During due diligence, after the LOI
Map the target’s exposure and size the risk you would be inheriting, while you can still act on it, adjust the price, add a condition, or reconsider.
In M&A, security due diligence is not optional, it is essential. You need to understand the target’s security posture before acquisition, and to measure risk accurately.
We can sign an NDA before you share any detail.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
A senior consultant will reply within one business day. We can sign an NDA before you share any detail.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















Map the target’s exposure and size the risk you would be inheriting, while you can still act on it, adjust the price, add a condition, or reconsider.
Confirm there are no critical, unresolved problems that would threaten the target’s continuity, its security or a clean integration, the kind of finding that changes a price or a term.
Align the two environments, close the inherited gaps, and make sure connecting the companies does not open a new way in.
Not every deal needs it, and not at the same point. These are the situations where an independent technical test changes what you decide.
The deal needs a technical read on the target’s security, not a questionnaire. We test what is exposed while there is still room to act on the price or on the terms.
Something already happened at the target, or nobody can say for certain that it did not. We look for the traces and size what you would be taking on.
Connecting the two companies is where inherited risk becomes yours. We map what breaks and what opens up before the two networks meet.
A regulator, an insurer or a large customer wants an independent assessment after close. We run it and leave the evidence in the form they accept.
The seller’s certificates and questionnaires say the controls exist. We test whether they hold, with no stake in whether the deal closes.
You are buying a division that shares identity, network and cloud with its parent, and still depends on it after close. We test which access paths from the parent are still open into the target, and set out what to close when they split.
Five steps, from first reconnaissance to validation, with evidence ready for the data room.
From day one, findings live in our platform, not just in a PDF: managed, assigned, remediated and closed with full traceability. Export as a due diligence report, an integration risk register, or evidence of post-acquisition security posture.
We at Etnia highly value our collaboration with Asperis Security.
If something here doesn’t match your situation, that’s the call, bring the context and we’ll scope around it.
Whatever is material to the deal: the perimeter, identity, the core product and its APIs, the internal network and cloud. Before we touch anything we map what the target exposes to the internet, its remote access, its cloud and the suppliers that reach inside it, and the specific list comes out of that.
We demonstrate impact safely, with no disruptive techniques and no risk to the deal. Scope, testing windows, restrictions and information handling are agreed under NDA before we start, and hands-on testing needs authorisation from whoever owns those systems.
It depends on the scope, which is why you will not find a number here: any timeline quoted before we know what is in scope would be made up. We fix the duration in the introductory meeting, with your deal dates on the table.
What we can tell you is how it fits your calendar. We scope tightly around what is material to the deal instead of testing everything, we work to your timeline and we can usually start on short notice. If the window between the letter of intent and close is short, we decide with you what gets tested first.
No, it complements them. A certificate or an audit tells you a control is documented; a test tells you whether it actually stops an attacker. In a deal, you want both: the paperwork for assurance, and an independent test for the truth behind it.
No. We do the technical cybersecurity part only, as an independent third party with no stake in the deal. Your corporate, legal and financial advisors handle their parts, and our neutral security risk picture slots in alongside theirs. Keeping the roles separate is what keeps our assessment unbiased.
You draw that line with your advisors. We have no stake in whether the deal closes, so we do not tell you what to accept: you get every finding proven and ranked by what it means for valuation, integration and the target’s continuity.
What usually stops a deal is an unresolved critical problem that threatens the target’s continuity, its security or a clean integration. And be careful with the score: it is a property of the flaw, and risk is a property of your environment. A medium that exposes the customer table outweighs a high with no real path to it.
They go into the integration plan: what has to be closed before the two networks touch, in what order and what it costs. No figure or date here: both depend on what we find and on who fixes it. The order and the cost go in the report, set against your integration dates.
Findings do not sit in a PDF. They live in the platform, assigned and tracked, and feed Jira or ServiceNow through remediation. When something is fixed, before close or during integration, we test it again and leave proof that it holds. The retest is included, at no cost and with no time limit.
You do, and whoever you choose to share it with. In the introductory meeting we agree under NDA who is involved and who receives what, along with the information-handling rules and the access controls.
The engagement ends with a report for the deal team and a debrief to walk through it. It is written in the terms a board asks in: what each finding means for the deal. Exports come out ready for the virtual data room and the deal file, which is how it reaches your advisors. The sample report does not go out by email; we walk you through it on the call.
An M&A security assessment is a risk conversation. You ask the questions, we run the testing, we deliver the answers. What exists, what it costs to fix, what you are assuming on closing day.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
A senior consultant will reply within one business day. We can sign an NDA before you share any detail.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.