Industries · Private Equity
IT risk is deal risk. On both sides of the table.
Whether you’re acquiring a company or preparing to be acquired, the technology environment is under scrutiny. Our IT and cybersecurity due diligence goes deeper than questionnaires, surfacing the exposures that affect valuation, negotiation, and life after close.
Pre-acquisition diligence
Post-close assessment
Exit readiness
Sound familiar?
Questionnaires only tell you what the target knows.
Diligence built on self-reporting
A questionnaire goes out, answers come back, and someone writes a summary. What the target doesn’t know never makes it in.
Old compromises that were never closed
An email compromise from months ago, “handled” with a password reset, is still an open exposure.
Security that exists on paper
Tools that were bought but aren’t working, and cloud environments configured nothing like the target describes.
Insurance that won’t pay out
Controls that don’t match the cyber policy’s requirements turn a covered incident into an uncovered one.
What changes
Know what you’re buying before you sign.
For buyers it’s unpriced risk. For sellers it’s a valuation hit they never saw coming. We find it first.
01
Risk priced before close
Independent findings that inform valuation, negotiation, and deal terms, not a restatement of what the target told you.
02
Hidden incidents brought to light
We reconstruct historical compromises, including the timeline, the scope, and what data was accessed and by whom.
03
Exposure the target doesn’t know about
Leaked credentials, exposed API keys, and sensitive data discoverable through public and semi-public sources.
04
The gap between claimed and actual
Unpatched systems, misconfigured cloud environments, weak identity controls, and security tooling that isn’t doing its job.
05
Remediation costs you can plan around
Cost estimates and integration complexity in the readout, so post-close budgets hold.
06
A readout built for deal teams
An executive-level report written for investment committees and operating partners, not for IT departments.
How pre-acquisition diligence works
We walk in already knowing where to look.
1
Outside-in intelligence
Before any conversation with the target, we build a risk profile from their publicly observable footprint: exposure, attack surface, signs of past compromise, and the technology in use. No access or cooperation required.
2
Directed validation
Targeted interviews and technical validation with the target’s team. We don’t ask whether they have issues. We ask about the specific exposures we’ve already found.
3
Risk and remediation readout
A clear report covering risk posture, identified exposures, historical incidents, remediation cost estimates, and integration complexity, built to inform valuation and post-close planning.
Three engagements
Diligence for every stage of the deal.
Pre-acquisition due diligence
An independent assessment of IT and cyber risk before the deal closes, surfacing hidden liabilities and informing valuation. Typically 2 to 4 weeks, depending on target complexity.
Post-close IT assessment
The deal closed, and now you need to know exactly what you own. We baseline the environment, flag immediate risks, and build a prioritized remediation roadmap. Typically 3 to 6 weeks, starting right after close.
Exit readiness
For companies approaching a sale, merger, or recapitalization. We find and fix what a buyer’s team would find, then document it. Typically 60 to 90 days, aligned to your exit timeline.
For companies approaching a sale
Fix it on your timeline, not the buyer’s.
Buyers are getting more sophisticated about IT and cyber diligence, and what they find affects your valuation and your leverage. We assess your environment through the same lens we use when we work for acquirers, remediate what will actually create deal friction, and hand you a clean technology profile to share proactively. A well-documented environment signals operational maturity, and that turns into confidence at the table.
Clear scope, no overreach
What diligence covers
We stay in our lane. If the deal needs capabilities outside IT and cybersecurity, we’ll tell you and help you find the right partner.
Infrastructure and security
IT infrastructure assessment, cybersecurity posture and controls, identity and access management, and endpoint and network security.
Cloud environments
Configuration review across Microsoft 365, Google Workspace, Azure, and AWS.
Incidents and exposure
Historical incident reconstruction and data exposure analysis, including leaked credentials and exposed keys.
Compliance and cost
Compliance alignment against HIPAA, SOC 2, NIST, PCI-DSS, and CMMC, plus remediation cost estimates and integration planning.
Out of scope
Operational software and business applications, business process and workflow evaluation, financial systems and ERP, and legal or regulatory advice.
Why AlignLayerNine
Operators, not consultants.
We run IT and security environments every day, so we know what things cost to fix because we fix them. When a deal needs it, we carry the work from diligence through remediation to managed operations. When a firm just needs the report, we deliver it and step back.
The foundation
AlignCORE
Fully managed or co-managed IT: support, monitoring, and protection for every user and device.
Learn more →
Add-on to AlignCORE
AlignSHIELD
Advanced defense and financial protection, built on top of AlignCORE.
Learn more →
Stands on its own
AlignASSURE
vCISO leadership and a compliance program, with or without AlignCORE.
Learn more →
Direction
IT Strategy
A roadmap and a budget your leadership can act on.
Learn more →
Questions
What people ask first.
How long does diligence take?
Pre-acquisition diligence typically takes 2 to 4 weeks, depending on target complexity. Post-close assessments take 3 to 6 weeks and can start immediately after close. Exit readiness typically runs 60 to 90 days, aligned to your timeline.
Do you need access to the target to start?
No. We begin with outside-in intelligence from the target’s publicly observable footprint, then move to targeted interviews and technical validation with their team.
“We’ve never had an incident.” Is that good news?
Not necessarily. It usually means incidents happened and weren’t detected, not that the environment is clean. Buyer diligence teams, including ours, can reconstruct historical compromises.
Can you fix what you find?
Yes. We can take the engagement through remediation to fully managed operations with AlignCORE, AlignSHIELD, and AlignASSURE, or deliver the report and step back.
Your next deal deserves better diligence.
Evaluating an acquisition or preparing for sale? We’ll scope the engagement to your deal timeline.