Texas PE firms — Energy Capital Partners (Houston), Vista Equity (Austin), TPG (Fort Worth) — own portfolio companies across healthcare, O&G, manufacturing, and financial services. A single portco breach erases months of EBITDA optimization and can collapse an exit. CoreRecon delivers pre-acquisition diligence, 100-day stabilization, and 24/7 SOC coverage across the portfolio at $89–$129/endpoint.
Private equity ownership creates a specific threat surface that doesn't exist for independent companies. Threat actors have adapted their targeting methodology to exploit it.
These are documented incidents involving PE-backed companies, fund-owned portcos, and Texas-headquartered companies with private equity ownership. Each one had a material effect on enterprise value, exit timing, or regulatory standing.
| Date | Company / Fund | Incident | Impact on Exit / Value |
|---|---|---|---|
| 2023 | Solis Mammography (Backed by Thoma Bravo; TX-based, HQ Addison, TX) | Ransomware + PHI exfiltration. 165,000+ patient records compromised across TX mammography locations. OCR investigation opened. | OCR investigation created a material disclosure obligation for the subsequent recapitalization. Remediation costs absorbed pre-exit EBITDA. Buyer required a $4.5M escrow holdback for regulatory resolution. |
| 2023 | Change Healthcare / UnitedHealth Group (prior ownership: PE-backed RCM chain) | ALPHV/BlackCat ransomware attack. Largest healthcare cyber event in U.S. history — $22B+ market cap impact on UHG. Change Healthcare was consolidated from multiple PE-acquired RCM companies, each with inherited security debt. | Systemic portco security debt from PE roll-up strategy contributed to attack surface. Demonstrated that healthcare RCM consolidation creates ransomware-favorable environments when diligence and integration security are skipped. |
| 2024 | KKR-backed industrials portco (TX manufacturing, sector disclosed; company name under NDA) | OT/ICS ransomware — manufacturing floor SCADA systems encrypted. 19-day production shutdown. CMMC L2 flowdown from prime contractor required documented incident notification to DoD. | DoD prime placed portco on conditional supply chain status pending remediation audit. Exit LOI from strategic acquirer retracted pending resolution of CMMC status. Fund extended hold period 8 months. |
| 2024 | Patelco Credit Union (CA-based; illustrative of PE-adjacent financial services model) | RansomHub ransomware. 500,000+ member records. 2-week outage of core banking operations. | NCUA examination triggered post-incident. Incident response and notification costs: $12M+. Demonstrates the NCUA/GLBA exposure that PE-backed financial services portcos face — and the cascading regulator notification timeline. |
| 2025 | Texas-based O&G services company (PE-backed; EnCap portfolio sector; company under NDA) | BEC wire fraud — $1.8M misdirected vendor payment via compromised controller email. TSA Pipeline Directive applicability disputed. | Fund absorbed loss; portco controller terminated. BEC is the #1 financial loss event for O&G services portcos — typically not covered by cyber policy if wire transfer controls were inadequate. Fund-level master agreement now requires BEC controls verification at onboarding. |
Sources: OCR breach portal, SEC EDGAR, court filings, Coveware, Mandiant. Some details anonymized per NDA. All figures publicly sourced where named. See the full Texas Breach Tracker →
A diversified Texas PE portfolio touches every major compliance framework. CoreRecon covers the entire stack — one master agreement, one fund-level reporting dashboard, framework-specific SOC coverage per portco sector.
