Governance / Portfolio: Cybersecurity and data protection
Cybersecurity and data protection in the portfolio
We work closely with our portfolio companies to help them identify and proactively manage cybersecurity risks, implement data protection measures and cultivate a culture of cybersecurity awareness across their organisations.
As digital transformation accelerates and cyber threats grow in sophistication, cybersecurity remains one of the most material risk areas across our portfolio. Protecting sensitive data, safeguarding operations and maintaining stakeholder trust are fundamental to long-term value creation.
In 2025, Oakley made significant advances in the monitoring and active management of cybersecurity performance across its portfolio. Building on the launch of our portfolio-wide monitoring platform, Vantage, in 2024, we have strengthened our ability to assess risk exposure consistently, identify vulnerabilities in real time and support management teams in implementing targeted improvements. Although aggregate metrics are not disclosed externally for security reasons, this enhanced visibility has allowed us to move from periodic assessment to continuous monitoring and structured capability building.
Portfolio-wide engagement and knowledge sharing
A key development in 2025 was the introduction of quarterly cybersecurity huddles – virtual sessions bringing together Chief Technology Officers, Chief Information Security Officers and relevant technology leaders from across the portfolio.
Each session focuses on a topical cybersecurity theme. During the year, discussions included analysis and review of high-profile cyber attacks that occurred in the UK market. These sessions examined root causes, common failure points and practical mitigation strategies, enabling portfolio companies to apply real-world learnings to their own environments.
We also hosted a dedicated session on backup and recovery, led by our portfolio company Assured Data Protection, providing practical guidance on resilience planning and disaster recovery best practice.
To reinforce positive momentum and peer learning, we introduced year-end cybersecurity awards, recognising companies with the lowest cybersecurity risk score and those demonstrating the most significant improvement over the year. Award recipients were invited to share the practical steps they had taken to strengthen their control environment. Feedback from portfolio companies on these huddles has been overwhelmingly positive, with participants highlighting the value of structured peer exchange and continued offline collaboration.
95%
of companies actively engaged in Vantage
cybersecurity monitoring programme
11
new companies onboarded onto Vantage in 2025