Turning Diligence Findings Into Deal Terms

16 minute read
Intermediate

Price adjustment, escrow, specific indemnity, or closing condition? How technology findings become enforceable language, and why R&W cover fails.

Six Instruments, and the Facts That Select Them

Three variables select the instrument. Is the cost quantified or uncertain? Is the liability known or unknown? Can it be fixed before money moves? Answer those three and the instrument is usually obvious. Skip them and you will default to an escrow, because an escrow feels like doing something.

InstrumentUse whenWhat it doesSeller's response
Purchase price adjustmentCost is quantified and undisputedReduces the number, permanently and with certaintyResists hardest. It is the only instrument they feel immediately.
Escrow or holdbackCost is probable but uncertain in amount or timingFunds set aside, released on completion or expiryAccepts more readily. They expect to get it back.
Specific indemnityLiability is known and identifiedDollar-one recovery outside the general cap, longer survivalResists hard. It reaches past the policy to their pocket.
Representations and warrantiesRisk is unknownAllocates what nobody found, backed by policy or escrowNegotiates qualifiers, not the concept.
Closing conditionThe problem is fixable before closingNo money moves until the work is done and verifiedAccepts more readily than price. Costs time, not cash.
Retention packageKey person or single-point-of-knowledge riskTies an individual in past closing with payment milestonesNegotiates who pays. Depends when you raise it.

Purchase Price Adjustment

The cleanest instrument and the hardest to obtain, because it is the only one where the seller feels the money leave. Use it when the cost is quantified, undisputed, and preferably evidenced by a third party: a written audit fee quote, a licence true-up invoice from the vendor, a migration statement of work from a named integrator, a remediation estimate built from engineer-months with a disclosed loaded-cost assumption. See Quantifying Technical Debt for the Deal Model for how to construct that number so it survives challenge.

Buyers frequently accept an escrow when a price reduction was available, because the escrow sounds less confrontational. That is a bad trade and it is worth being clear about why. A price reduction is certain and permanent. An escrow is a claim you may have to make, against release mechanics the seller negotiated, within a survival period the seller shortened, subject to a basket you may not clear. If the cost is known and certain, take it out of the price.

Escrow or Holdback

For costs that are probable but not yet fixed: a remediation program whose final scope depends on work not yet done, a regulatory matter with an uncertain outcome, an open contract dispute.

Prefer a third-party escrow over a seller-held holdback against future consideration. A holdback is worth the credit of the entity holding it, and a private seller entity that distributes proceeds to a fund's limited partners and winds up is not a credit you can collect against in year three. This is a structural point that matters far more in sponsor-to-sponsor deals than in corporate acquisitions, and it is why the Yahoo liability-sharing arrangement discussed below worked in a way that would not transfer to a private transaction.

The release mechanics are where the value sits, and they are usually drafted as an afterthought. A calendar release converts your negotiating position into a waiting game: the seller simply has to not cooperate for eighteen months. Tie release to completion of an enumerated remediation schedule, verified by a named third party, with the buyer selecting the verifier. And be careful who controls the work. If the seller controls remediation and the escrow releases on the seller's own certification of completion, you have funded a ceremony.

Specific Indemnity

For a known, identified liability: a prior security incident, an open compliance failure, an unresolved regulator inquiry, a licence dispute, an unassigned piece of intellectual property, a customer contract in breach.

The features that make it worth fighting for are the ones sellers strip out first. A specific indemnity should sit outside the general indemnification cap, should not be subject to the basket or deductible, should recover from dollar one, and should survive beyond the general survival period, typically to the expiry of the applicable statute of limitations rather than twelve or eighteen months. Define the matter by reference to the specific disclosure schedule item so there is no argument later about what was covered. Define covered losses expressly to include notification and credit monitoring costs, forensic and legal fees, third-party claims and defense costs, customer contractual remedies, and remediation, rather than relying on a general definition of losses to reach them.

Sellers resist specific indemnities harder than any other instrument, and the resistance is information. It is the one mechanism that reaches past the representations and warranties policy and back into the seller's own proceeds. How hard a seller fights a specific indemnity is the most honest available signal of how that seller privately rates the risk.

Representations and Warranties

Reps allocate unknown risk. That is their entire function. Once diligence finds something, the rep stops protecting you as to that thing, which is the mechanism explained in the next section.

