Skip to content
Solvex Space
Governance / CompliancePrivate equity / software acquisition3-week diligence window

Cyber due diligence that repriced an acquisition before signing

Mid-market PE firm acquiring a ~$40M vertical-software company

A private equity firm was days from a letter of intent on a vertical-software company when passive assessment surfaced exposed credentials, an unreported historical intrusion and an estate of end-of-life systems. The findings didn't kill the deal — they repriced it: remediation cost moved into the purchase price, cyber warranties into the agreement, and a 100-day security plan into the closing conditions.

Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.

Red-flag summary delivered
day 6
inside the deal team's decision window
Material findings surfaced pre-signing
3
including an unreported historical intrusion
Remediation estimate negotiated into terms
7-figure
priced into the deal, not inherited blind
Post-close roadmap
100 days
identity, network and monitoring integration sequenced

The challenge

  • The deal team had financial and legal diligence covered but no independent view of the target's security posture.
  • The target's data room presented a clean self-assessment with no third-party evidence behind it.
  • The diligence window was three weeks, with the red-flag deadline inside the first.

What we did

  • Ran passive external assessment of the target's estate — exposure, leaked credentials, breach-history indicators — with no contact with target systems.
  • Reviewed the data room's security program evidence against what the external picture actually showed.
  • Quantified the top risk scenarios as loss-exposure ranges so the deal team could negotiate in financial terms.
  • Delivered the red-flag summary inside week one and fed the follow-up question set into the data-room process.
  • Built the 100-day post-close integration roadmap covering identity consolidation, network separation and monitoring.

The outcome

  • Findings moved directly into the negotiation: estimated remediation cost was reflected in the price, and cyber representations and warranties were strengthened.
  • An unreported historical intrusion surfaced before signing rather than after, when it would have been the buyer's problem and reputation.
  • The acquirer entered day one with a sequenced security integration plan instead of a discovery project.
We price working capital risk, legal risk, customer concentration — pricing cyber risk the same way should have been obvious years ago. This paid for itself before the LOI.
Operating Partner, mid-market PE firmIllustrative — composed to show the kind of feedback this work draws, not a quotation from a named client.
M&A Cyber Due Diligence | Case Study — Solvex Space