Back to Blog

Cyber Diligence in a Q3 Close: The 5-Day Version

What a compressed cyber diligence honestly delivers in five business days — Tier-1 exposure analysis, vendor concentration, data sensitivity, and a defensible Cyber Cost of Deal number. What you cut, what you can't safely cut, and where the compression breaks down into pretend work.

Quick Answer

What a compressed cyber diligence honestly delivers in five business days — Tier-1 exposure analysis, vendor concentration, data sensitivity, and a defensible Cyber Cost of Deal number. What you cut, what you can't safely cut, and where the compression breaks down into pretend work.

The Q3 close is September 30. Deal teams doing an August or September signing on a company they started diligence on in late July are running a compressed diligence window on the cyber side whether they meant to or not. This piece walks through what a five-business-day cyber diligence looks like, what you get, what you cut, and where the compression breaks down into pretend work if you cut past a certain point.

The premise most PE deal teams operate on is that cyber diligence is a checkbox item that fits in a two-day sprint at the tail end of the confirmatory phase. That premise held when the number a diligence report was expected to produce was a qualitative letter grade and the acquirer's exposure was theoretical. It has stopped holding. The recent case law around acquirer liability for pre-close cyber conduct — Bain / PowerSchool being the one that changed the legal posture — puts a dollar figure on what happens when the target's cyber posture turns out to be worse than diligence indicated. The deal team's job is now to produce a number the audit committee can sit with, not a letter grade.

5 days
Minimum for defensible CCOD without target cooperation
$1.5-5M
CCOD range where price adjustment typically negotiable on mid-market
24 mo
Typical escrow tail for cyber-specific reserves

What five business days should actually produce

A five-day cyber diligence should deliver five artifacts: an external attack-surface assessment with dollarized loss exceedance; a vendor concentration analysis with the top-five critical vendors named and their incident-notification SLAs pulled from the actual contracts; a data-sensitivity assessment for the target's largest data categories with regulatory exposure priced; a summary of the target's insurance coverage and policy limits against the exposures found; and a single Cyber Cost of Deal number with a written basis. Everything else is nice-to-have.

The compression trade-off, upfront

The normal cyber diligence window on a mid-market deal is fifteen to twenty business days. In that window, a full diligence produces: internal-and-external attack-surface analysis, control-effectiveness testing based on documentation review and interviews, a full vendor risk pull with 200-question questionnaires sent and reviewed, a data-inventory verification with sample-based validation, a technical debt assessment on legacy infrastructure, an incident-history review going back three to five years, and a fully-costed CCOD with sensitivity analysis on the top three risk drivers. That is the twenty-day version.

The five-day version cannot do all of that. What it can do well is the subset that produces a credible number without target cooperation. What it cannot do is the parts that depend on documents the target has not yet produced, interviews with people who have not yet returned calls, or scans that require legal authorization that has not yet cleared general counsel.

Fits in 5 days
Requires 15-20 days
External attack surface (Tier-1 observation)
Internal network scanning with target authorization
Public vendor concentration + top-5 contract pulls
Full vendor questionnaire round (200 questions each)
Data inventory triangulation from public filings
Sample-based data classification verification
CCOD from Tier-1 inputs with named assumptions
CCOD with sensitivity analysis + assumption testing
Insurance coverage vs. exposure summary
Broker interview + prior-claims history review

Days one and two: what gets cut, and what doesn't

The first thing that comes out of a compressed diligence is the target-cooperation piece. In a normal window, days one and two are for interviews with the target's security lead, walkthrough of the SOC 2 or ISO 27001 report if one exists, and a preliminary vulnerability scan against systems the target has authorized. In a compressed window, the target's security lead is on vacation, the SOC 2 arrives on day four, and the vulnerability scan requires an authorization letter that has to travel through the target's general counsel and does not come back in time.

What replaces it is Tier-1 external observation: the parts of the attack surface that are directly observable without any target cooperation. Public DNS records, exposed management interfaces, TLS posture, email authentication (SPF, DKIM, DMARC), credential-exposure searches against HaveIBeenPwned and stealer-log corpora, subdomain enumeration, and cloud-service fingerprinting. This is not a substitute for the cooperative view. It is the floor on what can be said with confidence in the window available.

The output of days one and two is a Tier-1 exposure report with a probability-weighted expected annual cost. This is defensible in an audit committee because every input is externally verifiable: anyone can rerun the analysis and get within a small tolerance of the same numbers.

