CommandPortfolio Lens Every holding · One scorecard · Read-only
CommandSeat 03 · Portfolio Lens

Govern security
across the portfolio.

Security across a book of companies is invisible until a deal or a breach. Portfolio Lens normalizes every holding onto one scorecard, rolled up and drillable, from a seat that never takes the keys.

See the lens

Fig. 01 · Portfolio Lens · posture across the book

Portfolio Lens: Hudson's portfolio briefing, average maturity across the book, and every portfolio company ranked worst first

Every holding reports security differently, on its own cadence, in its own format. So a sponsor can compare EBITDA across nine companies in a morning and cannot compare their security at all. Portfolio Lens puts every company on one normalized scorecard, rolled up for the committee and drillable to the finding.

§ 01The portfolio

Every company,
one scorecard.

Maturity, 30-day trend, open criticals and audit posture, normalized so a 2.9 at a logistics business means the same thing as a 2.9 at a healthtech one. Sorted by what is slipping, so the company that needs the operating partner is already at the top.

Portfolio Lens Portfolio posture
9 companies · 2 need youPortfolio posture
3.1/5book average
CompanyMaturity30dCriticalsStatus
GIGranite IndustrialManufacturing · NIST CSF2.6▼ 0.22 openNeeds you
HHHelix HealthHealthtech · HITRUST2.8▼ 0.11 openNeeds you
TLTidewater LogisticsLogistics · SOC 22.9▼ 0.31 openWatch
ARAperture RoboticsRobotics · ISO 270013.7▲ 0.30 openHealthy
NFNorthwind FoodsCPG · SOC 23.5▲ 0.10 openHealthy
Hudson
§ 02Risk stories

The review narrative,
already written.

Hudson reads every assessment, finding, trend and portfolio benchmark for each company, then writes the story in plain English. Not a score with no explanation. The paragraph the operating partner would otherwise have to write the night before the committee.

Portfolio Lens Risk stories
3 companies need attentionRisk stories
Granite Industrial2.6 / 5GradeC

Granite still has two critical findings open and sits below the portfolio average at 2.6 out of 5. Threat detection is its weakest area, and nothing has moved in 30 days. Worth pushing on before the next board meeting.

Review findings →Raise concern →
Helix Health3.4 / 5GradeB+

Helix is in solid shape at 3.4 out of 5, with one minor finding open. Incident response is the only area trailing the rest and the 30-day trend is flat, so a light push on response keeps it on track.

Review findings →Raise concern →
§ 03Across the book

Go deeper
on any company.

Four things a sponsor asks between board meetings: what do I send the committee, who is behind on which framework, what can an attacker see, and how do I tell nine companies the same thing at once. All four read across the whole book.

Portfolio Lens Reports
Cross-portfolio · written by HudsonGenerate a report
Portfolio rollupQuarterly posture across every companyReady
LP quarterly summaryAggregate, anonymized fund reportReady
Diligence briefPre-acquisition security diligence
Attack surfaceExternal exposure, all companies

Board and LP reports, generatedPortfolio rollups, LP summaries and pre-deal diligence briefs, drawn from the live record and ready to send.

Portfolio Lens Framework coverage
Every company, every frameworkCoverage
CompanyNISTISOSOC 2HITRUST
ARAperture92%88%84%79%
NFNorthwind84%76%90%61%
TLTidewater74%62%80%58%
GIGranite44%26%52%18%

Coverage, every framework, every companyOne matrix of how far each holding has gotten against everything it is held to, so the gap stands out without opening a data room.

Portfolio Lens External monitoring
Aperture Robotics · updated 2d ago · monitored 24/7Attack surface
84score
SSLA
HeadersA+
DNSA
EmailA+
No threats detected
Posture score
Subdomains 41Open ports 12

What an attacker seesEvery company's external surface scanned around the clock: SSL, headers, DNS, email posture and breach signals, without touching their network.

Portfolio Lens Broadcasts
To the whole bookBroadcast
High · threat intelRotate long-lived cloud keys

Every company with a cloud environment: rotate long-lived access keys before Aug 1 and confirm MFA on admin roles. Hudson drafted the per-company steps.

GraniteHelixTidewater+6 more
6 of 9 acknowledgedSent · tracked

One message, the whole bookPush an advisory or a board-prep request to every company at once, or to a segment, and track who has acted, per company.

§ 04Assessments

Run an assessment
on any company.

Walk a holding's framework out loud on the call you were already having. Command transcribes, drafts the status and maturity for every control, and pulls the evidence it already holds, so diligence and quarterly reviews write themselves.

Granite Industrial NIST CSF PR.AA Access control
Listening · 11:08Rec
Analyst

How do you manage and review access to your OT and production systems?

Granite · IT Director

Access goes through Azure AD groups, and plant managers approve requests. We do an access review twice a year with system owners.

Analyst

Is that review documented and signed off?

Granite · IT Director

Yes, the H1 review is signed off in Command with owner attestations

Ambient capture · nobody is taking notes

Hudson · drafting

Access is provisioned via Azure AD groups with plant-manager approval. A semi-annual access review is performed with system owners and signed off in Command with attestations.

Suggested statusMet
Maturity3.0
Evidence pulled · 1
H1-Access-Review.pdfJul 02
ApproveOverride
§ 05Access

Each company owns
its program.
You see it all.

The objection to portfolio-wide security tooling is always the same: the sponsor does not want to run the company's program, and the company does not want the sponsor in its systems. The access model answers it directly. Governance never means taking the keys.

Portfolio company

Their own Command.

Each holding runs its full program in a dedicated instance: assessments, findings, controls, evidence and projects, owned by their team.

Read · write

The firm

One read-only lens.

The sponsor sees every company's posture rolled up and drillable, can run assessments and send broadcasts, but never edits a company's program directly.

Read-only

§ 06Other seats

Same record.
Different chair.

Portfolio Lens is one of three seats on the same program model. A company that graduates to its own security leader keeps its record, and an advisor running several books works from the same underlying data.

§ 07Next

Bring the book.
We will normalize it.

Tell us how many companies you hold and what each one is held to. We will walk through what your portfolio looks like on one scorecard, with your material rather than a demo tenant.

Command overview