DSE Cybersecurity · Post-close diligence for private equity

Diligence you couldn't run before close. Now you can.

A post-close cybersecurity review is a fixed-fee, evidence-based assessment of an acquired company's identity, endpoint, email, and data controls, scoped for private equity firms and search funds that could not get system access before the deal closed. DSE runs it in the weeks after close and delivers a risk-ranked findings report with evidence, plus a 100-day remediation roadmap with an owner, an effort estimate, and a cost for every item, so IT and security risk gets into the integration plan instead of surfacing later, unplanned.

This review is built for the case where system access to the target was not available before close, leaving a gap between what diligence promised and what the target's environment actually looks like. It is built on the same evidence-based method as DSE's cybersecurity assessment services, scoped to the questions a post-close review actually needs to answer.

For private equity firms, search funds, and independent sponsors closing on a platform or add-on acquisition. Not scoped for venture diligence or pre-close corporate-development review.

Why this runs after close, not before

You can't review a system you can't reach. So we wait for the day you can.

This is the case where system access to the target was not available before close. Until closing, IT and security review is confined to whatever the seller puts in the data room: policy documents, an org chart, maybe a vendor list. None of that tells you whether the identity provider actually enforces multi-factor authentication, whether the endpoint fleet is patched, or whether the records you are about to hold are what you were told they are. A post-close review is the first point in the transaction where someone can actually look. DSE typically kicks off within five business days of close, and treats the gap between signing and system access as the reason this offer exists, not a limitation to work around.

Said before you ask

What this is not. On purpose.

We don't do penetration testing, SOC 2 or ISO attestation, or legal opinions, and we don't certify compliance. If you need an attestation alongside this, we'll tell you and point you to the right firm. What we do is look at what's actually there, evidence in hand, and tell you what it means for the 100 days after close.

One review, six areas

Every system the data room couldn't show you.

The review covers the six areas that actually decide whether a target's IT and security posture matches what closing assumed:

01 · Identity

Identity and access

Provisioning, authentication, and offboarding across the target's identity provider and core business applications.

02 · Endpoint

Endpoint and device

Device management, authentication controls, and configuration for corporate endpoints, laptops, and mobile devices.

03 · Email

Email security

Phishing exposure, mail-flow controls, and the authentication stack protecting the company's domain and mailboxes.

04 · Data

Sensitive data

Safeguards around sensitive records the target holds, including PHI, cardholder data, or GLBA-covered nonpublic personal information.

05 · Governance

Governance and oversight

Who actually owns IT and security decisions today, and whether that ownership survives the transition to new ownership.

06 · Baseline

Baseline technical controls

Endpoint protection, patching, backups, and network security: the fundamentals a 100-day plan depends on holding.

What you get

Findings your integration team can act on day one.

01

Risk-ranked findings, with evidence

Each finding states what we observed, the supporting evidence, and why it matters to the integration plan and the 100 days that follow.

02

100-day remediation roadmap

Every item sequenced with a named owner, an effort estimate, and a cost, so the deal team and the operating partner are reading the same plan.

Fee and timeline

One number, confirmed before we start.

Fixed fee: $38,000 to $55,000. That is a non-binding estimate range, not a quote; the fee is fixed in writing after a scoping call, and we do not bill time and materials. The single question that moves the number, and the framework we map findings to, is whether the records in scope contain PHI, cardholder data, or GLBA-covered nonpublic personal information: regulated data changes both the evidence we need and the standard we hold it to.

Typical timebox: four weeks from first system access; five weeks where regulated data is in scope, both confirmed in the written scope. Kickoff is typically within five business days of closing, subject to system access.

This reviews the company you just acquired, not one AI system's attack surface; if what you need instead is an adversarial test of an AI system you already run, see DSE's AI Red Team Sprint, a similar fee band answering a different question.

Before we start

One 30-minute call. Six questions.

Scoping is a 30-minute call, and it moves faster when you can answer six questions going in:

  1. Headcount, locations, and the percentage of the workforce working remotely.
  2. What the records actually contain, in plain terms.
  3. The identity, endpoint, and email stack currently in use.
  4. Whether IT is run in-house or by a managed service provider.
  5. Any prior penetration test, SOC 2 report, or cyber insurance application already on file.
  6. Who owns remediation once the report lands, and who it should be addressed to.

The person who scopes the call leads the review. Where a specialist from our expert network is involved, we tell you that when we scope it.

Named methodology

One method. Evidence, not access.

The Post-Close Cybersecurity Review Method follows DSE's bounded-evidence assessment method: a bounded evidence request, focused interviews, a business-context severity rating, and a roadmap with named owners. We work from client-provided exports, screenshots, screen shares, and documents once the buyer has system access; we do not request administrator credentials, we do not connect tooling to the target's environment, and we do not run automated scans.

