- 78%Third-party risk reduced
- 12 weeksFrom assessment to completion
- 0Incidents post-engagement
The challenge
A mid-size manufacturer was preparing for acquisition by a European group. Its exposure ran through a long tail of suppliers and OT vendors — none of it mapped, most of it unmonitored.
The acquirer’s board wanted assurance that cyber risk would not surface after close. A questionnaire would not provide it.
In an acquisition, a risk that does not appear in the data room does not disappear — it merely changes owner. The sensitive part was not the company’s own IT but the extended perimeter — integrators, remote maintainers and suppliers with access to production systems — where assumptions stood in for controls.
My approach
I ran an evidence-based assessment of the supplier base and operational technology, quantified the exposure that mattered, and separated it from the noise.
Findings became a prioritised, costed roadmap and a Day 1 plan — access, monitoring and the controls that could not wait — agreed before completion.
Over twelve weeks, the highest-impact issues were closed and the residual risk was documented for the board, usable with any counterparty.
In hindsight, the difference was not a score but a sturdier conversation: the acquirer knew what it was buying, and the seller was surprised by nothing at the table.
Related
You might also like
Third-party riskPre-transaction posture assessment of an insurance group
A security posture and third-party risk assessment ahead of a corporate transaction, distilled into a board-level roadmap with clear priorities and timelines.Insurance / M&A
Supply ChainSupply-Chain Risk for a Manufacturing Group
Suppliers mapped and continuously monitored, bringing third-party risk under control.Manufacturing
M&ACybersecurity in M&A: beyond the checklist
Why evidence-based due diligence changes deal outcomes.10 Feb 2026 · 2 min read