The technology and cyber reps worth negotiating carefully: no unauthorized access to or security incident affecting systems or data, with a defined lookback; compliance with applicable data protection law and with the target's own published privacy commitments; ownership of all intellectual property including written assignments from every employee and contractor who contributed code; open source usage, with a representation that no copyleft-licensed component is incorporated into or distributed with the products in a manner triggering source disclosure obligations; sufficiency of the systems and assets to operate the business as conducted; and disclosure of all material third-party technology dependencies and transitional arrangements.

The fight is over the knowledge qualifier. "To Seller's knowledge, there has been no unauthorized access to the Company's systems." That formulation converts a risk allocation into a statement about what a handful of named executives happen to remember, which is worth close to nothing in an environment with thirty days of log retention and no detection capability. Push for a flat representation. If you must qualify it, define knowledge persons by name to include the people who would actually know, and include constructive knowledge, meaning knowledge that would be acquired after reasonable inquiry. A seller who will give you a flat no-incident rep is telling you something. A seller who insists on actual-knowledge-only is telling you something else. See What Is M&A Cyber Due Diligence.

Closing Condition

The most underused instrument in technology diligence and the one with the best success rate, because it costs the seller time rather than cash. Use it for anything genuinely fixable in the period between signing and closing.

Examples that get agreed: multi-factor authentication enforced on all privileged accounts and all remote access, evidenced by a configuration export; rotation of all administrative credentials and long-lived API keys with attestation; removal of a specific copyleft component from the distributed product; execution of a data processing agreement with a named subprocessor; assignment of a critical vendor contract; delivery of a final forensic report from a named firm confirming eradication; written IP assignments obtained from three named former contractors.

Draft them objectively and verifiably. Never draft a technology closing condition as satisfaction "in the Buyer's sole discretion" or "in form and substance reasonably satisfactory to the Buyer." Sophisticated sellers will not accept it, and if they do you have bought a dispute rather than a condition. Name the deliverable, name who produces it, and name the standard it has to meet.

Retention Package

Not a pricing instrument. A risk instrument, for the finding that appears in nearly every mid-market software diligence: one named engineer holds the deployment knowledge, the production credentials, and the only working mental model of the billing logic.

Structure it with three components. A retention bonus, escrowed, paid in tranches over twelve to twenty-four months. A confirmatory intellectual property assignment and restrictive covenant signed at closing, which is frequently the first time the assignment has ever been properly papered. And knowledge transfer milestones as a condition of payment: documented runbooks, infrastructure as code, a named and trained second person. Pay for the transfer, not just the presence.

Who funds it depends entirely on when you raise it. Raised before signing, it is a seller cost negotiated into the deal. Discovered after signing, it is yours. See Post-Close Technology Integration.

The Representations and Warranties Insurance Trap

Most buyers operate on a premise that is wrong in both directions: we have a policy, so the reps are covered, so we disclose what diligence found and the policy absorbs it.

Understand the mechanism precisely, because it determines whether your findings end up in an agreement or in a file.

Known Issues Are Excluded, By Design

The underwriting process is not a formality. The underwriter reads your diligence reports. That is what the underwriting call is for. They will ask, directly, what you found. Anything identified in diligence becomes a known matter, and known matters are excluded, both through specific policy exclusions and through the no-claims declaration.

The no-claims declaration is the part deal teams underestimate. Signed at signing and brought down at closing, it states that the deal team has no actual knowledge of any breach of any representation. Signing that with knowledge of a matter is a serious problem. Disclosing the matter produces an exclusion. There is no third door.

The consequence sounds perverse and is not: the better your diligence, the more is excluded from your policy. The policy was never designed to cover what you found. It covers what nobody could have found. A buyer who scopes thin diligence hoping the policy will backstop everything has misunderstood the product.

Inadequate Diligence Is Also Uncovered

The other direction fails too. Underwriters scope coverage to areas that were actually diligenced, and they say so in the policy. A representation covering a subject matter the buyer did not investigate is frequently excluded outright or subjected to a heightened standard. If a claim arises in an area where diligence was thin, the underwriter has a straightforward argument that the buyer did not conduct diligence consistent with a reasonable buyer in the circumstances, and coverage becomes contested at exactly the moment you need it.

So both failure modes end in the same place. Find it, and it is excluded. Do not look, and it is excluded or contested. The policy does not solve the problem either way. It was never the instrument for findings.

