M&A Security Due Diligence
You are about to inherit someone else's infrastructure, their technical debt, and any compromise already sitting inside it. Independent technical diligence, sized to the deal clock and scoped to what actually moves price.
Security findings are priced late or not at all
Financial and legal diligence are established disciplines with defined scopes. Technical security diligence frequently reduces to a questionnaire and a request for the target's most recent certification, both of which the target controls.
The gap between what a target reports and what is true is not usually deception. It is that nobody adversarial has looked. A current SOC 2 report and an unauthenticated administrative interface coexist comfortably, because one is a statement about controls and the other is a fact about the internet.
When the gap is discovered after close it is priced anyway, through remediation spend, an extended integration window, or a breach in the first year of ownership. Verizon's 2017 acquisition of Yahoo was repriced by $350 million following disclosure of prior breaches, which is the publicly documented illustration of a cost that is ordinarily absorbed quietly.
Buy-side and sell-side
The work is the same; what it is for is not. We act for one side of a given transaction.
Buy-side: PE and corporate development
Establish what you are inheriting before capital moves, and attach a number to it that survives contact with the seller.
Sell-side: exit preparation
Find what a buyer's diligence would find, early enough to fix it quietly.
Engagement types this combines
A solution is not a separate capability. It is the engagement types from Services sequenced against a specific situation: here, a deal deadline.
Penetration Testing
Hands-on testing of the target's applications, APIs, and cloud estate. Establishes what is genuinely exploitable, which is what materiality has to be argued from.
View engagementSecurity Consulting
Architecture and program assessment, remediation cost estimation, and the integration view. Turns technical findings into deal-relevant numbers.
View engagementWhat gets assessed
Prioritised by deal impact. On a compressed window the lower half of this list is explicitly excluded.
Infrastructure and cloud
- Externally reachable surface and exposed services
- Cloud identity model and escalation paths
- Network segmentation between environments
- Patch currency on internet-facing systems
- Recovery capability and backup integrity
Application and product
- Testing of the primary revenue-generating application
- API authorization and tenant isolation
- Development practice and review discipline
- Dependency exposure and supply chain hygiene
- Known vulnerability backlog and its age
Data handling
- What sensitive data exists and where it actually sits
- Encryption at rest and in transit
- Access control over customer data
- Retention and disposal practice against stated policy
- Prior breach history and how it was handled
Identity and access
- Privileged access management and its actual use
- MFA coverage on administrative identities
- Access review practice
- Contractor and vendor access still live
- Orphaned accounts and accumulated privilege
Governance and compliance
- Certification status, and what its scope actually covers
- Outstanding audit findings and their age
- Policy documentation versus observed practice
- Vendor risk management
- Regulatory exposure inherited on close
Detection and response
- Logging coverage and retention
- Whether anyone monitors what is collected
- Incident response capability and whether it has been used
- Past incidents and their handling
- Indicators of an unreported active compromise
How the engagement runs
Durations compress against the deal clock. What compression removes is coverage, and the report says which coverage was removed.
01
Confidential discovery
30-45 minutes
Transaction stage, diligence deadline, which side we would act for, and what a dealbreaker would look like for you specifically. Confidential regardless of whether the engagement proceeds.
Output: Agreement on objectives, timeline pressure, and whether we are the right diligence partner.
02
Scope against the deal clock
1-2 days
The investment thesis determines what matters. A platform acquisition where the product is the asset scopes differently from an acqui-hire. We align with counsel, agree the access plan, and state up front what a short window will exclude.
Output: Rules of engagement, access plan, and an explicit statement of what will not be covered.
03
Documentation and external reconnaissance
2-3 days
Data room materials, prior audits, incident records, and architecture documentation, read against what the external surface actually shows. Discrepancies between the two are frequently the most informative finding available.
Output: Annotated documentation review, external surface picture, and the questions to put to management.
04
Technical assessment
1-2 weeks
Hands-on testing of the systems that carry the value or the risk. Prioritised by what would change the price or the integration cost, not by comprehensive coverage. Comprehensive coverage is not available on a deal clock, and pretending otherwise is how diligence misses things.
Output: Validated technical findings with evidence, each mapped to a materiality judgement.
