Asked and answered
Frequently asked questions
The questions private equity, corporate acquirers and their advisers bring to us before commissioning due diligence, answered plainly. Anything the list does not settle, put to us on the scoping call and you will get a direct answer.
What is cyber due diligence?
Cyber due diligence is an independent assessment of a target company's cyber security during a merger, acquisition or investment. It gives the buyer a clear view of the risk they are taking on: how the target protects its systems and data, whether it has been breached, and what it would cost to bring its security up to an acceptable standard after completion.
On the buy side it protects deal value by surfacing risk before you sign. On the sell side it prepares the target so avoidable findings do not slow the process or reduce the price. CyPro delivers cyber due diligence in-house through its 3DD practice, with clear red-amber-green reporting scoped to the deal.
What is technology due diligence?
Technology due diligence is a broader review of a target's technology as a whole: its product and code, architecture, scalability, technical debt, engineering team and security. Where cyber due diligence focuses on security risk, technology due diligence answers whether the technology can support the investment thesis and what it will take to scale it.
It is the review private equity firms and corporate acquirers most often commission before backing a technology-enabled business. CyPro's 3DD practice covers architecture, code quality, scalability, technical debt, team and security in a single deal-ready report.
What is the technology due diligence process?
The process runs in clear stages. We scope the review with you around the target and the deal, then gather evidence from the data room, management interviews and a review of the architecture, code and systems. We analyse what we find against the investment thesis and the risks that matter to an acquirer, then report.
The output is a deal-ready report with red-amber-green findings, the material risks, an indication of the cost and effort to put them right, and a clear view on whether the technology supports the plan. It is written for an investment committee, not a technical audience.
What are the 4 types of due diligence?
Buyers commonly group due diligence into four broad types: financial, legal, commercial and operational. Financial confirms the numbers, legal reviews contracts and liabilities, commercial tests the market and the growth story, and operational examines how the business actually runs.
Technology, cyber and IT due diligence sit within the operational strand and, on technology-enabled deals, are usually carried out as a dedicated workstream in their own right. That is the work CyPro's 3DD practice delivers alongside the financial, legal and commercial advisers on the deal.
What are the 4 P's of due diligence?
The 4 P's are a framework investors use to assess a business or a fund: People, Performance, Philosophy and Process. People looks at the team and its track record, Performance at the results, Philosophy at the strategy and how it is meant to create value, and Process at how the business runs day to day.
It is an investor's lens rather than a technical one, but technology and cyber due diligence feed directly into the People and Process elements: the strength of the engineering team and whether the systems and controls behind the business are sound enough to support the plan.
What is the difference between CDD and VDD?
CDD is commercial due diligence, commissioned and paid for by the buyer to test the target's market, customers and growth story. VDD is vendor due diligence, commissioned and paid for by the seller and then shared with prospective buyers to support the sale. Both are financial and commercial exercises carried out by accountancy and corporate-finance firms.
Cyber, technology and IT due diligence are a different discipline again, and they can be commissioned by either side: a buyer assessing a target, or a seller preparing for sale. CyPro's 3DD practice delivers that technology and cyber review; the financial CDD and VDD sit with the deal's accountants.
What is IT due diligence?
IT due diligence assesses a target's IT estate rather than its product: infrastructure, systems, software licensing, cloud spend, third-party contracts and the cyber risk sitting inside them. It answers what the acquirer is inheriting, what it costs to run, and what integration or remediation will cost after completion.
It differs from technology due diligence, which looks at the product, code and engineering, by focusing on the operational IT the business depends on. On many deals the two run together as a full pre-acquisition review, delivered by CyPro's 3DD practice.
How long does technology due diligence take?
There is no single answer: the timeline depends on the size and complexity of the target, the scope you need, and how well the data room and management team are prepared. A focused review of a small target is quicker than a full review of a large, multi-product business.
Due diligence runs to the deal, so we scope the work to fit your exclusivity period or investment committee date and agree the timeline with you up front. We will tell you at scoping what is realistic for the deadline in front of you.
How much does technology due diligence cost?
Indicative fixed-fee pricing is published on our pricing page, banded by deal size. The figure for your deal depends on the size of the target, the scope you need across cyber, technology and IT due diligence, and the complexity of the systems in question.
Nearly everyone in this market quotes only on request, so we put indicative 'from' prices on the page and set the fixed fee in writing once the scoping call has pinned down the scope. Cyber, technology and IT due diligence are commonly commissioned together for a full pre-acquisition review, and we can quote them as one.
Who pays for vendor due diligence?
Vendor due diligence (VDD) is commissioned and paid for by the seller, or vendor, then shared with prospective buyers to support the sale. It is a financial and commercial exercise carried out by accountancy and corporate-finance firms, and it is a different service from the cyber, technology and IT due diligence CyPro provides.
Cyber and technology due diligence can be paid for by either side of a deal: a buyer assessing a target, or a seller preparing for sale. If you need financial vendor due diligence, that sits with an accountancy firm. If you need the technology and cyber picture, whichever side of the table you are on, that is what our 3DD practice delivers.
A question we missed?
Bring it to the scoping call
That is what the scoping call is for: 45 minutes, free, on the target, the deal timeline, the scope you need and the indicative fixed fee, whether or not you go on to instruct the work. It is taken by a consultant from our 3DD practice, not a salesperson.