Vetting
Digital Vetting & Cyber Due Diligence
Cyber due diligence on the company, the counterparty or the asset you are about to acquire.
The situation
What the client receives
Schedule of deliverables
- External attack surface and exposure assessment (passive OSINT, no intrusive testing without mandate)
- Breach history and dark-web exposure review
- Regulatory exposure assessment (NIS2 / DORA / GDPR / CRA scope and gaps)
- Security debt remediation cost estimate for the deal model
- Red-flag report for investment committee
- Day-1 and Day-100 integration security plan
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- NIST CSF 2.0
- ISO/IEC 27001
- OSINT tradecraft
- ISO 31000
Related services
Discuss this engagement
Tell us about the target, the access available and the transaction timetable and we will set out the scope, the method and the reporting format.