Annual publications on what actually happens where cyber risk meets the way modern businesses move — deals, vendors, compliance, autonomous systems, portfolios.
Three commitments, on every piece we publish.
An annual account of what cyber risk does to mergers, acquisitions and private equity deals. Issue 01 runs 22 findings across 31 sources: how often posture moves a price, what diligence actually covers today, and why the practice thins out almost entirely below $25B AUM.
Every vendor incident asks a customer the same thing on day one: are we in scope, and what is it worth? Almost no program is built to answer it. A full calendar year of vendor incidents — what they cost, who they reached, and how to price your own exposure the next time one lands.
Long-form, annual, heavily sourced. The Diligence Gap Report is the first. These take months and are built to be cited.
AnnualShorter pieces written from live work — a threat cluster worth naming, a pattern in an assessment, an argument that needs making now rather than in January.
As warrantedSurveys we field ourselves, where the public record has a gap in it. Respondents get the dataset before it is published.
One open nowCyber risk has been priced into deals more consistently than it has been diligenced — and the gap is economic, not attitudinal. 22 findings, a venture appendix, 31 sources.
The integrity model underlying Trustworthy Autonomy: how an AI decision can be re-derived by a party that does not trust the system that produced it, and what that requires of the substrate underneath.
A California federal judge ruled Bain Capital can be sued for the PowerSchool breach based partly on conduct before the deal closed. The contractual disclaimer of control didn’t hold. Control-in-fact ate control-on-paper — and that’s the shift.
A five-week vishing wave hit every top private equity firm, every top hedge fund, plus CME and Moody’s. The industry read is “financial firms are targets now.” The durable read is what the deal-team targeting reveals about M&A cyber due diligence.
A quantitative framework for M&A cyber due diligence: how to put a defensible dollar figure on the cyber liability an acquirer inherits, broken down by category, before the deal is signed. The academic basis for the Cyber Cost of Deal methodology.
A practitioner’s guide to third-party risk and incident management. The book underlying DC-TPIR — four failure modes, four decision options, and the institutional-memory-and-mitigation-debt lens the paper formalized.
The quantitative framework behind our M&A cyber diligence practice — the Cyber Cost of Deal model in five pillars, and what to do about each of them.
Reports and field notes, sent when they publish. Have an idea for research? Send us a note!
Thank you — you’ll get the next piece the day it publishes.
Corrections and counter-evidence are welcome at [email protected] — the next edition is better for them.