1. Define the disclosure question
Determine what happened, what remains exposed, what a buyer needs to know and how evidence should be sequenced.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a cyber-history disclosure thesis.
The principal failure occurs when silence or indiscriminate disclosure replaces a materiality and transaction-risk analysis. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for define the disclosure question should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
2. Set the incident perimeter
Reconcile events, alerts, investigations, outages, fraud, privacy breaches, vulnerabilities and near misses across entities and systems.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is an incident perimeter schedule.
The principal failure occurs when different teams maintain incompatible definitions and incident counts. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for set the incident perimeter should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
3. Build the incident register
Record date, system, data, actor, vector, duration, severity, containment, recovery, cost, notification and owner.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a transaction-grade incident register.
The principal failure occurs when management relies on narrative memory rather than a controlled chronology. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for build the incident register should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
4. Preserve evidence
Protect logs, images, tickets, communications, forensic outputs, legal holds and chain of custody.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is an evidence-preservation protocol.
The principal failure occurs when remediation destroys the evidence needed to support conclusions. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for preserve evidence should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
5. Separate facts from hypotheses
Classify confirmed facts, analytical hypotheses, unresolved questions and closed findings with sources.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a fact-hypothesis ledger.
The principal failure occurs when early assumptions become embedded as final transaction statements. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for separate facts from hypotheses should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
6. Establish root cause
Trace control failures, exploit path, privilege, persistence and organisational contributors.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a root-cause evidence map.
The principal failure occurs when a technical symptom is labelled as the root cause. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for establish root cause should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
7. Define affected assets
Identify systems, identities, records, data classes, customers, suppliers and operational processes within scope.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is an affected-asset schedule.
The principal failure occurs when asset impact is inferred from incomplete inventories. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for define affected assets should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
8. Measure data exposure
Test access, acquisition, exfiltration, alteration, encryption, deletion and downstream misuse for each data class.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a data-impact assessment.
The principal failure occurs when possible access is reported as proven exfiltration or dismissed without evidence. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for measure data exposure should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
Table 1. Incident evidence screen
| Question | Evidence | Decision |
|---|---|---|
| access | forensic artefacts | scope |
| exfiltration | network and endpoint evidence | impact |
| notification | jurisdictional analysis | action |
| closure | independent validation | residual risk |
Illustrative analytical design; company-specific evidence and professional advice govern.

Values are illustrative evidence indices and require company-specific support.
9. Reconstruct the timeline
Align detection, escalation, containment, eradication, recovery, notification and learning milestones.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a verified incident timeline.
The principal failure occurs when elapsed time is calculated from inconsistent clocks or incomplete logs. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for reconstruct the timeline should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
10. Assess business interruption
Reconcile service degradation, downtime, workarounds, lost output, backlog and recovery against operational records.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is an interruption-to-recovery bridge.
The principal failure occurs when technical restoration is treated as complete business recovery. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for assess business interruption should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
11. Quantify direct cost
Reconcile forensics, counsel, notification, restoration, ransom, credit monitoring, overtime and vendor spend.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is an incident cost ledger.
The principal failure occurs when headline cost omits committed and future remediation cash flows. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for quantify direct cost should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
12. Quantify revenue exposure
Analyse churn, concessions, delayed sales, failed renewals, pipeline loss and pricing effects by customer cohort.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a revenue-impact bridge.
The principal failure occurs when revenue impact is asserted without customer-level evidence. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for quantify revenue exposure should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
13. Assess regulatory exposure
Map notification, investigation, enforcement, remediation and recordkeeping obligations by jurisdiction and data type.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a regulatory exposure map.
The principal failure occurs when one regulator's response is treated as global closure. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for assess regulatory exposure should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
14. Assess litigation exposure
Catalogue claims, threatened actions, class proceedings, contractual disputes and privilege boundaries.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a claims exposure schedule.
The principal failure occurs when absence of filed litigation is treated as absence of contingent liability. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for assess litigation exposure should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
15. Assess contractual exposure
Review security commitments, audit rights, notification clauses, indemnities, service levels, termination and change of control.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a contract exposure matrix.
The principal failure occurs when customer contracts are sampled without testing the highest-risk commitments. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for assess contractual exposure should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
16. Assess insurance response
Reconcile policies, notices, reservations, retentions, sublimits, exclusions, recoveries and renewal effects.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is an insurance recovery model.
The principal failure occurs when policy limits are presented as certain recovery. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for assess insurance response should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
Table 2. Exposure bridge
| Exposure | Evidence | Model |
|---|---|---|
| operations | service records | interruption |
| customers | contracts and cohorts | revenue |
| regulators | notices and inquiries | contingency |
| insurance | coverage and recovery | cash |
Illustrative analytical design; company-specific evidence and professional advice govern.

