ServicesVantageIndustriesCase StudiesInsightsAboutContactSchedule a Consultation
Home / Insights / Private Equity

What PE Firms Should Ask About Cybersecurity Before Close

The diligence questions that reveal real risk — and the ones that just generate paperwork.

Most cyber due diligence I have seen produces a document nobody reads after the deal closes. A questionnaire goes out, the target’s IT lead fills it in as favorably as honesty allows, a consultant scores the answers, and the deal team gets a heat map that says “medium.” Nothing in that process changes the price, the reps and warranties, or the first hundred days.

That is not because cybersecurity does not matter to the deal. It is because the questions were the wrong ones. Here are the ones that actually move the number.

Start with what the business runs on, not what the policy binder says

A policy is a statement of intent. What you are buying is the systems, the data, and the people who operate them. So the first questions are about inventory:

  • Which systems, if they went down for a week, would stop revenue? Who administers them, and what happens if that person leaves at close?
  • Where does customer data live, who can reach it, and does anyone know for certain?
  • Which vendors have access to the environment, and who reviews that access?

If the target cannot answer these in a first meeting, that is the finding. You do not need a scan to know that a company that cannot list its own systems is not protecting them consistently.

Ask about the last incident, not whether there has been one

“Have you experienced a breach?” invites a “no.” A better question is: “Walk me through the last security incident of any size, what you did, and what changed afterward.” Every operating company has had something: a phishing compromise, a lost laptop, a vendor outage, a ransomware attempt that the backups handled.

The answer tells you three things at once. Whether the target detects incidents at all. Whether it has a working process when it does. And whether leadership is candid, which matters more than any control.

Separate the compliance question from the security question

SOC 2 reports, HIPAA attestations, and PCI DSS letters are useful, and you should read them rather than check that they exist. Read the scope section first. A SOC 2 that covers one product and excludes the acquisition’s corporate environment says very little about the corporate environment. Read the exceptions. Read the bridge letter dates.

Then ask a different question: if the target had no compliance obligation at all, what would it still be doing to protect the business? Companies that only do what an auditor asks for tend to have gaps exactly where the audit does not look, and that is usually where the operational risk sits.

Price the remediation, not the risk

The heat map is where most diligence stops. The useful next step is a remediation estimate: what it would cost, in dollars and months, to bring the target to the standard the fund expects across its portfolio. That number can go into the model. “Medium risk” cannot.

A good remediation estimate separates three buckets:

  1. Must fix before or at close. Anything that creates immediate legal exposure or that the buyer’s own insurers and customers will not accept.
  2. First 100 days. Identity and access cleanup, backup verification, endpoint coverage, the basics that reduce the chance of a bad first year.
  3. Portfolio standard. The longer program that brings the company to the level the fund holds every platform to.

Ask who owns security after close

Founder-led companies often have security living in the founder’s head or in a single IT contractor. When the founder rolls equity and steps back, that knowledge goes with them. Ask explicitly: who will own this on day one, and is that a role the company already has or one you are going to have to fund?

This is where the diligence connects to the value-creation plan. If the answer is “nobody yet,” the cost of the answer belongs in the model, alongside the CFO hire and the ERP migration.

The questions that mostly generate paperwork

Some questions are worth asking only if you intend to act on the answer:

  • Long control questionnaires with hundreds of yes/no items. The target will answer “yes” to most of them. Sample five and verify instead.
  • Requests for every policy document. Ask for the three that matter (access control, incident response, vendor management) and read those.
  • Penetration test reports older than a year, without the retest. The findings are stale and the fix status is unknown.

What good looks like

A diligence engagement that earns its fee gives the deal team a short list of material findings with dollar and time estimates, a clear position on whether anything should affect price or terms, and a day-one plan that the new leadership can actually execute. It fits on a few pages, it is written for a partner rather than a security engineer, and someone reads it after close.

That is what we build our M&A cyber due diligence around. If you have a deal in process and want a second opinion on the questions, a scoping call takes an hour.

More insights

This site