Most portfolio company IT reports are useless to a PE operating partner. Not because they lack data — usually they have too much of it — but because they were written for the wrong reader. The typical monthly IT report was designed for a full-time board reading only one company’s numbers. It runs eight to twelve pages, mixes vanity metrics with real ones, and buries the two or three things that would justify a phone call.
An operating partner reviewing five to twenty portfolio companies each month cannot use that report. Either it gets skimmed and problems are missed, or it gets read fully and consumes hours that should have gone to intervention on the companies that need attention.
What the operating partner needs is a one-page monthly technology report with a fixed twelve KPIs, delivered on a strict cadence, with escalation rules that produce a call before a KPI stays red for a third month. This piece is that report — what to include, what to cut, how to structure it, and how to roll it up to the fund level.
Why the Standard IT Report Doesn’t Work for PE
Portfolio company IT reports fail the operating partner in three predictable ways.
Too much noise, too little signal. Ticket counts, uptime aggregated across every system in the environment, storage utilization, and employee training completion percentages fill pages without predicting a single future problem. They’re easy to produce because they come out of the RMM or ticketing tool. That’s exactly why they crowd out the metrics that require judgment.
Inconsistent definitions across the portfolio. When each portfolio company defines uptime differently, defines “critical system” differently, and reports IT spend at different points in the general ledger, fund-level roll-up becomes impossible. The operating partner can’t compare portfolio company A to portfolio company B even at the metric level.
Written by the CIO for the CIO. Standard IT reports assume the reader knows the environment, the vendors, and the technical vocabulary. The operating partner does not. A metric that’s meaningful in context is meaningless without it. If the report requires the reader to reconstruct context, it fails.
The fix isn’t a longer report or a better-designed dashboard. It’s a shorter report with a fixed set of metrics, a fixed page format, and standardized definitions across every portfolio company in the fund. One page. Twelve KPIs. Same format everywhere. That’s the design constraint.
The 12 KPIs That Actually Predict Technology Health
Five categories, twelve metrics. Each metric predicts either a future problem or a change in value creation velocity. Each is measurable with data the portfolio company already has. Each has a defensible definition that can be applied consistently across the portfolio.
Reliability (2 metrics)
1. Uptime on critical systems (%). Not aggregate uptime across every server and SaaS integration. Uptime on the named list of systems that the business cannot operate without — typically five to ten systems including the ERP, the primary financial system, the identity provider, the customer-facing web platform if applicable, and the phone or communications system. Critical system list is defined once and reviewed annually. Uptime is measured against a defined SLA, not against an aspirational goal.
2. Mean time to restore (MTTR) on P1 incidents. Time from incident declaration to service restoration for priority-one incidents in the reporting period. MTTR is the operational answer to the question “when things break, how fast do we recover?” It matters more than incident count because count reflects environment complexity and monitoring sensitivity, not operational discipline.
Cost Trajectory (3 metrics)
3. IT run-rate as percent of revenue (trailing 3-month). Fully-loaded IT operating cost divided by revenue. Trailing three-month rather than point-in-time because monthly IT spend is spiky. The trend line matters more than the absolute number; a portfolio company at 3.5% moving to 4.2% over four months is a different signal than one at 4.5% moving to 4.3%.
4. Fully-loaded technology cost per employee. Total IT operating cost divided by full-time equivalent employee count. This normalizes for growth. A portfolio company that grows headcount 20% while IT spend grows 30% is not scaling efficiently.
5. Vendor concentration (% of IT spend in top three vendors). Concentration risk on the vendor stack. A portfolio company with 65% of IT spend concentrated in three vendors has both leverage risk (renewal negotiations dominated by those vendors) and continuity risk (any vendor issue is a material issue). Concentration alone isn’t bad, but it should be visible.
Risk Posture (3 metrics)
6. Critical CVE patch compliance (%). Percentage of systems patched to CVSS-critical vulnerabilities within the defined SLA (typically 14 or 30 days). Not aggregate patching. Not average time. The specific number of systems that are inside the SLA window on critical severity.
