Buy-side cyber due diligence: beyond the questionnaire

Identifying material risks, validating controls and quantifying exposure to support valuation and price.

A due diligence questionnaire tells you what the target’s management believes about its own controls. That is a starting point, not a conclusion. When you buy a company you also buy its security debt, its undeclared exposures and the odds that an incident lands in the months after close. None of that surfaces from a checklist the seller filled in.

Serious buy-side cyber due diligence starts from a different premise: evidence matters more than assertions. Your goal is not to collect answers but to understand how much the risk you are about to take on is really worth — and whether that risk moves the valuation, the terms, or your decision to proceed.

Beyond the questionnaire

The questionnaire is still useful for one reason: it structures the conversation and tells you where the target is aware of its own gaps. But self-attestation has three known limits. It reflects what management believes, not what is configured in production. It covers documented controls, not the ones actually operating. And it rarely captures the exposures no one inside is watching: the forgotten asset, the shared credential, the vendor access never revoked.

The advisor’s job is to close that gap. Don’t ask whether a patch-management policy exists; look at the median remediation window on critical vulnerabilities over the last twelve months. Don’t ask whether MFA is in place; verify which systems enforce it and where it can be bypassed.

A practical principle helps decide where to look: follow the value. Where revenue, regulated data and operational dependencies concentrate, so does the risk that matters. Everything else can wait for ordinary work after close, and telling the two apart is half the craft.

Identifying material risks

Material means one thing: capable of moving value or the decision. In a time-boxed diligence you cannot look at everything, so you must prioritise what carries real economic or legal impact. In practice that means focusing on a few recurring areas: the internet-exposed surface, identity and access management, protection of regulated data, continuity of the processes that generate revenue, and the history of past incidents.

A prior incident that was handled poorly is often the most informative signal you will find. It tells you how the company detects, decides and recovers under pressure — and whether a breach that already happened could still produce notification duties, litigation or penalties that you would inherit.

Validating controls, not policies

A policy is an intention. A control is a configuration that is either active or not. The most valuable part of technical diligence is validation: taking the key claims and comparing them against the real state of the systems, as far as the deal perimeter allows.

Where permitted, passive external reconnaissance and a review of the key configurations — identity provider, cloud posture, endpoint management, segmentation — say more than a hundred questionnaire answers. Where the seller restricts access, the restriction is itself data: what they won’t let you verify tends to be what you should weigh most cautiously.

Quantifying exposure

A list of findings without numbers does not help a board decide. The step that sets useful diligence apart is translating risk into an economic range: what it would cost to remediate the structural gaps over the first 12-18 months and what expected loss is associated with the most likely scenarios.

You don’t need false precision. You need a defensible order of magnitude, built on likelihood and impact, that separates the issues which move price — remediation in the hundreds of thousands or millions, concrete legal liabilities — from the noise that ordinary hygiene resolves after close.

From report to price

The output of diligence is not a document: it is a negotiating position. Material, quantified findings can translate into a price adjustment, targeted representations and warranties, a specific indemnity or closing conditions. They can also become the basis of the Day 1 plan, so the acquirer inherits a plan instead of a surprise.

The value of this work is not finding problems. It is giving the decision-maker an honest picture of the risk they are buying, expressed in the language of the deal.

The takeaway

Treat cyber due diligence as part of the deal, not a formality alongside it. Go beyond the questionnaire, validate controls rather than policies, quantify what you find and report it in terms of price and decision. That is how evidence protects a valuation.

From reading to deciding

Turn this into a decision you can defend.

A confidential 30-minute conversation to apply it to your situation — or start from a practical resource.