Lachlan George is Cyber Security Partner at BCG and European PE Cyber Expert Lead. He contributed to our latest whitepaper on defining the CISO mandate, and his perspective on how PE firms should approach cyber due diligence challenges much of the current orthodoxy. 

We sat down with Lachlan to explore why standardised maturity assessments are failing investors, what better due diligence looks like, and how the right CISO hire connects directly to the investment thesis. 

The problem with generic maturity assessments

“We often over-index on the importance of generic maturity assessments using various industry frameworks,” Lachlan says. “These can be useful to get a broad sense of cyber capabilities, but they don’t provide a view on business risk exposure.” 

The distinction matters. A framework-based assessment tells you whether a company has certain controls in place. It does not tell an investment lead whether the gaps that exist are material in the context of that specific business, its value chain, or its growth strategy. 

“Most PE investment leads, as part of a due diligence process, will struggle with what to do with the results of a maturity assessment,” Lachlan explains. “They can’t make meaningful decisions about valuation or post-acquisition investment needs from that alone.” 

What better looks like

The alternative is due diligence that links cyber findings to specific value drivers. Rather than assessing security against an abstract scale, the assessment maps risk to the commercial activities that generate revenue. 

“The real value comes from linking findings to specific value drivers, such as customer acquisition, operations, fulfilment and data monetisation, so it’s obvious which risks are commercially critical,” Lachlan says. 

This approach produces actionable output. It tells the investor which risks could erode value, which areas of security maturity could become a differentiator, and critically, what kind of CISO the business needs. 

“The best due diligence provides you the roadmap to what kind of CISO you need: strategic, transformational, product-focused, operational, or somewhere in between.” 

The risk of getting the hire wrong

Lachlan is equally clear on what happens when the CISO mandate is not properly defined. A leader brought in without a clear understanding of the business’s risk appetite and strategic direction can actively destroy value. 

“Overly zealous CISOs can destroy value by blocking transformations, due to a poor understanding of risk,” he says. “In growth-focused businesses, you need someone pragmatic who understands cyber is only relevant insofar as it hinders or enables strategic objectives.” 

What this means for PE firms

The implication is that cyber due diligence and the CISO hire should not be treated as separate workstreams. The due diligence shapes the mandate, and the mandate shapes the hire. Getting this sequence right is the difference between a CISO who accelerates the value creation plan and one who becomes a bottleneck. 

The full framework for defining the CISO mandate, including how to link business value chains, investment thesis and risk tolerance to a specific leadership profile, is set out in our whitepaper. 

Download the whitepaper

Our whitepaper, Defining the CISO Mandate: How Do You Align Risk & Value, sets out the full framework for moving from readiness assessment through to a defined remit, including a formula for mapping business value chains, investment thesis and risk tolerance to the specific capabilities and experience the mandate requires. 

 

Defining the CISO mandate

Defining the CISO Mandate Report

Name(Required)