Cyber and Data Privacy Exclusions Are Common and Broad

Beyond the known-issue mechanism, representations and warranties policies routinely carry standalone exclusions or sublimits for data security and privacy matters. In some industries and for some risk profiles the exclusion is close to automatic, and it is frequently triggered by the simple absence of a dedicated cyber diligence workstream in the buyer's scope.

This is the commercial argument for scoping cyber diligence that almost no buyer makes, and it is the strongest one. Underwriters will often narrow or remove a cyber exclusion when presented with a credible cyber diligence report. The cost of the workstream is measured in tens of thousands of dollars. The exclusion it removes sits on a policy with a limit measured in tens of millions.

Where cyber coverage is available, read for four things: a sublimit well below the policy limit; a higher retention applying only to cyber claims; exclusion of regulatory fines and penalties, and separately of payment card industry assessments, which are contractual rather than regulatory and are frequently excluded under a different provision; and a carve-out for any incident whose underlying cause predates the policy inception or a stated retroactive date. That last one is the killer in a deal where the target has been running without detection capability, because the underlying cause of almost anything predates inception. See What Is a Cyber Insurance Attestation.

The Resolution

Stop treating the policy as the destination for findings. Findings go into the agreement. The sequence is:

  • Find it. Which requires a scope that actually looks, including at whether the environment is currently compromised. See What Is a Compromise Assessment.
  • Quantify it. A dollar figure with a method behind it, not a severity rating.
  • Classify it. One-time cost or permanent cost, known liability or unknown risk, fixable before closing or not.
  • Select the instrument and draft the language.
  • Negotiate it into the agreement.
  • Then disclose it to the underwriter and accept the exclusion without concern, because the matter is already papered somewhere that will actually pay.

The finding is covered by the specific indemnity you negotiated. Not by the policy. That is the whole answer, and the reason it is rarely given is that it requires negotiating rather than buying.

Sizing an Escrow Against a Plausible Post-Close Breach Cost

The most common sizing error is using an expected value. An escrow is only needed in the bad case. Sizing it to the mean of a distribution that includes a large number of near-zero outcomes guarantees it will be inadequate precisely when it matters.

Build it in layers, from the specific facts of the target rather than from a benchmark.

  • Response cost. Forensics, breach counsel, crisis communications, and internal cost. Largely fixed and largely independent of record count.
  • Notification and monitoring. Per record, and therefore driven entirely by the population at risk and the data categories involved. Establish the record count and the fields. Identity document numbers, payment data, and health information escalate the cost and the obligation.
  • Regulatory. Under GDPR, administrative fines for the most serious infringements reach the higher of 20 million euros or 4 percent of total worldwide annual turnover of the preceding financial year. In the United States, state attorney general settlements, sector regulators, and Federal Trade Commission consent orders each carry their own exposure. Whether a contractual indemnity can reach a regulatory fine is a question of governing law and policy, and counsel decides it.
  • Third-party litigation. Class action defense and settlement. The Yahoo consumer data breach litigation settled for 117.5 million dollars, approved in 2020, which is a useful order-of-magnitude anchor for a consumer-scale event.
  • Customer contractual remedies. The line buyers miss most often. Read the target's largest customer agreements for security incident notification obligations, service credits, audit rights, termination rights on a security event, and indemnity flow-downs. In B2B software the contractual exposure to twenty enterprise customers frequently exceeds the regulatory exposure.
  • Business interruption. Revenue lost during an outage and churn afterward, modeled against the actual recovery capability rather than the documented one.

Use published averages only as a sanity check, never as the number. IBM's Cost of a Data Breach Report 2025 put the global average at 4.44 million dollars and the United States average at 10.22 million dollars, a record for the country. If your layered build lands an order of magnitude away from those figures, re-examine your assumptions before you present it.

Then subtract insurance. Establish the target's cyber policy limit, retention, sublimits, and whether the prior knowledge and retroactive date provisions would allow it to respond at all. The escrow sizes to the uninsured portion of a plausible adverse outcome, not the gross figure.

Finally, set the release period against the real tail rather than the general survival period. Regulatory matters surface on a multi-year timeline. In the Marriott case, an intrusion that began in 2014 was discovered in 2018 and produced a final penalty in 2020. A twelve-month escrow against that risk profile is theater. See When Diligence Finds an Active Compromise and What Is Sponsor Cyber Liability.

When to Walk, and When to Use the Finding

Five Findings That Are Walk-Aways Rather Than Price Items

Almost everything has a price. These do not, because money and time do not reliably fix them inside a hold period.

