Third-Party Risk and Transaction Advisory
Much of an organization's cyber risk originates outside its own walls: in the vendors, service providers, and platforms it depends on, and in the companies it acquires. We assess third parties and build the programs that manage them at scale.
For acquirers, sellers, and investors, we provide cybersecurity due diligence with findings expressed in terms that inform valuation, representations and warranties, and integration planning, followed by the post-close work that brings two environments together safely.
Services in this practice
Third-Party Risk Assessment. Vendor and service provider security assessments scaled to criticality, covering controls, attestations, contracts, fourth parties, and monitoring.
Third-Party Risk Management Program Design. Build a TPRM program: vendor inventory, tiering, assessment methodology, onboarding and renewal workflow, contract requirements, and monitoring.
Vendor Diligence Operations. Ongoing vendor security reviews performed on your behalf, absorbing assessment volume while keeping a consistent standard of evaluation.
Cyber Due Diligence for Acquisitions. Buy-side cyber due diligence on security posture, compliance, hidden compromise, product security, and remediation cost, framed for valuation.
Sell-Side Readiness and Vendor Due Diligence. Prepare for buyer security diligence: find and fix the issues that reduce valuation or delay close, and assemble a diligence package that moves fast.
Post-Close Integration Assessment. Plan and manage security integration after close: identity consolidation, network connection risk, control harmonization, and compliance scope.
Portfolio Company Security Assessment. Standardized cybersecurity assessments across a private equity or venture portfolio, with comparable scoring and portfolio-wide risk visibility.
How engagements work
Every engagement is scoped individually and conducted under a master services agreement and mutual confidentiality terms. Work begins with a scoping conversation to understand your objectives, constraints, and deadlines, followed by a written statement of work defining scope, deliverables, and timeline. Both parties retain the right to decline an engagement where the fit is not right.
Frequently asked questions
What does cybersecurity due diligence cover in an acquisition?
It evaluates the target's security program, control environment, regulatory compliance position, incident history and signs of undiscovered compromise, product security, data protection obligations, and technical debt, and estimates the remediation investment required after close.
What is a third-party risk management program?
A third-party risk management (TPRM) program is the structured process an organization uses to identify, assess, contract with, monitor, and offboard vendors according to the risk each relationship presents, so assessment effort is concentrated where the exposure is greatest.
Can you help us prepare to be acquired?
Yes. Sell-side readiness identifies and remediates the findings a buyer's diligence team is likely to raise, and assembles the documentation that lets the security workstream close quickly rather than delay the transaction.
Services in this practice
7 services. Each has its own page describing scope, who it is for, and what you receive.
Vendor and service provider security assessments scaled to criticality, covering controls, attestations, contracts, fourth parties, and monitoring.
Build a TPRM program: vendor inventory, tiering, assessment methodology, onboarding and renewal workflow, contract requirements, and monitoring.
Ongoing vendor security reviews performed on your behalf, absorbing assessment volume while keeping a consistent standard of evaluation.
Buy-side cyber due diligence on security posture, compliance, hidden compromise, product security, and remediation cost, framed for valuation.
Prepare for buyer security diligence: find and fix the issues that reduce valuation or delay close, and assemble a diligence package that moves fast.
Plan and manage security integration after close: identity consolidation, network connection risk, control harmonization, and compliance scope.
Standardized cybersecurity assessments across a private equity or venture portfolio, with comparable scoring and portfolio-wide risk visibility.
Start with a confidential conversation
Every engagement is scoped individually and begins with a conversation about where your program stands and where it needs to be. Work is conducted under a nondisclosure agreement and a master services agreement.
Consultations are available Monday to Friday, 9:00am to 3:00pm Central.