Skip to content

Free post-close planning resource

A 100-day cyber plan for private equity.

Adapt five phases into named owners, evidence requests, and funding decisions. This is a suggested planning sequence; urgent incidents or obligations may need immediate action.

Prepared by ValtyUpdated

Ungated planning worksheet

Replace roles with named owners and day numbers with calendar dates.
Phase / reviewDecision and ownerEvidence neededOutput and review
Days 1–15

Review: day 15

Agree scope and stabilize urgent issues

Company IT/security lead + operating partner

Critical services, open incidents, control exports, recovery records, existing obligationsNamed approver, first-year cap, evidence register, urgent action owners

Day 15: confirm scope and unresolved evidence.

Days 16–30

Review: day 30

Validate the assumptions that could change the choice

Evidence owners + finance

Recovery tests, scoped cost quotes, outage cost basis, dependency and access coverageSource, collection date, coverage and confidence for each input

Day 30: decide which options can be compared.

Days 31–45

Review: day 45

Choose fund, defer, or validate

Company budget approver

Alternatives, required spend, loss objective, cost horizon, sensitivity resultsApproved decision or evidence hold, named execution owner

Day 45: record the decision and conditions.

Days 46–75

Review: day 75

Execute the approved scope

Company team or authorized provider

Approved change scope, test plan, execution records, rollback plan where relevantCompleted work, exceptions, and fresh verification evidence

Day 75: compare actual control state with intended change.

Days 76–100

Review: day 100

Review the result and the next funding cycle

Operating partner + company approver

Current validation, actual spend, residual gaps, revised model inputsBoard update separating observed control change from modeled loss change

Day 100: agree next review date and unresolved owners.

Replace roles with named owners and day numbers with calendar dates.

  1. Days 1–15

    Decision
    Agree scope and stabilize urgent issues
    Owner
    Company IT/security lead + operating partner
    Evidence needed
    Critical services, open incidents, control exports, recovery records, existing obligations
    Output
    Named approver, first-year cap, evidence register, urgent action owners
    Review checkpoint
    Day 15: confirm scope and unresolved evidence
  2. Days 16–30

    Decision
    Validate the assumptions that could change the choice
    Owner
    Evidence owners + finance
    Evidence needed
    Recovery tests, scoped cost quotes, outage cost basis, dependency and access coverage
    Output
    Source, collection date, coverage and confidence for each input
    Review checkpoint
    Day 30: decide which options can be compared
  3. Days 31–45

    Decision
    Choose fund, defer, or validate
    Owner
    Company budget approver
    Evidence needed
    Alternatives, required spend, loss objective, cost horizon, sensitivity results
    Output
    Approved decision or evidence hold, named execution owner
    Review checkpoint
    Day 45: record the decision and conditions
  4. Days 46–75

    Decision
    Execute the approved scope
    Owner
    Company team or authorized provider
    Evidence needed
    Approved change scope, test plan, execution records, rollback plan where relevant
    Output
    Completed work, exceptions, and fresh verification evidence
    Review checkpoint
    Day 75: compare actual control state with intended change
  5. Days 76–100

    Decision
    Review the result and the next funding cycle
    Owner
    Operating partner + company approver
    Evidence needed
    Current validation, actual spend, residual gaps, revised model inputs
    Output
    Board update separating observed control change from modeled loss change
    Review checkpoint
    Day 100: agree next review date and unresolved owners

Use these phases to turn diligence findings into one company’s owned funding decisions. This is a suggested planning sequence, not a Valty delivery promise. An active incident or urgent obligation may need action immediately.

Every action needs seven fields

Finding or scenario; business service affected; owner; evidence link and date; first-year cost; approval or hold condition; next review date. Record implementation dependencies beside the cost.

Separate required work from modeled benefit

A sponsor requirement can consume budget without receiving modeled loss-reduction credit. Record the actual source of the requirement. Do not turn a sponsor policy into a legal or insurer obligation.

Worked handoff: the decision is due on day 45.

For fictional Example Manufacturing Co., the first-year cap is $100,000. The proposed P95 plan combines a required $15,000 tabletop with a $75,000 recovery investment, leaving $10,000. The company security lead holds segmentation until a quote, tested coverage, and a defensible loss-scenario mapping are available.

The day-75 review asks whether the approved recovery scope was implemented and tested. A configuration check alone does not prove restoration works. At day 100, updated model outputs remain labeled modeled; observed control evidence and actual spend are reported separately.

Use the IC memo handoff to carry pre-close gaps into this plan, then the board report template for the funding decision and next review.

Portfolio interface product surface
Portfolio interfaceActual Valty portfolio interface shown with illustrative data. Post-close planning starts with one company's funding decision; portfolio expansion follows agreed evaluation.Open full-size product view ↗

The planning artifact

Set the funding decision your team can act on.

When post-close planning creates an unresolved cyber spend request, use Valty to review the fund, defer, or validate choice for that company, the modeled annual loss with its assumptions and time horizon, and the evidence gaps a reviewer should see first. Read the fictional sample memo and its methodology before you request a platform demo.

Read the sample decision memo

Who needs to be in the room

Name who sponsors, approves, and supports the decision.

When post-close planning creates an unresolved cyber spend request, the company still needs the same three names before anything is priced:

  • Sponsor: raises the unresolved spend request coming out of post-close planning.
  • Budget approver: the company's own budget approver, who authorizes the spend for this one decision.
  • Evidence owner: approves the exports the platform evaluation uses.

The planning stays inside what already exists:

  • Begin with a defined company workflow; agree portfolio expansion after evaluation
  • The company's existing tools and providers execute whatever is funded
  • Permission to use the company's evidence for this engagement
  • Platform evaluation access and commercial terms are agreed after the demo
01

Supported evaluation scope

Quantify loss

Name the company, loss objective, funding question, approved evidence pathway, and assumptions before the evaluation is scoped.

02

Funding review

Fund next

Work from approved company evidence and compare supported actions, costs, and time horizons against the company's available budget.

03

Company authority

Authorize change

The budget approver reviews the recommendation, its assumptions and gaps, and the named owner before authorizing the company or its provider to act.

04

Basis stated at review

Prove reduction

At the scheduled next review, inspect current evidence against the decision baseline and state whether any movement is modeled or observed.

Make the first decision explicit, then move on.

Request the free platform demo for one company. It is reviewed personally, with a reply and a private booking link within two business days if there's a fit.

Platform evaluation scope, commercial terms, and onboarding timing are agreed in writing after the demo. Recurring review is included only when supported and agreed; no day-30, day-60, or day-100 deliverable is promised.

Request a platform demoTry the assumption worksheet