Live: Tesla PDF 3s (DI-1F0059F32F) - median 15s across 4 real orders - code DI20-WELCOME - $49 to $39.20 - Order now →
Home / Technology DD / Cybersecurity Due Diligence

Cybersecurity Due Diligence: Attack Surface, Controls, and Ransomware Reality for Deal Teams

A practical guide to cybersecurity due diligence — how PE, search funds, and M&A buyers size breach risk, protect purchase price, and plan Day-1 security integration before specialists run deep technical testing.

Technology / cyber workstream
6
Cyber pillars
50
Checklist items
$20K+
Specialist start
$49
First-pass pack

What cybersecurity due diligence means

Cybersecurity due diligence answers an operational and valuation question: can this company protect customer data, keep operations online under attack, and meet the security expectations of regulators, insurers, and enterprise customers after close?

Buyers review security governance, identity controls, cloud and network posture, vulnerability management, detection and response, backup and recovery, third-party risk, incident history, and compliance artifacts (SOC 2, ISO 27001, HIPAA, PCI where relevant). Findings feed price chips, special indemnities, escrow, cyber insurance strategy, and a 100-day security roadmap.

Cyber diligence sits beside technology due diligence, operational due diligence, and legal due diligence. Tech DD tests product and architecture; ops DD tests process resilience; legal DD tests contracts and liability; cyber DD tests whether attackers can break the business model.

Best practice: Separate (1) known incidents and claims, (2) control gaps that are remediable, (3) structural risk (legacy OT/IT, flat networks, shadow SaaS), and (4) customer/regulatory obligations that change Day-1 priorities. Never treat "we will get a pen test later" as a substitute for early breach and ransomware readiness screens.

Cyber DD vs technology DD vs legal privacy

Work productPrimary questionTypical ownerOutput
Technology DDIs the product/architecture investable?Tech diligence / CTO advisorsArchitecture + debt memo
Cybersecurity DDIs the control plane and recovery credible?CISO advisors / cyber firmsRisk register + 100-day plan
Legal / privacy DDWhat contractual and statutory liability?CounselLiability + notice analysis
Ops DDCan operations survive disruption?Ops diligenceBCP / continuity view

Six pillars of cybersecurity due diligence

1. Identity & access

MFA coverage, privileged access management, joiners/movers/leavers, SSO, service accounts, and dormant admin paths. Identity failures remain the fastest path to ransomware.

2. Attack surface & infrastructure

Internet-facing assets, cloud configuration, network segmentation, endpoint coverage, email security, and OT/IT boundary where factories or field devices exist.

3. Data protection

Data inventory, encryption in transit/at rest, key management, DLP where claimed, retention, and handling of regulated data (PII, PHI, cardholder, trade secrets).

4. Detect, respond, recover

Logging coverage, EDR/XDR, SIEM or MDR, IR playbooks, tabletop evidence, backup immutability, restore tests, and ransomware communication plans.

5. Third parties & supply chain

Critical SaaS, MSPs, hosting, software dependencies, vendor access into production, and concentration risk on a single managed-security or cloud provider.

6. Governance & compliance

Security ownership, board reporting, policies, training, insurance history, certifications, customer security questionnaires, and open audit findings.

Where cyber diligence sits in the deal timeline

StageCyber focusDepth
Screening / pre-LOISector threat profile, disclosed breaches, customer concentration on security SLAs, public dark-web or news signalsLight
Post-LOI confirmatoryQuestionnaires, architecture interviews, control evidence, incident log, insurance, vendor listMedium
Technical testing windowExternal attack surface, limited internal review, config samples, backup restore demoDeep (access-dependent)
SPA / closeReps, indemnities, escrow, cyber insurance condition precedent, Day-1 access cutover planLegal + ops
100 days post-closePrivilege cleanup, MFA gaps, backup hardening, MDR upgrade, policy harmonizationIntegration

Cost and timeline reality

ApproachTypical costTimelineBest for
Public-info first-pass pack$49 ($39.20 with DI20-WELCOME)Minutes to hoursTriage many names before specialist spend
Questionnaire + interview cyber DD$20,000–$60,0001–2 weeksMiddle-market software / services
Full specialist + limited testing$60,000–$150,000+2–4 weeksRegulated, high-data, or prior-incident targets
Deep red-team / multi-cloud assess$150,000+3–6+ weeksPlatform deals, critical infrastructure, high valuation
Cost reality: specialist cyber DD vs first-pass screen

Traditional cyber diligence often starts around $20,000–$150,000+ once multi-cloud, OT, or regulated data appears. A structured public-info pack at $49 (or $39.20 with code DI20-WELCOME) helps you decide whether a name deserves that spend.

Order first-pass $39.20 → See sample report

Red flags that move price or kill deals

SeveritySignalWhy it matters
Deal-KillerActive or recent ransomware with incomplete recoveryOperations, customer trust, and insurance may be broken
Deal-KillerMaterial breach not disclosed to buyers or regulatorsFraud / indemnity risk; SPA liability expands
HighNo MFA on privileged or remote accessPrimary ransomware entry path still open
HighBackups not immutable or never restore-testedRecovery claims are unproven
HighFlat network / domain admin sprawlOne foothold becomes enterprise-wide
HighCritical unpatched internet-facing systemsKnown exploits may already be in play
WatchShared passwords or spreadsheet vaultsScale-up cost after close
WatchSingle MSP with broad admin rightsSupply-chain concentration
WatchSOC 2 report with open major findingsEnterprise sales friction post-close
WatchNo security owner or board reportingProgram will not improve without investment

50-point cybersecurity due diligence checklist

Use this as a first-pass buyer checklist. Severity tags: Deal-Killer, High, Watch.

