Quantitative Cyber Diligence

Cyber diligence, from both sides of the table.

One platform, whether you’re evaluating a target or preparing to be evaluated. Quantitative, defensible, and repeatable for every engagement.

Part of the vCISO Lite Ultra subscription.

See the real cyber posture. Before the deal closes.

42% of deals that encounter a cyber incident during or after close lose value. 84% of organizations can’t align their cybersecurity policies post-close. The gap isn’t awareness — it’s a standardized, quantitative way to assess cyber risk fast enough to keep up with the deal. That’s what we built.

42%
of deals that encounter a cyber incident during/after close lose value
69%
of executives say a post-transaction cyber incident negatively impacted the deal
84%
can’t align cybersecurity policies after the transaction closes
39%
of leaders have no integration plan at close

Source: FTI Consulting, M&A and Cybersecurity, 2026

Financial diligence has a methodology. Legal diligence has a methodology. Cyber diligence has a forty-page questionnaire and three weeks of Slack threads.

The QCD Methodology

Five pillars. One dollar figure.
Defensible at the IC.

Each pillar produces a dollar-denominated score with its own inputs, comparables, and sensitivity. Summed and risk-adjusted into a single Cyber Cost of Deal.

01

Attack Surface & Exposure

Probability-weighted loss from the target’s current external attack surface — unpatched exposures, misconfigured cloud resources, leaked credentials, dormant services.

Quantified as expected annual loss
Typical range $50K – $5M
02

Third-Party & Vendor Concentration

Dollar impact if a critical vendor compromises or fails. Concentration, integration depth, data flows, and substitutability.

Quantified as max single-vendor loss + concentration index
Typical range $100K – $25M
03

Data Sensitivity & Regulatory Exposure

Regulatory, reputational, and operational cost of the target’s worst-case breach. Data classification, jurisdictional coverage, breach-notification obligations.

Quantified as probable maximum loss (PML)
Typical range $500K – $50M+
04

Security Program Maturity

Cost to bring the target’s security program to industry-peer parity. Benchmarked against sector- and stage-matched companies using our cross-customer posture data.

Quantified as cost-to-parity, 12-month spend
Typical range $150K – $3M
05

Integration & Post-Close Risk

Estimated remediation cost and operational risk in the first 90 days post-close. Identity merge complexity, vendor consolidation, policy harmonization, detection coverage gaps.

Quantified as 90-day integration budget + go-live value at risk
Typical range $200K – $10M
OUTPUT
Five dollar-denominated scores, summed with correlation adjustment, producing a single Cyber Cost of Deal (CCOD) figure expressed in dollars and as a percentage of enterprise value.
How It Works

From kickoff to deliverable, in 72 hours.

01
DAY 0
Submit the target

Basic target information and a signed NDA. No target-side participation required for a Tier 1 external assessment; deeper assessments engage the target through their team.

02
DAY 1–2
Run the assessment

The platform runs the five-pillar quantitative assessment: external attack surface by direct observation, vendor concentration from disclosed lists, data sensitivity, security maturity scored against peers, integration risk against your environment.

03
DAY 3
Board-ready report

CCOD in dollars and as percent of EV, per-pillar scores with driver analysis, best/expected/worst scenarios, a 90-day post-close remediation plan, and a defensible valuation adjustment recommendation.

What you get

Read it in 15 minutes.
Defend it in any valuation discussion.

A number
Not a heat map of CVEs. Not a red-yellow-green dashboard. An actual dollar figure with provenance.
A defense
Every pillar score shows its inputs, its comparables, and its sensitivity to top drivers.
A plan
If you proceed, you have a 90-day remediation budget. If you walk, you have the defensible reason.
A clean handoff
Engagement ends at the deletion certificate — raw target data doesn’t live in our system. If the deal closes, analysis artifacts port into the operating company’s own tenant for Year-1 tracking.
How It’s Built

Ephemeral by design.
Portable by architecture.

Every diligence engagement is a disposable scope. Raw target data lives only as long as the engagement. Analysis outputs become portable artifacts.

Ephemeral by design

Target data deleted at engagement close. Every close event produces a JWS-signed deletion certificate verifiable against our public JWKS endpoint.

Logically isolated

Every engagement lives in its own organization boundary. Portfolio subscriptions include single-tenant deployment isolation on request.

Standard controls

MFA required. NDA enforced at room creation. End-to-end encryption. Watermarked deliverables. No print or copy/paste on target materials.

Clean handoff

On close, analysis outputs (CCOD, remediation plan, risk register) port into the operating company’s vCISO Lite tenant as Year-0 baseline. Raw target data never is.

For Private Equity

Running a fund, not an operating company?

If you’re a PE firm, family office, or M&A advisor evaluating targets across a portfolio, there’s a version of this built specifically for your workflow. Per-engagement, no platform subscription, designed for IC defense and portfolio rollups.

Ready to see a live portfolio walkthrough?

20 minutes. We’ll show you the platform, walk through a sample target assessment, and answer the specific questions your deal team has been stuck on. No sales pitch, no follow-up cadence if it’s not a fit.