05
Management interviews
2-4 days
Engineering, IT, and compliance leadership walk through how things actually operate. The purpose is to test whether documented practice matches observed practice, and to gauge whether the capability survives the retention risk of the transaction.
Output: Capability readout, including which findings depend on individuals who may not stay.
06
Materiality and cost
3-5 days
Each finding is costed to remediate and ranked by deal impact: what must be fixed before close, what is a first-90-days problem, what is a price adjustment, and what is genuinely acceptable to carry.
Output: Materiality matrix with remediation cost estimates and integration blockers identified.
07
Reporting and presentation
2-3 days
An executive narrative a non-technical committee member can act on, with the technical basis in an appendix. Delivered live so it can be challenged in the room.
Output: Diligence report, technical appendix, and the talking points for the deal committee.
08
Post-close support
Optional, first 90 days
Where the deal proceeds: oversight of the remediation that was priced in, integration sequencing, and validation that what was supposed to be fixed was fixed.
Output: Integration roadmap with owners, milestones, and validation checkpoints.
What you receive
Written to be taken into a deal committee without translation, and to hold up if the counterparty disputes it.
Executive summary
- Material risks, separated from everything else
- Severity with the materiality reasoning shown
- Remediation cost estimate per material finding
- Implication for price and deal structure
- Integration complexity assessment
- Explicit statement of what was not examined
Technical appendix
- Each finding with evidence and reproduction
- Exposure inventory across the estate
- Architecture and design-level issues
- Technical debt quantified in remediation effort
- Access level each finding was reached under
Remediation plan
- What must be fixed before close
- What belongs in the first 90 days post-close
- Cost and timeline estimate per item
- Resourcing required, including whether it exists in the target
- What is reasonable to accept and carry
Integration view (buy-side)
- Security integration sequencing
- System consolidation dependencies
- Compliance harmonisation requirements
- Retention risk on security-critical individuals
- Tooling and vendor overlap
What we need to quote
The deadline and the available access level determine everything else. Both are worth stating in the first message.
- →Which side you are on, and whether the counterparty knows diligence is happening.
- →Transaction stage and the diligence deadline, stated as a date.
- →Investment thesis: what you are actually buying, whether that is product, customers, team or revenue.
- →Access available: data room only, management presentations, or live environment.
- →What the target's technology estate looks like, to whatever resolution you have.
- →Prior security artefacts the target has produced, and their dates.
- →What a dealbreaker looks like for you, and what is merely a price adjustment.
- →Counsel contact, for the information barrier and engagement letter.
Common questions
How early should security diligence be engaged?+
Before the LOI where possible. Post-LOI, the clock constrains scope, and scope constraints are exactly what a target with something to hide benefits from. Pre-LOI work using public reconnaissance and limited data room access can surface a dealbreaker before capital is committed.
Can you work inside a compressed diligence window?+
Yes, with an explicit trade. On a short window we prioritise material risk over coverage: the systems that hold the data, the identity model, and the externally reachable surface. The report states plainly what was not examined, so nobody mistakes silence for a clean result.
How is confidentiality handled between buyer and seller?+
Separate engagement letters and counsel-approved information barriers. We will not act for both sides of the same transaction.
What if the target will not grant full access?+
Normal in early diligence. We work from data room materials, external reconnaissance, and management presentations. Every finding is qualified by the access level it was reached under, and limited access is itself reported as a finding.
What if you find something that kills the deal?+
Better before close than after. The report gives the evidence and a remediation cost estimate, which is what a renegotiation or a walkaway is argued on.
Why not rely on the target's own security team?+
They may be competent and still have blind spots, and they have an obvious incentive not to surface material problems during their employer's sale. An independent adversarial read either corroborates their account with evidence or does not.
Why an offensive security practice rather than a general consulting firm?+
Because the question in diligence is exploitability, not policy coverage. A target can hold a current SOC 2 report and an exposed administrative interface at the same time. We test the second thing.
Do you support the period after close?+
Optionally. Remediation oversight and integration sequencing for the first 90 days, scoped separately once the deal has actually closed.
How to start
Send the side you are on, the deadline, and the access you have. The first conversation is confidential whether or not it leads anywhere.
Direct: hello@principlebreach.com