What is a vulnerability assessment in due diligence?
A vulnerability assessment in technology due diligence gives an investor a deal-focused view of exploitable security weaknesses, exposed data, remediation cost, and timing risk before signing or completing a transaction. It is broader than a scan report: findings are validated, prioritised by exploitability and business impact, then translated into valuation, SPA protections, and the first 100-day remediation plan.
This page is for PE, VC, and M&A buyers evaluating a target business. We translate technical risk into transaction impact: where the finding is high risk, where the remediation burden is acceptable, and where price, timing, or protections should change.
Vulnerability assessment versus penetration test
Investors often need both terms separated. A vulnerability assessment is the broader diligence layer: it reviews evidence, scan results, cloud and application controls, remediation history, and business impact. A penetration test is narrower and proof-based: it attempts controlled exploitation where a deal team needs stronger evidence before close.
Vulnerability assessment
Identifies and prioritises known weaknesses across infrastructure, applications, cloud configuration, access controls, and evidence records so investors can judge exposure, cost, and urgency.
Typical output: Risk-ranked issue register, exploitability notes, evidence gaps, remediation plan, and deal-impact commentary.
Penetration test
Uses controlled exploitation to prove whether a realistic attack path can reach sensitive systems, data, or privileged access.
Typical output: Attack narrative, reproduced exploit paths, proof evidence, retest scope, and any required containment actions.
PE/VC/M&A security DD checklist
Use this checklist as the core scope for security assessments in investment diligence:
- Vulnerability assessment depth. Review recent scan results, open findings, and remediation status before final diligence sign-off.
- Cloud/IAM controls. Validate access reviews, privileged account governance, and multi-factor authentication coverage.
- Data protection. Confirm data mapping, encryption standards, retention schedules, and GDPR/compliance evidence.
- Incident history. Check response timelines, post-incident remediations, and root-cause ownership.
- Penetration testing evidence. Review report quality, ownership, time-to-fix critical/high findings, and re-test records.
- Remediation cost. Estimate effort in sprints, external specialist input, and post-close workstream timing.
- Deal-risk severity. Grade each exposure against valuation exposure, integration effort, and legal/regulatory consequence.
Detailed security assessment scope
A scoped investor assessment should be explicit about which testing and evidence streams are included, which are excluded, and what level of assurance each stream provides.
External attack-surface scanning
Evidence reviewed: Internet-facing domains, exposed services, certificates, vulnerable dependencies, stale admin panels, and leaked technical metadata.
Investor question: Could an outside attacker find a credible entry point before or shortly after close?
Internal vulnerability scanning
Evidence reviewed: Server, endpoint, network, patching, privileged access, segmentation, and legacy estate findings where access is available.
Investor question: Would integration or post-close access reveal material hygiene debt that affects the 100-day plan?
Application and API testing
Evidence reviewed: Authentication, authorisation, input handling, session management, API exposure, dependency risk, and sensitive workflow controls.
Investor question: Can customer data, revenue workflows, or partner integrations be abused through the product surface?
Cloud and configuration review
Evidence reviewed: IAM, MFA, logging, storage exposure, key rotation, backup controls, deployment settings, and environment separation.
Investor question: Are cloud controls mature enough for the target's data, scale, and regulatory commitments?
Remediation validation
Evidence reviewed: Closure evidence, retest records, patch verification, compensating controls, owner accountability, and unresolved exceptions.
Investor question: Have critical and high findings genuinely been fixed, or are they open deal liabilities?
Penetration testing
Evidence reviewed: Existing test quality, attack-chain coverage, scope exclusions, proof-of-exploit records, retest evidence, and recommended fresh testing.