An undisclosed active compromise the seller will not investigate or remediate. The refusal is the disqualifying fact, not the intrusion. A seller who will not fund an investigation into a live finding is telling you how the business has been run and how it will respond to the next one under your ownership.

Code the company cannot demonstrate it owns. Contractor-developed code with no written assignment. Founder code written while employed elsewhere. Offshore development agreements with no intellectual property clause, or one governed by a jurisdiction where assignment requires formalities nobody completed. You cannot indemnify your way out of not owning the asset. The theoretical remedy, which is obtaining signatures from developers who left four years ago, is unenforceable in practice and the failure case is the thesis.

A copyleft obligation attached to the core product. GPL or AGPL licensed components incorporated into distributed or network-served software with no compliance analysis. AGPL is the one that matters in software as a service, because the network use provision reaches software that is never distributed in the traditional sense. The remedy is replacing the component or releasing the source, and for a software business the second is not a remedy. This requires genuine legal and engineering analysis rather than a scanner output: many GPL findings sit in build tooling and development dependencies and create no obligation at all. But the analysis has to be done, and the absence of a dependency inventory means it has not been. See What Is an SBOM.

A regulated-data compliance failure with an open regulator matter. An undisclosed investigation, an unremediated examination finding, a consent order with outstanding obligations. The problem is not the size of the eventual penalty. The problem is that a regulator now controls your timeline, your ability to execute the plan, and in some sectors your ability to complete the acquisition at all.

Financial statements that depend on a system nobody can audit. If revenue recognition runs through a spreadsheet or a bespoke application with no access controls, no change management, and no audit trail, then the quality of earnings work is built on unverifiable inputs and everything downstream of it is an estimate. This is a technology finding that invalidates a financial workstream, and technology diligence is usually the only workstream positioned to catch it.

For a fuller catalogue of what should stop a process, see Technology Due Diligence Red Flags.

Your Position Decays. Time Your Findings Accordingly.

The timing question gets answered badly because it gets answered by instinct. Bargaining power and information move in opposite directions across a process, and the window where both are adequate is narrow.

StageYour positionYour informationWhat a finding achieves
Pre-LOI, competitive processStrongest. You have spent nothing and they have other bidders.Lowest. Data room only.Sets expectations. Raising something soft and being wrong costs credibility for the whole process.
In exclusivityGood. They have stopped talking to others and have a clock.Highest. Full access, management sessions, technical review.This is the re-trade window. A quantified, evidenced finding with an instrument attached lands here.
SPA negotiationDecaying. They know what you have spent and that you told your committee.Complete.Findings get papered into reps and indemnities rather than priced.
Signed, pre-closingMinimal, unless you negotiated a condition or a walk right.Complete.Nothing, absent an instrument you already secured.

One rule governs the whole table. Never raise a finding you cannot price. A seller will dispose of an unquantified concern in a single conversation, and once disposed of you cannot credibly re-raise it when the number arrives three weeks later. Hold the finding until it has a dollar figure and a proposed instrument, then raise it inside exclusivity as a package.

Present a Markup, Not a List of Problems

The difference between a re-trade that lands and one that gets dismissed is almost entirely presentation, and the principle is simple: sellers negotiate against drafted language and reject demands.

For each item, deliver four things together. The finding, stated factually. The number, with the method. The evidence, in one sentence. And the specific clause, drafted. "We found X. It costs Y, calculated this way. Here is the evidence. Here is the indemnity language." A seller handed drafted language starts editing it, and editing is conceding. A seller handed a demand takes a position.

Bundle the technology ask into a single package with a total, and know in advance which two or three items you are prepared to trade away. A seller who wins a few items feels they negotiated and signs. A seller facing seven non-negotiable demands escalates to the principal and the process stalls. For how the underlying deliverable should be structured to support this, see The Technology Due Diligence Report.

The Disclosure Schedule Is the Permanent Record

Every finding you raise either lands on the disclosure schedules or it does not, and that placement determines its treatment for years.

Scheduled items are known. They are excluded from the representations and warranties policy, they cannot support a claim under the general reps, and they must be addressed directly through a specific indemnity, an escrow, a price adjustment, or a closing condition. Unscheduled items remain unknown and stay inside the representation regime, where the policy may respond.

