A practical guide to cybersecurity due diligence — how PE, search funds, and M&A buyers size breach risk, protect purchase price, and plan Day-1 security integration before specialists run deep technical testing.
Cybersecurity due diligence answers an operational and valuation question: can this company protect customer data, keep operations online under attack, and meet the security expectations of regulators, insurers, and enterprise customers after close?
Buyers review security governance, identity controls, cloud and network posture, vulnerability management, detection and response, backup and recovery, third-party risk, incident history, and compliance artifacts (SOC 2, ISO 27001, HIPAA, PCI where relevant). Findings feed price chips, special indemnities, escrow, cyber insurance strategy, and a 100-day security roadmap.
Cyber diligence sits beside technology due diligence, operational due diligence, and legal due diligence. Tech DD tests product and architecture; ops DD tests process resilience; legal DD tests contracts and liability; cyber DD tests whether attackers can break the business model.
| Work product | Primary question | Typical owner | Output |
|---|---|---|---|
| Technology DD | Is the product/architecture investable? | Tech diligence / CTO advisors | Architecture + debt memo |
| Cybersecurity DD | Is the control plane and recovery credible? | CISO advisors / cyber firms | Risk register + 100-day plan |
| Legal / privacy DD | What contractual and statutory liability? | Counsel | Liability + notice analysis |
| Ops DD | Can operations survive disruption? | Ops diligence | BCP / continuity view |
MFA coverage, privileged access management, joiners/movers/leavers, SSO, service accounts, and dormant admin paths. Identity failures remain the fastest path to ransomware.
Internet-facing assets, cloud configuration, network segmentation, endpoint coverage, email security, and OT/IT boundary where factories or field devices exist.
Data inventory, encryption in transit/at rest, key management, DLP where claimed, retention, and handling of regulated data (PII, PHI, cardholder, trade secrets).
Logging coverage, EDR/XDR, SIEM or MDR, IR playbooks, tabletop evidence, backup immutability, restore tests, and ransomware communication plans.
Critical SaaS, MSPs, hosting, software dependencies, vendor access into production, and concentration risk on a single managed-security or cloud provider.
Security ownership, board reporting, policies, training, insurance history, certifications, customer security questionnaires, and open audit findings.
| Stage | Cyber focus | Depth |
|---|---|---|
| Screening / pre-LOI | Sector threat profile, disclosed breaches, customer concentration on security SLAs, public dark-web or news signals | Light |
| Post-LOI confirmatory | Questionnaires, architecture interviews, control evidence, incident log, insurance, vendor list | Medium |
| Technical testing window | External attack surface, limited internal review, config samples, backup restore demo | Deep (access-dependent) |
| SPA / close | Reps, indemnities, escrow, cyber insurance condition precedent, Day-1 access cutover plan | Legal + ops |
| 100 days post-close | Privilege cleanup, MFA gaps, backup hardening, MDR upgrade, policy harmonization | Integration |
| Approach | Typical cost | Timeline | Best for |
|---|---|---|---|
| Public-info first-pass pack | $49 ($39.20 with DI20-WELCOME) | Minutes to hours | Triage many names before specialist spend |
| Questionnaire + interview cyber DD | $20,000–$60,000 | 1–2 weeks | Middle-market software / services |
| Full specialist + limited testing | $60,000–$150,000+ | 2–4 weeks | Regulated, high-data, or prior-incident targets |
| Deep red-team / multi-cloud assess | $150,000+ | 3–6+ weeks | Platform deals, critical infrastructure, high valuation |
Traditional cyber diligence often starts around $20,000–$150,000+ once multi-cloud, OT, or regulated data appears. A structured public-info pack at $49 (or $39.20 with code DI20-WELCOME) helps you decide whether a name deserves that spend.
| Severity | Signal | Why it matters |
|---|---|---|
| Deal-Killer | Active or recent ransomware with incomplete recovery | Operations, customer trust, and insurance may be broken |
| Deal-Killer | Material breach not disclosed to buyers or regulators | Fraud / indemnity risk; SPA liability expands |
| High | No MFA on privileged or remote access | Primary ransomware entry path still open |
| High | Backups not immutable or never restore-tested | Recovery claims are unproven |
| High | Flat network / domain admin sprawl | One foothold becomes enterprise-wide |
| High | Critical unpatched internet-facing systems | Known exploits may already be in play |
| Watch | Shared passwords or spreadsheet vaults | Scale-up cost after close |
| Watch | Single MSP with broad admin rights | Supply-chain concentration |
| Watch | SOC 2 report with open major findings | Enterprise sales friction post-close |
| Watch | No security owner or board reporting | Program will not improve without investment |
Use this as a first-pass buyer checklist. Severity tags: Deal-Killer, High, Watch.
Specialists need system access, config exports, and interviews. Before that budget unlocks, deal teams still need a structured screen: disclosed incidents, sector threat intensity, customer security requirements, litigation, and whether the target markets itself as security-sensitive without evidence of a program.
dodilligence delivers a public-information diligence pack that helps you prioritize which names justify $20K+ cyber specialist work. It is not a penetration test, SOC report, or legal opinion — it is a fast, consistent first-pass for IC triage and shortlist building.
It is the buy-side review of security controls, incidents, third parties, and recovery so deal pricing and integration plans reflect real cyber risk.
Identity, infrastructure, data protection, detection/response, backups, vendors, insurance, certifications, and incident history.
Often 1–4 weeks for middle-market deals; longer when multi-cloud, OT, or regulated data requires deeper testing.
Active ransomware, major undisclosed breaches, systemic privileged access without MFA, critical unpatched exposure, and unrecoverable backups.
Technology DD covers product and architecture; cyber DD covers protection, detection, and recovery of the business and customer data.
Yes for light screening. Deep technical testing usually requires post-LOI access under NDA.
Evidence that the company can prevent, detect, contain, and restore from destructive attacks — especially immutable backups and privileged access control.
Yes. Use it to triage which targets deserve full specialist cyber budgets. Screening research is not a pen test or audit.
Institutional first-pass diligence pack — $49 list, $39.20 with DI20-WELCOME. PDF delivery for PE and M&A teams.