Cybersecurity Policy

Governance policy

Cybersecurity Policy

The Cybersecurity Policy establishes the firm's framework for protecting the confidentiality, integrity, and availability of the firm's information assets, including limited partner data, portfolio company data, firm intellectual property, and operating systems.

← Governance

Policy OwnerChief Technology Officer & Chief Information Security Officer
Approving BodyAudit Committee
Effective DateJanuary 1, 2024
Last ReviewedJanuary 1, 2026
Next ReviewJanuary 1, 2027
Version2.0

1. Purpose

The Cybersecurity Policy establishes the firm's framework for protecting the confidentiality, integrity, and availability of the firm's information assets, including limited partner data, portfolio company data, firm intellectual property, and operating systems. The Policy reflects the firm's recognition that cybersecurity is a fiduciary obligation owed to limited partners and a regulatory obligation under the Investment Advisers Act, state breach notification laws, and emerging federal cybersecurity rules.

2. Scope

This Policy applies to all Personnel, all information systems operated by or on behalf of the firm, all data classified as Confidential or Restricted under the firm's data classification standard, and all third-party vendors with access to firm or limited partner data.

3. Governance

The Chief Technology Officer and Chief Information Security Officer jointly own the firm's cybersecurity program. The Chief Compliance Officer is consulted on regulatory matters and breach notification. The Audit Committee receives a cybersecurity report at least semi-annually. Material incidents are reported to the Chief Executive Officer and the Audit Committee within twenty-four hours of confirmation.

4. Threat Model

The firm's cybersecurity program is designed to address: (a) phishing, business email compromise, and credential theft; (b) ransomware and destructive malware; (c) unauthorized access by insiders and former personnel; (d) third-party vendor compromise; (e) data exfiltration; (f) denial-of-service attacks on limited-partner-facing infrastructure; (g) state-sponsored threats to private fund advisers and their portfolio companies. The threat model is reviewed annually.

5. Access Control

Access to firm systems and data is granted on a least-privilege basis. Access requests are reviewed by the Chief Information Security Officer and approved by the data owner. Multi-factor authentication is mandatory for all access to firm systems, limited partner portals, and external SaaS platforms. Privileged access is logged, time-bound, and reviewed quarterly. Access is revoked within one business day of termination or role change.

6. Data Classification

Firm data is classified as Public, Internal, Confidential, or Restricted. Restricted data, including limited partner personally identifiable information, deal-stage material non-public information, and personnel records, requires encryption at rest and in transit, access logging, and additional handling controls. Data classification standards are reviewed annually by the Chief Information Security Officer and the Chief Compliance Officer.

7. Encryption

Data classified as Confidential or Restricted is encrypted at rest using AES-256 or stronger and in transit using TLS 1.2 or stronger. Encryption keys are managed in a dedicated key management system with separation of duties between key custodians and data administrators. Backup data is encrypted with the same standard as production data.

8. Endpoint and Network Security

All firm-managed endpoints run endpoint detection and response software with centralized telemetry. Endpoints are required to meet minimum operating system version, patch level, and configuration standards. Network access is segmented between corporate, guest, and operational networks. Firewalls, intrusion detection, and DNS filtering are in continuous operation. Personnel may not connect personal devices to the corporate network without enrollment in the firm's mobile device management.

9. Incident Response

The firm maintains a written Incident Response Plan covering detection, triage, containment, eradication, recovery, notification, and post-incident review. The Plan defines roles, communication channels, and decision authorities. Incident drills are conducted at least annually. Limited partners are notified of any incident materially affecting limited partner data or fund operations in accordance with state breach notification laws and the firm's regulatory obligations. Notification to the Chief Executive Officer and the Audit Committee occurs within twenty-four hours of confirmation of a material incident.

10. Vendor Risk Management

Vendors with access to firm or limited partner data are subject to a written vendor risk assessment prior to onboarding and at least annually thereafter. Assessments cover the vendor's information security program, incident history, certifications, sub-processor relationships, and contractual data protection commitments. Critical vendors are subject to right-to-audit, breach notification, and exit assistance terms in their contracts.

11. Penetration Testing and Vulnerability Management

The firm engages a qualified independent firm to perform external penetration testing at least annually, with additional targeted tests upon material system change. Internal vulnerability scanning is continuous. Critical vulnerabilities are remediated within seven days; high vulnerabilities within thirty days; medium vulnerabilities within ninety days. The Chief Information Security Officer reports remediation status to the Audit Committee semi-annually.

12. Training and Awareness

All Personnel complete cybersecurity awareness training upon onboarding and annually thereafter. Personnel with elevated access or roles handling Restricted data complete additional role-specific training. Phishing simulation exercises are conducted at least quarterly. Training completion is tracked by the Chief Information Security Officer and reported to the Audit Committee annually.

13. Business Continuity and Disaster Recovery

The firm maintains a Business Continuity Plan and a Disaster Recovery Plan covering material operational scenarios, including ransomware, primary site failure, vendor outage, and personnel unavailability. Recovery time and recovery point objectives are defined for each critical system. Plans are tested at least annually. Limited partners are notified of any continuity event materially affecting fund operations.

14. Reporting

The Chief Information Security Officer reports to the Audit Committee at least semi-annually on the cybersecurity program, including incidents, vulnerability posture, training completion, third-party assessment results, and program investments. Limited partners receive a cybersecurity summary on request.

Notice

This document is a summary of the firm's internal cybersecurity policy as adopted by the Audit Committee. The complete policy as adopted by the Audit Committee governs in any case of conflict between this summary and the underlying policy document. Limited partners and other authorized parties may request the full policy from the Chief Technology Officer & Chief Information Security Officer. This document does not create contractual rights, employment rights, or third-party beneficiary rights, and may be amended at any time by action of the Audit Committee.

Questions about this policy should be directed to the Chief Technology Officer & Chief Information Security Officer via [email protected]. Confidential or anonymous reports may also be made through the channels described in the Whistleblower Policy.

Questions about firm governance

Limited partners, regulators, and counterparties with questions about firm governance, policies, or compliance should contact [email protected].