The Tier-1 signals worth surfacing

Not everything observable is worth reporting. The signal-to-noise ratio matters when the audit committee is sitting with the memo. The Tier-1 items that consistently move CCOD are: exposed remote management (RDP, SSH, or admin panels reachable from the public internet, each one a Known Exploited Vulnerabilities candidate); DNS misconfiguration allowing subdomain takeover (typical loss scenario: brand impersonation costing $200K-$2M depending on customer base); TLS posture below industry median (SSL Labs grade below A means the target has not patched their edge in the last twelve months, which correlates with a broader patch-hygiene problem); missing or lax DMARC (baseline for email-based fraud losses, and a named carrier ask in cyber insurance renewals); and credential exposure in stealer-log corpora (each exposed corporate credential is a candidate account-takeover path).

What is NOT worth surfacing in the memo: the target's WHOIS registration privacy settings, the exact CMS platform of the marketing site, the number of open ports on random development systems, or theoretical CVE counts without weaponization context. These bloat the report and dilute the number that the deal team needs to defend.

Day three: vendor concentration, priced

Vendor risk work in a five-day window is not a 200-question questionnaire round. It is a targeted pull of the target's top-five most-critical vendors, verification that the vendor's SOC 2 Type II is current (not the one from 2023), extraction of the incident-notification SLA from the actual MSA, and a Herfindahl-Hirschman concentration analysis on the vendor spend.

The number that comes out of day three is a Max Single-Vendor Loss figure, adjusted upward by a concentration penalty if the HHI crosses the moderate or high thresholds. A moderately concentrated vendor base (HHI between 1500 and 2500) adds a ten-percent uplift on Max Single-Vendor Loss. A highly concentrated one (HHI over 2500) adds twenty-five percent. This is where the acquirer discovers that the target has bet the business on a single payment processor with a 72-hour notification SLA and no material breach liability cap in the contract.

What "top-five critical" means, in practice

The five vendors that get the day-three treatment are not the five largest by spend. They are the five whose failure would interrupt the target's business or expose the target to a reportable breach. That usually breaks down as: primary cloud provider (AWS/Azure/GCP), primary payment processor (Stripe/Braintree/Adyen), primary identity provider (Okta/Auth0/Azure AD), primary email/collaboration platform (Google Workspace/Microsoft 365), and one industry-specific critical vendor that varies by target (e.g., core banking platform for a fintech, EHR for a healthtech, LMS for an edtech).

The artifacts the day-three worker needs from each: current SOC 2 Type II (Type I is not sufficient; the target's insurance carrier already knows this), the incident-notification SLA in the executed MSA (not the marketing page), the data-processing addendum with liability caps, and the sub-processor list with the target's approval workflow. If any of the five vendors are missing any of these four artifacts, that becomes a named line item in the CCOD.

Day four: data sensitivity and regulatory exposure

Day four is a data-inventory triangulation from public sources: the target's privacy policy, its terms of service, its SEC filings if it has them, and the incident-notification statutes that would apply to the jurisdictions it operates in. The output is a Probable Maximum Loss figure at a 95th-percentile confidence level, decomposed into notification cost, litigation cost, regulatory penalty, and business-interruption cost.

The compressed version of this analysis makes assumptions that the cooperative version would verify. For example, that the record count for a given data category matches what the privacy policy implies. Those assumptions are named explicitly in the report so the deal team can decide whether to reserve against them or press for post-close verification as a condition.

The regulatory exposure model, in brief

PML calculations at a 95th-percentile confidence for a breach with regulatory exposure typically use IBM's Cost of a Data Breach Report as the baseline anchor, adjusted by the target's jurisdictional footprint. Healthcare data in a HIPAA-covered environment carries a $250-$500 per-record notification cost with HHS OCR penalty exposure up to $2M per calendar year per violation type. Payment card data under PCI DSS carries $50-$100 per-record forensics cost with card-brand assessments that can reach $500K per event. General PII in a jurisdictionally-mixed footprint (US state statutes plus GDPR-covered EU residents) carries the highest per-record cost because the notification obligations stack. The target sends different letters, at different intervals, to different regulators, in different formats.

The PML figure is less important than the decomposition. The audit committee wants to know which data category drives the number so they can decide if the deal thesis needs to change. If the target's US-Europe revenue mix means GDPR exposure is 60% of PML, that changes the appetite for the deal at all.

Day five: the number, the basis, and what the deal team does with it

The single output

Cyber Cost of Deal (CCOD), decomposed into Risk Cost (the expected annual dollar loss from the target's current cyber posture) and Remediation Cost (what it takes in the first twelve months post-close to bring the posture to the acquirer's standard). A CCOD number without both decompositions and a written methodology is a letter grade with a dollar sign attached, not a defensible figure.

The deal team uses the CCOD number in one of three ways. It moves against the purchase price as a direct reduction. It becomes the basis for an escrow reserve against post-close cyber events for a defined tail period. Or it becomes the basis for a closing condition: the target agrees to remediate a named set of findings between signing and closing, verified by the diligence firm at close.

What the deal team does not do with a credible CCOD number is nothing. If cyber diligence produces a number and it does not influence the term sheet, the target has learned that the diligence was theater. The next cyber diligence they see, from a different acquirer, will get the same treatment.

