Every holding reports security differently, on its own cadence, in its own format. So a sponsor can compare EBITDA across nine companies in a morning and cannot compare their security at all. Portfolio Lens puts every company on one normalized scorecard, rolled up for the committee and drillable to the finding.
Every company,
one scorecard.
Maturity, 30-day trend, open criticals and audit posture, normalized so a 2.9 at a logistics business means the same thing as a 2.9 at a healthtech one. Sorted by what is slipping, so the company that needs the operating partner is already at the top.
The review narrative,
already written.
Hudson reads every assessment, finding, trend and portfolio benchmark for each company, then writes the story in plain English. Not a score with no explanation. The paragraph the operating partner would otherwise have to write the night before the committee.
Granite still has two critical findings open and sits below the portfolio average at 2.6 out of 5. Threat detection is its weakest area, and nothing has moved in 30 days. Worth pushing on before the next board meeting.
Helix is in solid shape at 3.4 out of 5, with one minor finding open. Incident response is the only area trailing the rest and the 30-day trend is flat, so a light push on response keeps it on track.
Go deeper
on any company.
Four things a sponsor asks between board meetings: what do I send the committee, who is behind on which framework, what can an attacker see, and how do I tell nine companies the same thing at once. All four read across the whole book.
Board and LP reports, generatedPortfolio rollups, LP summaries and pre-deal diligence briefs, drawn from the live record and ready to send.
Coverage, every framework, every companyOne matrix of how far each holding has gotten against everything it is held to, so the gap stands out without opening a data room.
What an attacker seesEvery company's external surface scanned around the clock: SSL, headers, DNS, email posture and breach signals, without touching their network.
Every company with a cloud environment: rotate long-lived access keys before Aug 1 and confirm MFA on admin roles. Hudson drafted the per-company steps.
One message, the whole bookPush an advisory or a board-prep request to every company at once, or to a segment, and track who has acted, per company.
Run an assessment
on any company.
Walk a holding's framework out loud on the call you were already having. Command transcribes, drafts the status and maturity for every control, and pulls the evidence it already holds, so diligence and quarterly reviews write themselves.
How do you manage and review access to your OT and production systems?
Access goes through Azure AD groups, and plant managers approve requests. We do an access review twice a year with system owners.
Is that review documented and signed off?
Yes, the H1 review is signed off in Command with owner attestations
Ambient capture · nobody is taking notes
Access is provisioned via Azure AD groups with plant-manager approval. A semi-annual access review is performed with system owners and signed off in Command with attestations.
Each company owns
its program.
You see it all.
The objection to portfolio-wide security tooling is always the same: the sponsor does not want to run the company's program, and the company does not want the sponsor in its systems. The access model answers it directly. Governance never means taking the keys.
Their own Command.
Each holding runs its full program in a dedicated instance: assessments, findings, controls, evidence and projects, owned by their team.
Read · write
One read-only lens.
The sponsor sees every company's posture rolled up and drillable, can run assessments and send broadcasts, but never edits a company's program directly.
Read-only
Same record.
Different chair.
Portfolio Lens is one of three seats on the same program model. A company that graduates to its own security leader keeps its record, and an advisor running several books works from the same underlying data.
The in-house program
One company, one program, one team. The loop, the record, and a board brief that is current because it was never assembled by hand.
Command overview → Seat 02The vCISO practice
A dozen clients, one console. Every program's maturity, trend and open criticals side by side, sorted so the client who needs you today is already at the top.
For vCISO practices →Bring the book.
We will normalize it.
Tell us how many companies you hold and what each one is held to. We will walk through what your portfolio looks like on one scorecard, with your material rather than a demo tenant.