Services  /  Lead and decide  /  Cyber due diligence

08 · Cyber due diligence

Know the cyber risk you are buying.

Focused, independent cyber due diligence for acquisitions and investments, written for deal teams and delivered to the deal timetable.

Deal readiness

Pre-deal · Post-deal · Vendor-side

  • ✓  Target security maturity assessed
  • ✓  Incident and data protection history reviewed
  • ✓  Key technology and supplier risks found
  • ✓  Red flags reported to the deal team
  • ✓  Remediation costs estimated

Know what you are inheriting →

Why it matters

Acquisitions transfer cyber risk along with value. Problems found after completion are paid for by the buyer.

A short, time-boxed review before the deal closes shows buyers and investors what they are inheriting, what it will cost to fix and what to negotiate.

Sound familiar?

01   You are acquiring or investing in a business that holds sensitive data.

02   The target’s security has been described, but never tested.

03   You need a clear security plan for the first 100 days.

How we help

From first look to day one.

01

Before the deal

  • Pre-deal cyber due diligence
    An independent view of the target’s security, scoped to the deal.
  • Target security maturity assessment
    How mature the target’s controls really are, against a recognised framework.
  • Data protection and incident history review
    Past breaches, regulatory issues and how they were handled.
  • Key technology and supplier risks
    Critical systems, legacy technology and supplier dependencies.

02

At the table

  • Red-flag reports for deal teams
    Clear, prioritised findings written for investors, not engineers.
  • Remediation effort estimates
    What it will take, and roughly what it will cost, to fix what we find.

03

After completion

  • Integration and separation planning
    Secure plans for joining or carving out systems.
  • 100-day post-deal security plans
    A practical security plan for day one and beyond.
  • Vendor due diligence for sellers
    Find and fix issues before buyers do.
  • Investor-ready security reporting
    Clear security reporting for portfolio companies and boards.

Assessed against

NIST CSF 2.0  ·  ISO/IEC 27001  ·  Cyber Essentials

A typical engagement

Five steps. Built around your deal timetable.

01

Scoping call

Free and confidential. Timeline, target and what matters most.

02

Document review

Policies, evidence and history requested from the target.

03

Interviews and checks

Structured interviews and, where agreed, technical checks.

04

Red-flag report

Prioritised findings and remediation estimates for the deal team.

05

Day-one plan

A 100-day security plan once the deal completes.

What you walk away with

■  A clear view of inherited risk

■  Findings deal teams can act on

■  A security plan for day one

Who you work with

Findings written for deal teams.

Time-boxed

Delivered to the deal timetable.

Discreet

Security-cleared consultants, handled confidentially.

Plain English

Findings written for investors, not engineers.

Related services

02

Cyber risk management

Exposure made clear, owned and reduced.

05

Third-party and supply chain risk

The suppliers that could hurt you most.

01

Cyber strategy and leadership

Direction, ownership and board reporting.

Is a deal on the table?

Book a free, confidential 30-minute call to scope a review around your timetable.