7. MFA coverage on privileged accounts (%). Percentage of privileged accounts (administrators, service accounts with elevated permissions, remote access) with MFA active. Any gap here is a red flag independent of other controls. Cyber insurance renewal, incident response, and post-close diligence all hinge on this metric.
8. Days since last validated backup restore. Not days since last backup ran. Days since the last time a backup was actually restored end-to-end and validated as usable. Most portfolio companies have backups running. Fewer have proof that the backups work. This one metric surfaces the difference.
Value Creation Velocity (2 metrics)
9. Roadmap milestone status (RAG). Green, yellow, red status against the named technology initiatives on the value creation plan. Not a list of all technology projects. The three to seven initiatives that were committed at close or at the last operating plan review. Each milestone dated. Each with a named owner.
10. Change failure rate (%). Percentage of changes deployed during the period that caused an incident or required rollback. High change failure rate is a leading indicator of technical debt, poor change management discipline, or an environment operating without adequate testing. Change failure rate correlates with future outages more reliably than most security metrics correlate with future breaches.
People and Capability (2 metrics)
11. Key-person concentration on critical systems. Number of critical systems where knowledge is held by a single individual. This is a bus-factor metric. A portfolio company with five critical systems, three of which have a single named owner with no documented backup, is one resignation away from an operational crisis. Key-person concentration is invisible in most reports because it isn’t a system metric — it’s an organizational one.
12. Open technology hires + days-to-fill for the CIO, CTO, or CISO seat. If the executive technology seat is vacant, that’s a material operational risk that deserves visibility every month it stays open. Open non-executive technology roles matter less, but the fully-loaded number for open technology hires plus days-open is a strong signal about hiring pipeline health.
Twelve metrics. Five categories. All measurable. All predictive. All actionable.
Vanity Metrics to Cut
Every metric that made it onto the list above displaced a common metric that didn’t. The ones that should not be on the report:
- Tickets opened, tickets closed, average time to close. These metrics measure ticketing tool activity, not business health. High ticket volume can mean many small issues (bad) or an unusually vigilant user base (good). Average time to close depends more on classification hygiene than on operational quality.
- Aggregate uptime across all systems. A number so diluted by non-critical systems that it stays at 99.9% while a critical system is down half the month.
- Number of security tools deployed. Tool count doesn’t measure security posture. Two tools with staffed monitoring beats seven tools with none.
- Employee training completion percentage. Training completed with no measured behavior change is compliance theater.
- Total storage utilization or bandwidth utilization. Capacity metrics belong in a capacity plan, not in a business report.
- Number of MSP escalations. This measures the MSP’s escalation policy, not the environment.
- Percentage of MSP SLAs met. A vendor performance metric, not a business metric. Belongs in the MSP QBR, not in the portfolio company report.
Cutting these metrics is unpopular with the people who produce them, because they’re easy to produce and they typically look good. The signal-to-noise trade is the point of the report.
The One-Page Format
The physical layout of the report matters as much as the metric selection. A report that requires the operating partner to scan across pages to piece together a picture fails the design constraint.
Header row. Portfolio company name, reporting month, overall RAG summary chip (green, yellow, or red), name of the report owner, and date delivered.
Body grid. Twelve KPIs in a 3-by-4 or 4-by-3 grid. Each cell contains: metric name, current value, prior-period value, RAG status, one-line commentary. The commentary is where judgment lives; it’s the difference between a report that gets read and a spreadsheet.
Footer row. Three items only: (1) any KPI that turned red this month, with a named owner and target date; (2) the top ask of the operating partner for the coming month (or explicit “none”); (3) confirmation of the next report delivery date.
No appendix. No supporting tables. No embedded links to dashboards. If a KPI needs supporting detail, that detail lives in the underlying system and is available on request. The report itself is the report.
Formatting details that matter: consistent metric definitions between months (so trend is real), prior-period value shown next to current-period value (so change is visible without arithmetic), RAG defined against pre-set thresholds (not against the report owner’s judgment each month), and one-line commentary that explains change, not that restates the metric.
Cadence and Escalation Rules
Monthly, delivered within three business days of month-end. That’s the cadence.
Weekly is too frequent for operating-partner-level review and produces reporting fatigue. Quarterly is too slow to catch problems before they become material. Monthly, tied to a defined period-end, keeps the discipline of a closed reporting period.