Investor question: Is proof-based testing needed before close, or can it sit safely in the 100-day plan?
| Scope area | Evidence reviewed | Investor question |
|---|---|---|
| External attack-surface scanning | Internet-facing domains, exposed services, certificates, vulnerable dependencies, stale admin panels, and leaked technical metadata. | Could an outside attacker find a credible entry point before or shortly after close? |
| Internal vulnerability scanning | Server, endpoint, network, patching, privileged access, segmentation, and legacy estate findings where access is available. | Would integration or post-close access reveal material hygiene debt that affects the 100-day plan? |
| Application and API testing | Authentication, authorisation, input handling, session management, API exposure, dependency risk, and sensitive workflow controls. | Can customer data, revenue workflows, or partner integrations be abused through the product surface? |
| Cloud and configuration review | IAM, MFA, logging, storage exposure, key rotation, backup controls, deployment settings, and environment separation. | Are cloud controls mature enough for the target's data, scale, and regulatory commitments? |
| Remediation validation | Closure evidence, retest records, patch verification, compensating controls, owner accountability, and unresolved exceptions. | Have critical and high findings genuinely been fixed, or are they open deal liabilities? |
| Penetration testing | Existing test quality, attack-chain coverage, scope exclusions, proof-of-exploit records, retest evidence, and recommended fresh testing. | Is proof-based testing needed before close, or can it sit safely in the 100-day plan? |
Sample finding → deal risk → remediation/action
The table below shows how technical findings should be translated into transaction language before a final IC packet.
Critical access controls missing on two admin systems
Deal risk: Data exposure and process interruption during onboarding
Remediation / action: Mandatory privileged account audit, immediate role reset, and MFA enforcement before close
Unpatched high-severity vulnerability in payment-facing API
Deal risk: Potential breach and operational outage in first quarter
Remediation / action: Block release path, patch dependency, and require post-deploy verification within 14 days
No documented incident playbook and unclear ownership
Deal risk: Longer response windows and valuation uncertainty on continuity risk
Remediation / action: Introduce runbooks, define incident lead rota, and run a 24-hour tabletop exercise
| Finding | Deal risk | Remediation / action |
|---|---|---|
| Critical access controls missing on two admin systems | Data exposure and process interruption during onboarding | Mandatory privileged account audit, immediate role reset, and MFA enforcement before close |
| Unpatched high-severity vulnerability in payment-facing API | Potential breach and operational outage in first quarter | Block release path, patch dependency, and require post-deploy verification within 14 days |
| No documented incident playbook and unclear ownership | Longer response windows and valuation uncertainty on continuity risk | Introduce runbooks, define incident lead rota, and run a 24-hour tabletop exercise |
Evidence to deal impact
Diligence findings become useful when the evidence is tied to a decision: whether to proceed, change price, ask for protection, or fund a remediation workstream.
Exploitability
Investor impact: Separates theoretical scanner noise from issues a credible attacker could use to reach systems, data, or privileged workflows.
Deal action: Prioritise conditions precedent, holdback logic, or immediate post-close fixes for exploitable high-impact paths.
Data exposure
Investor impact: Shows whether customer, employee, payment, health, or commercially sensitive data could be accessed, leaked, or mishandled.
Deal action: Map exposure to disclosure duties, customer commitments, cyber insurance, and data-room representations.
Regulatory exposure
Investor impact: Identifies whether GDPR, sector obligations, contractual security terms, or audit commitments create liability beyond technical remediation.
Deal action: Convert compliance gaps into legal review points, warranties, indemnity scope, or pre-close evidence requests.
Remediation cost and timing
Investor impact: Estimates whether fixes are a quick hygiene sprint, a platform workstream, or a delay to product and integration plans.
Deal action: Reflect material effort in valuation, completion timing, 100-day resourcing, and specialist budget assumptions.
SPA and 100-day protections
Investor impact: Turns the findings register into specific transaction protections and accountable post-close workstreams.