Values are illustrative evidence indices and require company-specific support.
17. Test containment
Evidence credential resets, access revocation, segmentation, blocking, takedown and monitoring against the attack path.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a containment verification pack.
The principal failure occurs when containment is declared from activity rather than adversary-removal evidence. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for test containment should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
18. Test eradication
Show removal of persistence, vulnerable components, malicious artefacts and compromised accounts.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is an eradication certificate.
The principal failure occurs when systems are restored while the exploitable condition remains. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for test eradication should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
19. Test recovery
Validate restored services, data integrity, backup quality, capacity, monitoring and customer operations.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a recovery assurance pack.
The principal failure occurs when availability returns before integrity and resilience are demonstrated. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for test recovery should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
20. Test remediation closure
Map every finding to owner, action, validation, residual risk, due date and independent evidence.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a remediation closure register.
The principal failure occurs when a completed action is mistaken for an effective control. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for test remediation closure should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
21. Measure recurrence risk
Compare residual attack paths, control coverage, adversary capability and exposure change.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a recurrence-risk assessment.
The principal failure occurs when a single clean scan is treated as proof against recurrence. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for measure recurrence risk should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
22. Review vulnerability management
Analyse discovery, prioritisation, patching, exceptions, exposure windows and verification for material assets.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a vulnerability performance series.
The principal failure occurs when patch statistics obscure internet-facing or exploited vulnerabilities. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for review vulnerability management should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
23. Review identity and access
Test privileged access, multifactor authentication, joiners, movers, leavers, service accounts and secrets.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is an identity-control evidence pack.
The principal failure occurs when policy compliance is assumed from tool deployment. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for review identity and access should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
24. Review detection capability
Assess telemetry coverage, alert logic, tuning, investigation quality, dwell time and blind spots.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a detection coverage map.
The principal failure occurs when a modern toolset is treated as effective detection. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for review detection capability should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
Table 3. Control validation
| Domain | Test | Proof |
|---|---|---|
| identity | privilege path | effective |
| detection | telemetry replay | coverage |
| vulnerability | exploit closure | verified |
| recovery | restore exercise | resilient |
Illustrative analytical design; company-specific evidence and professional advice govern.

Values are illustrative evidence indices and require company-specific support.
25. Review third-party involvement
Map suppliers, processors, managed services, software and shared responsibilities in each incident.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a third-party incident chain.
The principal failure occurs when the seller treats a vendor-origin event as outside its own exposure. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for review third-party involvement should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
26. Review governance
Evidence board oversight, risk appetite, accountable executives, escalation, exercises and investment decisions.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a cyber-governance record.
The principal failure occurs when meeting minutes record discussion without owned decisions or follow-through. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for review governance should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
27. Review reporting consistency
Reconcile board, regulator, insurer, customer, public and financial-statement descriptions.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a disclosure consistency matrix.
The principal failure occurs when different audiences receive statements that cannot all be true. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for review reporting consistency should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
28. Assess materiality
Evaluate financial, operational, legal, strategic and reputational factors using documented judgement.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a materiality decision memorandum.
The principal failure occurs when materiality becomes a mechanical cost threshold. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for assess materiality should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
29. Set privilege boundaries
Coordinate legal direction, factual work product, expert materials and disclosure needs without overclaiming protection.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a privilege and disclosure protocol.
The principal failure occurs when privilege is used as a blanket reason to withhold transaction evidence. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for set privilege boundaries should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
30. Design the data room
Organise incident register, evidence index, reports, costs, notices, claims, contracts, insurance, remediation and validation.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a tiered cyber data room.
The principal failure occurs when buyers receive either a document dump or an unsupported summary. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for design the data room should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
31. Sequence disclosure
Use controlled stages, access permissions, redaction, clean teams and management sessions based on relevance.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a disclosure sequencing plan.
The principal failure occurs when sensitive technical detail is released too early or material history too late. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for sequence disclosure should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
32. Prepare management answers
Align executives on chronology, impact, response, residual risk, investment and open matters with evidence.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a cyber-history Q&A book.
The principal failure occurs when inconsistent answers cause buyers to distrust unrelated diligence. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for prepare management answers should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
Table 4. Disclosure sequence
| Stage | Audience | Content |
|---|---|---|
| initial | core buyer team | material summary |
| diligence | cyber experts | controlled evidence |
| terms | decision makers | residual exposure |
| signing | authorised parties | final disclosure |
Illustrative analytical design; company-specific evidence and professional advice govern.

