Attack Surface & Exposure
Probability-weighted loss from the target’s current external attack surface — unpatched exposures, misconfigured cloud resources, leaked credentials, dormant services.
One platform, whether you’re evaluating a target or preparing to be evaluated. Quantitative, defensible, and repeatable for every engagement.
Part of the vCISO Lite Ultra subscription.
42% of deals that encounter a cyber incident during or after close lose value. 84% of organizations can’t align their cybersecurity policies post-close. The gap isn’t awareness — it’s a standardized, quantitative way to assess cyber risk fast enough to keep up with the deal. That’s what we built.
Source: FTI Consulting, M&A and Cybersecurity, 2026
Financial diligence has a methodology. Legal diligence has a methodology. Cyber diligence has a forty-page questionnaire and three weeks of Slack threads.
Each pillar produces a dollar-denominated score with its own inputs, comparables, and sensitivity. Summed and risk-adjusted into a single Cyber Cost of Deal.
Probability-weighted loss from the target’s current external attack surface — unpatched exposures, misconfigured cloud resources, leaked credentials, dormant services.
Dollar impact if a critical vendor compromises or fails. Concentration, integration depth, data flows, and substitutability.
Regulatory, reputational, and operational cost of the target’s worst-case breach. Data classification, jurisdictional coverage, breach-notification obligations.
Cost to bring the target’s security program to industry-peer parity. Benchmarked against sector- and stage-matched companies using our cross-customer posture data.
Estimated remediation cost and operational risk in the first 90 days post-close. Identity merge complexity, vendor consolidation, policy harmonization, detection coverage gaps.
Basic target information and a signed NDA. No target-side participation required for a Tier 1 external assessment; deeper assessments engage the target through their team.
The platform runs the five-pillar quantitative assessment: external attack surface by direct observation, vendor concentration from disclosed lists, data sensitivity, security maturity scored against peers, integration risk against your environment.
CCOD in dollars and as percent of EV, per-pillar scores with driver analysis, best/expected/worst scenarios, a 90-day post-close remediation plan, and a defensible valuation adjustment recommendation.
Every diligence engagement is a disposable scope. Raw target data lives only as long as the engagement. Analysis outputs become portable artifacts.
Target data deleted at engagement close. Every close event produces a JWS-signed deletion certificate verifiable against our public JWKS endpoint.
Every engagement lives in its own organization boundary. Portfolio subscriptions include single-tenant deployment isolation on request.
MFA required. NDA enforced at room creation. End-to-end encryption. Watermarked deliverables. No print or copy/paste on target materials.
On close, analysis outputs (CCOD, remediation plan, risk register) port into the operating company’s vCISO Lite tenant as Year-0 baseline. Raw target data never is.
If you’re a PE firm, family office, or M&A advisor evaluating targets across a portfolio, there’s a version of this built specifically for your workflow. Per-engagement, no platform subscription, designed for IC defense and portfolio rollups.
20 minutes. We’ll show you the platform, walk through a sample target assessment, and answer the specific questions your deal team has been stuck on. No sales pitch, no follow-up cadence if it’s not a fit.