vCISO Lite for Private Equity

Cyber risk,
in dollars.

Quantitative Cyber Diligence is a five-pillar, dollar-denominated read on a target’s real cyber posture — control maturity, exposure surface, threat exposure, financial impact, and remediation cost.

72 hours for the full QCD report. 48 hours for a Tier 1 external snapshot. Priced like legal and QofE — per engagement, invoiced on agreement.

Quantitative Cyber Diligence is cyber due diligence for M&A — built specifically for private equity deal teams, operating partners, and corporate development. Where a traditional cybersecurity assessment produces a heat map, QCD produces a dollar figure: the Cyber Cost of Deal, defensible at IC, comparable across portfolio companies, and tied directly to enterprise value.

Get started
79
Au
Dd
DUE DILIGENCE
Au · 79.00
The cost of the status quo

Skipping cyber diligence has a price tag.

42%
of deals that encounter a cyber incident during or after close lose value.
84%
of executives say a post-transaction cyber incident negatively impacted the deal.
53%
of acquirers can’t align cybersecurity policies after the transaction closes.
60%
of leaders at close have no integration plan for cyber.

Source: FTI Consulting, M&A and Cybersecurity, 2026.

Financial diligence has a methodology. Legal diligence has a methodology. Cyber diligence has a forty-question checklist. We must do better.

The QCD Methodology

Five pillars. One dollar figure. Defensible at the IC.

Traditional M&A cybersecurity due diligence answers the wrong question. It tells you whether a target has policies, certifications, and a SOC. It does not tell you what their cyber posture will cost you across the hold period — in remediation spend, in integration risk, in regulatory exposure, or in the catastrophic-tail scenario every investment committee actually worries about. QCD answers that question. Five pillars, one number, in dollars.

Each pillar produces a dollar-denominated score. Summed with correlation adjustment, they produce a single figure — the Cyber Cost of Deal (CCOD), expressed against enterprise value.

01

Attack Surface & Exposure

Probability-weighted loss from the target’s external attack surface — unpatched exposures, misconfigurations, exposed credentials.

Quantified asExpected annual loss
Typical range$50K – $5M
02

Third-Party & Vendor Concentration

Dollar impact if a critical vendor compromises or fails. Concentration, integration depth, and data flow priced in.

Quantified asMax single-vendor loss + concentration index
Typical range$100K – $25M
03

Data Sensitivity & Regulatory Exposure

Worst-case regulatory, reputational, and operational cost of a breach. Built up from data classification and jurisdictional reach.

Quantified asProbable maximum loss (PML)
Typical range$500K – $50M+
04

Security Program Maturity

Cost to bring the target’s security program to peer parity. Benchmarked against sector- and size-matched comparables.

Quantified asCost-to-parity, 12-month spend
Typical range$150K – $3M
05

Integration & Post-Close Risk

Remediation cost and operational risk in the first 90 days post-close — identity merge, vendor consolidation, detection gaps.

Quantified as90-day integration budget + go-live value at risk
Typical range$200K – $10M
Output
Cyber Cost of Deal (CCOD)
Five dollar-denominated scores, summed with correlation adjustment, producing a single figure expressed as both an absolute dollar amount and as a percent of enterprise value.
Cover of Someone Else's Debt by Yolonda Smith

The framework, in print

Someone Else’s Debt

A Quantitative Framework for Cyber Diligence at Deal Speed

The methodology behind every QCD engagement — five pillars, dollar-denominated, written for deal teams. By Yolonda Smith.

The Platform

One view per question.

Every QCD engagement lives in the same platform your portfolio does. Three views, three questions.

Per engagement

Is this deal worth doing — and at what terms?

CCOD with Monte Carlo distribution, five-pillar decomposition, top drivers, and a recommended action. When the Q99 breaches 15% of EV, the platform names the structural intervention — price reduction or R&W escrow, sized to your tolerance.

vCISO Lite engagement view: Apex Healthtech CCOD $14.3M, 6.5% of enterprise valueengagement view · apex healthtech · ccod $14.3M · 6.5% of EV
vCISO Lite portfolio rollup: Q2 2026, 4 active engagements, avg CCOD/EV 6.2%portfolio rollup · q2 2026 · 4 active engagements · avg CCOD/EV 6.2%
Across deals

What does our cyber-risk pipeline look like?

