Cybersecurity Solutions features explained
for Operations and Finance
Every feature we track for Cybersecurity Solutions products, with a description of what each one means.
Access Control and Identity Management
Mechanisms to ensure only authorized individuals can access sensitive information and systems, essential for maintaining confidentiality in VC operations.
- Account Lockout Threshold
- Number of failed login attempts allowed before an account is locked.
- Audit Trail Retention Period
- Length of time that records of user access and changes are kept.
- Integration With Directory Services
- Can synchronize with corporate directories (e.g., Active Directory, LDAP).
- Mandatory Password Expiry
- Enforces periodic password changes to reduce the risk of compromise.
- Multi-factor Authentication (MFA)
- Requires users to verify identity using multiple credentials for critical systems.
- Privileged User Monitoring
- Tracks activities of high-access users for early detection of misuse.
- Role-Based Access Control (RBAC)
- Assigns system permissions based on job role to enforce least-privilege access.
- Self-Service Password Reset
- Allows users to securely reset passwords without admin involvement.
- Single Sign-On (SSO) Support
- Allows seamless, secure access to multiple systems using one set of credentials.
- User Provisioning and De-provisioning Speed
- Time required to add or revoke user access upon onboarding or departure.
Backup, Recovery, and Business Continuity
Capabilities and protocols that ensure business operations and data can be rapidly restored after disruptions, critical for continuous VC operations.
- Automated Backups
- Scheduled, automatic backups of all critical data.
- Automated Failover Support
- Enables seamless transition to backup systems automatically.
- Backup Frequency
- How often backups are taken.
- Backup Restore Testing Frequency
- How often backup restores are tested for integrity.
- Disaster Recovery Playbooks
- Pre-defined procedures for different disaster scenarios.
- Encrypted Backups
- All backup data is encrypted during storage and transit.
- Geo-Redundant Backup Storage
- Backups are replicated in multiple data centers or regions.
- Granular Restore Capability
- Can restore individual files, folders, or full systems.
- Recovery Point Objective (RPO)
- Maximum acceptable age of files in backup, indicating potential data loss time window.
- Recovery Time Objective (RTO)
- Maximum acceptable time to restore systems after a failure.
Compliance and Regulatory Support
Assists in meeting relevant global and regional compliance requirements for the venture capital sector.
- Audit-trail for Compliance Actions
- Proof of compliance actions is logged and accessible.
- Automated Data Subject Requests
- Can handle right-to-access, right-to-be-forgotten, and correction requests.
- California Consumer Privacy Act (CCPA) Support
- Compliant with CCPA for handling California data subjects.
- Compliance Certifications Dashboard
- Displays current compliance certifications (e.g., SOC 2, ISO 27001).
- Compliance Report Generation Speed
- Time required to produce a full compliance report for auditors.
- Customizable Data Retention Policies
- Allows organizations to define bespoke regulatory retention periods.
- Data Residency Controls
- Can restrict data storage and processing to certain jurisdictions.
- GDPR Support
- Product supports General Data Protection Regulation for EU LPs and companies.
- Policy Change Alerting
- Alerts administrators when compliance policies change or are updated.
- Vendor Risk Assessment Integration
- Integrates third-party assessments into compliance reporting.
Data Encryption and Confidentiality
Protects sensitive deal, portfolio, and LP data using strong encryption both in transit and at rest.
- At-Rest Encryption
- Ensures stored data in databases and file systems is encrypted.
- Compliance with Industry Encryption Standards
- Effectively meets standards such as FIPS 140-2/3 or ISO/IEC 27001.
- Data Loss Prevention (DLP)
- Monitors and blocks unauthorized data transfers inside and outside the organization.
- Encryption Key Management
- Automated and audited management of cryptographic keys.
- End-to-End Encryption for Communications
- All communication channels (email, messaging, file transfer) support end-to-end encryption.
- Granularity of Data Encryption
- Defines whether encryption is file-level, database-level, or field-level.
- Hardware Security Module (HSM) Integration
- Supports securing keys within HSMs for added protection.
- In-Transit Encryption
- Utilizes strong cryptographic protocols (e.g., TLS 1.2+) for data moving across networks.
- Real-time Data Encryption Speed
- The speed at which the system can encrypt or decrypt data in real-time.
- Secure File Sharing
- Enables secure, encrypted document sharing with third parties or LPs.
Monitoring, Logging, and Reporting
Tracks activities, system operations, and security events to ensure transparency and support forensic investigations.
- API Access to Logs
- Logs and reports accessible via standard APIs.
- Alert Customization
- Users can define thresholds and triggers for alerting.
- Anomaly Detection in User Activity
- Automatically highlights unusual user behavior for investigation.
- Audit Log Search/Filtering Speed
- Rate at which logs can be queried for specific events.
- Automated Compliance Reports
- Generates reports for regulatory and LP compliance needs.
- Comprehensive Audit Logs
- Records all relevant system and user activities for auditing purposes.
- Customizable Reporting Dashboards
- Flexible dashboard tools for real-time monitoring and historical analysis.
- Log Integrity Monitoring
- Detects if audit logs have been tampered with.
- Log Retention Period
- Set length of time all logs are retained for compliance.
