Skip to content

Home Expertise / Specialist security

SPC / SPC-03

Cyber due diligence and post-acquisition integration

Assess cyber risks in an acquisition or merger and plan integration without propagating weaknesses between environments. The project provides decision evidence, not a guarantee against every hidden risk.

WHEN IT HELPS

A focused response
to a defined need.

Acquisition, merger, business takeover, planned interconnection of two environments or investor seeking to understand required security investment.

AT A GLANCE

Family
Specialist security

Engagement
Specialist expertise

Reference
SPC-03

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Authorised document access
  • interviews
  • critical assets
  • known incidents
  • identities
  • contracts
  • technical debt
  • exposure
  • limited testing where authorised
  • integration plan and priorities

Deliverables

  • Executive summary
  • risk register
  • verification limits
  • integration scenarios
  • preconnection controls
  • investment needs to estimate
  • takeover roadmap

Acceptance evidence

Findings link to available evidence; uncertainty is visible; preconnection actions are separated from later improvements; owners and decision points are identified.

DELIVERY

How the work is structured.

Approach

Verify expertise and authorisation; scope constraints; collect without unapproved risk; assess and propose; validate with competent owners.

Prerequisites & responsibilities

Customer: decision authority, operators, control engineers or transaction leads as applicable. Provider: validated expertise; specialist partners where needed and approved.

Scope factors

Sites, systems, safety, evidence access, independence and qualification requirements. Bespoke engagement; effort and subcontracting confirmed before proposal.

Questions to clarify

Which information is accessible before the transaction? When must systems connect? Which dependencies and responsibilities will transfer?

IMPORTANT BOUNDARIES

Access is subject to transaction authorisation and confidentiality. The service replaces neither financial/legal due diligence nor a full investigation; costs remain estimates before detailed scoping.

Delivery is conditional on the specialist resources, authorisations and framework requirements established during scoping. Formal qualifications and clearance are confirmed where required.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A group acquires a company and wants immediate network connectivity. Project: review identity, exposure and access before connecting. Target outcome: interconnection conditional on minimum controls and a restricted scope.

Scenario 02

An investor has only a limited data room. Project: review evidence and identify blocking questions. Target outcome: an informed view of visible risks; missing documents are treated as uncertainty, not evidence of security.

Technology and reference context

References: NIST risk management and relevant technical controls; collection proportionate to transaction stage and authorisation.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.