vC vCISO Lite
Platform Services Field notes Research Learn
vCISO Lite Research

Independent research on cyber diligence third-party risk AI governance continuous compliance cyber insurance

Annual publications on what actually happens where cyber risk meets the way modern businesses move — deals, vendors, compliance, autonomous systems, portfolios.

Three commitments, on every piece we publish.

Sourced. Every figure carries its origin and its date. Bounded. We state what we couldn’t verify, in the same breath as what we could. Unsponsored. Nobody pays for placement in our research.
The Diligence Gap Report, Issue 01 cover
Inaugural issue · annual Issue 01 in 133 days

The Diligence Gap Report

An annual account of what cyber risk does to mergers, acquisitions and private equity deals. Issue 01 runs 22 findings across 31 sources: how often posture moves a price, what diligence actually covers today, and why the practice thins out almost entirely below $25B AUM.

$26K Spent per deal
$2.1M Average impact
81 / 29 Diligence rate by AUM
Get Issue 01 on release Contribute to the survey
The exposure question, Issue 02 cover
Next drop · April 2027 Issue 02 · Third-party risk

The exposure question

Every vendor incident asks a customer the same thing on day one: are we in scope, and what is it worth? Almost no program is built to answer it. A full calendar year of vendor incidents — what they cost, who they reached, and how to price your own exposure the next time one lands.

Vendor incident response Concentration AI dependency
See what it covers Get on the list Jan 2026 – Jan 2027

Three lines of work

Different cadence, same standard
01 Rp

Reports

Long-form, annual, heavily sourced. The Diligence Gap Report is the first. These take months and are built to be cited.

Annual
02 Fn

Field notes

Shorter pieces written from live work — a threat cluster worth naming, a pattern in an assessment, an argument that needs making now rather than in January.

As warranted
03 Sv

Primary research

Surveys we field ourselves, where the public record has a gap in it. Respondents get the dataset before it is published.

One open now

Everything we’ve published

Newest first
Report January 2027 Forthcoming

The Diligence Gap Report, Issue 01

Cyber risk has been priced into deals more consistently than it has been diligenced — and the gap is economic, not attitudinal. 22 findings, a venture appendix, 31 sources.

Paper 2026 · SSRN

Trustworthy Autonomy

The integrity model underlying Trustworthy Autonomy: how an AI decision can be re-derived by a party that does not trust the system that produced it, and what that requires of the substrate underneath.

Field note August 2026

The Court Just Priced Pre-Close Control

A California federal judge ruled Bain Capital can be sued for the PowerSchool breach based partly on conduct before the deal closed. The contractual disclaimer of control didn’t hold. Control-in-fact ate control-on-paper — and that’s the shift.

Field note August 2026

The Acquirer Is the Attack Surface

A five-week vishing wave hit every top private equity firm, every top hedge fund, plus CME and Moody’s. The industry read is “financial firms are targets now.” The durable read is what the deal-team targeting reveals about M&A cyber due diligence.

Paper March 2026 · SSRN

Quantitative Cyber Diligence

A quantitative framework for M&A cyber due diligence: how to put a defensible dollar figure on the cyber liability an acquirer inherits, broken down by category, before the deal is signed. The academic basis for the Cyber Cost of Deal methodology.

Book 2026 · Amazon

Someone Else’s Breach

A practitioner’s guide to third-party risk and incident management. The book underlying DC-TPIR — four failure modes, four decision options, and the institutional-memory-and-mitigation-debt lens the paper formalized.

Book 2026 · Amazon

Someone Else’s Debt

The quantitative framework behind our M&A cyber diligence practice — the Cyber Cost of Deal model in five pillars, and what to do about each of them.

Get it when it lands

Reports and field notes, sent when they publish. Have an idea for research? Send us a note!

Corrections and counter-evidence are welcome at [email protected] — the next edition is better for them.