What changed
Someone Else’s Debt is the book-length treatment of Quantitative Cyber Diligence (QCD), the methodology that drives our diligence product for M&A, PE, and investment-committee deal teams. The book publishes today on Amazon and Kindle; the product itself lives at diligence.vcisolite.com, with the version-launched-for-deal-teams milestone covered in the separate QCD product changelog entry.
Why it matters
QCD decomposes cyber risk into a single Cyber Cost of Deal (CCOD) figure across five defensible pillars. Attack surface and exposure is probability-weighted 12-month financial loss at current posture, decomposed via FAIR-style LEF × LM math over eight observable categories. Third-party and vendor concentration is max single-vendor loss weighted by an HHI concentration penalty; see the Vendor Risk cluster for the underlying methodology. Data sensitivity and regulatory exposure covers probable maximum loss and expected annual cost from a reportable breach across HIPAA, GDPR, CCPA/CPRA, GLBA, PCI-DSS, and state laws.
Security program maturity places the target’s program on the operating-maturity curve, which translates into remediation cost and time-to-close rather than a red/yellow/green rating. Integration and post-close risk names what the target brings into the acquirer’s environment at day one and through integration: the risks that don’t resolve at close and become the acquirer’s liabilities on day-91.
The book is written for deal teams: PE partners, corp-dev leads at strategic acquirers, and the security and GRC operators who advise them. The methodology, the math, the sourcing, and the worked examples are all in the book, and the platform at diligence.vcisolite.com automates it into a per-engagement diligence workflow. Read the QCD executive brief and academic paper for the short version, or explore the M&A Security Diligence series and the Someone Else’s Breach series for the deep-dives that shaped the book. The Risk Quantification cluster collects the companion pieces, and The PE Buyer’s Playbook for Cyber Due Diligence and Cyber Cost of Deal: A Worked Example walk the LOI-to-IC framework and the CCOD methodology end to end.
Availability
Publishing today on Amazon and Kindle. The platform at diligence.vcisolite.com is available to M&A, PE, and investment-committee deal teams on the diligence product tier.
Readers who want the short version before the book arrives can start with the QCD executive brief and academic paper, both free. The QCD product changelog entry covers what the platform ships today.
Known limitations
The book is a snapshot of the methodology at publication. Refinements to the FAIR-style LEF × LM math, new jurisdictional breach data, and new worked examples appear first on the platform and in the briefs; the next edition folds them into the printed text.
Worked examples in the book use representative deal profiles. Your target's data categories, record counts, and jurisdictional footprint will drive the specific CCOD calibration your engagement produces at diligence.vcisolite.com.