The three-business-day delivery deadline matters. Reports that arrive on the tenth of the month lose their tie to the period they cover and become rolling updates that no one anchors to. A late report is worse than a slightly less polished report.
Two escalation rules:
New red status triggers a call within one week. Not the next monthly review. When a KPI moves from green or yellow to red, the report owner initiates a call with the operating partner and the portfolio company technology owner. Fifteen minutes. Objective: agree on whether the change is signal or noise, and if signal, agree on the fix and the owner.
Two consecutive months of red triggers a working session. If the same KPI is red in the current report and was red in the prior report, that triggers a working session with the portfolio company CEO, CFO, technology owner, and operating partner. Written remediation plan out of the session, with dates and named owners. Third month of red without remediation progress means the reporting isn’t producing action and either the report or the ownership needs to change.
Silent reds that persist across three or four monthly reports are the sign that the report has stopped functioning. The escalation rules exist to prevent that.
Portfolio-Wide Roll-Up
The value of standardized reports across a portfolio isn’t just at the portfolio company level. It’s at the fund level, where trends visible across five or twenty companies are often stronger signals than any single company’s report.
A useful fund-level roll-up shows:
- KPI heat map. Portfolio companies as rows, twelve KPIs as columns, RAG status in each cell. One page. The operating partner can scan for patterns — is one KPI going red across the fund? Is one portfolio company red across many KPIs? Both signals matter and are invisible in per-company reports.
- Trend view on portfolio-level metrics. Weighted-average IT spend as percent of revenue across the portfolio. Weighted-average MFA coverage. Change in the number of open technology executive seats. Fund-level trends often precede portfolio company alarms.
- New red status this month, across all portcos. The list of KPIs that turned red this month, with the portfolio company and the target-fix date. This is the operating partner’s intervention agenda for the month.
- KPIs red for two or more consecutive months, across all portcos. The escalation list. Any portfolio company on this list has committed remediation, and the fund tracks progress.
The fund-level roll-up doesn’t replace the per-portfolio-company report. It reads it faster. And it lets the operating partner spend intervention time on the companies where intervention will change outcomes.
Calibrating Thresholds Across Different Portfolio Companies
Standardize the metrics. Calibrate the thresholds.
A software company and a distribution business will have different acceptable IT-spend-to-revenue ratios. A retailer and a manufacturer will have different critical system lists. A newly-acquired portfolio company still integrating IT will have different acceptable change failure rates than a stabilized portfolio company in year three of the hold.
The twelve KPIs and their definitions stay identical across the portfolio. What varies is the green / yellow / red threshold for each KPI at each portfolio company. Thresholds are set at the operating plan review, documented, and reviewed annually. That way the RAG has meaning at each portfolio company and is comparable across the portfolio in structure, even where absolute levels differ.
What This Means for the Operating Partner
The one-page monthly report changes what the operating partner does with monthly IT information.
With eight-page reports written for the CIO, the operating partner either reads them and loses hours of higher-value work, or skims them and misses signals. The one-page report with fixed KPIs and RAG-based escalation lets the operating partner run monthly technology governance across a portfolio in the same amount of time it currently takes to review one portfolio company’s report.
Three changes result:
Consistent visibility across the portfolio. The operating partner knows the health of every portfolio company at the same twelve dimensions each month. Comparison across companies is possible. Trend across companies is visible. The blind spots collapse.
Earlier intervention. New reds trigger calls, not reports. Two-month reds trigger working sessions, not another cycle of watching. The lag between problem emergence and problem intervention drops.
A common vocabulary at portfolio company reviews. When every portfolio company’s CEO sees the same twelve KPIs each month, the operating plan review starts with a shared understanding of what is measured, what green means, what red means, and what is escalated. That’s the goal.
Vertex CIO Advisory produces this report as part of the fund-level technology operating partner engagement, calibrated to each portfolio company at onboarding and reviewed with the fund monthly. The report is one deliverable in a broader engagement that also covers post-close integration, cybersecurity oversight, and pre-close diligence.
Learn how Vertex CIO acts as the technology operating partner for PE funds →