The PDF lives in a SharePoint folder no one opens. The diligence findings — every single one — die on the day the deal closes. This is how operating partners stop that from happening.
The average PE-backed company inherits a CCOD assessment at close. It documents what's broken, what it costs, and what remediation looks like. Then the deal closes, the diligence team moves to the next deal, and the target company moves into integration mode. Six months later, no one can find the assessment. Twelve months later, the same findings show up in the exit diligence for the next buyer.
The Year-0 cyber baseline is the mechanism that converts diligence findings into a living operational program. It's what operating partners do when they want diligence to be worth something post-close.
Why diligence findings die at close
The diligence team and the operating partner team are different people with different incentives. The diligence team is optimizing for IC approval. Once the deal closes, their job is done. The findings live in a report that belongs to the diligence process, not the portfolio company or the operating partner.
At the portfolio company, the close creates a burst of integration activity — legal entity work, financial system integration, leadership alignment, go-to-market changes. Cyber remediation is on the list, but it's rarely prioritized against the integration work that has immediate revenue impact.
The operating partner's attention is split across the whole portfolio. A single portco's 47 dormant accounts don't register against a fund-wide view of 12 companies with varying degrees of urgency.
No one is accountable for post-close cyber remediation unless someone is explicitly made accountable. The CCOD lives in the diligence file. The portco's security team (if it exists) doesn't know the CCOD exists. The operating partner knows the CCOD exists but doesn't own the remediation. This gap is where the $1.4M average incident cost comes from.
What the Year-0 baseline is
The Year-0 baseline is three things: a transfer document, an ownership assignment, and a measurement framework.
As a transfer document, it takes the CCOD findings from the diligence report and converts them into a format the portco's operational team can work with — specific controls, specific owners, specific timelines, specific verification criteria. Not the five-pillar ALE summary, but the underlying finding detail.
As an ownership assignment, it explicitly assigns each finding to either the operating partner or the portco leadership. Some remediation (IR retainer, SIEM procurement) requires fund-level vendor relationships. Most remediation (MFA deployment, patch cadence improvement) belongs to the portco's team. Ambiguity about ownership is what kills remediation programs.
As a measurement framework, it establishes the baseline metrics that will be tracked through Year 1 and beyond — so that next year's operating review, and eventually the exit diligence, can show a documented posture improvement trajectory rather than the same findings from close.
A new assessment. You already have the CCOD from diligence. The Year-0 baseline is a conversion of that assessment into operational terms — not a repeat of the technical work. If you're commissioning a second assessment three months post-close, something went wrong with the diligence handoff.
The 90-day post-close sprint
Day 1–14: Transfer and orient
Transfer CCOD findings to portfolio company leadership. Brief the portco CISO (or equivalent) on the five-pillar findings, the ALE calculations, and the remediation cost estimates from diligence. Establish the operating partner point of contact for cyber oversight. Confirm which findings are on the escrow milestone list and verify escrow terms are understood by both teams.
Day 15–30: Ownership assignment
For each finding, assign: (1) owner — portco or operating partner; (2) resources — budget approved, vendor selected; (3) timeline — milestone date and interim checkpoints. Document this in a tracker that both the portco and the operating partner can access. Flag any findings where ownership is ambiguous for explicit resolution by the deal partner.
Day 31–60: Quick wins
Prioritize findings that can be closed in under 30 days and under $25K. Typical quick wins: MFA deployment on admin accounts, dormant account cleanup, SSH key rotation, IR retainer contract signed, security awareness training launched. Quick wins reduce the annualized risk materially and demonstrate that the remediation program is operational.
Day 61–90: Program infrastructure
Commission longer-lead remediation projects: EDR deployment across all endpoints, SIEM implementation, patch management tooling, vendor security assessment program. Set quarterly review cadence with portco leadership. Define the metrics that will be reported at each quarterly review: patch compliance rate, MFA coverage percentage, open finding count by severity, incident response test completion.
