Cybersecurity Tools for Due Diligence
Cybersecurity due diligence doesn’t have to rely solely on questionnaires, policies, and representations from the target. Security and intelligence tools can help deal teams independently investigate what they’re buying, identify risks, and test whether the target’s security actually works.
Outside the Target
Black Kite — Assess a target’s cyber risk from the outside, without requiring access to its environment. Black Kite provides external risk intelligence, third-party monitoring, cyber-risk quantification, and supply-chain analysis. It specifically supports M&A and acquisition assessments.
Diligence question: What can we learn about the target before we ever touch its systems?
Recorded Future — Discover internet-facing infrastructure, forgotten assets, shadow IT, misconfigurations, and vulnerabilities associated with a target. Recorded Future specifically identifies M&A as a use case for finding infrastructure and security gaps that may otherwise be inherited with an acquisition.
Diligence question: What does the target expose to the outside world that it may not even know about?
Inside the Environment
ExtraHop RevealX — Observe what’s actually happening across the target’s network. ExtraHop provides network visibility down to packets, applications, protocols, communications, and lateral movement, with physical and virtual sensor options.
Diligence question: What’s actually happening inside the target’s network?
TrueFort — Examine application and workload behavior, relationships, dependencies, data flows, identities, and unexpected activity across cloud and on-premises environments.
Diligence question: What are the target’s critical applications actually doing, and what do they depend on?
Test & Validate
SafeBreach — Safely simulate real attack techniques to determine whether security controls actually prevent or detect them. SafeBreach can test infiltration, lateral movement, and exfiltration and identify the potential blast radius after a breach. Intriguingly for our purposes, SafeBreach even features a customer describing it as “invaluable for acquisitions.”
Diligence question: Don’t just ask whether the target has security controls. Can an attacker actually get anywhere?
LAVA Insights
Practical insights on cybersecurity, technology, law, and risk.
A note about these tools: We include tools because we think they’re interesting and potentially useful, not because we’ve tested or endorsed every product or claim. Do your own diligence. (It is a due diligence page, after all.)
If LAVA has a commercial relationship with a company listed here, we’ll tell you.