Deal action: Draft protections around known issues, required evidence, owner accountability, retest milestones, and board reporting cadence.
| Evidence | Investor impact | Deal action |
|---|---|---|
| Exploitability | Separates theoretical scanner noise from issues a credible attacker could use to reach systems, data, or privileged workflows. | Prioritise conditions precedent, holdback logic, or immediate post-close fixes for exploitable high-impact paths. |
| Data exposure | Shows whether customer, employee, payment, health, or commercially sensitive data could be accessed, leaked, or mishandled. | Map exposure to disclosure duties, customer commitments, cyber insurance, and data-room representations. |
| Regulatory exposure | Identifies whether GDPR, sector obligations, contractual security terms, or audit commitments create liability beyond technical remediation. | Convert compliance gaps into legal review points, warranties, indemnity scope, or pre-close evidence requests. |
| Remediation cost and timing | Estimates whether fixes are a quick hygiene sprint, a platform workstream, or a delay to product and integration plans. | Reflect material effort in valuation, completion timing, 100-day resourcing, and specialist budget assumptions. |
| SPA and 100-day protections | Turns the findings register into specific transaction protections and accountable post-close workstreams. | Draft protections around known issues, required evidence, owner accountability, retest milestones, and board reporting cadence. |
Pre-LOI screening or confirmatory due diligence?
Pre-LOI screening
Fast, low-friction review of public attack surface, available security evidence, prior reports, cloud posture indicators, and obvious data-risk signals.
Output: Early red flags, likely confirmatory-DD scope, specialist budget range, and questions to request in the next data-room round.
Confirmatory due diligence
Deeper validation under NDA with target access, management interviews, evidence sampling, selected testing, and remediation planning.
Output: Board-ready conclusions, deal-protection recommendations, priority fixes, owner actions, and 100-day roadmap input.
Vulnerability management and compliance exposure
For UK and EU-relevant businesses, GDPR readiness can materially affect risk transfer and post-close workstreams. We review practical compliance posture across data mapping, lawful basis, consent, retention and breach response obligations. We also consider sector-specific obligations where relevant.
Compliance is not binary. We provide a realistic view of where practices are fit for purpose and where gaps could lead to customer, legal or reputational impact.
How findings affect deal economics
Common findings include over-privileged admin access, incomplete logging, unresolved high findings, weak key rotation, and immature incident processes. We rank each issue against commercial impact so you can decide whether it changes valuation assumptions, triggers conditions precedent, or belongs in the post-close roadmap.
Deliverables include a risk-ranked findings report, immediate remediation priority list, and phased roadmap mapped to value-creation assumptions. We cross-link findings with broader diligence themes from buy-side DD, code review, and post-acquisition planning. For a full framework, see our technology DD guide.
Board-ready deliverables
The output is written for investment committees, boards, deal leads, CTOs, and legal advisers who need a common risk view rather than a raw scanner export.
- Board-ready risk heatmap
- Exploitability-ranked findings register
- Data and regulatory exposure summary
- Remediation cost and timing estimate
- SPA and 100-day protection notes
- Retest and remediation validation plan
Security assessment FAQs
What is a vulnerability assessment during security due diligence?
A vulnerability assessment during security due diligence reviews technical exposure, control maturity, and whether discovered issues materially affect a deal's risk profile, operational continuity, and value-transfer confidence.
Is a vulnerability assessment the same as a penetration test?
No. A vulnerability assessment finds, validates, and prioritises weaknesses across the target environment. A penetration test goes further by attempting controlled exploitation of selected attack paths. Investors often use assessment first, then commission targeted pentesting where proof is needed before close.
Should investors run security assessment before LOI or during confirmatory DD?
Pre-LOI security screening is useful when a target handles sensitive data, has internet-facing software, or carries regulatory risk. Confirmatory DD is the right phase for deeper evidence review, management interviews, target access, validation testing, and transaction-protection recommendations.
What is typically included in security due diligence scope for investors?
Investor-focused security DD usually covers vulnerability management, cloud and IAM governance, data protection controls, incident response, third-party risks, and remediation planning with commercial implications.
When do security findings affect valuation?
Security findings affect valuation when unresolved critical or high issues increase integration risk, delay growth assumptions, create compliance exposure, or materially increase the post-close remediation budget.