MITG
CDD

Cyber Due Diligence

CDD is transaction cyber due diligence for acquirers and their deal teams. It identifies material cybersecurity and IT risks at a target before and after close, in language a deal team can act on.

Two phases

Close
Phase 1 · Pre-close · External
Phase 2 · Typically post-close · Internal
Informs
Deal negotiations and evaluation of material cyber risks.
Informs
Remediation budgeting and integration planning.
PHASE 1

Before close, MITG reviews the target’s security practices and external exposure using diligence questions and an external assessment.

Deliverables
A findings report, executive summary, and risk matrix.

Transaction relevance
Identify material cyber risks for deal negotiations and representations and warranties.

PHASE 2

Typically after close, MITG assesses the internal environment to establish the work needed to address security and IT risks.

Deliverables
Detailed findings, a prioritized remediation roadmap with cost context, and integration recommendations.

Transaction relevance
Set remediation budgets and plan integration around the risks identified.

How assessments are conducted

Assessments identify vulnerabilities without exploiting them or changing assessed systems. Scanning is planned around operational constraints, with additional precautions for fragile systems.

Discuss your transaction

Tell us about the target, your transaction timeline, and the access available for assessment.

Request an introductory meeting