Sell-side readiness: preparing a target for cyber diligence
Evidence, documentation and reducing the surprises that move price.

Most companies face a cyber diligence defensively: they answer questions as they arrive, hunt for documents at the last minute, and discover their own problems at the same moment the buyer does. That is the worst case for a seller, because every surprise that emerges under pressure tends to move the price in one direction only.
Sell-side readiness reverses the logic. If you are preparing a company for sale — whether you are the founder or the fund that controls it — you can run the cyber diligence before the buyer does, fix what is fixable and credibly document what remains. The goal is not to look perfect. It is to avoid being surprised.
Why preparation pays for the seller
In a negotiation, information asymmetry works against whoever discovers it last. If the buyer finds a gap you did not know about, that gap becomes theirs: they use it to renegotiate price, demand warranties or justify an indemnity. If instead you already know it, have put it in context and perhaps fixed it, their negotiating leverage shrinks.
Preparation does not eliminate real problems. But it shifts the moment they emerge from «during the negotiation, by surprise» to «earlier, on your terms» — and that difference is measured in value.
The evidence a buyer will look for
A serious buyer will not settle for your policies. They will look for evidence: how quickly you close critical vulnerabilities, where multi-factor authentication is enforced, how you manage privileged access, whether backups of critical systems are tested, how you handled past incidents, and which regulatory obligations apply to you.
It is worth building this dossier in advance, viewing it through the eyes of whoever will buy. Every claim should be supportable by a data point or a document. Where evidence is missing, it is better to know first and decide whether to fill the gap or explain it.
One often-neglected aspect is temporal consistency: the evidence should tell a continuous story, not a snapshot taken the week before the process. An attentive buyer can tell a programme that has worked for months from one assembled quickly for the sale, and the second impression is hard to correct.
Documenting without inflating
There is a temptation, when selling, to make the security programme look more mature than it is. It is counterproductive. A competent buyer validates what you tell them, and every discrepancy between claim and reality erodes trust across the whole negotiation, not just on the specific point.
Effective documentation is accurate and proportionate: it describes controls as they really are, acknowledges known gaps and shows a credible plan to address them. A seller who says «here is what works, here is what we are improving and by when» is stronger than one who claims a perfection that does not survive verification.
Reducing the surprises that move price
Not every gap can be closed before a sale, but the most expensive ones often can. Some actions have a very favourable value-to-time ratio in the months before a process: removing orphaned and no-longer-justified third-party access, enforcing MFA on critical systems where it is missing, verifying that backups are restorable, closing the most obvious external exposures, and putting the documentary history of incidents in order.
These are exactly the areas where diligence tends to stumble. Addressing them in advance removes the findings that, once found by the buyer, would have turned into discounts or warranties.
An honest vendor due diligence
In some deals the seller commissions its own diligence — a vendor due diligence — to share with prospective buyers. Done honestly, it accelerates the process and reduces uncertainty for both sides. Done to conceal, it backfires: a buyer who discovers a sanitised report will stop trusting everything else.
The value of a vendor due diligence lies in its credibility. A report that acknowledges the real weaknesses and places them in a plan is a negotiating asset; one that omits them is a latent liability.
The takeaway
Preparing a target for cyber diligence means doing in advance, on your terms, the work the buyer would otherwise do under pressure during the negotiation. Gather the evidence, document accurately, close the low-cost high-impact gaps, and be honest about what remains. Surprises move price; preparation takes them off the table.



