THE LOGINOV INDEX
For private equity and transaction advisory diligence teams

The AI & cyber investment risk index for private equity.

A structured, evidence-first assessment of investment targets: AI governance, cybersecurity, threat history, crown jewel assets, supply chain, operating model, financial exposure and physical security, scored, red-flagged and priced for an investment committee.

8Weighted domains
57Evidence-tested controls
31Deal-critical red-flag triggers
100Day remediation plan, generated
What it measures

One converged estate. Eight domains.

Attackers exploit the seams between teams and technologies, so the Index audits the whole estate, digital and physical, as one connected system: IT, OT, IoT, the AI and data estate, sites, hardware and people.

AIG

AI Governance & Regulatory Readiness

EU AI Act classification, NIST AI RMF, model documentation, conformity pathway.

CYB

Cybersecurity Posture

NIST CSF 2.0 end to end: govern, identify, protect, detect, respond, recover, patch.

THR

Threat Exposure & Incident History

Breach history, ransomware record, dark web exposure, testing discipline.

CJA

Crown Jewel Assets

Model weights, training data rights, IP chain of title, insider risk, DPO and GDPR roles.

SCR

Supply Chain & Third-Party Risk

Concentration risk, AI-BOM, licence contamination, contract protections.

OPM

Operating Model, People & Competence

Leadership, RACI, key-person risk, budget adequacy, enterprise risk governance.

FIN

Financial Exposure & Insurability

Insurance warranties, indemnity exposure, regulatory penalties, revenue at risk.

PHY

Physical & Converged Security

Sites, OT and IoT, media and paper disposal, bug sweeps, converged governance.

How it works

Evidence beats assertion, and one fact can override the arithmetic.

Step 1

Engagement record

Company profile, certifications, senior leadership, and a full respondent log: who answered, their role, and when. Every finding carries provenance.

Step 2

57 controls, scored on evidence

Five-point maturity per control, N/A only with a recorded reason, and asserted controls without evidence score as though they do not exist.

Step 3

Red flags override

A single disqualifying fact, an undisclosed breach, contested training data, uncapped indemnities, forces the tier down regardless of average maturity.

Step 4

Closing judgement

The questions no scanner asks: how easy would it be to breach this company, from the people who know, and what would the adversary do?

Transparent by design. Every number the Index produces can be reproduced by hand from the documented methodology. Value-at-risk bands are calibrated against published evidence including IBM's Cost of a Data Breach series, GDPR and EU AI Act penalty ceilings, and documented transaction repricings. Anonymised results build the Loginov Index benchmark across engagements.
What the committee receives

A report an IC can price, not just read.

Risk tier & investment stance Domain maturity profile Red flag register SWOT, investment lens Estimated remediation cost Value at risk to enterprise value 100 day remediation plan Deal mechanics: indemnities, escrow, conditions
Provenance

Built from the operator's side of the table.

The Loginov Index was developed by Michael J. Loginov from more than thirty years of executive security leadership: sixteen security leadership mandates at CISO level and above, over one hundred board and audit committee briefings, and cyber due diligence practice across private equity transactions. The methodology, training programme and consultant certification are delivered through MichaelLoginov.com.

UK CISO of the Year 2020 UK Cyber Security Hall of Fame Author, CISO: Defenders of the Cyber Realm EU AI Act · NIST · ISO/IEC 42001 · IEC 62443 aligned
Access

Available to selected PE firms and transaction advisers.

Delivery is by trained, named consultants under written terms; access is individual, revocable, and tied to completion of the consultant training programme. A five day assignment, subject to client-side interviewee availability.