vCISO Lite for Private Equity
Cyber risk,
in dollars.
Quantitative Cyber Diligence is a five-pillar, dollar-denominated read on a target’s real cyber posture — control maturity, exposure surface, threat exposure, financial impact, and remediation cost.
72 hours for the full QCD report. 48 hours for a Tier 1 external snapshot. Priced like legal and QofE — per engagement, invoiced on agreement.
Quantitative Cyber Diligence is cyber due diligence for M&A — built specifically for private equity deal teams, operating partners, and corporate development. Where a traditional cybersecurity assessment produces a heat map, QCD produces a dollar figure: the Cyber Cost of Deal, defensible at IC, comparable across portfolio companies, and tied directly to enterprise value.
Get startedSkipping cyber diligence has a price tag.
Source: FTI Consulting, M&A and Cybersecurity, 2026.
Financial diligence has a methodology. Legal diligence has a methodology. Cyber diligence has a forty-question checklist. We must do better.
Five pillars. One dollar figure. Defensible at the IC.
Traditional M&A cybersecurity due diligence answers the wrong question. It tells you whether a target has policies, certifications, and a SOC. It does not tell you what their cyber posture will cost you across the hold period — in remediation spend, in integration risk, in regulatory exposure, or in the catastrophic-tail scenario every investment committee actually worries about. QCD answers that question. Five pillars, one number, in dollars.
Each pillar produces a dollar-denominated score. Summed with correlation adjustment, they produce a single figure — the Cyber Cost of Deal (CCOD), expressed against enterprise value.
Attack Surface & Exposure
Probability-weighted loss from the target’s external attack surface — unpatched exposures, misconfigurations, exposed credentials.
Third-Party & Vendor Concentration
Dollar impact if a critical vendor compromises or fails. Concentration, integration depth, and data flow priced in.
Data Sensitivity & Regulatory Exposure
Worst-case regulatory, reputational, and operational cost of a breach. Built up from data classification and jurisdictional reach.
Security Program Maturity
Cost to bring the target’s security program to peer parity. Benchmarked against sector- and size-matched comparables.
Integration & Post-Close Risk
Remediation cost and operational risk in the first 90 days post-close — identity merge, vendor consolidation, detection gaps.
One view per question.
Every QCD engagement lives in the same platform your portfolio does. Three views, three questions.
Is this deal worth doing — and at what terms?
CCOD with Monte Carlo distribution, five-pillar decomposition, top drivers, and a recommended action. When the Q99 breaches 15% of EV, the platform names the structural intervention — price reduction or R&W escrow, sized to your tolerance.
engagement view · apex healthtech · ccod $14.3M · 6.5% of EV
portfolio rollup · q2 2026 · 4 active engagements · avg CCOD/EV 6.2%What does our cyber-risk pipeline look like?
Active engagements, closed counts, and average CCOD/EV trended by quarter. Defensible to LPs, queryable by your IC.
Is our portfolio improving or degrading?
Every portco measured against its Year-0 diligence baseline. Posture trends, remediation progress, and degrading positions surface automatically — without re-engaging.
portfolio companies · 7 total · 1 degrading · year-0 baseline vs currentNow with an analyst built in.
APRI™ — AI-Powered Risk Intelligence — is the diligence analyst built into every engagement view. Knows the QCD methodology cold. Cites every claim against live engagement data. Logs every conversation on an independent audit chain. Included with every Diligence subscription.
See how APRI works in Diligence →
APRI panel · Project Phoenix IC prepFrom LOI to IC, in 72 hours.
Submit on Day 0. Board-ready report on Day 3.
Submit the target
Basic target info and a signed NDA. No target-side participation required for Tier 1.
Run the assessment
Five pillars run in parallel: attack surface, vendor concentration, data exposure, program maturity, post-close risk.
Board-ready report
CCOD in dollars and as % of EV. Per-pillar drivers, scenarios, and a 90-day remediation plan.
Read it in 15 minutes. Defend it in any valuation discussion.
A number
Not a heat map. A dollar figure with provenance.
A defense
Every pillar shows its inputs, comparables, and top-driver sensitivity.
A plan
If you proceed, a 90-day remediation budget. If you walk, the defensible reason.
A clean handoff
Deletion certificate at close. If the deal closes, outputs port into the portco’s own tenant.
If you walk, the data walks with the deal.
Every engagement is a disposable scope. Deletion is provable, not promised.
Ephemeral by design
Target data deleted at close. Every close event produces a JWS-signed deletion certificate, verifiable against our published key.
Logically isolated
Each engagement is its own organization boundary. Portfolio subscriptions add single-tenant isolation.
Standard controls
MFA, NDA-at-room-creation, end-to-end encryption, watermarked deliverables.
Clean handoff
On close, CCOD and remediation plan port into the portco’s own vCISO Lite tenant.
Independently verifiable audit chain
Every APRI™ conversation lands on a dedicated, hash-linked audit chain — separate database, separate event stream, separate verification path. A forensic auditor can verify integrity without depending on any other vCISO Lite system.
Behind the QCD engagement is the vCISO Lite platform — the same compliance and risk-quantification infrastructure used by SOC 2 and ISO 27001 customers, with multi-tenant isolation, JWS-signed audit events, and a published cryptographic transparency log. If the deal closes, the portfolio company inherits a working vCISO Lite tenant with their Year-0 baseline already populated. Learn more about the platform →
Priced the way you price every other workstream.
Below legal. Below financial. Per-engagement, invoiced on agreement.
Pillar 1 in 48 hours
External attack surface only. No target engagement required.
Runs at LOI before formal diligence opens. Direct-observation findings, ranked by expected loss, with a go/no-go signal for full QCD.
Request a Tier 1 snapshot →All five pillars in 72 hours
Priced by target enterprise value.
Full CCOD with scenarios, driver analysis, and a 90-day remediation plan. Portfolio subscriptions for repeat deal flow.
Request a Full QCD engagement →Questions deal teams actually ask.
If yours isn’t here, the request form below is the fastest way to ask.
What is Quantitative Cyber Diligence (QCD)?
How is QCD different from a typical M&A cybersecurity assessment?
Do you need target-side cooperation to run an assessment?
What is CCOD and how is it calculated?
When does CCOD trigger a deal-term change?
Where does the target’s data live after the engagement closes?
How does QCD relate to the book Someone Else’s Debt?
How is QCD priced?
What’s APRI™ Diligence?
Are APRI™ conversations retained as work product?
Not a fund — an operator?
If you’re an operating company doing your own diligence on a target you’re acquiring, or preparing your security posture for an investment round, the same QCD methodology is available inside vCISO Lite — bundled with the Ultra subscription. No per-engagement invoice, no separate platform.
Cyber diligence inside vCISO Lite →Quantitative Cyber Diligence
See the real cyber posture before the deal closes.
Tell us a bit about your firm and what you’re trying to do. We’ll get back to you within 24 hours to scope the engagement and get an invoice in your hands.
72-hour target assessment
Five-pillar quantitative analysis with dollar-denominated risk exposure
Signed deletion certificates
Ed25519 JWS-signed proof of data destruction after every engagement
Per-engagement pricing
Tier 1 external snapshot or full QCD. Invoiced on agreement, not subscription.
Request access
We respond to every request within one business day.
