Cyber due diligence (M&A)
What you are buying, in security terms, in time for it to affect the price.
- Duration
- 2–3 weeks
- Price
- €8,000 to €18,000
- excl. VAT, indicative
Four practices, held by one team.

Services
A security strategy the board can fund and the CISO can execute.
Most security programmes fail at the join between the board and the engineers. The board is asked to fund controls it cannot evaluate; the engineers are handed a budget with no sequence. Strategic advisory is the work of building that join.
We start with where you stand — a maturity assessment scored against NIST CSF 2.0 or ISO 27001 with the gaps ranked by exposure — and turn it into a three-year master plan with costs, owners and the order things have to happen in. The same method applies to the cloud: which providers, how sovereign, where the data may sit, and what an exit would cost.
Where you need the function and not just the plan, a virtual CISO carries it: a senior specialist at a fixed number of days a month who attends your committees, owns the roadmap and answers for it.
Where you stand, where you need to be, and the sequence of decisions in between.
A structured read of where you stand against NIST CSF 2.0 or ISO 27001, scored by domain, with the gaps that matter ranked by exposure rather than by framework order.
A multi-year security plan tied to budget, headcount and regulatory deadlines, so the next three board meetings already have their agenda.
Application-by-application analysis of what to retire, retain, rehost, replatform or rebuild, with the business case and the regulatory constraints in the same table.
A structured comparison of AWS, Azure, GCP, OVHcloud, Scaleway, S3NS and Bleu against your technical, contractual, sovereignty and exit requirements.
Where your data physically sits, who can legally compel access to it, and what it would take to change that — documented for the regulator and the board.
What you are buying, in security terms, in time for it to affect the price.
A senior security leader on your management team for a defined number of days each month: strategy, board reporting, supplier reviews, incident decisions and the compliance calendar.
A cyber maturity assessment takes four to six weeks and gives you the scored picture and the costed plan the board will ask for.