Cyber due diligence for private equity

Cyber risk,
in the language
of value

RiskPoint reads a portfolio company the way an attacker would — its perimeter, its code, its cloud, its suppliers and the breach news about it — and returns a posture score and a £ figure, not a PDF of findings nobody prices.

Built for the people who own the asset: Operating Partners, COOs and CFOs running diligence on a target or monitoring the companies they already hold.

0–850

Deterministic posture score

6

NIST CSF domains scored

Cyber £

Enterprise value at risk

Daily

Breach desk on every target

What it runs

Six scans, one score

Every pipeline emits the same issue contract, so a semgrep hit, a confirmed pentest finding and a ransomware listing are ranked on one scale instead of three reports.

Passive

OSINT with no packets sent in anger: attack surface, email security, breach exposure, threat intel, compliance filings, corporate structure and hiring signals.

Active

An autonomous agentic pentest against the live perimeter — confirmed, reproducible findings with the evidence attached, not a vulnerability guess.

GitHub

Static analysis across every repository the company owns, so the code the value sits on is read, not assumed.

Cloud

The Azure/AWS tenancy assessed against its own configuration — identity, exposure and the controls that were meant to be on.

Breaches

A daily desk watching public incident reporting, ransomware leak sites and breach catalogues for the companies and suppliers you actually hold.

Manual

The controls no scanner can see, captured as an analyst assessment with its evidence and folded into the same score.

How it works

From a domain to a number

01

Point it at a company

A name, a domain and a valuation. Add its suppliers and the scans start themselves — no questionnaire round trip, no diligence window to wait for.

02

Every pipeline lands as one issue list

Six very different scans, one contract: each finding carries its severity, its NIST function and the evidence behind it, so they can be ranked against each other.

03

Scored, then priced

That list scores a 0–850 posture deterministically — code, not a language model — and the same findings drive Valuation at Risk: the equity value exposed if this company is breached.

The £ figure is conditional and shown as a range, with every input labelled by where it came from — read the methodology.

Third parties

Your suppliers are your attack surface

Suppliers are scanned in their own right — passively, never intrusively, because nobody authorised a pentest of someone else's vendor — and their posture rolls up into the company that depends on them.

Monitoring

A breach desk that knows your watchlist

Every day it sweeps public incident reporting, extortion leak sites and breach catalogues and asks one question: is this about a company or supplier on file? What it finds scores the target the morning it appears — usually before the victim confirms anything.

See it scored on a company you already hold

Speak to an analyst, hand over one domain, and get the posture, the findings and the £ back.