Cyber due diligence (M&A)
What you are buying, in security terms, in time for it to affect the price.
- Duration
- 2–3 weeks
- Price
- €8,000 to €18,000
- excl. VAT, indicative
AI & Cybersecurity
Deploy AI you can defend, and defend with AI.
Legal

Services
A security strategy the board can fund and the CISO can execute.
Most security programmes fail at the join between the board and the engineers. The board is asked to fund controls it cannot evaluate; the engineers are handed a budget with no sequence. Strategic advisory is the work of building that join.
We start with where you stand — a maturity assessment scored against NIST CSF 2.0 or ISO 27001 with the gaps ranked by exposure — and turn it into a three-year master plan with costs, owners and the order things have to happen in. The same method applies to the cloud: which providers, how sovereign, where the data may sit, and what an exit would cost.
Where you need the function and not just the plan, a virtual CISO carries it: a senior specialist at a fixed number of days a month who attends your committees, owns the roadmap and answers for it.
Where you stand, where you need to be, and the sequence of decisions in between.
For a ministry, regulator or sector body: the strategy document, the governance behind it, the capability roadmap and the indicators that show whether it is working.
Standing up a computer emergency response team: mandate, constituency, services, tooling, staffing and the procedures, to the FIRST and ENISA models.
Designing and standing up a security operations centre — or choosing not to and buying it — with the use cases, data sources, tooling, tiers and metrics that make it worth having.
For operators of essential services: the asset and dependency map, the protection baseline, the sector obligations, and a plan that survives a regulator's inspection.
Who decides, who speaks, who calls the regulator and when: the crisis organisation, escalation criteria, communication templates and decision logs, exercised once before you need them.
A structured read of where you stand against NIST CSF 2.0 or ISO 27001, scored by domain, with the gaps that matter ranked by exposure rather than by framework order.
One framework that joins security, continuity and recovery: the critical services, their tolerances, the controls that protect them and the tests that prove they hold — the shape DORA and NIS2 both expect.
A multi-year security plan tied to budget, headcount and regulatory deadlines, so the next three board meetings already have their agenda.
Application-by-application analysis of what to retire, retain, rehost, replatform or rebuild, with the business case and the regulatory constraints in the same table.
A structured comparison of AWS, Azure, GCP, OVHcloud, Scaleway, S3NS and Bleu against your technical, contractual, sovereignty and exit requirements.
Where your data physically sits, who can legally compel access to it, and what it would take to change that — documented for the regulator and the board.
What you are buying, in security terms, in time for it to affect the price.
A senior security leader on your management team for a defined number of days each month: strategy, board reporting, supplier reviews, incident decisions and the compliance calendar.
A cyber maturity assessment takes four to six weeks and gives you the scored picture and the costed plan the board will ask for.