All press releases

For Immediate Release

vCISO Lite Launches Quantitative Cyber Diligence — Dollar-Denominated Cyber Cost of Deal for M&A, PE, and Investment Committees, Delivered in 72 Hours

A five-pillar diligence product for deal teams: Cyber Cost of Deal (CCOD) in dollars and as a percentage of enterprise value, defensible at the IC, comparable across a portfolio — Tier 1 external snapshot at $12,500, Tier 2 full engagement priced against target EV.

ATLANTA — May 29, 2026 — vCISO Lite today launched Quantitative Cyber Diligence (QCD), a dedicated diligence product for M&A deal teams, private equity operating partners, and investment committees. QCD replaces the forty-page cyber-diligence questionnaire and the three-week Big-4 engagement with a five-pillar, dollar-denominated Cyber Cost of Deal (CCOD)figure — delivered in 72 hours, defensible at the IC, and comparable across a portfolio. The product is live at diligence.vcisolite.com.

The launch answers a pattern deal teams already know well. FTI Consulting’s 2026 M&A and Cybersecurityreport found that 42% of deals encountering a cyber incident during or after close lose value, 69% of executives say a post-transaction cyber incident negatively impacted the deal, and 84% of organizations can’t align cybersecurity policies after the transaction closes. Westbourne Research (2025) put 21% of deals as delayed, repriced, or abandoned over cybersecurity issues surfaced in diligence — the Verizon acquisition of Yahoo cut its price by $350 million on undisclosed breach exposure alone. The signal is priced-in on every deal. The method for pricing it is not.

“Cyber is the only line item on the diligence checklist that still gets scored red-yellow-green,” said Yolonda Smith, founder of vCISO Lite. “Financial diligence has a methodology. Legal diligence has a methodology. Cyber diligence has a forty-page questionnaire and three weeks of Slack threads. That’s not diligence — that’s hope. QCD gives deal teams what they already have for every other risk on the deal: a number, sourced to specific inputs, defensible against a real audience, and comparable across the portfolio.”

What’s in the release

The QCD product is live today for M&A buyers, PE operating partners, corporate development teams, and founders preparing to be diligenced. In the initial release, deal teams can commission the following on any active engagement:

  • Tier 1 External Snapshot — delivered in 48 hours. Attack Surface & Exposure pillar only, no target-side participation required. Designed for the LOI stage. Published at $12,500 flat.
  • Tier 2 Full QCD — delivered in 72 hours. Board-ready report covering all five pillars, per-pillar driver analysis, three-scenario CCOD (best / expected / worst), 90-day remediation budget, and a valuation-adjustment recommendation. Priced against target enterprise value, starting at $15,000.
  • Founder-side preparation.The same methodology run against your own posture, packaged as a shareable diligence artifact you can hand to a prospective buyer at deal start — eliminating the three-week back-and-forth on cyber.
  • Portfolio rollup + IC briefing generator.Cross- engagement portfolio dashboard, drift attribution across CCOD components, and a one-click IC briefing PDF for the operating partner’s next investment committee.
  • Ephemeral-then-portable delivery.Raw target data lives only for the engagement window; every close event produces a JWS-signed deletion certificate. If the deal closes, analysis artifacts port into the operating company’s vCISO Lite tenant as its Year-0 baseline. Detail in “The Year-Zero Cyber Baseline”.

The five pillars of the CCOD

QCD decomposes cyber risk into five defensible line items, each producing a dollar-denominated score summed with correlation adjustment into a single CCOD figure expressed in dollars and as a percentage of enterprise value:

  • Attack Surface & Exposure— probability- weighted expected annual loss from the target’s current external attack surface: unpatched exposures, misconfigured cloud resources, leaked credentials, dormant services. Measured by direct observation, no target cooperation required. Typical range $50K–$5M.
  • Third-Party & Vendor Concentration— dollar impact if a critical vendor compromises or fails. Combines maximum single-vendor loss with an aggregate concentration index. Typical range $100K–$25M.
  • Data Sensitivity & Regulatory Exposure— probable maximum loss from a reportable breach, incorporating data classification, jurisdictional coverage (GDPR, CCPA/CPRA, HIPAA, GLBA, PCI DSS, state laws), and breach-notification obligations. Typical range $500K–$50M+.
  • Security Program Maturity— cost to bring the target’s program to industry-peer parity, benchmarked against sector- and stage-matched companies using vCISO Lite’s cross-customer posture data. Typical range $150K–$3M.
  • Integration & Post-Close Risk— 90-day remediation budget and go-live value at risk during identity merges, vendor consolidation, and detection-coverage stitching. Typical range $200K–$10M.