That trade-off means the decision about what to raise in writing, and how to characterize it, has consequences beyond the immediate negotiation. There are circumstances in which a buyer is better served by a matter remaining within the general representation than by having it scheduled and specifically addressed, and circumstances where the opposite is plainly true. That judgment sits with counsel, informed by the technology findings. It is not a decision for a diligence vendor and it is not a decision to make at eleven at night during schedule exchange.

A Short Note on What This Is Not

Nothing in this article is legal advice. The instruments described here derive their effect entirely from drafting, governing law, and the facts of a specific transaction. Survival periods, sandbagging provisions, indemnity caps and baskets, and the enforceability of a contractual indemnity for regulatory penalties all vary by jurisdiction and by agreement. The purpose here is to give a deal team the vocabulary and the selection logic to instruct counsel precisely, which is a materially better outcome than handing a lawyer a technology report and hoping.

Related Reading

Frequently Asked Questions

Which deal instrument should be used for a technology diligence finding?

Three questions select it. If the cost is quantified and undisputed, take a purchase price adjustment. If it is probable but uncertain in amount or timing, use an escrow with release tied to verified remediation rather than a calendar date. If it is a known, identified liability such as a prior incident or an open compliance failure, negotiate a specific indemnity outside the general cap with extended survival. If the risk is genuinely unknown, that is what representations are for. If the problem can be fixed before money moves, make it a closing condition, which costs the seller time rather than cash and therefore succeeds most often.

Does representations and warranties insurance cover issues found in due diligence?

No. Underwriters exclude known matters by design. They read your diligence reports during underwriting, they ask what you found, and identified matters are excluded both through specific exclusions and through the no-claims declaration signed at signing and brought down at closing. The perverse-sounding consequence is that better diligence produces more exclusions. The policy covers what nobody could have found, not what you found. Identified findings have to be negotiated directly into the agreement through a specific indemnity, escrow, price adjustment, or closing condition.

If known issues are excluded, is it better not to look?

No, and the reason is that inadequate diligence is also uncovered. Underwriters scope coverage to areas the buyer actually investigated. A representation covering a subject the buyer did not diligence is frequently excluded outright or held to a heightened standard, and if a claim arises in a thin area the underwriter argues the buyer failed to conduct diligence consistent with a reasonable buyer. Both failure modes end in the same place. The difference is that a buyer who looked can negotiate the finding into the agreement, where it will actually be paid.

Why do R&W policies exclude cyber and data privacy?

Because the risk is difficult to underwrite, the tail is long, and the underlying cause of most incidents predates policy inception. Standalone cyber and privacy exclusions and sublimits are common, and the exclusion is frequently triggered by the absence of a dedicated cyber diligence workstream in the buyer's scope. Underwriters will often narrow or remove it when presented with a credible cyber diligence report, which is the strongest commercial argument for scoping one. Where coverage exists, read for sublimits, elevated retentions, exclusion of regulatory fines and PCI assessments, and retroactive date carve-outs.

How should an escrow be sized against a possible post-close breach?

Against a plausible adverse outcome, not an expected value. An escrow is only needed in the bad case, so sizing to a mean that includes many near-zero outcomes guarantees inadequacy. Build in layers from the target's specific facts: response cost, per-record notification and monitoring driven by the population and data categories, regulatory exposure, third-party litigation, customer contractual remedies under the largest agreements, and business interruption. Then subtract what the target's cyber policy would actually pay after retention, sublimits, and prior knowledge provisions. Set release against the real multi-year tail, not a twelve-month survival period.

When should a diligence finding be used to re-trade the price?

Inside exclusivity. Before the letter of intent your negotiating position is strongest but your information is weakest, and raising a soft issue you later cannot substantiate costs credibility for the remainder of the process. During exclusivity the seller has stopped talking to other bidders and has a clock, while you have full access and complete information. By SPA negotiation your position has weakened because the seller knows what you have spent and that you have already been to committee. One rule governs the whole sequence: never raise a finding you cannot price.

What technology findings justify walking away rather than repricing?

Five. An undisclosed active compromise the seller refuses to investigate or remediate, where the refusal is more disqualifying than the intrusion. Code the company cannot demonstrate it owns, because you cannot indemnify your way out of not owning the asset. A copyleft obligation attached to the core product, particularly AGPL in software as a service, where the remedy is replacement or source disclosure. A regulated-data compliance failure with an open regulator matter, where the regulator controls your timeline. And financial statements produced by a system with no controls or audit trail, which invalidates the quality of earnings work.

