Who I Help · Private Equity and Corporate M&A

Strategic cyber due diligence and vCISO advisory for PE and M&A

Clear line of sight into digital exposure before you buy, while you hold, and when you exit.

Most cyber diligence is priced for deals ten times the size of the ones you are actually doing. Below $100 million enterprise value the workstream gets compressed, delegated to the target's own IT provider, or skipped. I do it at a size that fits the deal, and I have no contract with the target's provider to protect.

$25,630
Average cyber due diligence spend per deal, across 100 private equity professionals in the US and EMEA.
S-RM, reported 10 July 2025
Deal lifecycle advisory flow

Three points where a CISO changes the outcome

The same exposure looks different depending on when you look at it. These are the three moments where an outside read is worth paying for, and what you get out of each.

Stage 01
Stage 02
Stage 03

Pre-close diligence

Before the LOI expires
  • Outside-in exposure read on the target
  • Governance and control interviews
  • Incident and breach history
  • Remediation cost estimate for the model

Post-close integration

Day one through the hold
  • First hundred days, sequenced by risk
  • Standing oversight without taking over IT
  • The IT provider held to a contract
  • Board-level reporting the LPs can read

Exit readiness

12 to 18 months before you go to market
  • Run the buy-side diligence on yourself
  • Close the findings before they are findings
  • Evidence pack for the data room
  • Answers ready for the buyer's questions

The 12 to 18 month exit lead time follows the only published vendor figure I could find for it. The rest is my own engagement structure.

Understanding the risk landscape

Private equity and corporate M&A are not exposed the same way

A sponsor holds a set of unrelated companies for a defined period and sells them. A corporate buyer absorbs one company into its own network permanently. Those are different risks and they call for different work.

Private equity

Risk sits across the portfolio, not inside one company

You are not integrating. You are governing a set of companies you do not operate, on a clock.

Corporate M&A

Risk sits at the seam where two networks join

You are integrating. Whatever the target was carrying becomes yours the day the networks touch.

PE / 01

Concentrated third-party exposure

Sponsors often push portfolio companies onto a shared IT provider or a shared stack for cost reasons. That is a real efficiency, and it is also a single point of failure that nobody at the fund is measuring.

M&A / 01

Inheriting a toxic network

An attacker already resident in the target's environment becomes an attacker in yours the moment the two networks are joined. Integration timelines are set by the deal, not by whether the target has been cleared.

PE / 02

Valuation bleed during the hold

Cyber losses do not show up as a single event on the P and L. They show up as remediation, downtime, insurance renewals and a discount at exit. Kroll puts the average impact at $2.1 million per incident, and 94 percent of the firms it surveyed had absorbed cyber-related losses.

M&A / 02

The deal announcement spike

Announcing an acquisition tells attackers exactly when finance teams are distracted, approval chains are in flux and unfamiliar counterparties are normal. Wire fraud and impersonation attempts cluster around the announcement.

PE / 03

Inherited dormant liabilities

A breach that happened before you owned the company is still your regulatory problem after you do. Notification obligations, class actions and contract breaches do not reset at close, and they are rarely disclosed voluntarily.

M&A / 03

Intellectual property theft

In a strategic acquisition the IP is usually the thesis. If it has already been taken, you are paying for an asset a competitor also has, and nothing in a standard financial diligence will tell you.

PE / 04

Ransomware target profile

Lower-middle-market companies are attractive precisely because they have real revenue and thin security. Operators know a sponsor-backed company has a backer with capital and a timeline.

M&A / 04

Regulatory whiplash

The target may sit under obligations the acquirer has never had to meet, or the combined entity may cross a threshold neither one crossed alone. That gets discovered at the first audit if nobody looks first.

Kroll, State of Portfolio Cybersecurity in Private Equity, 11 February 2026, 300 plus PE executives.

Strategic comparison

Side by side

If you only read one thing on this page, read this.

Dimension
Private equity
Corporate M&A
Primary danger
Exposure concentrated across companies you govern but do not operate, with no single owner accountable for it at the fund.
A compromised target joined to a clean network on the integration timeline.
Attacker goal
Extortion and disruption. Revenue with a sponsor behind it and a deadline attached.
Persistent access and intellectual property. Espionage value, not ransom value.
Duration of risk
The full hold period, three to seven years, then again at exit.
Concentrated at announcement and integration, then permanent once absorbed.
Key strategic action
Independent oversight and a consistent standard across the portfolio, set without taking over anyone's IT.
Clear the target before the networks touch, and hold the integration date to that finding.
What I do

Three engagements, one relationship

Take them one at a time, or as a single relationship across the hold.

01

Pre-close cyber due diligence

  • External exposure assessment of the target, run without touching their production environment
  • Governance and control interviews with whoever actually runs their IT, including the outside provider
  • Incident, breach and notification history, including what was never disclosed
  • Regulatory posture against whatever regime the target actually falls under
  • A remediation cost estimate you can put in the model, not a risk rating

You get: a written findings memo with a go, go-with-conditions or stop recommendation, the specific conditions if any, and a costed remediation plan. Delivered in time to matter to the negotiation.

02

Post-close integration and portfolio oversight

  • A first hundred days plan sequenced by risk and by what the business can absorb
  • A single security standard applied across the portfolio, sized to each company
  • Provider governance: the incumbent keeps the contract and starts getting measured
  • Standing reporting at a level a board and an LP can both read
  • Incident response readiness at each portfolio company, which only 54 percent of sponsors in the S-RM survey said they ensure

You get: retained fractional CISO time across the portfolio. Governance without operational control, which is the arrangement that keeps the fund advising rather than operating.

03

Exit readiness

  • Buy-side diligence run against your own asset, 12 to 18 months out
  • Findings closed while there is still time to close them
  • Documentation and evidence assembled for the data room
  • Prepared answers for the questions a buyer's diligence team will ask

You get: the buyer's report before the buyer writes it, and the chance to fix what is in it.

S-RM survey of 100 private equity professionals, reported 10 July 2025: 54 percent ensure portfolio companies have defined incident response plans.

Questions

Common questions

How is this different from the technical diligence my IT consultant already does?

Technical diligence asks whether the systems work. Cyber diligence asks what happens when someone attacks them, what has already happened, and what it will cost you to fix. They overlap by maybe a third. The bigger difference is independence: if the assessment is done by the firm that will win the managed services contract afterwards, or by the target's own provider, the incentives are wrong.

Our deals are too small to justify a six-figure diligence line item.

Agreed, and that is the actual problem. At $10 to $25 million enterprise value a $100,000 technology diligence is three to five percent of annual EBITDA, so the workstream gets compressed or dropped. A scoped cyber read is a fraction of that and answers the questions that change price.

We already have an IT provider across the portfolio. Is this duplicative?

No, it is the opposite. A provider delivers services. Someone still has to decide what good looks like, verify the provider is delivering it, and report that to the fund. Today that is usually the provider grading its own work.

Does taking security oversight make the fund an operator?

Worth asking your counsel, and it is a live question in the market right now. The structure I work in is governance without operational control: I set the standard and report on it, the portfolio company's own provider executes, and the fund receives reporting rather than issuing instructions.

Let's connect

Book a security clarity session

Twenty five minutes. Bring a live deal or a portfolio company that worries you.

No slides and no assessment. We talk through what you are looking at, I tell you what I would want to know before I signed, and you leave with that whether or not you hire me.