Back to Blog

The Private Equity Buyer's Playbook for Cyber Due Diligence: From LOI to IC in 72 Hours

The IC meeting is Thursday. The cyber report landed at 4pm Tuesday. Forty pages, three heat maps, no number. Here's how PE deal teams fix that before the next deal.

Quick Answer

The IC meeting is Thursday. The cyber report landed at 4pm Tuesday. Forty pages, three heat maps, no number. Here's how PE deal teams fix that before the next deal.

The IC meeting is Thursday. The cyber report landed at 4pm Tuesday. Forty pages, three heat maps, no number. Here's how PE deal teams replace that report with a quantitative output that survives the IC defense.

The standard cyber diligence report is a liability document dressed up as analysis. It tells the IC there are risks. It doesn't tell them how much those risks cost, which ones to negotiate against, or what a remediation program actually runs. The deal partner has to translate it into commercial terms on the fly — which means either waiving cyber risk entirely or making up a number that opposing counsel will challenge.

There's a better process. It runs from LOI to IC in six to eight weeks if scoped correctly from day one. The output is a Cyber Cost of Deal (CCOD): a single dollar figure with five defensible components that the legal and financial workstreams can each stress-test independently.

78%
of PE deals have cyber findings that materially affect deal terms (PwC M&A Integration Survey, 2024)
43 days
average time from cyber finding discovery to commercial resolution in M&A (Marsh McLennan, 2024)
return on investment for pre-LOI cyber scoping vs. post-close remediation (Deloitte M&A Cyber Study, 2024)
31%
of acquirers discovered a material breach within 12 months of close (IBM Security, 2024)

What goes wrong with the standard approach

Most PE deal teams commission a cyber assessment the same way they commission environmental due diligence: a vendor comes in, produces a report, and the report goes into the data room. The report ranks findings by severity — critical, high, medium, low — and recommends remediation. The deal partner reads the executive summary and passes it to the legal team to negotiate reps and warranties.

Three things break this process.

First, severity ratings aren't dollar values. A "critical" finding at a $200M SaaS company with a healthcare customer base is a completely different commercial risk than a "critical" finding at a $50M manufacturing company with no regulated data. The rating doesn't tell you what to negotiate against.

Second, the timing is wrong. A report delivered two days before IC gives the deal team no time to validate findings, get remediation quotes, or build the commercial argument. It also gives opposing counsel maximum ammunition to challenge the methodology.

Third, the report doesn't talk to the other workstreams. The legal team is negotiating reps and warranties. The financial team is modeling the post-close integration cost. Cyber findings should be inputs to both — but they rarely are because no one has translated them into dollar terms.

The Fix

Commission a Quantitative Cyber Diligence (QCD) assessment, not a traditional security audit. The difference: QCD produces an Annual Loss Expectancy for each finding and a total Cyber Cost of Deal that the IC can act on. A security audit produces a finding list that the IC can't act on.

What to scope at LOI

The LOI is when you set the terms for cyber access. Most deal teams ask for "relevant security documentation" in the data room request. That's too vague to be useful and usually produces a collection of outdated policies and a SOC 2 report from two years ago.

The cyber ask at LOI should be specific. Request these seven categories in writing:

Identity and access management inventory

Active user accounts, admin privilege list, MFA enforcement status, dormant account audit (last 90 days), service account inventory, and external/contractor access list with access dates.

Endpoint and patch management status

Total device count, EDR deployment coverage percentage, patch compliance report for critical patches in the last 90 days, and list of systems running end-of-life software.

Third-party vendor list

Vendors with access to production data or infrastructure. For each: contract date, data categories accessed, SOC 2 or equivalent report status, and breach notification clause in contract.

Compliance posture

Active certifications or attestations (SOC 2, ISO 27001, HIPAA BAAs, PCI-DSS SAQ). Any open audit findings. Any regulatory inquiries or notifications in the last 24 months.

Incident history

All security incidents in the last 36 months. For each: date, nature, scope, customer notification, regulatory notification, and resolution cost. Self-reported incidents included.

Cloud and infrastructure configuration

Cloud provider accounts, security posture management tool output if available, and public-facing asset inventory.

Insurance

Cyber insurance policy declarations page, coverage limits, deductible, and any claims in the last 36 months.

This request signals to the target that you're running QCD, not a checkbox audit. Sophisticated sellers — and their counsel — will recognize the specificity and prepare accordingly. That's fine. Targets who are slow to produce these materials are telling you something.

The LOI-to-IC timeline

Six to eight weeks is the right planning horizon for a full QCD engagement on a mid-market target. Here's how that time should be allocated:

Weeks 1–2: Passive assessment

No direct access to target systems required. External attack surface scan — what can be seen from the internet. Data room review against the seven LOI request categories. Gap analysis: what's missing and why. Preliminary finding classification by pillar. First call with target CISO or senior technical staff to fill gaps.

Weeks 3–4: Active assessment

Exclusivity typically begins. Direct access to target systems for configuration review. IAM audit against active directory or identity provider. Cloud security posture review. Technical interview with engineering and security leadership. Vendor contract review. Finding validation and draft ALE calculations.

Weeks 5–6: Quantification

ALE finalization for each pillar. Remediation cost estimation — vendor quotes, not estimates. CCOD number built and reviewed by deal team. Commercial recommendation drafted: price adjustment vs. escrow vs. R&W. IC slide prepared. Legal team briefed on finding-to-rep mapping.

