating converging pressures that are weighing on profits and growth," and cyber sits at the intersection of those pressures: it is simultaneously an operational risk, an insurance cost, a lender conversation, and a diligence finding, which is why it outranks threats that only hit one of those lines.

For a mid-market company, the economics are unforgiving. The same AI tooling that lowered the cost of writing a phishing email lowered the cost of running a convincing invoice-fraud campaign against a 200-person finance team. Attack cost fell while defense cost stayed flat, and the mid-market sits in the exposed middle: large enough to be worth defrauding, small enough to run without a security function.

3. How 1 breach reprices the whole platform

The financial mechanics run through 3 channels, and each one prices at the platform level:

  • Insurance: a claim at one portco moves the renewal conversation for every holding under the same sponsor, and underwriters increasingly ask about portfolio-wide standards rather than single-company controls

  • Lender terms: credit agreements now carry cyber representations and incident-notification clauses, and an incident during the hold gives the lender a repricing conversation the sponsor did not plan for

  • Buyer diligence: at exit, a documented incident without a documented remediation reads as unquantified liability, and the buyer's advisors will haircut for it

The asymmetry is what makes this an operating priority. The cost of the baseline controls is a rounding error against the platform-level repricing a single incident triggers, and the spend is one of the few line items that directly protects the exit multiple rather than the P&L.

This is our own data, and it is the cheapest chart in this edition to act on. Every figure here is visible from outside the company, which means every buyer's technical advisor sees it too. When half the mid-market fails a check that costs a configuration change to pass, the first mover in a sale process gets a cleaner diligence narrative for close to zero spend, and that is the kind of asymmetry we build portfolio playbooks around at DevriX.

4. The third-party gap operators control least

The 65% figure deserves attention because it names the part of the risk that sits outside the company. A mid-market portco runs on dozens of SaaS vendors, a payroll provider, an MSP, and an agency or two with production access. Every one of those relationships carries credentials, and stale credentials at third parties have driven several of the largest incident chains of the past year.

The operational response is unglamorous and effective. An access inventory that lists every vendor with system access, credential rotation on a calendar, offboarding that actually revokes tokens rather than just disabling accounts, and contractual notification clauses with the vendors that matter. Only 33% of companies in the WEF data comprehensively map their supplier ecosystem, so the portco that does this work is ahead of two thirds of the market at close to zero capital cost.

5. The portfolio baseline that catches exposure early

The practical move for a sponsor is a portfolio-wide minimum standard, scanned quarterly, reported like a covenant. The public-facing layer is measurable from outside without agent installs or audits: security headers, TLS configuration, exposed services, consent tooling, and platform patch levels. Our website data shows the mid-market fails on exactly these basics, and they are the same checks a buyer's cybersecurity due diligence covers on day 1 of a process.

Behind the public layer, the baseline is a short list: MFA everywhere, tested backups, an incident-response plan with named owners, the vendor access inventory from section 3, and cyber insurance whose exclusions someone has actually read. None of this requires a CISO per company. It requires one standard, one owner at the fund level, and a quarterly scan that turns security posture into a number a board can track.

This week, run a 30-minute review with your COO and whoever owns IT across the platform. Three questions to think about:

  1. If our largest portco took a breach today, which insurance policies, credit agreements, and customer contracts would be affected, and who has read those clauses.

  2. Do we have a vendor access inventory for each holding, and when were third-party credentials last rotated.

  3. What would a buyer's external scan show on our public layer right now, and would any finding surprise us.

Score each one red, yellow, or green; any red is exposure a diligence team will find before you fix it.

Mario

My take

Instagram Post

šŸ—‚ļø A $40M portco was running 47 SaaS subscriptions. The CFO had signed off on 31, procurement knew of 22, and software spend was climbing 18% a year with no owner map, the kind of sprawl that becomes a purchase-price adjustment at diligence. 12 to 20% of it is usually redundant.

šŸ“ˆ GTM is a value creation lever, and most portcos run it in silos. Marketing counts MQLs, sales counts SQLs, and customer data sits in three systems, so a centralized RevOps function is the single biggest fix, worth over 15% more post-acquisition revenue growth. Avoid the GTM pitfalls.

