Case BCFDDE · GRC · L5 Expert
Cyber Due Diligence in M&A
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Pre-signing: assess posture, past incidents, open regulatory matters and security debt, then price findings into deal terms.
- Breaches before close become yours: Marriott inherited the 2014 Starwood intrusion, found in 2018, and was fined by the UK ICO.
- Run a compromise assessment before connecting networks or AD trusts; assume the target may already be breached.
- Contract levers: security reps and warranties, specific indemnities, escrow or holdback, and R&W insurance exclusions.
- Integration: keep the target segmented, migrate identities to your IdP, and set a dated plan to bring it under your controls.
If the interviewer pushes back
- The deal team gives you 10 days and no network access. What do you assess now, and what do you defer to post-close?
- How do you choose between a temporary AD trust and a full identity migration during integration?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.