Identity and access
Provisioning, authentication, and offboarding across the target's identity provider and core business applications.
A post-close cybersecurity review is a fixed-fee, evidence-based assessment of an acquired company's identity, endpoint, email, and data controls, scoped for private equity firms and search funds that could not get system access before the deal closed. DSE runs it in the weeks after close and delivers a risk-ranked findings report with evidence, plus a 100-day remediation roadmap with an owner, an effort estimate, and a cost for every item, so IT and security risk gets into the integration plan instead of surfacing later, unplanned.
This review is built for the case where system access to the target was not available before close, leaving a gap between what diligence promised and what the target's environment actually looks like. It is built on the same evidence-based method as DSE's cybersecurity assessment services, scoped to the questions a post-close review actually needs to answer.
For private equity firms, search funds, and independent sponsors closing on a platform or add-on acquisition. Not scoped for venture diligence or pre-close corporate-development review.
This is the case where system access to the target was not available before close. Until closing, IT and security review is confined to whatever the seller puts in the data room: policy documents, an org chart, maybe a vendor list. None of that tells you whether the identity provider actually enforces multi-factor authentication, whether the endpoint fleet is patched, or whether the records you are about to hold are what you were told they are. A post-close review is the first point in the transaction where someone can actually look. DSE typically kicks off within five business days of close, and treats the gap between signing and system access as the reason this offer exists, not a limitation to work around.
We don't do penetration testing, SOC 2 or ISO attestation, or legal opinions, and we don't certify compliance. If you need an attestation alongside this, we'll tell you and point you to the right firm. What we do is look at what's actually there, evidence in hand, and tell you what it means for the 100 days after close.
The review covers the six areas that actually decide whether a target's IT and security posture matches what closing assumed:
Provisioning, authentication, and offboarding across the target's identity provider and core business applications.
Device management, authentication controls, and configuration for corporate endpoints, laptops, and mobile devices.
Phishing exposure, mail-flow controls, and the authentication stack protecting the company's domain and mailboxes.
Safeguards around sensitive records the target holds, including PHI, cardholder data, or GLBA-covered nonpublic personal information.
Who actually owns IT and security decisions today, and whether that ownership survives the transition to new ownership.
Endpoint protection, patching, backups, and network security: the fundamentals a 100-day plan depends on holding.
Each finding states what we observed, the supporting evidence, and why it matters to the integration plan and the 100 days that follow.
Every item sequenced with a named owner, an effort estimate, and a cost, so the deal team and the operating partner are reading the same plan.
Fixed fee: $38,000 to $55,000. That is a non-binding estimate range, not a quote; the fee is fixed in writing after a scoping call, and we do not bill time and materials. The single question that moves the number, and the framework we map findings to, is whether the records in scope contain PHI, cardholder data, or GLBA-covered nonpublic personal information: regulated data changes both the evidence we need and the standard we hold it to.
Typical timebox: four weeks from first system access; five weeks where regulated data is in scope, both confirmed in the written scope. Kickoff is typically within five business days of closing, subject to system access.
This reviews the company you just acquired, not one AI system's attack surface; if what you need instead is an adversarial test of an AI system you already run, see DSE's AI Red Team Sprint, a similar fee band answering a different question.
Scoping is a 30-minute call, and it moves faster when you can answer six questions going in:
The person who scopes the call leads the review. Where a specialist from our expert network is involved, we tell you that when we scope it.
The Post-Close Cybersecurity Review Method follows DSE's bounded-evidence assessment method: a bounded evidence request, focused interviews, a business-context severity rating, and a roadmap with named owners. We work from client-provided exports, screenshots, screen shares, and documents once the buyer has system access; we do not request administrator credentials, we do not connect tooling to the target's environment, and we do not run automated scans.
Synthetic sample, not client data. It contains no client information and is not a finding about any organization.
