Open cardosec

Case BCFDDE · GRC · L5 Expert

Cyber Due Diligence in M&A

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Pre-signing: assess posture, past incidents, open regulatory matters and security debt, then price findings into deal terms.
  2. Breaches before close become yours: Marriott inherited the 2014 Starwood intrusion, found in 2018, and was fined by the UK ICO.
  3. Run a compromise assessment before connecting networks or AD trusts; assume the target may already be breached.
  4. Contract levers: security reps and warranties, specific indemnities, escrow or holdback, and R&W insurance exclusions.
  5. Integration: keep the target segmented, migrate identities to your IdP, and set a dated plan to bring it under your controls.

If the interviewer pushes back

  • The deal team gives you 10 days and no network access. What do you assess now, and what do you defer to post-close?
  • How do you choose between a temporary AD trust and a full identity migration during integration?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.