CDD
Cyber Due Diligence
CDD is transaction cyber due diligence for acquirers and their deal teams. It identifies material cybersecurity and IT risks at a target before and after close, in language a deal team can act on.
Two phases
Close
Phase 1 · Pre-close · External
Phase 2 · Post-close · Internal
Informs
Negotiation, price, and representations and warranties, from an executive summary and risk matrix built without access to the target's systems.
Informs
Remediation budget and integration planning, from full findings and a roadmap with priorities and cost context.
PHASE 1
Pre-close: an external assessment built on MITG’s regularly updated diligence questionnaire and an external review of the target’s posture, with a findings report that includes an executive summary and a risk matrix oriented to representations and warranties.
PHASE 2
Typically post-close: an internal assessment with full findings, a remediation roadmap with priorities and cost context, and integration planning recommendations.
How assessments are conducted
Assessments validate exposure and identify vulnerabilities. They do not include exploitation of findings, credential attacks, phishing simulations, or changes to assessed systems. Scanning is paced to avoid disrupting operations, fragile systems are excluded or assessed with additional precautions, and MITG pauses promptly on request.
A commitment to the companies we assess
If MITG identifies a critical issue presenting imminent risk to the assessed company, MITG notifies that company so the issue can be addressed, and the engaging client is informed.