Security risk you inherit

Third-Party & M&A Security Due Diligence

This is the security half of diligence, not the financial, tax or commercial half. A vendor security program that scales past a spreadsheet, and cyber due diligence on acquisitions, so you find out what you are buying before the wire clears rather than after integration.

The situation

Most of your risk now sits on someone else's infrastructure

  • Vendor reviews are a questionnaire nobody reads, filed by nobody in particular.
  • You're acquiring a company and have two weeks to judge its security debt.
  • A fourth-party outage took you down and you had no idea the dependency existed.

What we do

  • Build a tiered vendor risk program proportionate to actual data and access exposure
  • Run assessments on critical vendors, including the ones already embedded
  • Set security requirements and contract language: DPAs, right to audit, breach notice, SLAs
  • Map concentration and fourth-party dependency risk
  • Perform pre-close security due diligence on acquisition targets
  • Quantify remediation cost and integration risk as a deal input
  • Plan post-close integration: identity merge, network join, control harmonization
  • Support divestiture and carve-out separation without leaving doors open
  • Work alongside your financial, tax and legal diligence teams, covering the security scope only
Deliverables

What you actually receive.

Artefacts your team can operate after we leave, not a slide deck and a wave goodbye.

DeliverableWhat it contains
Vendor risk programTiering model, assessment workflow, SLAs and the reassessment calendar
Critical vendor assessmentsFindings and required remediation per vendor, with contract hooks
Contract security scheduleReusable language your legal team can drop into every agreement
Diligence reportTarget's posture, material findings and quantified remediation cost
Integration planDay-1, day-30 and day-90 security actions with owners
Concentration risk mapWhere a single third or fourth party would take you down
Ways to engage

Sized to the problem in front of you.

4–8 weeks

TPRM program build

Program design, tooling and first wave of assessments.

1–3 weeks

Deal diligence

A focused cyber review delivered inside the timetable the deal sets.

3–6 months

Integration support

Post-close security integration run alongside your team.

Talk it through with someone senior

Thirty minutes on your situation specifically, what is driving the timeline, what you have already tried, and what we would do first.