Active engagements, closed counts, and average CCOD/EV trended by quarter. Defensible to LPs, queryable by your IC.

Per portco

Is our portfolio improving or degrading?

Every portco measured against its Year-0 diligence baseline. Posture trends, remediation progress, and degrading positions surface automatically — without re-engaging.

vCISO Lite portco trends: 7 portfolio companies, 1 degrading vs Year-0 baselineportfolio companies · 7 total · 1 degrading · year-0 baseline vs current
NEWAPRI™ Diligence

Now with an analyst built in.

APRI™ — AI-Powered Risk Intelligence — is the diligence analyst built into every engagement view. Knows the QCD methodology cold. Cites every claim against live engagement data. Logs every conversation on an independent audit chain. Included with every Diligence subscription.

See how APRI works in Diligence →
APRI panel docked in a Diligence engagement, mid-response on Project Phoenix — privileged-record banner visible, CCOD figures and per-pillar drivers shown.APRI panel · Project Phoenix IC prep
How It Works

From LOI to IC, in 72 hours.

Submit on Day 0. Board-ready report on Day 3.

D0
Day 0

Submit the target

Basic target info and a signed NDA. No target-side participation required for Tier 1.

D1
Day 1–2

Run the assessment

Five pillars run in parallel: attack surface, vendor concentration, data exposure, program maturity, post-close risk.

D3
Day 3

Board-ready report

CCOD in dollars and as % of EV. Per-pillar drivers, scenarios, and a 90-day remediation plan.

What you get

Read it in 15 minutes. Defend it in any valuation discussion.

A number

Not a heat map. A dollar figure with provenance.

A defense

Every pillar shows its inputs, comparables, and top-driver sensitivity.

A plan

If you proceed, a 90-day remediation budget. If you walk, the defensible reason.

A clean handoff

Deletion certificate at close. If the deal closes, outputs port into the portco’s own tenant.

How It’s Built

If you walk, the data walks with the deal.

Every engagement is a disposable scope. Deletion is provable, not promised.

Ephemeral by design

Target data deleted at close. Every close event produces a JWS-signed deletion certificate, verifiable against our published key.

Logically isolated

Each engagement is its own organization boundary. Portfolio subscriptions add single-tenant isolation.

Standard controls

MFA, NDA-at-room-creation, end-to-end encryption, watermarked deliverables.

Clean handoff

On close, CCOD and remediation plan port into the portco’s own vCISO Lite tenant.

Independently verifiable audit chain

Every APRI™ conversation lands on a dedicated, hash-linked audit chain — separate database, separate event stream, separate verification path. A forensic auditor can verify integrity without depending on any other vCISO Lite system.

Behind the QCD engagement is the vCISO Lite platform — the same compliance and risk-quantification infrastructure used by SOC 2 and ISO 27001 customers, with multi-tenant isolation, JWS-signed audit events, and a published cryptographic transparency log. If the deal closes, the portfolio company inherits a working vCISO Lite tenant with their Year-0 baseline already populated. Learn more about the platform →

Pricing

Priced the way you price every other workstream.

Below legal. Below financial. Per-engagement, invoiced on agreement.

Tier 1 · External snapshot

Pillar 1 in 48 hours

External attack surface only. No target engagement required.

$12,500flat

Runs at LOI before formal diligence opens. Direct-observation findings, ranked by expected loss, with a go/no-go signal for full QCD.

Request a Tier 1 snapshot →
FAQ

Questions deal teams actually ask.

If yours isn’t here, the request form below is the fastest way to ask.