A worked example — how the five pillars sum on a realistic mid-market target — is available in “Inside a Cyber Cost of Deal: A Worked Example for Investment Committee”. The 72-hour engagement shape — from LOI-stage engagement creation to IC-ready deliverable — is walked step-by-step in “The Private Equity Buyer’s Playbook for Cyber Due Diligence: From LOI to IC in 72 Hours”.

What grounds the methodology

QCD’s pillar math sits on established loss-quantification and risk-assessment standards, adapted to the transaction-diligence context:

  • Factor Analysis of Information Risk (FAIR)— The Open Group’s open standard for loss-event frequency × loss-magnitude decomposition. Pillar 1 and Pillar 3 use FAIR-shaped math over observable inputs.
  • NIST SP 800-30 Rev. 1— the U.S. federal guide for conducting information-security risk assessments, including threat-source and adverse-event modeling. Provides the risk-assessment scaffolding around the pillar decomposition.
  • ISO/IEC 27005:2022— the international standard for information security risk management, referenced for risk-treatment decisions and the escrow / reprice / walk recommendation tier.
  • SEC cybersecurity disclosure rule (Item 106 of Regulation S-K; Item 1.05 of Form 8-K)— effective December 2023. Makes cyber material to public-company reporting and to any deal that will surface a covered issuer — and gives the acquirer a defined obligation to know what they are buying.

The complete methodology, including per-pillar rubrics, correlation adjustment, and the tiered recommendation surface (proceed → escrow → reprice → walk), is published in the QCD executive brief and the QCD academic paper (v0.6, May 2026), available at vcisolite.com/briefs-and-specs. A book-length treatment — Someone Else’s Debt (Smith, 2026) — is available on Amazon and Kindle.

How the number changes the deal

The CCOD is not a report you read and file. It plugs into the valuation model as a dollar line item and into the deal-terms conversation as an escrow amount, a reps-and-warranties trigger, or a price adjustment. When the Q90 outcome or a single pillar breaches deal-team thresholds, the platform surfaces mechanical recommendations (proceed, escrow, reprice, walk) with the supporting math attached. vCISO Lite’s guidance on using the number at the negotiating table — specifically how to choose between rep-and-warranty insurance and a straight price cut — is at “R&W Insurance or Price Reduction?”.

For deal teams that want end-to-end QCD engagements run by AI agents, with cryptographic proof of every action the agent takes, vCISO Lite’s Trustworthy Autonomy™layer covers M&A cyber diligence in its public-beta program alongside TPRM, audit preparation, and KRI monitoring.

Availability

Quantitative Cyber Diligence is generally available today at diligence.vcisolite.com, priced per engagement rather than by subscription: Tier 1 External Snapshot at $12,500 flat (48-hour delivery), and Tier 2 Full QCD priced against target enterprise value with a $15,000 floor (72-hour delivery). A companion product experience for operating-company teams — running QCD on their own posture ahead of an anticipated deal, or on a target inside the vCISO Lite Ultra subscription — is at vcisolite.com/diligence. The QCD executive brief and academic paper, plus companion briefs on DC-TPIR, Continuous Maturity Assessment, and Trustworthy Autonomy, are at vcisolite.com/briefs-and-specs. Editorial coverage lives in the M&A Security Diligence series and the Someone Else’s Breach series. The published product changelog for the QCD launch is at vcisolite.com/changelog/qcd-book.


About vCISO Lite

vCISO Lite is a compliance and cyber risk platform for growing companies that don’t have a full-time CISO. The platform helps customers close compliance gaps across every framework mapped in the Secure Controls Framework (SOC 2, ISO 27001, PCI DSS, HIPAA, DORA, NYDFS Part 500, GDPR, NIST 800-53 and 800-171, FedRAMP, CMMC, and more), quantify cyber risk in the language their board and deal teams already speak, and — with Quantitative Cyber Diligence — turn M&A cyber risk into a dollar figure deal teams can act on. vCISO Lite is headquartered in Atlanta, Georgia. Learn more at vcisolite.com, read related product releases in the changelog, or explore the Trustworthy Autonomy editorial series.

Media Contact

Press & Analyst Inquiries
Yolonda Smith, Founder
press@vcisolite.com

###