Is a specific indemnity enough protection in a sponsor-to-sponsor deal?

Not on its own. An indemnity is worth the credit of the party giving it. A private seller that distributes proceeds to a fund's limited partners and winds up is not a counterparty you can collect from in year three or four. The Verizon and Yahoo liability-sharing arrangement worked in part because the seller remained in existence as a capitalized public entity. In private transactions, back the indemnity with funded security: a third-party escrow rather than a holdback against future consideration, sized to the uninsured portion of a plausible outcome and released on a schedule matching the real tail.

Verizon and Yahoo: What a Mid-Deal Breach Disclosure Actually Costs

Verizon agreed to acquire Yahoo's operating business in July 2016 for approximately 4.83 billion dollars.

In September 2016, after signing, Yahoo disclosed a 2014 intrusion affecting at least 500 million user accounts. In December 2016 it disclosed a separate incident dating to August 2013, initially reported as affecting more than one billion accounts. In October 2017, after the deal closed, the company revised that figure to all three billion accounts in existence at the time.

On 21 February 2017 the parties amended the definitive agreement. The terms are worth reading as a set of instrument choices rather than as a news item.

  • Purchase price reduction of 350 million dollars, taking the price to approximately 4.48 billion dollars. Roughly 7.2 percent of the original consideration. A quantified, certain, permanent adjustment.
  • Retained liabilities. The remaining Yahoo entity, which became Altaba, retained 100 percent of liabilities arising from shareholder lawsuits and from the SEC investigation into the breaches.
  • Shared liabilities. Yahoo would be responsible for 50 percent of any cash liabilities incurred after closing relating to non-SEC government investigations and third-party litigation connected to the breaches.
  • The MAE was expressly disabled. The parties agreed that the breaches would not be taken into account in determining whether a business material adverse effect had occurred or whether the closing conditions had been satisfied.

That last point deserves emphasis because it runs against instinct. Here were two enormous public companies, with excellent counsel, facing a disclosed breach affecting billions of accounts after signing. They did not litigate the material adverse effect clause. They negotiated a price reduction and a liability allocation and then contractually removed the MAE from the analysis. The message for a mid-market deal team is unambiguous: the MAE is not the instrument, specific terms are.

The subsequent numbers show why the work mattered. In April 2018 the SEC announced that Altaba had agreed to pay a 35 million dollar penalty for failing to disclose the 2014 breach, the first enforcement action of its kind. In 2020 a federal court approved a 117.5 million dollar settlement in the consumer data breach litigation. Under the amended agreement, the SEC penalty sat entirely with the seller and the consumer litigation fell into the shared category.

Two cautions before importing this structure into a private transaction. First, the 50/50 split means Verizon accepted half of an unbounded future liability, which is what a buyer takes when the exposure cannot be bounded and the seller holds the stronger position. It is not a template for a favourable outcome, it is a template for a negotiated one. Second, and more important for sponsors, the arrangement worked because the seller remained in existence as a capitalized public entity with assets. A private seller that distributes proceeds to a fund's limited partners and winds up is not a counterparty you can collect from in year four. In sponsor-to-sponsor transactions, escrow beats indemnity for precisely this reason, and an indemnity without funded security is an instrument with no engine behind it.

350 million dollars

That is what Verizon took off the Yahoo purchase price in February 2017 after breach disclosures surfaced mid-deal, alongside a negotiated split of post-closing liabilities. The parties expressly agreed the breaches would not count toward a material adverse effect. Two sophisticated buyers and sellers looked at the MAE, decided it was unreliable, and wrote specific terms instead.

How Cloudskope Can Help

Cloudskope runs technology and cyber due diligence for private equity sponsors, corporate development teams, and their counsel, and we write findings so they can be used. Every item carries a dollar figure, a method, a classification, and a proposed instrument: price, escrow, specific indemnity, closing condition, or accepted and funded in the plan. We work directly with deal counsel on the language, and we produce the report the representations and warranties underwriter needs to narrow or remove a cyber exclusion. Our M&A Cyber and IT Technical Due Diligence practice is built around that output rather than around a maturity model.

Where the question is whether the target's environment is currently compromised, which is the finding that changes instruments rather than numbers, Cloudskope SARTUS delivers the assessment on a diligence timeline: scoped, evidence-preserving, and written to be read by counsel and an investment committee. A no-incident representation is a statement about the state of a network. Someone should check it before it is signed.