What the Bain/PowerSchool ruling means for private equity firms.
A PE firm closes on a platform acquisition. The 100-day plan executes on schedule. Domestic IT functions are offshored to reduce run rate. A few cybersecurity and engineering roles are eliminated to hit synergy targets. The board is replaced. Standard playbook.
Twelve months later, a breach surfaces at the portfolio company. The litigation that follows names the firm, not just the company. And the court allows the case to proceed.
That outcome is no longer hypothetical.
On March 18, 2026, the U.S. District Court for the Southern District of California allowed claims against Bain Capital to move forward in connection with a data breach at PowerSchool, the K-12 education software company Bain acquired in October 2024 for $5.6 billion. The court permitted claims of negligence, negligence per se, aiding and abetting, unjust enrichment, and violations of the California Unfair Competition Law to proceed against Bain directly, under both agency and direct liability theories. The breach exposed the personal data of more than 50 million students, teachers, and parents. It is the first ruling of its kind to hold a private equity firm potentially answerable for a portfolio company’s cybersecurity failures.
Corporate separation was supposed to insulate the PE owner from the portfolio company’s operational liabilities. That assumption just narrowed.
It Is Not Unusual PE Behavior. It Is Standard PE Behavior.
Bain did nothing unusual. That is what should worry every firm reading this ruling. Everything the court singled out is standard mid-market PE governance.
The court relied on a specific set of allegations to establish that Bain’s involvement “went beyond what an ordinary investor would do.” Pre-close, Bain held contractual veto rights over capital expenditures above $5 million, material vendor contracts, and major workforce decisions. Pre-close, Bain conditioned its offer on cost reduction measures that included laying off domestic cybersecurity staff. Post-close, Bain replaced the entire board, directed the offshoring of cybersecurity and IT functions, and reduced the workforce by at least 5%, including critical domestic IT personnel.
Read that list again with a PE lens. There is nothing exceptional in it. Veto rights on capex above a threshold are boilerplate. Cost reduction is the value creation lever. Board replacement is the first move post-close. Offshoring of IT and back-office functions is a recurring entry in the 100-day plan.
The novelty is not the behavior. It is the cumulative legal weight the court gave it when cybersecurity outcomes were at stake.
Contractual disclaimers of control did not save Bain either. Boilerplate language that says the fund is not operating the portfolio company does not insulate the firm if the operating actions tell a different story.
A caveat. This was a motion to dismiss, which means the court took the plaintiffs’ allegations as true and found nobody liable. Bain may well win. What it cannot do anymore is avoid discovery, and for most firms that is the part worth registering. Plaintiff attempts to reach sponsors through alter ego and aiding and abetting claims are not new. Courts throwing them out early is what used to be reliable, and that reliability is eroding.
Operating partner influence has always been the value creation lever. Bain turns it into a liability vector when cybersecurity is in scope and nobody governed the influence alongside it
What This Means for the Firm, Specifically
Three things change for deal teams and operating partners.
Pre-close cybersecurity due diligence now has a forward-looking dimension. Historically, cybersecurity due diligence has been a backward-looking exercise. What controls are in place. What incidents have occurred. What gaps require remediation. Now it has to run forward as well. Cost takeouts the firm plans to drive in the first hundred days are part of the cyber risk picture, because those decisions will be discoverable if a breach surfaces. If the post-close plan calls for offshoring IT and cyber functions, that decision needs an independent risk assessment before it executes, not after.
Operational decisions touching cybersecurity are now governance decisions. Cut IT headcount and you have created a document. Plaintiffs’ counsel will read it back to you in a deposition. Operating partners who direct or condition cyber-relevant cost reductions are creating exactly the evidence a court needs to establish agency liability. The firm’s role in those decisions should be governed and documented, not improvised.
Documentation cuts both ways. PE firms have generally treated documented cyber oversight as a portfolio company obligation. After Bain, documentation at the firm level becomes a defensive asset. A firm that can show independent cyber risk review before cost reduction decisions, board-level cyber governance, and a record of risk-informed decision-making is in a meaningfully different legal posture than one that cannot.
Litigation is not the only firm-level exposure that shifted this year. The SEC’s amended Regulation S-P took effect for larger advisers in December 2025 and for smaller advisers on June 3, 2026. It requires a written incident response program, notification to affected individuals within 30 days, oversight of service providers, and recordkeeping. Reg S-P covers investor data at the management company. It has nothing to do with the student records at issue in PowerSchool. Notice where both obligations land, though. On the fund.
The IBM 2025 Cost of a Data Breach Report puts the average U.S. breach cost at a record $10.22 million, up 9% year over year. For healthcare portfolio companies, the average is $7.42 million. You do not need a model to see the problem. A modest increase in liability probability, multiplied across a dozen holdings, becomes a real drag on fund-level returns.
Cybersecurity due diligence outlives the deal now. Bain turned a pre-close gate into a hold-period obligation.
What to Do Now
Three actions belong on the operating partner agenda this quarter.
Extend cybersecurity due diligence scope to include the firm’s intended post-close changes. Any cost reduction or operational change that touches cybersecurity controls, headcount, or vendor relationships should be assessed for risk before it is executed, with independent advisory rather than portfolio company self-attestation. Offshoring follows the same rule. The cost case must be paired with a documented cyber risk assessment.
Install board-level cyber governance with an external advisory voice. Portfolio company management self-reporting does not satisfy the standard the Bain ruling implies. The firm needs a documented record of independent review at the board level, not a quarterly status update from a CIO whose performance review depends on the answer.
Align portfolio-wide cyber oversight to the firm’s actual risk appetite. PE firms hold inconsistent cyber postures across portfolios in part because each company is handled independently. That inconsistency is now expensive. A baseline standard for cyber governance, applied across the portfolio with tiered intensity based on data sensitivity and business model, is now defensive infrastructure.
Independent cyber oversight is what the firm points to when a portfolio company breach reaches the parent. Hygiene was never the only reason to have it.
The Bain ruling does not change what PE firms do. It changes what becomes evidence when something fails. Firms that adjust now will not remember this as a cost. They will remember it as the point where they stopped carrying portfolio company cyber risk on the fund’s balance sheet without knowing it was there.
The distinction between investor and operator has always been operational. The Bain ruling makes it legal.
If your firm is in the middle of a 100-day plan that touches IT or cybersecurity at the portfolio company level, the next 90 days are the right window for a forward-looking cyber risk review. That is a conversation worth having.
About the author
Aaron Higley is Vice President of Technology Advisory at Performance Improvement Partners, a PE-exclusive technology consulting firm. He has personally led 120+ M&A cyber and IT due diligence assessments, and previously served as CIO/CISO at Asset Living, Campus Crest, and Titan.