TrueValue M&A Network

Cybersecurity due diligence

A buyer inherits the target’s security posture on the day of completion — its unpatched systems, its unreported incidents and its data-protection liabilities. Cybersecurity due diligence finds out what those are before the price is agreed.

Cybersecurity due diligence

Verified and featured professionals are listed first. Refine by location, sector or deal size.

Searching…

What cybersecurity due diligence do

A cybersecurity due diligence provider assesses the target’s controls against a recognised framework, looks for evidence of past or current compromise, reviews incident history and data-protection compliance, tests the external attack surface and evaluates the security of key suppliers. The findings inform the price, the warranties and indemnities, the insurance and the first-hundred-days plan.

When to engage them

In exclusivity, in parallel with the other diligence workstreams, on any business that holds personal data at scale, processes payments, runs critical operations on connected systems, or sells software. A finding of an undisclosed breach is one of the few things that stops a deal outright.

Usually active at

  • In due diligence
  • Completed

What they typically help with

  • Security posture assessment against a framework
  • Compromise assessment and incident history
  • Data protection and regulatory exposure
  • External attack surface and supplier risk
  • Inputs to warranties, insurance and the integration plan

Questions to ask before you engage

  1. 1. Which framework do you assess against, and what does the output look like?
  2. 2. Can you look for evidence of an existing compromise, not only weaknesses?
  3. 3. How do you assess data-protection exposure and the likely regulatory position?
  4. 4. What can be done in the timetable without access to internal systems, and what needs access?
  5. 5. Do you also advise on the remediation plan after completion?

How cybersecurity due diligence are paid

Scoped fixed fees are usual, with the price driven by the size of the estate, whether internal access is available, and whether a compromise assessment is included. A remediation engagement after completion is a separate scope.

How TrueValue fits alongside

TrueValue’s due diligence software keeps the security request list and the evidence with the rest of the diligence, and its own security posture is set out on the security page, including what is held and what is being pursued.

Frequently asked

Is cybersecurity due diligence the same as a penetration test?

A penetration test is one technique that may be used within it. Due diligence is broader: governance, controls, incident history, regulatory exposure and supplier risk, as well as technical testing.

What happens if the target has had a breach?

It depends on what was compromised, whether it was reported as required, and what the ongoing exposure is. The findings should reach the lawyers for the warranties and indemnities and the insurer for cover, and may change the price or the structure.

Does a small business need this?

Scaled appropriately, yes, if it holds personal data or depends on connected systems. The regulatory exposure does not scale down with company size.

Listings in the TrueValue M&A Network are provided for information. A listing is not an endorsement or a recommendation, and TrueValue does not guarantee any professional’s performance. You must carry out your own due diligence before engaging anyone, verify regulated status independently with the relevant regulator, and seek qualified legal, financial and tax advice where appropriate.