Photo: Homa Appliances / Unsplash

Case Study · Manufacturing

Industrial Equipment Manufacturer

  • M&A
  • Third-Party Risk
  • Europe
  • 78%Third-party risk reduced
  • 12 weeksFrom assessment to completion
  • 0Incidents post-engagement

The challenge

A mid-size manufacturer was preparing for acquisition by a European group. Its exposure ran through a long tail of suppliers and OT vendors — none of it mapped, most of it unmonitored.

The acquirer’s board wanted assurance that cyber risk would not surface after close. A questionnaire would not provide it.

In an acquisition, a risk that does not appear in the data room does not disappear — it merely changes owner. The sensitive part was not the company’s own IT but the extended perimeter — integrators, remote maintainers and suppliers with access to production systems — where assumptions stood in for controls.

My approach

I ran an evidence-based assessment of the supplier base and operational technology, quantified the exposure that mattered, and separated it from the noise.

Findings became a prioritised, costed roadmap and a Day 1 plan — access, monitoring and the controls that could not wait — agreed before completion.

Over twelve weeks, the highest-impact issues were closed and the residual risk was documented for the board, usable with any counterparty.

In hindsight, the difference was not a score but a sturdier conversation: the acquirer knew what it was buying, and the seller was surprised by nothing at the table.

A similar situation?

Start with a confidential briefing.

Book a consultation