Insights

What is cyber due diligence and why is it essential to deal teams?

G3 Cyber due diligences vary in complexity, cost and required resource. Where the investment is sensitive and no contact with the asset is permitted, we can perform external attack surface reviews using passive scanning tools and manual deep and dark net scrapes that require no access to the target firm. These reviews provide a rapid assessment of the asset from the perspective of an attacker – what are the potential attack vectors and how easy would it be to compromise the perimeter?

We can go further and conduct a more detailed diligence working closely with the target asset. With a time-bound brief, access to a virtual data room, and targeted calls with the cyber leads and relevant critical third parties, we will provide assurance of cyber maturity and a clear understanding of cyber risk to the buying firm.

Why are deal teams doing more of it?

The G3 Cyber team has seen an increase in the demand for cyber security due diligences over the past 12 months from funds of all sizes and portfolio profiles, as well as emerging demand from acquisitive organisations concerned about the potential for inherited cyber risk.

We have run cyber due diligences across every geography and major industry, including energy, utilities, healthcare, technology and transport. As the proportion of our pre deal work has increased, we’ve been asking ourselves what has changed. Why do deal teams now see value in bringing in external specialists to conduct cyber due diligence where they didn’t before? In this blog we suggest six reasons why we think cyber due diligence is no longer a nice to have; it’s essential.

1. Cyber risk is real, and it is your responsibility

Gone are the days when cyber risk was the esoteric concern of a small IT team. Cyber risk in some shape or form sits firmly on the risk registers of every organisation we work with. Boards have woken up to the threat presented by cyber attacks. It takes a single breach for Executives and shareholders to understand the very real impact of a cyber attack which prompts a tail-end risk scenario.

Cyber risk should be a consideration for all organisations, but particularly for those conducting
acquisitions. Deals are moments of opportunity balanced against risk. Conducting partial due diligence could leave you vulnerable to neglected cyber risk and therefore investment exposure.

2. Set your investment expectations

Risk and investment expectations are heavily informed by due diligence. A specialist cyber due
diligence will enable you to proceed with a deal with a strong understanding not only of the cyber risks you will inherit, but the expenditure required to remediate and manage concerns. G3’s cyber due diligence identifies relevant cyber risks, current cyber maturity of the asset and outlines costed recommendations to mitigate risks posed. We help you set your expectations and define what is an acceptable cyber risk inheritance.

Cyber attackers are always looking to maximise the impact of their activity. Even for businesses with a low cyber risk profile, deals represent moments of increased risk due to the level of scrutiny and interest immediately pre and post-acquisition. The G3 Cyber due diligence considers this shift in threat profile and the team will make ‘quick win’ recommendations to improve defences in the immediate term.

4. Get an independent perspective

The volume of information exchanged throughout the diligence process is huge. The G3 Cyber team is well-practiced at dropping into the deal process, focusing on the most pertinent issues and independently assessing the target firm to provide the assurance, verification and challenge that you need to effectively consider cyber risk. And we won’t leave you with a 30-page list of vulnerabilities and actions to get the asset to platinum level cyber maturity. We will help you understand the top critical risk scenarios the asset faces, and produce prioritised, costed remediation steps to enhance defence both pre and post deal. We will set the context for your asset’s cyber maturity within its sector and against its peers. An independent, expert perspective is key.

5. Plan for future investments

We will work with you to understand the short and longer term investments required to bring the asset to your target cyber maturity. Our cyber due diligence will identify the costed initiatives required to get the target asset’s cyber risk in line with your tolerance. Without a specific cyber due diligence, it’s likely these costs will remain hidden until after the deal is signed.

6. It’s a negotiation

Our cyber due diligence can help you to strengthen your position. Our findings often form an important part of a negotiation, including around price, by specifying gaps and associated risks that require investment. Our findings have also supported negotiations indirectly. Where sellers have not been entirely transparent – or where risks have been underestimated – our clients have adjusted their negotiating positions accordingly.

Cyber due diligence is a cost-efficient way to understand what risk you stand to inherit, how to protect against it, and required expenditure postinvestment. Given the complexity of the regulatory landscape, the potential for enormous penalties, and the ever diversifying and aggressive tactics of the attackers, cyber due diligence is a critical way to reduce risk exposure and should be a part of every single pre-deal process.

To discuss our due diligence experience, or for more information, please contact:

Kate O’Loghlen, Global Head of Cyber

kateologhlen@g3.co