IT Advisory for Private Equity & Portfolio Companies
Private equity investors and their portfolio companies operate in a frame that resets with every transaction.
IT in Private Equity
Regulatory duties attach to the individual entity, not to the group: a carved-out company must assess its own NIS2 status — what counts is its sector under Annexes 1 and 2 of the German BSI Act and the size threshold in section 28 BSIG, for important entities at least 50 employees or an annual turnover and an annual balance sheet total each exceeding 10 million euro — and register with the BSI no later than three months after it first qualifies, under section 33 BSIG.
Management of the new company carries the duties of section 38 BSIG from day one, including mandatory training and personal liability. Data protection makes the transition phase non-trivial: services the seller continues to provide under a transitional service agreement normally constitute processing on behalf of the buyer and require an Article 28 GDPR contract before the first ticket is raised.
Technically a carve-out is decided in four places: separating directory services and tenants, disentangling network and data centre, standing up an independent backup and recovery capability before the TSA expires, and moving to owned licence and logging paths instead of borrowed ones. Alendris covers the full cycle. We run IT due diligence as a short sprint with a red-flag list, quantified investment requirements and an assessment of carve-out complexity, treating data centre, network and Active Directory as a distinct workstream because they are regularly the biggest unknowns in a deal.
For a manufacturing company we then planned and executed a complete IT carve-out: disentangling every relevant infrastructure component, migrating central services into a standalone environment, and defining cutover and operating processes for the parallel phase. During the hold period come standardisation across holdings, Microsoft 365 modernisation, hardening with Microsoft Defender XDR and FinOps discipline for cloud spend — and, well before exit, the IT hygiene the next buyer will examine.
Typical pain points
- IT risks in the transaction phase often underestimated — unpleasant surprises post-closing
- TSA timelines often too short — extensions cost money and negotiation capital
- Microsoft 365 tenant splits are complex (data, identities, licences)
- IT modernisation must be EBITDA-positive and run parallel to operating business
- Exit preparation: IT hygiene for the next buyer due-diligence sprint