A business may have security policies, a recent audit and an ambitious roadmap. Those are useful starting points. An investor still needs to understand what the evidence actually establishes, which risks remain and what the next owner may need to do.

Define the decision before requesting the evidence

A diligence exercise has a timetable and a purpose. Is the question whether to proceed, what to investigate further or what to prioritise after completion? The answer determines which information is material.

Begin with the business activities and dependencies that underpin the investment. A narrowly scoped review should say what it can establish in the time available and what remains outside its reach.

Examine the scope of existing assurance

The existence of a report does not explain its coverage. Which systems were examined? Which versions and environments? Was the work a documentary review or an active assessment? Were important findings subsequently verified as corrected?

These questions help establish how much confidence a decision-maker can place in the evidence. They also prevent one carefully bounded assessment from being interpreted as assurance about the whole organisation.

Look at operational ownership

Security work depends on people, permissions and processes. Ask who owns critical systems, who can authorise change and what happens when a key person or supplier is unavailable.

An issue may be technically straightforward to correct but operationally difficult because access, knowledge or authority is concentrated. That affects the practicality and sequencing of remediation after a transaction.

Make uncertainty visible

Access during diligence is often limited. Some questions will remain unanswered, and some assertions will rely on information provided by the target. Those limitations belong in the decision material.

A clear assessment separates verified observations, management representations and open questions. Further testing or specialist review can then be targeted where it is most likely to change the decision.

Carry the findings into integration

Diligence is most useful when its findings survive the transaction. Material exposures should translate into named actions, dependencies and a realistic sequence for the integration period.

Cyber findings inform the wider transaction process. Legal, financial and contractual judgements remain with the relevant advisers. The Cabinet’s role is to provide a clear security perspective that those decision-makers can use.

The objective is a clearer investment decision and a more informed plan for what comes next.

A perspective from the Cabinet
The Cybersecurity Cabinet