May 29, 2026 · Diligence · QCD

Quantitative Cyber Diligence — live for M&A, PE, and IC deal teams

The QCD product is live at diligence.vcisolite.com. Per-engagement, deal-team-shaped diligence that returns a single Cyber Cost of Deal (CCOD) number — five defensible pillars, priced against the acquirer's valuation model, not a red/yellow/green rating.

What changed

Quantitative Cyber Diligence (QCD) is now live for M&A, PE, and investment-committee deal teams at diligence.vcisolite.com. Each engagement returns a single number, Cyber Cost of Deal (CCOD), for the target company on the table.

CCOD engine
Five pillars (attack surface and exposure, third-party and vendor concentration, data sensitivity and regulatory exposure, security program maturity, integration and post-close risk), each decomposed into defensible line items that plug into the acquirer's existing valuation model.
Pricing
Tier 1 diligence at $12,500 flat, sized for tuck-in and lower-mid-market deals. Tier 2 diligence priced against target enterprise value, starting at $15,000, sized for platform investments and strategic acquisitions.
Workflow
Engagements run from LOI through IC in days, not weeks. Deliverables are a working paper, an executive brief, and a defensible line-item CCOD against the acquirer's valuation model, not a red/yellow/green rating no one can act on.
Year-0 handoff
After close, the target's diligence graph seeds the operating-company vCISO Lite deployment. The risks flagged in diligence become the Year-0 remediation plan, priced and sequenced against portfolio return.

Why it matters

The product operationalizes the QCD framework (the methodology published in the executive brief, the academic paper, and the book Someone Else’s Debt) into a per-engagement diligence workflow that returns a single number for the target on the table. The methodology itself is in the QCD executive brief and academic paper; the companion book is covered separately in the book’s changelog entry.

The audience is PE operating partners, corporate-development teams at strategic acquirers, investment committees who need a defensible cyber number for the IC memo, and the security and GRC advisors who work alongside them. The audience is deal teams, not IT teams, and the product is priced and built for them accordingly.

The deep-dives that shaped the methodology are in the M&A Security Diligence series and the Risk Quantification cluster. The LOI-to-IC playbook QCD Diligence delivers on is in The PE Buyer’s Playbook for Cyber Due Diligence; the CCOD walk-through is in Cyber Cost of Deal: A Worked Example; the negotiating-table application of the QCD number is in Cyber R&W Insurance or Price Reduction.

Availability

Live today at diligence.vcisolite.com for M&A, PE, and investment-committee deal teams. Engagements are booked per deal.

The full product launch write-up is in the press release. The companion book Someone Else’s Debt ships on the same date and carries the methodology end-to-end for readers who want the long form before booking.

Known limitations

Engagements are human-run. End-to-end AI-run QCD, with the same five-pillar decomposition and cryptographic proof of every read and every action, is the roadmap play from Trustworthy Autonomy™, not shipped today.

The workflow is sized for the LOI-through-IC window. Pre-LOI target screening and post-close operating-company work are booked as separate engagements.