Private Equity & M&A Advisory

The target's data room says green. The dark web says otherwise.

Standard IT due diligence checks software licences and server counts. It fails to quantify the multi-million-dollar remediation costs hidden in compromised admin credentials, dormant ransomware and critical compliance gaps. We give deal teams leverage at the negotiating table.

The M&A Blind Spot

What standard IT due diligence misses.

A target company's management team is financially incentivised to downplay security risks during a transaction. If you rely solely on the documentation they provide in the data room, you are acquiring their technical debt.

Illustrative

ControlData Room SaysTransaction Reality
Compliance certificationsISO 27001 active340 leaked credentials found on the dark web
Penetration test findings“No critical findings”3 C-suite credential leaks; unpatched internet-facing RDP
Security budget adequacyAdequateEst. $1.5M–$2.5M in post-close remediation

Illustrative — A Composite Outside-In Briefing

"The outside-in picture is concerning."

"We found 340 leaked credentials belonging to senior staff, three unpatched internet-facing systems, and evidence of a prior breach not disclosed in the data room. If the internal picture matches this external footprint, you are looking at $1.5M to $2.5M in immediate post-close remediation costs."

"We need five days of full access to quantify this technical debt and give you a hard number you can use at the negotiating table to drive down the valuation."

Composite example drawn from common patterns. Figures illustrate the shape of the finding, not a specific engagement.

Advisory Engagements

M&A cyber diligence tiers

From rapid outside-in intelligence scans to full-access technical diligence.

01

OSINT Red Flag Scan

$8K–$12K · 2-day turnaround

A strictly scoped outside-in intelligence scan of the target company. We identify material cyber risks before you commit to deeper diligence or sign the term sheet.

  • · Dark web credential exposure check
  • · External attack surface scan
  • · Public breach history and digital footprint
Request the red flag scan

02

The 5-Day Cyber Diligence Sprint

~$45,000 · Full internal access

Deep-dive internal assessment yielding a Costed Remediation Roadmap. The roadmap gives the deal team a specific financial number to negotiate a price reduction.

  • · Internal network and Active Directory review
  • · Incident response and backup validation
  • · Regulatory compliance check (SOCI, Essential Eight)
  • · Deliverable: Costed Remediation Roadmap
Book the diligence sprint

03

Portfolio Cyber Governance

From $25,000/mo · Full portfolio

Post-acquisition vCISO service protecting the valuation of your investments: consistent governance standards across every portfolio company, one relationship, one report to the fund.

  • · Monthly portfolio governance execution
  • · Quarterly PE board reporting
  • · Annual cyber posture assessments across the portfolio
  • · On-call advisory for portfolio incidents
Secure the portfolio

Governing a single portfolio company on its own is the fractional leadership retainer itself: see Virtual CISO → for the entry-tier pricing. Portfolio Cyber Governance above is priced for the whole portfolio, not one company at a time.

M&A Deal Team Resource

The 10-Point Cyber Deal Breaker Checklist

A one-page data room checklist detailing what to look for that proves a target company is misrepresenting its security posture. Specific, actionable, and immediately useful for your next transaction. No form, no gate.

Download the checklist →

Transaction Support

Book a deal scoping briefing

Portrait of Dean Kastelic

Dean Kastelic

Former Enterprise CISO & KPMG Director

Dean acts as the cyber diligence lead for private equity funds acquiring mid-market assets, translating highly technical vulnerabilities into direct financial impact: leverage for the negotiating table.

"We operate at the speed of M&A. Book fifteen minutes to discuss an active target or a portfolio governance requirement. All briefings are strictly under NDA."
Book directly on calendar →

Or send the brief directly

Get the hard number before you sign the term sheet.

Fixed scope, strictly under NDA, led personally by a former enterprise CISO.