The three uses, and when each fits

The full trade-off between R&W insurance, price reduction, and escrow reserve gets its own treatment, but here are the short versions.

Price reduction. Fits when the CCOD is meaningfully above the acquirer's threshold and the target has flexibility on price. A CCOD of $1.5M-$5M on a mid-market deal is typically in the range where a purchase-price adjustment is negotiable. Above that, the deal starts to lose economic sense; below that, the transaction friction of renegotiation exceeds the value moved.

Escrow reserve. Fits when the deal team is unable to fully verify the target's posture in the diligence window (typical of the five-day version) and wants a tail hedge. Escrow amounts typically range from 25% to 100% of CCOD, held for a tail period of 12-24 months post-close. The escrow releases if the specified cyber events do not occur; it funds remediation or losses if they do. The advantage: preserves the deal economics if the target's posture is actually better than diligence indicated. The disadvantage: locks up capital and adds legal complexity.

Closing condition. Fits when the diligence surfaces remediable findings that the target can fix between signing and closing. Typical examples: "close the six externally-reachable RDP ports before close," "execute the missing BAA with the healthcare-data subprocessor before close," "produce the current SOC 2 report or extend the SOC 2 audit window before close." The advantage: forces the target to fix named findings without unwinding the deal. The disadvantage: creates a verification burden at close that the diligence firm has to be paid to execute.

The five-day version, framed

The five-day version is a real workflow, not a compressed pretense of the twenty-day version. It cuts what depends on target cooperation and what can only be established through invasive access. It keeps everything that can be defended in a boardroom with a written methodology.

Where the compression breaks

The compression breaks below five days. A three-day diligence cannot produce a defensible CCOD, only a letter grade, which puts the deal team back in the pre-2025 posture the Bain case just made expensive. A one-day diligence is a compliance ceremony, and it should be labeled as such in the diligence memo so the audit committee understands what they received.

The compression also breaks when the target's cyber posture is not what public observation suggests. The Tier-1 view assumes the target's internal security discipline is broadly proportional to what it presents externally. If the target has been running with a Fortune-500-grade external posture on top of a badly under-resourced internal program, the five-day version will miss that. The counter is a two-week post-signing verification window written into the definitive agreement, with a named dollar remedy if the internal posture deviates from what diligence found.

The most common way the compression breaks in practice is the target's insurance coverage. A five-day diligence can pull the target's policy limits and named exclusions from public sources or from the target's disclosure schedule. What it cannot do is verify that the current premium reflects current risk, that the policy has been renewed on time, or that recent incidents have not triggered a mid-policy adjustment. The disclosure schedule is what the acquirer relies on for those, and the disclosure schedule is only as good as the target's willingness to disclose.

What the deal team should insist on, regardless of window

Three things transfer even into a one-day diligence and should never be cut regardless of compression: (1) a named, current cyber insurance policy with the aggregate limit and coverage exclusions on record; (2) confirmation that there has been no reportable breach in the last thirty-six months, or if there has been, a copy of the disclosure and the corrective action plan; and (3) a signed statement from the target's most senior security-aligned person (CISO, VP Engineering, or CTO depending on the org) attesting to the top three cyber risks they believe are present in the business. These are cheap to obtain and material to the audit committee's read on management credibility.

The signed statement in particular matters because it captures management's own view before the deal closes. If the acquirer later discovers a material cyber issue that the seller's own security lead knew about and did not disclose, that statement moves the case from "unfortunate diligence limitation" to "material misrepresentation." The delta in legal posture is substantial.

The deal team that wants to close September 30 with a credible cyber diligence signed off should start day one of the five days no later than the week of September 15. There is no compressed version of the compressed version.

The bottom line

Five business days is enough to produce a number the audit committee can sit with. It is not enough for the twenty-day version and pretending otherwise costs more later than it saves now. The right posture for a Q3 close is to buy the compressed scope, name the assumptions the compression forces, and structure the deal terms (price, escrow, closing condition) to reserve against what the five-day view could not verify. The wrong posture is to accept a letter-grade report from a firm that promises the twenty-day output on a five-day fee and calls it good.

The Bain case changed what "good" means. The number is the deliverable now, and it either influences the term sheet or it does not — and if it does not, the diligence was theater regardless of how many pages it produced.

Run this on your Q3 close

The five-day workflow above is what we run on live deals through diligence.vcisolite.com — Tier-1 exposure analysis, top-five vendor concentration, PML-anchored regulatory exposure, and a written CCOD with basis, delivered in five business days on a fixed-fee engagement. If your Q3 close has a cyber diligence question that needs a number by September 30, start the conversation this week.

Where this matters next

Share this article:

Ready to build your security program?

See how easy it can be.