What is Sponsor Cyber Liability?
A March 2026 federal ruling allowed breach claims against Bain Capital directly for a portfolio company's cyber failure. What sponsor cyber liability means for PE.
What the Bain/PowerSchool Ruling Established
Bain Capital acquired PowerSchool, a K-12 student information system provider, in October 2024 for $5.6 billion. A breach disclosed in early 2025 exposed data on roughly 60 million students, teachers, and parents. It was ultimately attributed to a 19-year-old who used stolen vendor credentials to exfiltrate data over several months.
Plaintiffs named Bain Capital directly. Bain moved to dismiss, arguing the standard position: it was an investor, the portfolio company was a separate legal entity, and the acquisition documents disclaimed operational control.
On March 18, 2026, Judge Rita F. Lin of the Southern District of California denied the motion in relevant part, allowing claims against Bain to proceed. The allegations the court found sufficient:
- Bain ratified and conditioned its offer on cost reduction measures, which included laying off domestic cybersecurity staff
- Pre-closing, Bain held contractual veto rights over vendor contracts and capital expenditures above $5 million
- Post-closing, Bain directed PowerSchool to offshore cybersecurity, engineering, and IT functions to Movate — the vendor whose compromised credentials the attacker used
The court explicitly rejected the argument that contractual disclaimers of control were dispositive. What matters is control actually exercised.
The Legal Theories
Agency. If the sponsor directs the portfolio company's conduct in a relevant domain, the portfolio company may act as the sponsor's agent in that domain, and the sponsor may be liable for the consequences.
Direct negligence. If the sponsor made or ratified decisions that created the risk — cutting security staff, directing an offshoring arrangement — the claim runs against the sponsor's own conduct rather than being derivative of the portfolio company's.
Ratification. Approving or requiring a course of action makes the sponsor a participant in it.
None of these theories require piercing the corporate veil, which is the defense sponsors are accustomed to relying on. They operate on what the sponsor did.
Where Sponsor Conduct Creates Exposure
The activities most likely to support a control theory are ordinary private equity value-creation activities:
- Cost reduction mandates that reach security or IT headcount
- Approval rights over vendor selection, particularly where the selected vendor is later implicated
- Capex approval thresholds that gate security investment
- Directed offshoring or outsourcing of technology functions
- Operating partner involvement in technology decisions
- Board control exercised over security matters specifically
This is uncomfortable because it describes the operating model. The answer is not to stop exercising operational control — that is the value-creation thesis — but to exercise it in a documented, defensible way where security is concerned.
What Reduces the Exposure
Document the security analysis behind cost decisions. A cost reduction that touches IT or security should be accompanied by a documented risk assessment showing the decision was considered rather than incidental. That record is the difference between a business judgment and an allegation of indifference.
Fund cyber diligence and post-close remediation, and keep the record. A sponsor that assessed the target's security posture, identified gaps, and funded remediation has a very different evidentiary position than one that did not look.
Apply a security standard to directed vendor decisions. If the sponsor directs or approves a vendor selection, that vendor should have been assessed. Directing a selection and not assessing it is the Bain fact pattern.
Establish portfolio-wide security minimums. A documented baseline the sponsor requires across the portfolio, with periodic verification, demonstrates a governance posture rather than ad hoc intervention.
Get independent assessment. Third-party evidence of security posture, produced on a cadence, is the artifact that supports every one of the above.
The Practical Shift
Cyber diligence has historically been justified on underwriting grounds — know what you are buying, price it correctly. The Bain ruling adds a second justification: documented diligence and remediation is evidence of the sponsor's own reasonable conduct. That reframes cyber diligence from a cost of deal-making into a component of the sponsor's liability posture.
Related Reading
Bain Capital and PowerSchool
Bain acquired PowerSchool for $5.6 billion in October 2024. The 2025 breach exposed roughly 60 million student, teacher, and parent records. The attacker used stolen credentials belonging to Movate — the offshore vendor Bain had directed PowerSchool to engage for cybersecurity, engineering, and IT functions after closing.
The chain the plaintiffs drew: Bain conditioned its offer on cost reductions, those reductions included domestic cybersecurity layoffs, Bain directed the offshoring that replaced them, and the vendor selected in that arrangement was the source of the compromised credentials.
Bain was also named by Google's Threat Intelligence Group as a target of the 2026 vishing campaign that compromised Apollo Global Management. Cloudskope's full analysis: the two-front war on PE cyber.
the date a federal court allowed data breach claims to proceed directly against a private equity sponsor for a portfolio company's cyber failure, holding that contractual disclaimers of control are not dispositive.
.png)