The sample table scrolls horizontally on smaller screens. Keyboard users can focus the labeled table region and use horizontal navigation.
| Area | Observed evidence | Severity | 100-day action |
|---|---|---|---|
| Identity | Multi-factor authentication is enforced for email but not for the finance system's own login. | High | Extend MFA enforcement to the finance system; assign an owner and a 30-day close date. |
| Endpoint | A sample of laptops had not received a security patch in over 90 days. | Moderate | Confirm patch-management coverage and remediate the backlog inside the first 60 days. |
| The domain's authentication records (SPF, DKIM, DMARC) are configured, but DMARC is set to monitor-only. | Moderate | Move DMARC to enforcement once the sending-source inventory is confirmed. |
Final findings depend on the target's environment, the evidence available, and the agreed scope. We do not convert findings into a purported certification score.
DSE delivers through documented in-house expertise and qualified specialists from our expert network, selected for the technologies and risks in scope. DSE remains accountable for scope, quality, integration, and outcomes. Where specialist or partner delivery is involved, we disclose that role clearly.
Accountable owner: DSE delivery leadership.
This is a point-in-time review of the systems and records in the agreed scope, performed once DSE has access after closing. It is not legal advice, not an audit, not a certification, and not an attestation. It does not guarantee compliance, an insurance outcome, or a transaction outcome. It does not make your organization secure and does not prevent, detect, or reduce the likelihood of any security incident; it documents risk against a defined scope at a point in time. DSE does not operate a 24/7 security operations center, does not provide continuous monitoring or managed detection and response, does not perform live incident response or digital forensics and incident response (DFIR), and does not resell licenses. Penetration testing is a separate DSE engagement, quoted after scoping. Where you need any of those, we help you scope the requirement and select a provider you contract directly. Remediation implementation is performed only where it is separately scoped in writing. Counsel, auditors, and assessors retain their respective roles.
Because system access to the target was not available before close. Pre-close diligence is confined to documents the seller chooses to produce, not to the systems themselves. A post-close review is the first point in the transaction where someone can actually look at the identity provider, the endpoint fleet, and the mail system directly.
A fixed fee of $38,000 to $55,000. That is a non-binding estimate range, not a quote; the fee is fixed in writing after a scoping call, and we do not bill time and materials. Whether PHI, cardholder data, or GLBA-covered nonpublic personal information is in scope is the main driver of where the fee lands in that range.
Typical timebox: four weeks from first system access; five weeks where regulated data is in scope, both confirmed in the written scope. Kickoff is typically within five business days of closing, subject to system access.
The scope and the framework we map findings to both change. PHI maps to HIPAA, cardholder data to the PCI DSS contractual standard, and GLBA-covered nonpublic personal information to the FTC Safeguards Rule. Regulated data is the factor that moves the fee within the range and extends the timeline to five weeks.
No. We don't do penetration testing, SOC 2 or ISO attestation, or legal opinions, and we don't certify compliance with any framework. If you need an attestation alongside this review, we say so up front and point you to the right firm.
A risk-ranked findings report with the evidence behind each finding, and a 100-day remediation roadmap with a named owner, an effort estimate, and a cost for every item, so the deal team and the operating partner can act on the same plan.
When the pivot question turns up PHI, cardholder data, or GLBA-covered information, findings map to the same rules our dedicated lanes already cover: HIPAA Security Risk Analysis support for PHI, and FTC Safeguards Rule readiness for GLBA-covered nonpublic personal information. For the broader technical baseline this review draws on, see our national cybersecurity risk assessment and vendor and SaaS security review. That national cybersecurity risk assessment runs in days because it is a single, scoped baseline review; this one runs in weeks because it covers a whole newly acquired environment the buyer has only just gained access to, not a single scoped system. This page reviews the acquired company after close, from the acquirer's side; if you are the company that just raised, was just acquired, or grew fast and want your own readiness read before the board, an insurer, or an acquirer asks, see post-funding and M&A security readiness instead.