What is Quantitative Cyber Diligence (QCD)?
QCD is a five-pillar, dollar-denominated assessment of a target’s cyber posture, designed for M&A deal teams. Each pillar produces an expected-loss figure; together they roll up to a single Cyber Cost of Deal (CCOD) expressed in dollars and as a percent of enterprise value — defensible to your IC and comparable across portfolio companies.
How is QCD different from a typical M&A cybersecurity assessment?
A typical M&A cybersecurity assessment is qualitative: a maturity score, a heat map, a remediation backlog. It tells you what’s wrong, but not what it’s worth. QCD is cyber risk quantification applied to M&A — every finding maps to an expected-loss figure, every figure rolls up to a single Cyber Cost of Deal, and that number is expressed both in absolute dollars and as a percent of enterprise value. The output is the same shape as the financial and legal diligence reports already on your IC memo. It belongs next to them, not in an appendix.
Do you need target-side cooperation to run an assessment?
No for Tier 1. The external snapshot is direct-observation only — no questionnaires, no interviews, no target-side participation. Tier 2 (full QCD) typically benefits from limited target-side data (architecture diagrams, vendor list, sample SOC reports) but can be run without it when access isn’t available pre-close.
What is CCOD and how is it calculated?
Cyber Cost of Deal is the sum of five pillar-level expected-loss figures, adjusted for correlation, expressed in dollars and as a percent of enterprise value. The platform runs Monte Carlo across the input distributions; we report E[CCOD] plus Q10/Q50/Q90/Q99 quantiles so the IC sees both the median and the tail.
When does CCOD trigger a deal-term change?
When the Q99 (catastrophic tail) breaches 15% of EV, the platform automatically names the structural intervention: a price reduction or an R&W escrow sized to Q90 minus your tolerance. Below that threshold, CCOD informs the 90-day remediation budget but doesn’t typically change deal terms.
Where does the target’s data live after the engagement closes?
Nowhere. Every engagement is logically isolated and deleted at close. The deletion event produces a JWS-signed certificate (Ed25519) that is verifiable against our published public key — so deletion is provable, not just promised.
How does QCD relate to the book Someone Else’s Debt?
Someone Else’s Debt is the framework in print — the methodology behind every QCD engagement, written for deal teams. The platform is the productized version. You can run an engagement without reading the book; you can read the book without running an engagement.
How is QCD priced?
Per engagement, not per seat. Tier 1 is a flat $12,500. Tier 2 starts at $15,000 and scales with target enterprise value. Portfolio subscriptions are available for firms running 4+ engagements per year.
What’s APRI™ Diligence?
APRI™ — AI-Powered Risk Intelligence — is the diligence analyst built into every engagement view. It knows the QCD methodology (five pillars, CCOD aggregation, valuation adjustment bands) and answers questions about your engagements in plain English — with citations to live data you can re-run yourself. Included with every Diligence subscription. See the full breakdown at diligence.vcisolite.com/apri.
Are APRI™ conversations retained as work product?
Yes. APRI™ conversations are treated as diligence work product, retained 7+ years by default, with optional legal hold per session. They land on an independent, hash-linked audit chain that a forensic auditor can verify without depending on any other vCISO Lite system. Details at diligence.vcisolite.com/apri.
For Operating Companies

Not a fund — an operator?

If you’re an operating company doing your own diligence on a target you’re acquiring, or preparing your security posture for an investment round, the same QCD methodology is available inside vCISO Lite — bundled with the Ultra subscription. No per-engagement invoice, no separate platform.

Cyber diligence inside vCISO Lite →

Quantitative Cyber Diligence

See the real cyber posture before the deal closes.

Tell us a bit about your firm and what you’re trying to do. We’ll get back to you within 24 hours to scope the engagement and get an invoice in your hands.

72-hour target assessment

Five-pillar quantitative analysis with dollar-denominated risk exposure

Signed deletion certificates

Ed25519 JWS-signed proof of data destruction after every engagement

Per-engagement pricing

Tier 1 external snapshot or full QCD. Invoiced on agreement, not subscription.

Request access

We respond to every request within one business day.

Already have an account? Sign in