āœ‚ļø Corporate carve-outs are gems and traps in the same market. Untraceable shared-services allocations, intercompany revenue that disappears post-close, and management that never operated without corporate cover make the diligence about what you do not yet know. Tell the neglected gem from the deservedly neglected.

PE community notes

šŸŽ™ļø 73% of founder-CEOs are replaced within 18 months of a PE close, not because they can't run the business but because no one taught them the new game they're now playing - by Adam Coffey

šŸŽ™ļø The acquirers are becoming the acquired, as the alternative asset managers that spent decades buying companies increasingly become consolidation targets themselves - from Hugh MacArthur

šŸŽ™ļø "A-player" gets used lazily as a fixed personality trait, when in reality it's contextual: the right person for the right role at the right stage - insights by Dan Cremons

šŸŽ™ļø Deals get celebrated at close, then value quietly leaks because no one owns the follow-through when someone finally checks in 30 days later - see Kison Patel’s post

šŸŽ™ļø Q2 2026 data shows PE's entire technology segment up ~80% year over year, so the current boom is broader than AI alone: Sean Mooney on LinkedIn

Market insights & opportunities

The AI infrastructure build is hitting a power wall. Texas paused all new data center projects pending a grid audit, with ERCOT's interconnection queue now at 474 gigawatts, about 90% of it data centers and more than five times the state's peak demand, putting power availability and energy cost inside the diligence on any compute-heavy asset.

Leverage in the loan market is swinging back to lenders. Investors are demanding stronger covenants, more collateral, and better pricing before funding highly leveraged issuers, with about $240bn of leveraged loans maturing by 2028, which raises financing costs and reshapes deal structures, dividend recaps, and refinancing plans for PE sponsors.

Autonomous AI now carries legal exposure with no clear owner. After OpenAI and Anthropic admitted their unreleased models escaped their sandboxes and hacked several companies, lawyers call the liability uncharted territory under a 1986 statute, with victims likely to sue on negligence, which pushes AI indemnities, safeguards, and insurance up the agenda for anyone deploying agents.

Financing is now cheaper in Europe than in the US. European direct lending prices about 4 basis points tighter than comparable US loans, reversing a long-standing 22-basis-point European premium, as US redemption pressures curb deployment while European lenders compete for a thin deal pipeline, which makes financing geography a live lever for cross-border sponsors.

Full-Service Digital Marketing Agency: 3-year-old full-service agency specializing in performance marketing, lead generation, branding, web development, and creative production. Generates recurring revenue via annual retainer contracts and project-based engagements. $255,550

Fast-growing Authenticator iOS App: 2-year-old iOS Authenticator / 2FA iOS app monetized via an auto-renewable subscription model. Has a proven track record, strong subscription revenue, clean operations, and essentially zero infrastructure cost. $757,900

Multi-channel Compact Aircon Brand: 11-year-old patented personal, compact desktop cooling appliance brand sold via Shopify, Amazon, wholesale partners, and a direct-to-consumer website. Operated by a lean remote team with manufacturing and fulfillment managed by a 3PL. $2,750,000

Niche Brand Engagement SaaS: 4-year-old Web3, eSports, and gaming SaaS platform that licenses to brands in the luxury automotive and motorsport industries, including Lamborghini, Delorean and others. Generates revenue on licensing fees and digital products. $3,195,155

For PE partners and operators seeking alpha

🌐 Scaling $50M - $500M+ mid-market companies with value creation through RevOps, data engineering, and WordPress. DevriX provides full RevOps consulting + delivery with GTM enablement for PE-backed portfolio companies, traditional tech, healthcare, finance, and professional service businesses pacing toward revenue growth initiatives.

Our standard retainers between $10K-$60K/mo include revenue lifecycle services for marketing and sales leaders, FP&A for financial teams, pipeline enrichment through websites and dozens of lead sources, automations and delivery integrations, CRO and ongoing testing, product delivery and platform integration solutions, and more through our consulting solutions.

šŸš€ 1:1 Advisory retainers. Supporting operating partners, private equity funds, family offices, and mid-market executives in different capacities, from value creation through due diligence to portfolio digital GTM management in my async advisory programs via Growth Shuttle.

šŸ“ˆ GTM while scaling. European and international businesses can opt in for doola LLC and their ā€œBusiness in a Boxā€ model. Scaling founders can find smaller digital opportunities on Flippa. And additional opportunities across my investments can be found here.