Cyber Diligence & Governance
When to Use
- Scope and run M&A or investment cyber diligence on a target or portfolio company
- Plan vendor and third-party security assessments (onboarding, renewal, concentration)
- Review security questionnaires (SIG, CAIQ, custom) and map answers to evidence
- Perform control maturity and gap analysis for diligence or governance (not full audit)
- Assess integration and transition risk (identity, data, tooling, contracts, talent)
- Prepare investment committee, deal team, or board cyber briefs with red flags and asks
- Design ongoing security governance cadence (committee packs, exception reviews, metrics)
- Coordinate diligence workstreams with legal, IT, HR, and product without owning closing
When NOT to Use
- Execute authorized penetration tests or exploit validation →
penetration-tester, web-pentester, network-pentester
- Classify AI use cases, model cards, or AI vendor data terms →
ai-risk-governance
- Maintain enterprise risk registers, FAIR scoring, or risk appetite without deal/vendor lens →
security-risk-analyst
- Stand up GRC programs, framework scope, or audit walkthrough prep →
compliance-specialist
- Automate SOC 2/ISO evidence collection →
compliance-engineer
- Negotiate contract redlines, DPAs, or liability terms →
commercial-counsel
- Run closing matrix, signatures, funds flow, or data room logistics →
transaction-manager
- Deploy IAM, SIEM, EDR, or remediate findings →
information-security-engineer
- Define CISO program strategy, risk appetite, or board operating model →
chief-information-security-officer
- Lead active incidents or SOC triage →
incident-responder, soc-analyst
- Operate standing TPRM intake, scoring, and continuous vendor monitoring →
vendor-cyber-risk-analyst
Related skills
| Need |
Skill |
| AI use-case tiers, model governance, AI vendor review |
ai-risk-governance |
| Risk registers, inherent/residual scoring, treatment |
security-risk-analyst |
| GRC program, audit prep, questionnaire response library |
compliance-specialist |
| Contract, DPA, indemnity, and commercial terms |
commercial-counsel |
| Deal timeline, diligence coordination, closing |
transaction-manager |
| Control implementation and remediation engineering |
information-security-engineer |
| Executive security strategy and board operating model |
chief-information-security-officer |
| Pentest findings as diligence input |
penetration-tester |
| Enterprise security program and IR policy |
cybersecurity |
| Standing vendor TPRM operations and monitoring |
vendor-cyber-risk-analyst |
Core Workflows
1. Scope and charter
Define diligence or governance boundaries, stakeholders, timeline, and deliverables.
See references/cyber_diligence_governance_scope.md.
2. M&A and investment diligence
Request lists, evidence review, finding severity, deal protections, and integration themes.
See references/ma_and_investment_diligence.md.
3. Vendor and TPRM assessments
Tier vendors, depth of review, concentration, and renewal triggers.
See references/vendor_and_tprm_assessments.md.
4. Questionnaire and evidence review
Consistent answers, evidence pointers, stale-response controls, and SME routing.
See references/questionnaire_and_evidence_review.md.
5. Governance cadence and reporting
Committee rhythms, IC/board packs, metrics, and exception governance.
See references/governance_cadence_and_reporting.md.
6. Red flags and remediation
Severity rubric, deal terms, integration backlog, and acceptance criteria.
See references/red_flags_and_remediation.md.
Outputs
- Diligence scope memo — objectives, in/out of scope, timeline, roles
- Request list and tracker — ID, owner, status, evidence received
- Findings register — severity, evidence, recommendation, owner, target date
- IC or board brief — executive summary, top risks, asks, integration implications
- Vendor assessment summary — tier, gaps, conditions, renewal date
- Integration security backlog — Day 1 / 30 / 90 with dependencies
- Governance pack outline — agenda, metrics, exceptions, decisions needed
Principles
- Evidence over assertions — require artifacts; flag questionnaire-only claims
- Materiality and deal context — prioritize what affects valuation, liability, or integration
- Separate roles — diligence analysis ≠ legal advice ≠ control implementation
- Time-boxed depth — match review intensity to tier, deal stage, and access granted
- Explicit handoffs — route legal terms, AI programs, and engineering fixes to peer skills
When to load references
- Boundaries and RACI →
references/cyber_diligence_governance_scope.md
- Target or investment diligence →
references/ma_and_investment_diligence.md
- Vendor tiers and TPRM →
references/vendor_and_tprm_assessments.md
- SIG/CAIQ and evidence →
references/questionnaire_and_evidence_review.md
- Committees and board rhythm →
references/governance_cadence_and_reporting.md
- Severity and remediation →
references/red_flags_and_remediation.md