Identity & access (1–10)

  • Deal-Killer MFA on all remote and privileged access
  • High Privileged account inventory and PAM or vaulting
  • High Joiner/mover/leaver process with same-day revoke
  • High Service accounts documented and rotated
  • Watch SSO coverage across core apps
  • Watch Password policy and breached-password checks
  • High Admin RDP/SSH exposure minimized
  • Watch Contractor access time-boxed
  • High Domain admin / global admin count controlled
  • Watch Periodic access reviews evidenced

Infrastructure & attack surface (11–20)

  • High Asset inventory of internet-facing systems
  • Deal-Killer Critical CVEs on exposed hosts patched or mitigated
  • High EDR coverage on endpoints and servers
  • High Email security and phishing controls
  • Watch Network segmentation (esp. OT/IT)
  • Watch Cloud security posture (IAM, storage public access)
  • High Firewall / WAF change control
  • Watch Remote access architecture (VPN/ZTNA)
  • Watch Shadow IT / unsanctioned SaaS scan
  • High Vulnerability scan cadence and SLA

Data & privacy controls (21–28)

  • High Data classification for regulated data
  • High Encryption at rest for sensitive stores
  • Watch Key management ownership
  • High Customer data retention and deletion process
  • Watch Secrets management (no keys in repos)
  • Watch Production data in non-prod environments
  • High Logging of access to sensitive data
  • Watch Cross-border data transfer map

Detect, respond, recover (29–38)

  • High Centralized logging retention adequate
  • High 24x7 monitoring (internal or MDR)
  • High Written incident response plan
  • Watch Tabletop exercises in last 12 months
  • Deal-Killer Backup immutability / offline copies
  • Deal-Killer Successful restore test evidence
  • High Ransomware playbook and comms plan
  • Watch Forensic retainers or IR firm on call
  • High Incident log for last 24–36 months
  • Watch Metrics: MTTD / MTTR tracked

Third parties & compliance (39–50)

  • High Critical vendor list with access rights
  • High MSP / cloud provider concentration risk
  • Watch Vendor security reviews on cadence
  • High Cyber insurance limits, exclusions, claims
  • Watch SOC 2 / ISO / PCI / HIPAA status
  • High Open audit findings and remediation plan
  • Watch Security awareness training completion
  • High Named security owner (CISO/vCISO/IT lead)
  • Watch Board or PE reporting on cyber risk
  • High Customer contractual security obligations
  • Watch Bug bounty or coordinated disclosure
  • Watch Secure SDLC practices for product companies

How deal teams use cyber findings

  • Price / structure: escrow or special indemnity for known control debt; holdback tied to MFA and backup milestones.
  • Insurance: validate whether renewals will hold after ownership change; plan application answers early.
  • Integration: Day-1 identity cutover, privileged access freeze, and monitoring coverage for acquired environments.
  • Go / no-go: material undisclosed breach history or unrecoverable ransomware posture can stop a process.

First-pass public-info screen vs specialist testing

Specialists need system access, config exports, and interviews. Before that budget unlocks, deal teams still need a structured screen: disclosed incidents, sector threat intensity, customer security requirements, litigation, and whether the target markets itself as security-sensitive without evidence of a program.

dodilligence delivers a public-information diligence pack that helps you prioritize which names justify $20K+ cyber specialist work. It is not a penetration test, SOC report, or legal opinion — it is a fast, consistent first-pass for IC triage and shortlist building.

FAQ

What is cybersecurity due diligence?

It is the buy-side review of security controls, incidents, third parties, and recovery so deal pricing and integration plans reflect real cyber risk.

What is reviewed in M&A cyber diligence?

Identity, infrastructure, data protection, detection/response, backups, vendors, insurance, certifications, and incident history.

How long does traditional cyber due diligence take?

Often 1–4 weeks for middle-market deals; longer when multi-cloud, OT, or regulated data requires deeper testing.

What are common cyber deal-killers?

Active ransomware, major undisclosed breaches, systemic privileged access without MFA, critical unpatched exposure, and unrecoverable backups.

How does cyber diligence relate to technology due diligence?

Technology DD covers product and architecture; cyber DD covers protection, detection, and recovery of the business and customer data.

Should cyber diligence start before LOI?

Yes for light screening. Deep technical testing usually requires post-LOI access under NDA.

What is ransomware readiness?

Evidence that the company can prevent, detect, contain, and restore from destructive attacks — especially immutable backups and privileged access control.

Can a public-info first-pass help before hiring specialists?

Yes. Use it to triage which targets deserve full specialist cyber budgets. Screening research is not a pen test or audit.

Surface cyber risk before you fund deep technical testing

Institutional first-pass diligence pack — $49 list, $39.20 with DI20-WELCOME. PDF delivery for PE and M&A teams.

Order $39.20 → Sample report Free brief