Industries

IT for private equity

One standard, across the portfolio.

happier IT works with Canadian private equity firms in two places: the deal team’s own environment, where confidentiality is the whole job, and the portfolio companies, where IT is usually the first shared service anyone tries to standardise. Both need the same thing, a written baseline, applied the same way every time.

Who it's for

Two clients in one relationship.

A fund and a manufacturer it just bought share almost nothing technically. The connection is the standard you set.

The deal team’s environment
A small, senior group handling material non-public information on laptops that travel. Identity, device control and knowing where documents live matter more here than seat count.

Virtual data rooms
Datasite, Intralinks, SharePoint. The risk is rarely the platform. It is the access list nobody revoked once the process closed, and the local copies that left inside it.

Deal and portfolio systems
DealCloud for pipeline, portfolio monitoring tools for reporting, fund administration platforms behind them. Mostly vendor-hosted, which moves the question to who holds administrative rights.

The portfolio companies themselves
A distributor on an ageing file server, a services firm entirely in Microsoft 365, a manufacturer with a plant floor. Each arrives with its own idea of normal.

What's included

Where IT actually costs a deal money.

The items that show up as unplanned spend, a delayed integration, or a discount at exit.

  • Diligence that arrives too late to change the price

    IT diligence often happens after commercial terms are set, which turns findings into surprises. Ageing infrastructure, unlicensed software and an unsupported core application are all costable, if someone looks in time.

  • A carve-out on a TSA clock

    A TSA, a transition services agreement, is the arrangement under which a seller keeps running services for the business you bought, for a fixed period. Email, identity and the ERP are the last things to leave it, and extension fees are where budgets go.

  • A 100-day plan with a vague IT line

    “Review IT” is not a plan. What belongs there is specific and boring: administrative access recovered, backups restored from, multi-factor authentication enabled, leavers removed, licensing counted.

  • Every company doing it differently

    Five companies with five providers is five conversations every time the fund asks a question. A baseline is not identical systems, it is the same minimum, the same reporting, one answer to “are we covered”.

  • Confidentiality inside the deal team

    Material non-public information sits in mailboxes, on phones and in data rooms, moving between advisors. The controls are unremarkable: managed devices, controlled sharing, access that expires.

  • Exit diligence looking the other way

    On the way out, a buyer runs the examination you ran on the way in. Unlicensed software and undocumented systems all surface.

How it works

How we work across a deal.

Three points in a transaction, with different work at each.

  1. Diligence that produces numbers, not adjectives

    We assess infrastructure, applications, licensing, contracts, security posture and IT staffing, then hand back a report with costs attached: what must be spent in year one, what can wait, what carries risk.

  2. The first hundred days

    Administrative access recovered and documented, backups tested by restoring something, multi-factor authentication enabled, departed accounts removed, and every IT contract and renewal date in one list.

  3. A baseline the portfolio can hold

    A written minimum standard, applied as each company is ready. Where a company has a capable internal team we stand behind them, <a href="/co-managed-it/">co-managed IT</a>. Where it has nothing, we run it.

What it costs

The oversight comes from your investors and your regulator.

Not a sector with one technology statute. A sector where several parties ask for evidence.

Registered firms in Canada work under provincial securities regulators and the Canadian Securities Administrators, whose expectations cover record keeping, business continuity and the oversight of service providers. Your chief compliance officer owns that; we supply the technical evidence.

The other source of questions is your investors. LPs, limited partners, the institutions and individuals whose capital the fund invests, send due diligence questionnaires with cybersecurity sections covering identity controls, incident response, backup testing and where data is held. They arrive at fundraising, when the time to build an answer has passed.

Below the fund, each portfolio company carries its own regime: privacy law under PIPEDA, the federal Personal Information Protection and Electronic Documents Act, health privacy law for a clinic group, card standards for anything taking payments.

Cyber insurance at two levels

The fund carries a policy, and each portfolio company usually carries one too. Renewal questionnaires ask a near-identical list, which is a quiet argument for a common baseline: answer once, apply everywhere.

Underwriters increasingly verify rather than take your word.

Why us for this

Why this page carries no deal list.

Deal work is confidential by nature, so this page will never carry a list of transactions.

Verifiable today: happier IT is Canadian-owned, operates its own security operations centre in Canada staffed by its own employees rather than a resold monitoring platform, holds certifications across Microsoft, Cisco, Dell, VMware and CompTIA, and has been named to Business in Vancouver’s Top 100 Fastest-Growing Companies.

Questions

What people ask before they sign anything.

What does IT due diligence actually cover?

Infrastructure and its age, applications and whether they are supported, licensing and whether it is compliant, the security posture including backups and access control, and key-person risk. The output should be a costed picture: spend required in year one, spend deferrable, risks carried.

Do you work with the fund, the portfolio companies, or both?

Both, and they are different engagements. For the fund it is a small senior environment where confidentiality and device control dominate. For portfolio companies it is ordinary managed IT and security, most of ours sit between 15 and 200 people.

What is a TSA and why does IT keep extending it?

A transition services agreement is the contract under which a seller keeps providing services, often email, identity, the ERP and helpdesk, to a business it has sold. IT extends it because separation is larger than it looks: identity has to move without breaking access.

How do you standardise IT across companies that all do it differently?

By standardising the minimum rather than the systems. A baseline covering identity and multi-factor authentication, a second check, usually on a phone, before a login is accepted, endpoint protection, patching, tested backups and offboarding applies equally to a manufacturer and a services firm.

What do limited partners ask about cybersecurity?

The standard due diligence questionnaires ask who is responsible for security, what controls exist over access and devices, how incidents are detected and reported, whether backups are tested, and where data is stored. The difficulty is rarely the controls, it is producing evidence under fundraising timelines.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.