Vetting

Digital Vetting & Cyber Due Diligence

Cyber due diligence on the company, the counterparty or the asset you are about to acquire.

The situation

Before an acquisition, an investment, a major partnership or the onboarding of a high-value counterparty, someone should establish what they are actually buying.

We assess the target's security posture, exposed attack surface, breach history, regulatory exposure, technical debt and the cost of bringing it to an acceptable standard — and we express that as a number that belongs in the deal model. Post-deal, the same work becomes the integration security plan.

What the client receives

Schedule of deliverables

  1. 01External attack surface and exposure assessment (passive OSINT, no intrusive testing without mandate)
  2. 02Breach history and dark-web exposure review
  3. 03Regulatory exposure assessment (NIS2 / DORA / GDPR / CRA scope and gaps)
  4. 04Security debt remediation cost estimate for the deal model
  5. 05Red-flag report for investment committee
  6. 06Day-1 and Day-100 integration security plan

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • NIST CSF 2.0
  • ISO/IEC 27001
  • OSINT tradecraft
  • ISO 31000

Discuss this engagement

Tell us about the target, the access available and the transaction timetable and we will set out the scope, the method and the reporting format.

Contact us