All releases
Book · Someone Else’s Debt

The QCD framework, now a book — “Someone Else’s Debt”

Quantitative Cyber Diligence for M&A: how to translate cyber risk into a dollar figure your deal team can act on. The methodology that drives our diligence surface, in book form.

Someone Else’s Debt is the book-length treatment of Quantitative Cyber Diligence (QCD)— the methodology that drives our diligence product for M&A, PE, and investment-committee deal teams. The book publishes today on Amazon and Kindle; the product itself lives at diligence.vcisolite.com, with the version-launched-for-deal-teams milestone covered in the separate QCD product changelog entry.

The five pillars, one number

QCD decomposes cyber risk into a single Cyber Cost of Deal (CCOD) figure across five defensible pillars:

  • Attack surface & exposure.Probability-weighted 12-month financial loss at current posture, decomposed via FAIR-style LEF × LM math over eight observable categories.
  • Third-party & vendor concentration. Max single-vendor loss weighted by an HHI concentration penalty. See the Vendor Risk cluster for the underlying methodology.
  • Data sensitivity & regulatory exposure. Probable maximum loss and expected annual cost from a reportable breach. Covers HIPAA, GDPR, CCPA/CPRA, GLBA, PCI-DSS, and state laws.
  • Security program maturity.Where the target’s program actually sits on the operating-maturity curve — not a red/yellow/green rating, a defensible position that translates into remediation cost and time-to-close.
  • Integration and post-close risk.What the target brings into the acquirer’s environment at day one and through integration — the risks that don’t resolve at close and become the acquirer’s liabilities on day-91.

Who this is for

The book is written for deal teams: PE partners, corp-dev leads at strategic acquirers, and the security and GRC operators who advise them. The methodology, the math, the sourcing, and the worked examples are all in the book — and the platform at diligence.vcisolite.com automates it into a per-engagement diligence workflow.

Read the QCD executive brief and academic paper for the short version, or explore the M&A Security Diligence series and the Someone Else’s Breach series for the deep-dives that shaped the book.

Related reading: Risk Quantification cluster, QCD brief + paper, the QCD product changelog.

Related reading

The PE Buyer's Playbook for Cyber Due Diligence — the LOI-to-IC framework the QCD book anchors.

Cyber Cost of Deal: A Worked Example — the CCOD methodology walked through end to end.