How PE firms should pick a portfolio MSP without forcing every holdco into the same box
Five portfolio companies. Four MSPs. Three security stacks. Two identity models. The operating partner already knows each PortCo bought IT on its own: separate tickets, separate SLAs, separate renewals, and almost no shared leverage. What's missing is an MSP selection process that puts shared services (help desk, endpoint, identity baseline, backup, security management) under one portfolio catalog and rate card, while unique services still accommodate plant floors, clinical systems, and carve-out TSAs.
Deal teams rarely force a single MSP at close, so each portfolio company keeps its incumbent provider. Over a few add-ons you end up with multiple help desks, multiple SLAs, and multiple renewal calendars. It's expensive: the same baseline services get contracted five times at the small-customer rate. Unique needs still get forced into a generic package, or left as a permanent exception with no owner and no rate card.
The selection job for a PE firm isn't "find one MSP that can do everything." It's pick a portfolio MSP model that keeps common services common and treats unique needs as named, priced exceptions.
Why portfolio IT is on the value-creation agenda
Technology isn't a back-office footnote in the hold period anymore. Secondary PE technology write-ups cite a 2024 Deloitte Private Equity Technology framing that 72% of PE operating partners now rank IT modernization among their top three value levers (up from 49% three years earlier), while only 37% report consistent IT governance across portfolio companies.
Primary-market surveys point the same way with different numbers. BCG's digital value-creation work with senior PE investors found only about 15% of portfolio companies claim "very mature" IT capabilities, while roughly three-quarters sit at moderate maturity. When digital maturity lags or is underinvested, about 40% of investors report a valuation haircut of 5% or more. Digital levers are now common in diligence and value-creation plans, not a side workstream.
Cyber makes fragmentation harder to ignore. EY-sourced PE pulse material used in industry MSP briefs puts cybersecurity in the top three risk priorities for a large majority of PE firms, while ongoing IT audits across every holding remain far less common. One weak PortCo still sets the story buyers and insurers hear about the whole book.
What fragmented MSP spend actually costs
Fragmentation shows up as duplicate licensing, duplicate tooling, and duplicate "relationship managers" who never see the HoldCo or PE firm as one account. A PE-focused standardization playbook describes a familiar footprint after several add-ons: multiple Microsoft tenants, mixed Workspace and M365 estates, separate security stacks, and several MSPs that don't share runbooks. Cyber insurance premiums in that case rose about 60% over two years because every renewal questionnaire told the same story: inconsistent controls and no standard incident response.
The same playbook puts pure waste on a five-company portfolio with roughly 1,500 employees in a directional band of $1.5 million to $3 million a year, before slower bolt-on integration and messier exit diligence. That's the tax of treating each PortCo as a standalone SMB IT buyer.
Shared-services economics cut the other way when the model is right. Industry materials commonly cite 20-30% IT overhead reduction per company from scale, and material downtime cuts from centralized monitoring. Digital-enablement work is also where mid-market PE reports still hang large EBITDA claims.
Common services stay common
Start with a portfolio service catalog, not a vendor logo. The catalog should name what every PortCo gets the same way:
- Endpoint build, patch policy, and EDR baseline
- Identity baseline (MFA, privileged access rules, joiner-mover-leaver)
- Backup and recovery class tiers with tested restore evidence
- Ticket taxonomy, priority definitions, and after-hours coverage meaning the same thing at every company
- Security management baseline and a shared incident severity model
- A monthly IT performance report using the same metrics for every PortCo, so the PE operating team can compare companies side by side
- An add-on onboarding runbook with stage gates sized to the deal, not a generic "we'll be done in 90 days" claim with no entry or exit criteria
Common doesn't mean identical hardware everywhere. It means identical definitions, identical proof requirements, and identical commercial leverage. One portfolio commercial construct beats five small-customer MSAs. One metrics set beats five dashboards that change format when a number looks bad.
If a provider can't show multi-entity reporting from a single service delivery platform, they're selling five accounts with a shared brand, not a portfolio model.
Unique needs stay unique on purpose
Forcing a manufacturing plant, a clinic, and a multi-country distributor into one rigid package creates shadow IT and quiet failure. Unique needs belong in the model as exception SKUs with owners, SLAs, and exit criteria.
Typical exceptions worth writing into the RFP:
- OT and plant-floor networks that can't follow the office endpoint standard
- Regulated stacks (HIPAA, PCI, CMMC depth) that need control evidence beyond the SMB baseline
- ERP-adjacent operations or industry applications the generalist desk shouldn't "touch and pray"
- Carve-out TSA clocks and transition constraints the incumbent still owns
- Sites or countries with data residency or local support rules
- PortCos near exit that shouldn't absorb a disruptive stack swap mid-process
The selection test is operational, not philosophical. Can the bidder price the standard catalog, price each exception, and show how tickets route between the common desk and the specialist path without blame ping-pong? If unique work only lives in a sales appendix as "we partner with specialists," you'll rediscover that sentence during the first P1.
Default book versus designed model
Default: each PortCo renews its own MSP, the PE firm sees five invoices and five stories, insurance and exit diligence find the weakest controls, bolt-ons take months before their IT looks anything like the rest of the portfolio.
Designed model: common services run under one catalog with the same proof requirements for restores, controls, and ticket SLAs. Unique needs are listed, priced, and staffed. The PE operating team gets one monthly IT performance report it can act on. New acquisitions inherit a known onboarding path. PortCos with real vertical constraints keep what must stay unique without abandoning the portfolio baseline.
That's how you pick a portfolio MSP without forcing every PortCo into the same box. You standardize the work that should be boring and identical. You design the exceptions on purpose.
If you want a third-party score sheet for a PE portfolio MSP shortlist, including the common catalog and exception SKUs, book a free advisory session with IT Blu Print. Selection and vendor evaluation only. Not legal advice.