- Scheduled vs Real-time Reporting
- System can provide both scheduled and real-time reports.
Secure Communications
Platforms and protocols that safeguard internal and LP/portfolio communication channels.
- Automated Message Retention Policy
- Controls how long communication records are kept and when they are deleted.
- Communication Channel Redundancy
- System supports alternative communication methods in case of outages.
- Customizable Access Policies for Communications
- Ability to restrict communication tools usage by user or group.
- Digital Signatures on Communications
- Ensures authenticity and non-repudiation for critical messages.
- Encrypted Email Integration
- Email solutions support encrypted delivery and attachments.
- Encrypted Messaging
- Internal and external chat/messages are encrypted at rest and in transit.
- External Participant Verification
- Verifies the identity of external recipients in communications.
- Message Recall or Revocation
- Capability to retract messages sent in error.
- Secure Video Conferencing
- Video meetings use encryption and access controls to protect confidentiality.
- Watermarking Confidential Messages
- Messages can be automatically watermarked for traceability.
System Integration and Interoperability
Ensures effective and secure integration with internal and third-party tools often used in venture capital workflows.
- Automated Data Sync Frequency
- How frequently data is automatically synchronized across platforms.
- CRM Integration
- Works with Salesforce and other CRM systems for LP and portfolio tracking.
- Custom Integration Toolkit
- Offers SDKs/libraries for custom workflow integration.
- Granular Integration Permissions
- Permissions for integrations can be defined by user or group.
- Integration with Document Management Systems
- Works seamlessly with DMS like Box, Dropbox, SharePoint.
- Marketplace of Pre-Built Integrations
- Catalog of out-of-the-box plugins and connectors.
- Open API Availability
- Product offers open APIs for extensibility and automation.
- Real-time Integration Monitoring
- Notifies when integrations fail or are at risk.
- Support for SAML/OAuth Connectors
- Allows secure identity federation across multiple SaaS tools.
- Versioning and Backward Compatibility
- Ensures integration APIs remain available across product upgrades.
Threat Detection and Incident Response
Continuously monitors for cyber threats and provides rapid response capabilities to minimize risk and damage.
- 24/7 Monitoring
- Security monitoring is available at all times, not just business hours.
- Alert Notification Time
- Maximum time between threat detection and alerting security staff.
- Automated Incident Response Workflows
- System can automatically respond to certain threat types to contain damage.
- Customizable Threat Signatures
- Can create and tune custom detection signatures for sector-specific threats.
- Incident Response Playbooks
- Pre-defined, customizable workflows for different incident types.
- Integration with SIEM (Security Information and Event Management)
- Ability to feed data to SIEM platforms for correlated analysis.
- Mean Time to Detect (MTTD)
- Average time between threat occurring and being discovered.
- Phishing Detection and Prevention
- Alerts users and blocks suspicious communications targeting credentials.
- Real-time Threat Detection
- Ability to identify threats as they occur using AI/ML and signature-based detection.
- Security Event Log Retention
- How long security events/logs are retained for forensic analysis.
Vendor Management and Ecosystem Security
Tools to manage security across the ecosystem of software vendors, portfolio companies, and outsourced IT providers that VC firms interact with.
- Automated Vendor Offboarding
- Instant removal of vendor access once a contract ends.
- Continuous Vendor Security Monitoring
- Monitors ongoing risk from vendors (e.g., dark web exposure, breaches).
- Portfolio Company Security Guidance Tools
- Provides tools or frameworks for portfolio companies to follow security best practices.
- Third-party Risk Assessment Automation
- Automates evaluation and scoring of third-party risk.
- Vendor Access Control
- Restricts and monitors vendor/outsourced IT access to systems and data.
- Vendor Breach Notification Speed
- Time between vendor-reported security incidents and notifications to your firm.
- Vendor Contract Compliance Flags
- Alerts for upcoming expirations, lacking attestations, or non-compliance.
- Vendor Cost Monitoring
- Tracks and manages the cost of vendor cybersecurity services.
- Vendor Data Segmentation
- Ensures vendor access is limited to specific, well-defined areas and data sets.
- Vendor Security Questionnaire Management
- Centralizes collection and review of security documentation from vendors.
Workflow and User Experience Security
User interface and process designs that promote secure, efficient VC operations while minimizing friction.
- Accessibility Support in Secure Workflows
- Features and workflows accessible to all users, including those with impairments.
- Adaptive User Training Prompts
- In-app security learning for users when risky behaviors are detected.
- Context-aware Access Controls
- Adapts access policies based on user location, device, or time.
- Frictionless Delegated Access
- Temporarily delegate access securely and efficiently.
- Integrated Secure Approval Processes
- Enables approvals for sensitive actions within secured workflows.
- Minimal Security Task Completion Time
- Low latency for users performing security actions (e.g., reviewing access requests).
- Mobile Security Features
- Appropriate controls and protections for mobile users.
- Security Warnings/Explainability
- Clear and actionable security warnings for users.
- Session Timeout Configuration
- Customizable length before automatic user logout due to inactivity.
- User Activity Feedback
- System provides immediate visual/audible feedback for security events (e.g., successful login, warning for suspicious activity).