| name | cyber-diligence-governance |
| description | Guides cyber due diligence and governance—M&A/investment diligence, vendor and third-party
assessments, questionnaire and evidence review, control maturity and gaps, integration risk, IC/board
cyber briefs, and governance cadence.
Use for target or vendor security diligence, SIG/CAIQ review, deal or procurement committee packs,
post-close integration planning, or IC/board cyber briefs—not pentest (penetration-tester,
web-pentester, network-pentester), AI governance only (ai-risk-governance), risk register without
diligence (security-risk-analyst), GRC audit prep (compliance-specialist), contract redlines
(commercial-counsel), closing logistics (transaction-manager), control deploy
(information-security-engineer), CISO strategy (chief-information-security-officer), or TPRM ops
(vendor-cyber-risk-analyst). Draft only; counsel and deal leads approve binding positions.
|
Cyber Diligence & Governance
When to Use
- Scope and run M&A or investment cyber diligence on a target or portfolio company
- Plan vendor and third-party security assessments (onboarding, renewal, concentration)
- Review security questionnaires (SIG, CAIQ, custom) and map answers to evidence
- Perform control maturity and gap analysis for diligence or governance (not full audit)
- Assess integration and transition risk (identity, data, tooling, contracts, talent)
- Prepare investment committee, deal team, or board cyber briefs with red flags and asks
- Design ongoing security governance cadence (committee packs, exception reviews, metrics)
- Coordinate diligence workstreams with legal, IT, HR, and product without owning closing
When NOT to Use
- Execute authorized penetration tests or exploit validation →
penetration-tester, web-pentester, network-pentester
- Classify AI use cases, model cards, or AI vendor data terms →
ai-risk-governance
- Maintain enterprise risk registers, FAIR scoring, or risk appetite without deal/vendor lens →
security-risk-analyst
- Stand up GRC programs, framework scope, or audit walkthrough prep →
compliance-specialist
- Automate SOC 2/ISO evidence collection →
compliance-engineer
- Negotiate contract redlines, DPAs, or liability terms →
commercial-counsel
- Run closing matrix, signatures, funds flow, or data room logistics →
transaction-manager
- Deploy IAM, SIEM, EDR, or remediate findings →
information-security-engineer
- Define CISO program strategy, risk appetite, or board operating model →
chief-information-security-officer
- Lead active incidents or SOC triage →
incident-responder, soc-analyst
- Operate standing TPRM intake, scoring, and continuous vendor monitoring →
vendor-cyber-risk-analyst
Related skills
| Need | Skill |
|---|
| AI use-case tiers, model governance, AI vendor review | ai-risk-governance |
| Risk registers, inherent/residual scoring, treatment | security-risk-analyst |
| GRC program, audit prep, questionnaire response library | compliance-specialist |
| Contract, DPA, indemnity, and commercial terms | commercial-counsel |
| Deal timeline, diligence coordination, closing | transaction-manager |
| Control implementation and remediation engineering | information-security-engineer |
| Executive security strategy and board operating model | chief-information-security-officer |
| Pentest findings as diligence input | penetration-tester |
| Enterprise security program and IR policy | cybersecurity |
| Standing vendor TPRM operations and monitoring | vendor-cyber-risk-analyst |
Core Workflows
1. Scope and charter
Define diligence or governance boundaries, stakeholders, timeline, and deliverables.
See references/cyber_diligence_governance_scope.md.
2. M&A and investment diligence
Request lists, evidence review, finding severity, deal protections, and integration themes.
See references/ma_and_investment_diligence.md.
3. Vendor and TPRM assessments
Tier vendors, depth of review, concentration, and renewal triggers.
See references/vendor_and_tprm_assessments.md.
4. Questionnaire and evidence review
Consistent answers, evidence pointers, stale-response controls, and SME routing.
See references/questionnaire_and_evidence_review.md.
5. Governance cadence and reporting
Committee rhythms, IC/board packs, metrics, and exception governance.
See references/governance_cadence_and_reporting.md.
6. Red flags and remediation
Severity rubric, deal terms, integration backlog, and acceptance criteria.
See references/red_flags_and_remediation.md.
Outputs
- Diligence scope memo — objectives, in/out of scope, timeline, roles
- Request list and tracker — ID, owner, status, evidence received
- Findings register — severity, evidence, recommendation, owner, target date
- IC or board brief — executive summary, top risks, asks, integration implications
- Vendor assessment summary — tier, gaps, conditions, renewal date
- Integration security backlog — Day 1 / 30 / 90 with dependencies
- Governance pack outline — agenda, metrics, exceptions, decisions needed
Principles
- Evidence over assertions — require artifacts; flag questionnaire-only claims
- Materiality and deal context — prioritize what affects valuation, liability, or integration
- Separate roles — diligence analysis ≠ legal advice ≠ control implementation
- Time-boxed depth — match review intensity to tier, deal stage, and access granted
- Explicit handoffs — route legal terms, AI programs, and engineering fixes to peer skills
When to load references
- Boundaries and RACI →
references/cyber_diligence_governance_scope.md
- Target or investment diligence →
references/ma_and_investment_diligence.md
- Vendor tiers and TPRM →
references/vendor_and_tprm_assessments.md
- SIG/CAIQ and evidence →
references/questionnaire_and_evidence_review.md
- Committees and board rhythm →
references/governance_cadence_and_reporting.md
- Severity and remediation →
references/red_flags_and_remediation.md