ciso.diy
M&A Cyber Due Diligence Kit preview
Due Diligence M&Aprivate equitydue diligenceroll-up

M&A Cyber Due Diligence Kit

Find the breach before you buy it — a 3–4 week diligence method for mid-market add-ons and roll-ups. 46 phased requests, four interview tracks, and a red-flag model with anchored scoring that outputs cost-to-cure in basis points of EV and a proposed escrow multiple, with each SPA lever mapped back to the finding that justifies it.

What this actually gives you

  • Eight domains scored 0–4 against anchored descriptors, so two reviewers land on the same number, with two hard triggers that force WALK or RESTRUCTURE regardless of the total.
  • The model converts cost-to-cure into basis points of enterprise value and a proposed escrow multiple — so the output arrives in the vocabulary the investment committee already uses, and the conversation starts at price rather than at patching.
  • Each reps-and-warranties lever maps back to the finding that justifies it, so counsel is not asked to argue for language with no evidence behind it.
  • A 3–4 week method: 46 phased requests, four interview tracks, a passive external attack-surface check, and a funded 100-day plan.

Buyers inherit breaches. In a mid-market roll-up the target's security is usually one generalist and an MSP contract nobody has read, and the finding that moves the deal is rarely a vulnerability — it is an incident history nobody disclosed, or a domain admin account belonging to a contractor who left in 2023.

This is a 3–4 week engagement method, not a checklist: phased requests, four interview tracks, a scored red-flag model, findings written in deal-team voice, starter SPA language, and a funded 100-day plan. For PE operating partners, corp-dev, deal counsel and the fractional CISOs they bring in.

The red-flag model is what makes this a deal product rather than a security template. Eight domains, each scored 0–4 against anchored descriptors so two reviewers land on the same number, weighted toward ransomware readiness and incident history. Two hard triggers force WALK or RESTRUCTURE regardless of the total, because some findings are not averageable. Every domain carries a cost-to-cure, and the model converts that into basis points of enterprise value with a proposed escrow multiple — so the output arrives in the vocabulary the investment committee already uses, and the conversation starts at price rather than at patching.

01 Diligence Request List (XLSX) — 46 requests phased across LOI (15), confirmatory (24) and pre-close (7), each with why it matters, quality tracking and a red-flag cross-reference.

02 Red-Flag Scoring Model + findings log (XLSX) — the eight domains, the Acquisition-Debt Score, and the posture it produces: WALK / PRICE & PROTECT / PROTECT / PROCEED. Cost-to-cure, bps of EV, suggested escrow, and a findings log tagged by deal impact.

03 Interview Guides (DOCX) — CEO or owner, IT lead, MSP/MSSP, finance. 39 questions, each paired with what to listen for, because the answer that matters is usually the hesitation.

04 External Attack-Surface Quick-Check (Markdown) — a 2–4 hour passive procedure using microsec.tools and Bug-Hunter: exposure table, leak-site and credential checks, and a pre-close re-run. Passive by design — you do not have authorisation to test a company you have not bought.

05 Findings Report Template (DOCX) — IC-ready: three-paragraph summary, scorecard, finding blocks carrying severity, cost and the deal lever each one justifies, then recommendations and limitations.

06 Reps, Warranties & Indemnity Starter (DOCX) — 9 reps, 2 covenants, a specific indemnity and cyber escrow, definitions and an RWI note. Each lever maps back to the finding that justifies it, so counsel is not asked to argue for language with no evidence behind it.

07 100-Day Integration Plan (XLSX + DOCX) — 18 pre-loaded tasks in three blocks with budget, dependencies, finding references and a Gantt-lite view, plus the narrative with sign-offs. Funded at IC, not improvised at close.

08 Portfolio Roll-Up Dashboard (XLSX) — every target and portfolio company on one sheet: score, posture, cost, bps, worst domain, and a portfolio summary. This is the sheet an operating partner actually keeps open.

09 IC Memo Deck (PPTX) — two slides: the verdict and the money, then findings mapped to SPA levers with the scorecard.

10 Practitioner Guide (PDF) — deal economics, the four-week engagement, how to score, the levers, RWI, Day 1, the 100 days, roll-up specifics, the classic misses and an FAQ.

The worked example is invented. Northstar Roofing Group, a fictional six-brand roll-up, acquired by the fictional Harbor Point Capital — along with every other entity named anywhere in the kit. No client, target or engagement is described.

Sits alongside the M&A Cyber Diligence Workbook, which is the 13-tab modelling tool for a 10-day sprint; this kit is the full engagement around it. Most deal teams end up wanting both — the M&A Diligence Complete bundle is the pair at 25% off. Pairs with TPRM-01 when the target's MSP is the real risk, and INS-01 when you need to know whether the target's own insurance answers were true.

Deal intelligence, not legal advice. File 06 is starter language for counsel to adapt, not an opinion on your transaction.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-03
Pages 10