M&A diligence,
see the security debt before you buy it.
A target's security posture rarely surfaces in the data room. Rate a company from the outside before diligence starts, with no access, no NDA gymnastics and nothing for the target to install.
Mergers and Acquisitions, step by step
Diligence finds it late
By the time a penetration test is commissioned, the price is agreed and the leverage is gone.
Rate before you engage
Score the target from public data alone, at any point in the process, without signalling interest.
Priced-in, not discovered later
Security debt becomes a line in the model rather than a surprise in month three.

Every vendor discovered and rated, grouped by risk tier so the ones that need attention stand out
Cyber diligence usually happens too late and sees too little
Technical due diligence on an acquisition tends to run late in the process, on a short clock, using whatever the target chooses to disclose. Under a signed NDA in a data room, you get documents: policies, an audit report if you are fortunate, a summary of the security team's own assessment.
What you rarely get is an independent view of what the target actually looks like from outside. That matters, because the liability you are buying is not what their policies say. It is their exposed infrastructure, the credentials of their staff sitting in breach dumps, the domains impersonating their brand, and whatever is already in their environment that nobody has found yet.
External rating changes the timing, which is the part that has value. You can assess a target before the approach, during the auction, and throughout the exclusivity period, with no access, no disclosure and no signal to anyone that you are looking.
Assessing a target without telling them
Because assessment uses only public information, a target can be rated before any conversation happens. For a corporate development team screening several candidates, that turns cyber posture into an input at the shortlist stage rather than a late-stage surprise.
It is worth being direct about what this is: legitimate open-source assessment of publicly published information, the same thing any competitor, journalist or attacker can do. Nothing is exploited and no system is accessed. It is not intrusion and it does not become intrusion because the motive is commercial.
The practical value is asymmetry of preparation. Arriving at diligence already knowing that a target has an unmanaged staging environment running unsupported software, or forty subdomains from a brand nobody has maintained since 2019, changes what you ask and what you can price.
What tends to be worth pricing
Some findings are cheap to remediate and should not move a number. Others carry integration cost that materially affects what the deal is worth.
Sprawl is the expensive one. A target with hundreds of unmanaged internet-facing assets across domains acquired in their own previous acquisitions is not a patching exercise; it is a discovery and rationalisation programme measured in quarters. Credentials in breach data suggest either a past compromise or password practices that will need addressing before integration. Brand impersonation infrastructure often indicates active targeting that will become your problem on day one.
The item that most often gets underpriced is technical debt in identity and mail. Fixing a target's mail authentication after integration, once their domains sit inside your estate, is markedly harder than it looks on a diligence checklist, and it is on the critical path for anything involving customer communication.
The acquired estate is now your attack surface
On completion the target's exposure becomes yours, generally before your tooling covers it. This is the most reliably under-managed window in corporate security: the acquired estate is outside the scanning scope, outside the asset inventory, and often outside the security team's awareness for months.
Continuous rating from day one closes it without waiting for integration. The acquired domains enter the portfolio immediately, findings get owners, and you have a defensible position on what was inherited versus what appeared afterwards, which matters when something goes wrong and the question of when it started is asked.
It also gives integration a measurable objective. Posture converging toward the parent's over two or three quarters is a concrete, reportable outcome, rather than integration being declared complete when the project plan runs out.
Where an external rating adds value across a deal
| Stage | Access available | What a rating provides |
|---|---|---|
| Screening | None | Posture as a shortlist input, no signal to the target |
| Approach | None | Specific questions to raise, before the data room |
| Diligence | Data room documents | Independent verification of what is disclosed |
| Exclusivity | Limited | Integration cost estimate for sprawl and debt |
| Completion | Full | Inherited exposure baselined on day one |
| Integration | Full | Convergence toward parent posture, measurable |
“We repriced one deal and walked away from another on what the rating showed us.”
Mergers and Acquisitions | common questions
Can we assess a target before approaching them?
Yes. Assessment uses only public information, so no relationship, permission or disclosure is required, and nothing signals that you are looking.
Is it legal to rate a company we have no relationship with?
It observes what an organisation publishes to the public internet, the same vantage point any visitor has. Nothing is exploited and no system is accessed. It is open-source assessment, not intrusion.
What findings should actually affect valuation?
Ones with integration cost rather than remediation cost. Hundreds of unmanaged assets across previously acquired domains is a multi-quarter programme; a lapsed certificate is an afternoon. Identity and mail debt is the item most often underpriced.
When should the acquired estate enter monitoring?
Day one. The window between completion and integration is the most reliably under-managed period in corporate security, because the acquired estate sits outside your scanning scope and asset inventory for months.
Does this replace technical due diligence?
No. It provides an independent outside-in view that data room documents cannot, and it is available far earlier. Internal controls, code quality and engineering practice still need conventional diligence.
Can we measure integration progress?
Yes, posture converging toward the parent's over two or three quarters is a concrete outcome, rather than integration being declared complete when the project plan runs out.
Where this connects
Own enterprise visibility →
Bringing an acquired estate into a single portfolio.
Dark web monitoring →
Credentials and brand exposure attributable to a target.
Third-party risk →
The vendors the target brings with them.
Put your vendors on the board
Start with ten vendors. Expand when the first alert pays for the year.