← Consultancy
M&A cyber due diligence

Know the cyber risk before you sign

Independent cyber due diligence for investors and acquirers: external exposure, breach history, control maturity and the cost to fix, delivered to deal timelines.

Deal timelinesOutside-in & inside-outCost-to-fix estimatePost-deal integration
Target · Project HarbourRed-flag report
Exposure Internet-facing risk2 critical services exposed Red
Breach Breach historyCredentials in 3 leaks Amber
Controls Control maturityCIS IG1: 61% Amber
Cost Cost to remediateEstimated in 100-day plan Est.
Why it's different

Cyber risk priced into the deal, not discovered after

The usual way With Touchpoint
A questionnaire the target fills in Independent outside-in evidence, before access
Findings with no financial context Cost-to-fix estimates for the deal model
Weeks to report Red-flag report to deal timelines
Diligence ends at signing A 100-day plan and integration support after close
Portfolio risk unknown Ongoing exposure monitoring across portfolio companies
What we assess

Everything that affects value

External exposure What the target exposes to the internet today.
Breach & leak history Past incidents, leaked credentials and dark-web mentions.
Control maturity Against CIS Controls, ISO 27001 or NIST CSF.
Regulatory exposure GDPR, NIS2, DORA and sector obligations.
Technology debt Unsupported systems and integration risk.
Team & governance Who owns security and how it’s funded.
How it works

From outside-in to 100-day plan

  1. 01 Outside-in Passive review of exposure and breach history, no target access needed.
  2. 02 Inside-out Document review and management interviews in the data room.
  3. 03 Red flags Deal-breakers and price-affecting issues, reported fast.
  4. 04 Cost to fix Estimates for the deal model and SPA protections.
  5. 05 100 days A post-close plan, with our engineers available to deliver it.
What you get

Evidence for the investment committee

Clear enough for the deal team, detailed enough for the operating partner.

✓ Red-flag reportDeal-affecting issues, fast.
✓ Full diligence reportFindings, maturity and risk.
✓ Cost-to-fix estimateFor valuation and SPA.
✓ SPA recommendationsWarranties and conditions to consider.
✓ 100-day planPrioritised post-close actions.
✓ Portfolio viewComparable scoring across companies.
Engagement options

Match the deal stage

Pre-LOI Outside-in scan No target access needed.
  • ✓External exposure
  • ✓Breach history
  • ✓Red-flag summary
  • ✓48-hour turnaround
Get a fixed quote →
Most chosen Full diligence Outside-in plus data room.
  • ✓Management interviews
  • ✓Control maturity
  • ✓Cost-to-fix estimate
  • ✓SPA recommendations
Get a fixed quote →
Post-close Portfolio programme For PE firms and serial acquirers.
  • ✓100-day plan delivery
  • ✓Portfolio monitoring
  • ✓Quarterly maturity scoring
  • ✓Integration engineering
Get a fixed quote →
Questions

Before you ask

Do you need access to the target?+

Not for the outside-in stage. Full diligence uses the data room and management interviews.

How fast can you report?+

Outside-in red flags in about 48 hours; full diligence to the deal timeline.

Can you help after close?+

Yes. We can deliver the 100-day plan, including engineering work.

Is this confidential?+

Yes. We work under NDA, and the target need not know about the outside-in stage.

Price cyber risk into the deal

Tell us the target and the timeline. We’ll tell you what we can deliver by when.

Discuss a deal
Other consultancy services Penetration testing→ Cloud security→ Tabletop exercises→ vCISO→