1---2name: cyber-diligence-governance3description: Guides cyber due diligence and governance—M&A/investment diligence, vendor and third-party assessments, questionnaire and evidence review, control maturity and gaps, integration risk, IC/board cyber briefs, and governance cadence. Use for target or vendor security diligence, SIG/CAIQ review, deal or procurement committee packs, post-close integration planning, or IC/board cyber briefs—not pentest (penetration-tester, web-pentester, network-pentester), AI governance only (ai-risk-governance), risk register without diligence (security-risk-analyst), GRC audit prep (compliance-specialist), contract redlines (commercial-counsel), closing logistics (transaction-manager), control deploy (information-security-engineer), CISO strategy (chief-information-security-officer), or TPRM ops (vendor-cyber-risk-analyst). Draft only; counsel and deal leads approve binding positions.4---56# Cyber Diligence & Governance78## When to Use910- Scope and run **M&A or investment cyber diligence** on a target or portfolio company11- Plan **vendor and third-party security assessments** (onboarding, renewal, concentration)12- Review **security questionnaires** (SIG, CAIQ, custom) and map answers to evidence13- Perform **control maturity and gap analysis** for diligence or governance (not full audit)14- Assess **integration and transition risk** (identity, data, tooling, contracts, talent)15- Prepare **investment committee, deal team, or board cyber briefs** with red flags and asks16- Design **ongoing security governance cadence** (committee packs, exception reviews, metrics)17- Coordinate diligence **workstreams** with legal, IT, HR, and product without owning closing1819## When NOT to Use2021- Execute authorized penetration tests or exploit validation → `penetration-tester`, `web-pentester`, `network-pentester`22- Classify AI use cases, model cards, or AI vendor data terms → `ai-risk-governance`23- Maintain enterprise risk registers, FAIR scoring, or risk appetite without deal/vendor lens → `security-risk-analyst`24- Stand up GRC programs, framework scope, or audit walkthrough prep → `compliance-specialist`25- Automate SOC 2/ISO evidence collection → `compliance-engineer`26- Negotiate contract redlines, DPAs, or liability terms → `commercial-counsel`27- Run closing matrix, signatures, funds flow, or data room logistics → `transaction-manager`28- Deploy IAM, SIEM, EDR, or remediate findings → `information-security-engineer`29- Define CISO program strategy, risk appetite, or board operating model → `chief-information-security-officer`30- Lead active incidents or SOC triage → `incident-responder`, `soc-analyst`31- Operate standing TPRM intake, scoring, and continuous vendor monitoring → `vendor-cyber-risk-analyst`3233## Related skills3435| Need | Skill |36|---|---|37| AI use-case tiers, model governance, AI vendor review | `ai-risk-governance` |38| Risk registers, inherent/residual scoring, treatment | `security-risk-analyst` |39| GRC program, audit prep, questionnaire response library | `compliance-specialist` |40| Contract, DPA, indemnity, and commercial terms | `commercial-counsel` |41| Deal timeline, diligence coordination, closing | `transaction-manager` |42| Control implementation and remediation engineering | `information-security-engineer` |43| Executive security strategy and board operating model | `chief-information-security-officer` |44| Pentest findings as diligence input | `penetration-tester` |45| Enterprise security program and IR policy | `cybersecurity` |46| Standing vendor TPRM operations and monitoring | `vendor-cyber-risk-analyst` |4748## Core Workflows4950### 1. Scope and charter5152Define diligence or governance boundaries, stakeholders, timeline, and deliverables.5354**See `references/cyber_diligence_governance_scope.md`.**5556### 2. M&A and investment diligence5758Request lists, evidence review, finding severity, deal protections, and integration themes.5960**See `references/ma_and_investment_diligence.md`.**6162### 3. Vendor and TPRM assessments6364Tier vendors, depth of review, concentration, and renewal triggers.6566**See `references/vendor_and_tprm_assessments.md`.**6768### 4. Questionnaire and evidence review6970Consistent answers, evidence pointers, stale-response controls, and SME routing.7172**See `references/questionnaire_and_evidence_review.md`.**7374### 5. Governance cadence and reporting7576Committee rhythms, IC/board packs, metrics, and exception governance.7778**See `references/governance_cadence_and_reporting.md`.**7980### 6. Red flags and remediation8182Severity rubric, deal terms, integration backlog, and acceptance criteria.8384**See `references/red_flags_and_remediation.md`.**8586## Outputs8788- **Diligence scope memo** — objectives, in/out of scope, timeline, roles89- **Request list and tracker** — ID, owner, status, evidence received90- **Findings register** — severity, evidence, recommendation, owner, target date91- **IC or board brief** — executive summary, top risks, asks, integration implications92- **Vendor assessment summary** — tier, gaps, conditions, renewal date93- **Integration security backlog** — Day 1 / 30 / 90 with dependencies94- **Governance pack outline** — agenda, metrics, exceptions, decisions needed9596## Principles9798- **Evidence over assertions** — require artifacts; flag questionnaire-only claims99- **Materiality and deal context** — prioritize what affects valuation, liability, or integration100- **Separate roles** — diligence analysis ≠ legal advice ≠ control implementation101- **Time-boxed depth** — match review intensity to tier, deal stage, and access granted102- **Explicit handoffs** — route legal terms, AI programs, and engineering fixes to peer skills103104## When to load references105106- **Boundaries and RACI** → `references/cyber_diligence_governance_scope.md`107- **Target or investment diligence** → `references/ma_and_investment_diligence.md`108- **Vendor tiers and TPRM** → `references/vendor_and_tprm_assessments.md`109- **SIG/CAIQ and evidence** → `references/questionnaire_and_evidence_review.md`110- **Committees and board rhythm** → `references/governance_cadence_and_reporting.md`111- **Severity and remediation** → `references/red_flags_and_remediation.md`