The 72-hour IC prep

Lock the CCOD number. No changes without deal partner sign-off. Prepare three versions of the IC exhibit: the one-page summary, the five-pillar backup, and the remediation detail. Brief the financial model team on the post-close remediation timeline and cost. Prepare the counter-argument brief for opposing counsel's expected challenges.

How to run the technical assessment in parallel

The biggest time sink in QCD is sequential information flow: the legal team waits for the technical report, then negotiates reps, then the financial team models remediation costs. Run all three in parallel from week one.

Parallel Track Structure

Assign a single point of contact for cyber findings across all three workstreams. The QCD lead briefs the legal team weekly on emerging findings so rep negotiations aren't delayed waiting for the full report. The financial model has a cyber integration cost placeholder from week one, updated as findings are quantified. The deal partner gets a rolling CCOD estimate — not a final number — from week two onward.

This matters most in competitive processes where timeline compression is real. A deal team that can brief the IC on cyber risk in week six rather than week eight has a meaningful advantage — both in deal speed and in the quality of the commercial negotiation.

The management interview: what to ask

The technical assessment tells you what the controls are. The management interview tells you whether leadership knows about the gaps and has made deliberate decisions about them — or whether they simply don't know.

The distinction matters commercially. A CEO who is unaware of 47 dormant user accounts represents a governance finding as much as a technical one. A CTO who knows about the patch cadence problem and made an explicit tradeoff decision for headcount reasons is a different situation — and a better indicator of post-close remediation likelihood.

Ask three categories of questions:

Management Interview Framework

Awareness: "Walk me through how you learned about [specific finding]. When did you first become aware of it?" — Tests whether findings are known.

Decision: "What was the deliberate decision made about this gap? Was there a tradeoff analysis?" — Tests whether risk decisions are intentional or accidental.

Capability: "Who owns remediation of this finding today? What would it take to fix it in the next 90 days?" — Tests post-close remediation likelihood and organizational capacity.

Defending the number at IC

The CCOD number will be challenged. Opposing counsel will argue the probabilities are too high. The seller's technical team will argue the findings are less severe than characterized. The IC will ask why the acquirer can't just fix the issues post-close without a price adjustment.

The defenses are standard, but they need to be prepared in advance:

For probability challenges: each probability is sourced to a published benchmark adjusted for industry and company size. The probability isn't a guess — it's what the data says about companies with the same control profile in the same sector.

For severity challenges: the CCOD isn't based on what the findings are — it's based on what they cost when they materialize. A "medium" finding that triggers a BAA notification with a 67% ARR concentration is a bigger commercial risk than a "critical" finding in a low-impact system.

For the post-close fix argument: you can fix the controls post-close. You can't fix the breach that happens in the gap. The remediation escrow is precisely structured to close that gap.

For the quantitative methodology underlying the CCOD, see the worked example of a Cyber Cost of Deal — the same five-pillar framework applied to a representative mid-market target, with full ALE calculations and the IC slide structure.

How cyber connects to the rest of due diligence

Cyber findings don't live in isolation. An IAM gap is also an SOX finding if the target is heading toward a public offering. A HIPAA compliance gap is also a material representation in the reps-and-warranties insurance application. Endpoint coverage gaps affect cyber insurance limits.

The QCD process maps each finding to its relevant downstream implications: which reps are affected, which insurance provisions are relevant, which post-close integration milestones are implicated. That mapping — not just the finding list — is what makes cyber due diligence useful to the full deal team rather than just the technical workstream.

For the seller side of this process — what targets should prepare before a PE firm runs QCD — see cybersecurity due diligence from both sides of the M&A table.

Put the playbook to work

The LOI-to-IC process in this article runs on vCISO Lite's Quantitative Cyber Diligence platform — the seven-category data room request, the parallel-workstream tracking, and the CCOD output that survives the IC defense, all in one place. No more findings scattered across spreadsheets and email threads two days before the meeting.

If your fund runs more than two deals a year, standardization is the lever. Same data room template, same ALE methodology, same IC slide format across every deal — so your IC can compare cyber risk across targets in the same terms. Visit diligence.vcisolite.com to see how it works and enroll your fund.

Where this matters next

Gold: Cyber Due Diligencethe Gold surface at diligence.vcisolite.com — per-engagement QCD (Quantitative Cyber Diligence) methodology built specifically for PE deal teams and family offices.

Carbon: Diligence overviewthe Carbon marketing page covering the 72-hour Cyber Cost of Deal methodology for both PE evaluating targets and founders preparing for investor diligence.

Where this matters next

Inside a Cyber Cost of Deal: A Worked Example for Investment Committee — The target was a mid-market SaaS. $80M enterprise value, healthcare-adjacent. The deal partner wanted one IC slide

R&W Insurance or Price Reduction? How to Use a Quantified Cyber Number at the Negotiating Table — They picked R&W. Eighteen months later, the known-findings carve-out did exactly what those carve-outs always do

Cyber Risk Quantification for Mid-Market: FAIR Without an Enterprise Risk Team — FAIR was built for risk teams of 20+. Mid-market companies have one person doing security part-time

Cyber Insurance Is Broken Because Carriers Can't See Inside the Policyholder — Property insurance works because adjusters can see the roof. Auto works because police reports document the crash

Share this article:

Ready to build your security program?

See how easy it can be.