Third-Party & M&A Security Due Diligence
This is the security half of diligence, not the financial, tax or commercial half. A vendor security program that scales past a spreadsheet, and cyber due diligence on acquisitions, so you find out what you are buying before the wire clears rather than after integration.
Most of your risk now sits on someone else's infrastructure
- Vendor reviews are a questionnaire nobody reads, filed by nobody in particular.
- You're acquiring a company and have two weeks to judge its security debt.
- A fourth-party outage took you down and you had no idea the dependency existed.
What we do
- Build a tiered vendor risk program proportionate to actual data and access exposure
- Run assessments on critical vendors, including the ones already embedded
- Set security requirements and contract language: DPAs, right to audit, breach notice, SLAs
- Map concentration and fourth-party dependency risk
- Perform pre-close security due diligence on acquisition targets
- Quantify remediation cost and integration risk as a deal input
- Plan post-close integration: identity merge, network join, control harmonization
- Support divestiture and carve-out separation without leaving doors open
- Work alongside your financial, tax and legal diligence teams, covering the security scope only
What you actually receive.
Artefacts your team can operate after we leave, not a slide deck and a wave goodbye.
| Deliverable | What it contains |
|---|---|
| Vendor risk program | Tiering model, assessment workflow, SLAs and the reassessment calendar |
| Critical vendor assessments | Findings and required remediation per vendor, with contract hooks |
| Contract security schedule | Reusable language your legal team can drop into every agreement |
| Diligence report | Target's posture, material findings and quantified remediation cost |
| Integration plan | Day-1, day-30 and day-90 security actions with owners |
| Concentration risk map | Where a single third or fourth party would take you down |
Sized to the problem in front of you.
TPRM program build
Program design, tooling and first wave of assessments.
Deal diligence
A focused cyber review delivered inside the timetable the deal sets.
Integration support
Post-close security integration run alongside your team.
Talk it through with someone senior
Thirty minutes on your situation specifically, what is driving the timeline, what you have already tried, and what we would do first.