SPC / SPC-03
Cyber due diligence and post-acquisition integration
Assess cyber risks in an acquisition or merger and plan integration without propagating weaknesses between environments. The project provides decision evidence, not a guarantee against every hidden risk.

WHEN IT HELPS
A focused response
to a defined need.
Acquisition, merger, business takeover, planned interconnection of two environments or investor seeking to understand required security investment.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Authorised document access
- interviews
- critical assets
- known incidents
- identities
- contracts
- technical debt
- exposure
- limited testing where authorised
- integration plan and priorities
Deliverables
- Executive summary
- risk register
- verification limits
- integration scenarios
- preconnection controls
- investment needs to estimate
- takeover roadmap
Acceptance evidence
Findings link to available evidence; uncertainty is visible; preconnection actions are separated from later improvements; owners and decision points are identified.
DELIVERY
How the work is structured.
Approach
Verify expertise and authorisation; scope constraints; collect without unapproved risk; assess and propose; validate with competent owners.
Prerequisites & responsibilities
Customer: decision authority, operators, control engineers or transaction leads as applicable. Provider: validated expertise; specialist partners where needed and approved.
Scope factors
Sites, systems, safety, evidence access, independence and qualification requirements. Bespoke engagement; effort and subcontracting confirmed before proposal.
Questions to clarify
Which information is accessible before the transaction? When must systems connect? Which dependencies and responsibilities will transfer?
IMPORTANT BOUNDARIES
Access is subject to transaction authorisation and confidentiality. The service replaces neither financial/legal due diligence nor a full investigation; costs remain estimates before detailed scoping.
Delivery is conditional on the specialist resources, authorisations and framework requirements established during scoping. Formal qualifications and clearance are confirmed where required.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A group acquires a company and wants immediate network connectivity. Project: review identity, exposure and access before connecting. Target outcome: interconnection conditional on minimum controls and a restricted scope.
Scenario 02
An investor has only a limited data room. Project: review evidence and identify blocking questions. Target outcome: an informed view of visible risks; missing documents are treated as uncertainty, not evidence of security.
Technology and reference context
References: NIST risk management and relevant technical controls; collection proportionate to transaction stage and authorisation.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
