CLARITY by Pinnacle – Seeing through the complexity of fund investments

https://pinnaclefundservices.com/wp-content/uploads/2026/08/2.png

Your Security Ends at Send

All posts Next Post
Operations

In Part 1 of this series, Why Are We Still Sending Capital Calls by Email?, we challenged a long-standing industry practice. Banks, brokerage firms, payroll providers and tax authorities have largely moved sensitive financial information behind authenticated systems. So why does the private investment fund industry continue to rely on email for capital calls?  The security of these emails ends at send.

The discussion focused on whether investor convenience justifies the additional risk of delivering capital calls by email. Part 2 examines a different question: What happens to the security of a capital call once it leaves your organization? The answer has less to do with email itself and more to do with control.

Your Security Doesn’t End With Your Organization

Investment fund managers and administrators invest heavily in protecting their environments. They use multi-factor authentication, penetration testing, endpoint protection, employee awareness training and access controls. These measures reduce the risk of unauthorized access and help protect sensitive investor information.

However, the security model changes the moment a fund sends a capital call by email. Until that point, the fund controls where it stores the document, who can access it and how it protects it. Once the email reaches the investor, much of that control disappears. The security of the communication now depends on both the fund’s controls and the security of every investor who receives it.

Cybersecurity should protect the entire process, not simply the fund’s infrastructure.

 

Every Investor Becomes Part of Your Security Model

Every investor operates in a different technology environment. Some use highly secure corporate email systems, while others rely on personal email accounts and devices. Password practices and security settings vary. Some investors use multi-factor authentication, while others do not.

These differences do not mean investors are careless. They simply reflect the reality of communicating with a diverse investor base. Once the fund sends a capital call by email, it has little visibility into the environment where that information now resides.

Cybercriminals understand this vulnerability. They do not necessarily need to attack the fund or its administrator. Instead, they can target a single investor with a compromised email account. They can monitor communications, learn how the fund communicates and wait for an opportunity to redirect funds.

In that scenario, both the fund’s and administrator’s cybersecurity may work exactly as intended. A fraudulent transaction can still occur because the weakest point exists somewhere else in the process.

 

Authentication Improves More Than Security

Discussions about authenticated investor portals often focus on cybersecurity. However, authenticated delivery also provides a significant governance advantage.

When investors log into a secure portal, the fund gains visibility that email cannot provide. The system can record who authenticated, when they logged in and the IP address used. It can also record which capital call they accessed and when they downloaded it. If the fund updates a document, investors can access the current version rather than rely on an attachment saved days or weeks earlier.

Email offers little of this assurance. A fund knows that it sent the email and may know that the recipient received it. After that, visibility largely ends. The fund cannot confidently determine who viewed the attachment, whether someone forwarded it or where additional copies now exist. It also cannot ensure that the investor is using the latest version.

Authenticated delivery therefore provides more than additional security. It creates accountability, strengthens the audit trail and gives the fund better evidence of investor activity. It also allows the fund to maintain greater control over sensitive information after notifying the investor.

 

Delivery Is Part of the Control Environment

Investment funds devote significant attention to controls surrounding the movement of capital. They review transactions, document approvals, segregate duties and maintain audit trails. These controls exist because moving investor capital represents one of the highest-risk activities within a fund.

The method used to deliver a capital call deserves the same level of consideration. A capital call is not simply another investor communication. It instructs an investor to move capital and often includes sensitive banking information. If the fund sends that information outside its control environment, it also gives up important elements of oversight and accountability.

An authenticated environment allows the fund to maintain control over identity verification, document versions, access history and audit records. Email can still serve an important purpose by notifying investors that a new capital call is available. However, the fund can keep the capital call and funding instructions within the secure environment.

The objective is not to make investing more complicated. The objective is to apply appropriate controls to one of the most sensitive interactions between a fund and its investors.

 

In Summary

In Part 1, we asked whether private investment funds should continue distributing capital calls by email. Part 2 raises a related question: Should a fund’s control environment end when a capital call leaves its systems?

Protecting investor capital requires more than securing the fund’s infrastructure. Funds should also consider how investors access sensitive information and how the fund can verify that access. Authenticated delivery provides identity verification, access records, document control and a stronger audit trail.

Ultimately, this is not simply a cybersecurity issue. It is a governance issue. As cyber threats evolve, investment funds should treat capital call delivery as a critical part of their operational control framework—not simply an administrative task.

Contact David Smith at dsmith@pinnaclefundservices.com to see if how Pinnacle Fund Services can help secure your capital calls.

Related News

https://pinnaclefundservices.com/wp-content/uploads/2026/08/5-1.png
Operations

Liquidity Has to Come From Somewhere

Private market fund structures continue to evolve.
https://pinnaclefundservices.com/wp-content/uploads/2026/08/5.png
Operations

Why Are We Still Sending Capital Calls by Email?

For decades, email has been the standard method for distributing capital call
https://pinnaclefundservices.com/wp-content/uploads/2026/08/Web-Version-images-1.png
Operations

Accuracy and Financial Controls in 2026

As private investment funds continue to grow in complexity, maintaining accur