Sample output

A findings report the deal team can act on.

Synthetic sample, not client data. It contains no client information and is not a finding about any organization.

The sample table scrolls horizontally on smaller screens. Keyboard users can focus the labeled table region and use horizontal navigation.

Synthetic post-close findings excerpt: not client data
AreaObserved evidenceSeverity100-day action
IdentityMulti-factor authentication is enforced for email but not for the finance system's own login.HighExtend MFA enforcement to the finance system; assign an owner and a 30-day close date.
EndpointA sample of laptops had not received a security patch in over 90 days.ModerateConfirm patch-management coverage and remediate the backlog inside the first 60 days.
EmailThe domain's authentication records (SPF, DKIM, DMARC) are configured, but DMARC is set to monitor-only.ModerateMove DMARC to enforcement once the sending-source inventory is confirmed.

Final findings depend on the target's environment, the evidence available, and the agreed scope. We do not convert findings into a purported certification score.

How the work is delivered

Accountable delivery, disclosed clearly.

DSE delivers through documented in-house expertise and qualified specialists from our expert network, selected for the technologies and risks in scope. DSE remains accountable for scope, quality, integration, and outcomes. Where specialist or partner delivery is involved, we disclose that role clearly.

Accountable owner: DSE delivery leadership.

Clear boundaries

Evidence-based findings, not assurance.

This is a point-in-time review of the systems and records in the agreed scope, performed once DSE has access after closing. It is not legal advice, not an audit, not a certification, and not an attestation. It does not guarantee compliance, an insurance outcome, or a transaction outcome. It does not make your organization secure and does not prevent, detect, or reduce the likelihood of any security incident; it documents risk against a defined scope at a point in time. DSE does not operate a 24/7 security operations center, does not provide continuous monitoring or managed detection and response, does not perform live incident response or digital forensics and incident response (DFIR), and does not resell licenses. Penetration testing is a separate DSE engagement, quoted after scoping. Where you need any of those, we help you scope the requirement and select a provider you contract directly. Remediation implementation is performed only where it is separately scoped in writing. Counsel, auditors, and assessors retain their respective roles.

Common questions

What acquirers ask before they book.

Why does a private equity cybersecurity review happen after closing instead of during diligence?

Because system access to the target was not available before close. Pre-close diligence is confined to documents the seller chooses to produce, not to the systems themselves. A post-close review is the first point in the transaction where someone can actually look at the identity provider, the endpoint fleet, and the mail system directly.

What does a post-close cybersecurity review cost?

A fixed fee of $38,000 to $55,000. That is a non-binding estimate range, not a quote; the fee is fixed in writing after a scoping call, and we do not bill time and materials. Whether PHI, cardholder data, or GLBA-covered nonpublic personal information is in scope is the main driver of where the fee lands in that range.

How long does the review take?

Typical timebox: four weeks from first system access; five weeks where regulated data is in scope, both confirmed in the written scope. Kickoff is typically within five business days of closing, subject to system access.

What happens if the target holds PHI, cardholder data, or GLBA-covered information?

The scope and the framework we map findings to both change. PHI maps to HIPAA, cardholder data to the PCI DSS contractual standard, and GLBA-covered nonpublic personal information to the FTC Safeguards Rule. Regulated data is the factor that moves the fee within the range and extends the timeline to five weeks.

Is this a penetration test or a compliance certification?

No. We don't do penetration testing, SOC 2 or ISO attestation, or legal opinions, and we don't certify compliance with any framework. If you need an attestation alongside this review, we say so up front and point you to the right firm.

What do we actually receive at the end?

A risk-ranked findings report with the evidence behind each finding, and a 100-day remediation roadmap with a named owner, an effort estimate, and a cost for every item, so the deal team and the operating partner can act on the same plan.

Related work

Regulated data has its own lane.

When the pivot question turns up PHI, cardholder data, or GLBA-covered information, findings map to the same rules our dedicated lanes already cover: HIPAA Security Risk Analysis support for PHI, and FTC Safeguards Rule readiness for GLBA-covered nonpublic personal information. For the broader technical baseline this review draws on, see our national cybersecurity risk assessment and vendor and SaaS security review. That national cybersecurity risk assessment runs in days because it is a single, scoped baseline review; this one runs in weeks because it covers a whole newly acquired environment the buyer has only just gained access to, not a single scoped system. This page reviews the acquired company after close, from the acquirer's side; if you are the company that just raised, was just acquired, or grew fast and want your own readiness read before the board, an insurer, or an acquirer asks, see post-funding and M&A security readiness instead.