Day 91: Baseline snapshot
Capture the 90-day posture snapshot. This becomes the Year-0 baseline — the documented starting point against which all future measurements are relative. Include: findings closed, findings in progress, findings deferred with rationale, current ALE estimate (should be materially lower than close-date CCOD), and next milestone dates.
Operating partner vs. portco: who owns what
Operating partner owns
Fund-level vendor relationships (IR retainer, SIEM, cyber insurance program). Cross-portfolio security standards and tooling. Quarterly posture reviews and reporting to fund leadership. Escalation path for incidents that exceed portco capacity. Exit readiness assessment timeline and process.
Portfolio company owns
Day-to-day control implementation. Patch cadence and endpoint management. IAM program (user provisioning, dormant account cleanup, access reviews). Vendor security assessment program for their third parties. Incident detection and initial response. Compliance program maintenance.
The operating partner's role is oversight and resource provision, not execution. An operating partner who is executing portco security controls is filling a talent gap that should be addressed differently — through a fractional CISO, a managed security service provider, or a security hire, depending on the portco's stage and budget.
The portfolio posture dashboard
At fund level, the operating partner needs visibility across the portfolio without requiring deep per-company engagement on every review cycle. The portfolio posture dashboard accomplishes this with three metrics per company, reviewed quarterly:
1. Critical finding count: Number of CCOD findings still open, by pillar. Trend line from close. Target: zero open critical findings by 12 months post-close.
2. Residual ALE: Current annual loss expectancy based on open finding profile. Should decrease each quarter as remediation progresses. Provides a portfolio-wide dollar view of aggregate cyber risk.
3. IR readiness status: Tested IR plan (yes/no), retainer in place (yes/no), last tabletop exercise date. IR readiness is the force multiplier on everything else — a portfolio company with tested IR can contain any incident faster, which reduces the effective cost of every other open finding.
These three metrics are observable without deep technical involvement. The portco provides attestation quarterly; the operating partner spot-checks annually. Fund leadership sees the portfolio-wide ALE trend, which is the number that matters for fund-level risk management.
Making the Year-0 baseline work for exit
The Year-0 baseline creates compounding value through the hold period. Each year's improvement is documented. By exit, the next buyer's QCD assessment runs against a company with a clean control profile, documented remediation history, and a posture trend that's improving rather than degraded from close.
That documentation is commercial. Exit diligence that produces no material cyber findings — because those findings were identified at acquisition and remediated by Year 2 — removes a major negotiation lever from the next buyer's toolbox. The seller can truthfully say: "The CCOD at close was $736K. Today's residual ALE is $180K. Here is the remediation record, verified annually."
Build the exit-readiness cyber review into the operating plan 18–24 months before anticipated exit. This gives enough time to address any findings surfaced in the review before they become the next buyer's negotiation leverage. The Year-0 baseline, maintained quarterly, is the foundation of that review — not a new assessment starting from scratch.
The dollar-denominated risk quantification that powers the CCOD at entry is the same methodology that makes exit diligence go smoothly. For a deeper look at that methodology, see how to quantify cybersecurity risk in dollar terms — the same five-pillar ALE approach, applied to the ongoing portfolio measurement context.
For the entry-side diligence process that produces the CCOD the Year-0 baseline builds on, see Inside a Cyber Cost of Deal: A Worked Example for Investment Committee.
Stop letting diligence findings die at close
The Year-0 baseline process in this article is built into vCISO Lite's Quantitative Cyber Diligence platform. The CCOD from diligence converts directly into the post-close tracking format — findings, ownership assignments, remediation milestones, and the portfolio posture dashboard — so the handoff from deal team to operating partner is automatic, not a lost PDF.
If you're an operating partner managing cyber across multiple portfolio companies, or a deal team that wants diligence to be worth something after close, visit diligence.vcisolite.com to learn more and enroll your fund.