For Venture Capital & Investment Firms
Financial, legal and commercial diligence each end in a quantity. Cyber diligence ends in findings. A pentest tells you what is exposed, not what the exposure is worth, so nothing about it can be priced into the deal, held back at close, or written into a warranty. Üsta produces target cyber exposure as a loss distribution, in the terms an investment committee already weighs against revenue, burn and market risk.
Request a ConversationCyber exposure across your holdings by risk band, in terms that belong in an investment committee memo.
The Problem
A cyber incident in a portfolio company presents as a valuation event. Transaction processing stops, POPIA obligations are triggered, enterprise sales stall, and the capital plan moves onto someone else's timetable. Those are financial consequences, and they are the ones an investment committee is equipped to weigh.
A questionnaire or a vendor security scan produces neither a frequency nor a severity, and therefore no financial exposure. Without one, cyber cannot enter the price, the escrow, the warranty schedule, or the post-investment reporting pack. It stays in the security annex, which is the one part of the memo the investment decision is not made from.
The Value Proposition
Üsta operates both as a pre-investment due diligence tool and as ongoing portfolio risk infrastructure, covering the full investment lifecycle.
Quantify cyber risk in financial terms before you commit capital. Receive loss distributions and tail scenarios structured for investment committee use, so cyber risk sits alongside financial, legal, and market risk in the decision, not in a separate security annex.
Track cyber risk exposure across portfolio companies on a recurring basis. Identify material changes in risk posture, hold management teams to a baseline, and prepare companies for acquirer due diligence well in advance of an exit process.
What Partners Get
A penetration test tells you where the holes are. It does not tell you what a breach would cost. Üsta produces financial loss distributions: expected loss, tail scenarios, and recovery timelines. Together they translate cyber risk into the terms an investment committee can weigh alongside revenue, burn, and market risk.
Once you have committed capital, cyber risk does not disappear. Üsta provides periodic reassessment of portfolio companies, giving you early visibility of material changes in cyber exposure before they surface as incidents, regulatory actions, or valuation events.
Strategic acquirers and PE buyers now run cyber due diligence as standard. Portfolio companies that arrive at exit with a quantified, auditable cyber risk position, rather than a collection of compliance certificates, close faster and with fewer post-signing adjustments.
African digital infrastructure, regulatory environment, and threat landscape are materially different from the markets most cyber risk tools are built for. Üsta's models are calibrated to POPIA, FSCA, and African incident data, giving you assessments that reflect the actual environment your portfolio companies operate in.
How It Works
Üsta's structured assessment is administered to the target company during due diligence. No security tooling or infrastructure is required. The process is designed to be low-friction for the target while producing outputs that are meaningful to the investment committee.
We build a calibrated financial loss model based on the company's control posture, technology stack, sector, and scale. The output is a probability distribution of cyber losses, not a maturity score or a traffic-light rating.
You receive a financial risk summary, scenario analyses, and a control posture profile, structured for inclusion in your investment committee memo and data room. The outputs are designed to be read by financial decision-makers, not security professionals.
For portfolio companies, Üsta provides periodic reassessment on a cadence that suits your reporting cycle, flagging material changes in risk posture and tracking the impact of control improvements on financial exposure over time.
Who This Is For
Whether you want to embed cyber risk into a live due diligence process or build a monitoring framework for your existing portfolio, a conversation is the right place to start.