# Cyber Diligence Governance

> Guides cyber due diligence and governance—M&A/investment diligence, vendor and third-party assessments, questionnaire and evidence review, control maturity and gaps, integration risk, IC/board cyber briefs, and governance cadence. Use for target or vendor security diligence, SIG/CAIQ review, deal or procurement committee packs, post-close integration planning, or IC/board cyber briefs—not pentest (penetration-tester, web-pentester, network-pentester), AI governance only (ai-risk-governance), risk register without diligence (security-risk-analyst), GRC audit prep (compliance-specialist), contract redlines (commercial-counsel), closing logistics (transaction-manager), control deploy (information-security-engineer), CISO strategy (chief-information-security-officer), or TPRM ops (vendor-cyber-risk-analyst). Draft only; counsel and deal leads approve binding positions.

- Skill: `daemon-blockint-tech/cyber-diligence-governance` (Agent Skill, multi-file: 7 files)
- Install (CLI): `npx skillmds@latest add daemon-blockint-tech/cyber-diligence-governance`
- Raw SKILL.md: https://api.skillmd.com/api/skills/daemon-blockint-tech/cyber-diligence-governance/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: daemon-blockint-tech (https://skillmd.com/u/daemon-blockint-tech)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/daemon-blockint-tech/cyber-diligence-governance

---


# Cyber Diligence & Governance

## When to Use

- Scope and run **M&A or investment cyber diligence** on a target or portfolio company
- Plan **vendor and third-party security assessments** (onboarding, renewal, concentration)
- Review **security questionnaires** (SIG, CAIQ, custom) and map answers to evidence
- Perform **control maturity and gap analysis** for diligence or governance (not full audit)
- Assess **integration and transition risk** (identity, data, tooling, contracts, talent)
- Prepare **investment committee, deal team, or board cyber briefs** with red flags and asks
- Design **ongoing security governance cadence** (committee packs, exception reviews, metrics)
- Coordinate diligence **workstreams** with legal, IT, HR, and product without owning closing

## When NOT to Use

- Execute authorized penetration tests or exploit validation → `penetration-tester`, `web-pentester`, `network-pentester`
- Classify AI use cases, model cards, or AI vendor data terms → `ai-risk-governance`
- Maintain enterprise risk registers, FAIR scoring, or risk appetite without deal/vendor lens → `security-risk-analyst`
- Stand up GRC programs, framework scope, or audit walkthrough prep → `compliance-specialist`
- Automate SOC 2/ISO evidence collection → `compliance-engineer`
- Negotiate contract redlines, DPAs, or liability terms → `commercial-counsel`
- Run closing matrix, signatures, funds flow, or data room logistics → `transaction-manager`
- Deploy IAM, SIEM, EDR, or remediate findings → `information-security-engineer`
- Define CISO program strategy, risk appetite, or board operating model → `chief-information-security-officer`
- Lead active incidents or SOC triage → `incident-responder`, `soc-analyst`
- Operate standing TPRM intake, scoring, and continuous vendor monitoring → `vendor-cyber-risk-analyst`

## Related skills

| Need | Skill |
|---|---|
| AI use-case tiers, model governance, AI vendor review | `ai-risk-governance` |
| Risk registers, inherent/residual scoring, treatment | `security-risk-analyst` |
| GRC program, audit prep, questionnaire response library | `compliance-specialist` |
| Contract, DPA, indemnity, and commercial terms | `commercial-counsel` |
| Deal timeline, diligence coordination, closing | `transaction-manager` |
| Control implementation and remediation engineering | `information-security-engineer` |
| Executive security strategy and board operating model | `chief-information-security-officer` |
| Pentest findings as diligence input | `penetration-tester` |
| Enterprise security program and IR policy | `cybersecurity` |
| Standing vendor TPRM operations and monitoring | `vendor-cyber-risk-analyst` |

## Core Workflows

### 1. Scope and charter

Define diligence or governance boundaries, stakeholders, timeline, and deliverables.

**See `references/cyber_diligence_governance_scope.md`.**

### 2. M&A and investment diligence

Request lists, evidence review, finding severity, deal protections, and integration themes.

**See `references/ma_and_investment_diligence.md`.**

### 3. Vendor and TPRM assessments

Tier vendors, depth of review, concentration, and renewal triggers.

**See `references/vendor_and_tprm_assessments.md`.**

### 4. Questionnaire and evidence review

Consistent answers, evidence pointers, stale-response controls, and SME routing.

**See `references/questionnaire_and_evidence_review.md`.**

### 5. Governance cadence and reporting

Committee rhythms, IC/board packs, metrics, and exception governance.

**See `references/governance_cadence_and_reporting.md`.**

### 6. Red flags and remediation

Severity rubric, deal terms, integration backlog, and acceptance criteria.

**See `references/red_flags_and_remediation.md`.**

## Outputs

- **Diligence scope memo** — objectives, in/out of scope, timeline, roles
- **Request list and tracker** — ID, owner, status, evidence received
- **Findings register** — severity, evidence, recommendation, owner, target date
- **IC or board brief** — executive summary, top risks, asks, integration implications
- **Vendor assessment summary** — tier, gaps, conditions, renewal date
- **Integration security backlog** — Day 1 / 30 / 90 with dependencies
- **Governance pack outline** — agenda, metrics, exceptions, decisions needed

## Principles

- **Evidence over assertions** — require artifacts; flag questionnaire-only claims
- **Materiality and deal context** — prioritize what affects valuation, liability, or integration
- **Separate roles** — diligence analysis ≠ legal advice ≠ control implementation
- **Time-boxed depth** — match review intensity to tier, deal stage, and access granted
- **Explicit handoffs** — route legal terms, AI programs, and engineering fixes to peer skills

## When to load references

- **Boundaries and RACI** → `references/cyber_diligence_governance_scope.md`
- **Target or investment diligence** → `references/ma_and_investment_diligence.md`
- **Vendor tiers and TPRM** → `references/vendor_and_tprm_assessments.md`
- **SIG/CAIQ and evidence** → `references/questionnaire_and_evidence_review.md`
- **Committees and board rhythm** → `references/governance_cadence_and_reporting.md`
- **Severity and remediation** → `references/red_flags_and_remediation.md`