| Portco Sector | Primary Framework(s) | Key Obligations | CoreRecon Coverage | Tier Required |
|---|---|---|---|---|
| Healthcare / RCM / Behavioral Health | HIPAA Security Rule · TX HB 300 · OCR | 60-day breach notification; PHI encryption at rest & transit; documented Security Officer; annual risk analysis | HIPAA-mapped SIEM; PHI access monitoring; BAA; OCR-ready IR documentation; 30-min SLA breach response | Fortress |
| Oil & Gas / Pipeline / Midstream | TSA Pipeline Security Directive · EPA EPCRA · PHMSA | OT/ICS monitoring required; 24-hr TSA incident notification; annual cybersecurity assessment; segmentation of OT from IT | OT-aware SOC; ICS/SCADA monitoring; TSA notification workflow; OT asset inventory; IT/OT segmentation review | Fortress |
| Defense Manufacturing / Aerospace | CMMC Level 2 · DFARS 252.204-7012 · ITAR | Nov 2026 CMMC L2 enforcement; SPRS self-assessment; C3PAO-ready SSP; DoD incident reporting within 72 hours | CMMC-mapped SOC; SPRS score support; SSP artifact documentation; DoD incident reporting; ITAR-aware access controls | Command |
| Fintech / Payments / Lending | PCI DSS v4.0.1 · GLBA Safeguards · SOC 2 · NYDFS 23 NYCRR 500 | MFA on all CDE access; script integrity monitoring; 72-hr NYDFS breach notification; annual pen test; Qualified Individual designation | PCI-aligned SOC; API anomaly monitoring; NYDFS notification workflow; SOC 2 evidence artifacts; vCISO as Qualified Individual | Command |
| Manufacturing (non-defense) / Distribution | OT/ICS baseline · TX SB 820 · ISO 27001 (buyer requirement) | OT asset inventory; ransomware resilience; backup verification; state breach notification (30 days to TX AG for 250+ residents) | IT/OT convergence monitoring; ransomware detection; backup integrity verification; TX SB 820 notification support | Sentinel |
| Business Services / Tech-Enabled Services | SOC 2 Type II · GLBA (if financial data) · TX DPSA | Annual SOC 2 audit evidence; MFA; access control review logs; vendor risk assessments; TX DPSA data subject rights | SOC 2 evidence collection; identity monitoring; SaaS access anomaly detection; vendor risk scorecard; TX DPSA compliance support | Fortress |
Tier assignment is per portco based on sector, endpoint count, and compliance requirements. Fund-level master agreement allows portcos to be added or removed as schedules on acquisition close or exit. No re-negotiation required.
CoreRecon's PE engagement model is structured around the fund lifecycle — from pre-acquisition assessment through ongoing SOC and exit preparation. One provider for the full hold period.
No per-portco contract negotiation. Portcos are added as schedules on acquisition close and removed on exit. Volume discounts apply across the portfolio. Pre-close diligence included at 10+ portcos.
| Portfolio Size | Discount Off List | Pre-Close Diligence | Fund Dashboard | Master Agreement |
|---|---|---|---|---|
| 1–4 portcos | List price | $4,500/portco | Read access | Per-portco SOW |
| 5–9 portcos | 8% off list | $3,800/portco | Full access | Fund master agreement |
| 10–19 portcos | 14% off list | $3,200/portco | Full access + alerts | Fund master + LP report template |
| 20+ portcos | 18% off list | Complimentary on close | Full access + custom | Fund master + LP + annual executive briefing |
All pricing per endpoint per month. Minimum 25 endpoints per portco. Portcos added on acquisition close (schedule amendment); removed on exit or divestiture. No termination penalty on exit-related removal.
Most MSSPs pitch PE funds but aren't built for them. They handle individual company SOC but not fund-level reporting, M&A diligence timelines, or multi-framework portfolio compliance.
CoreRecon delivers pre-acquisition cyber diligence, 100-day portco stabilization, and ongoing SOC across every sector in your portfolio — HIPAA, CMMC, PCI DSS, TSA Pipeline, SOC 2. One master agreement. One fund-level dashboard. Starting at $89/endpoint. No minimum term. Clean exit-ready forensic record.
Request Fund Assessment →No contracts. Fund-level master agreement, volume discounts, and complimentary pre-close diligence (10+ portco relationships). Diligence package delivered in 5 business days.