M&a Cyber Due Diligence With No Access... How Are You All Mapping The Attack Surface Before Day 1?
Hi, security lead on the buy side here, currently living in the wonderful world of M&A cyber due diligence where I have ten business days, no prod creds, no scanner access, and a deal room that is basically a vibes based security questionnaire and two diagrams from 2019.
We have a list of primary domains but I do not trust that this is the full external attack surface at all. We want an outside in acquisition cybersecurity assessment that starts with company name and known domains, then pivots into related domains, certs, dns history, cloud endpoints, exposed admin interfaces, third party infra etc. All without turning this into unauthorized pen testing and without guessing our way into inherited cyber risk we cant prove.
The hard part is attribution and materiality. What evidence do you treat as strong enough to tie an asset to the target, and what can you responsibly call a transaction level risk vs Day 1 containment vs normal post close remediation when you have zero internal access. Would love any tips from people who do M&A attack surface assessment from the outside in before Day 1, especially on not overstating findings but still flagging the stuff that should worry the deal team... idk
[link] [comments]
Popular Products
-
Classic Oversized Teddy Bear$23.78 -
Gem's Ballet Natural Garnet Gemstone ...$171.56$85.78 -
Butt Lifting Body Shaper Shorts$95.56$47.78 -
Slimming Waist Trainer & Thigh Trimmer$67.56$33.78 -
Realistic Fake Poop Prank Toys$99.56$49.78