Values are illustrative evidence indices and require company-specific support.
33. Control expert access
Define scope, protocols, evidence boundaries, reliance and follow-up for buyer cyber advisers.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is an expert-access protocol.
The principal failure occurs when unstructured expert contact creates security risk and selective disclosure. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for control expert access should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
34. Model downside cases
Quantify plausible recurrence, interruption, remediation, customer, regulatory, claim and insurance outcomes.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a cyber downside scenario model.
The principal failure occurs when the model uses one arbitrary cyber haircut. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for model downside cases should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
35. Translate risk into valuation
Connect expected cash flows, capex, working capital, insurance, uncertainty and strategic effects to valuation.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a cyber-adjusted valuation bridge.
The principal failure occurs when incident count is translated directly into a valuation discount. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for translate risk into valuation should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
36. Translate risk into deal terms
Allocate known, remediable and residual exposure through conditions, covenants, indemnities, escrow and price mechanics.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a cyber-risk term map.
The principal failure occurs when broad cyber warranties replace precise evidence and ownership. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for translate risk into deal terms should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
37. Protect the sale process
Integrate secure sharing, bidder access, monitoring, breach response and communications into transaction operations.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a secure transaction protocol.
The principal failure occurs when the diligence process creates a new incident during the sale. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for protect the sale process should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
38. Run the first thirty days
Reconcile incident scope, preserve evidence, identify urgent exposure and establish disclosure governance.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a thirty-day cyber baseline.
The principal failure occurs when the seller drafts disclosure before facts and ownership are controlled. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for run the first thirty days should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
39. Run days thirty-one to ninety
Complete root cause, impact, remediation, validation, cost, contract, insurance and data-room work.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a ninety-day evidence sprint.
The principal failure occurs when workstreams progress without an integrated transaction conclusion. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for run days thirty-one to ninety should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
40. Close through evidence gates
Require reconciled history, validated remediation, quantified residual risk, consistent disclosure and owned deal protections.
The controlled record should identify the relevant customer, revenue stream, contract, cohort, relationship owner, commercial dependency, evidence source, baseline, trend, scenario, control, exception, accountable executive, deadline and approval. The immediate deliverable is a cyber-history close certificate.
The principal failure occurs when deal confidence rests on reassurance rather than reproducible evidence. Reviewers should connect the evidence to revenue durability, gross margin, cash conversion, renewal probability, switching behaviour, counterparty credit and transaction value; distinguish contractual protection from observed customer behaviour; and test whether the conclusion survives a downside scenario.
The decision pack for close through evidence gates should state the commercial question, measurement perimeter, historical evidence, customer-specific facts, forecast logic, sensitivity, management action, buyer implication, residual uncertainty and next gate. Material exceptions should flow into the valuation model, quality-of-earnings work, diligence room, sale-process narrative, transaction protections and board reporting.
Table 5. Cyber-history gates
| Gate | Required evidence | Outcome |
|---|---|---|
| history | reconciled register | complete |
| remediation | validated closure | controlled |
| impact | quantified scenarios | underwritten |
| disclosure | consistent record | credible |
Illustrative analytical design; company-specific evidence and professional advice govern.

Values are illustrative evidence indices and require company-specific support.
References
- US Securities and Exchange Commission, Cybersecurity Risk Management, Strategy, Governance and Incident Disclosure, https://www.sec.gov/files/rules/final/2023/33-11216.pdf
- US Securities and Exchange Commission, Compliance and Disclosure Interpretations on cybersecurity incidents, https://www.sec.gov/rules-regulations/staff-guidance/compliance-disclosure-interpretations/exchange-act-form-8-k
- National Institute of Standards and Technology, Cybersecurity Framework 2.0, https://doi.org/10.6028/NIST.CSWP.29
- National Institute of Standards and Technology, SP 800-61 Rev. 3 Incident Response Recommendations, https://doi.org/10.6028/NIST.SP.800-61r3
- National Institute of Standards and Technology, SP 800-184 Guide for Cybersecurity Event Recovery, https://doi.org/10.6028/NIST.SP.800-184
- National Institute of Standards and Technology, SP 800-53 Rev. 5 Security and Privacy Controls, https://doi.org/10.6028/NIST.SP.800-53r5
- Cybersecurity and Infrastructure Security Agency, Cybersecurity Performance Goals, https://www.cisa.gov/cross-sector-cybersecurity-performance-goals
- Cybersecurity and Infrastructure Security Agency, StopRansomware Guide, https://www.cisa.gov/stopransomware/ransomware-guide
- European Union, Directive (EU) 2022/2555 NIS2, https://eur-lex.europa.eu/eli/dir/2022/2555/oj
- European Union, Regulation (EU) 2022/2554 Digital Operational Resilience Act, https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- European Union, Regulation (EU) 2016/679 General Data Protection Regulation, https://eur-lex.europa.eu/eli/reg/2016/679/oj
- European Union Agency for Cybersecurity, Technical implementation guidance on cybersecurity risk management measures, https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance
- European Union Agency for Cybersecurity, Threat Landscape, https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025
- UK Information Commissioner's Office, Personal data breaches, https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/
- UK National Cyber Security Centre, Incident management guidance, https://www.ncsc.gov.uk/collection/incident-management
- UK National Cyber Security Centre, Cyber Assessment Framework, https://www.ncsc.gov.uk/collection/caf
- UK Government, Data Security and Protection Toolkit, https://www.dsptoolkit.nhs.uk/
- Australian Signals Directorate, Essential Eight Maturity Model, https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight
- International Organization for Standardization, ISO/IEC 27001 Information security management, https://www.iso.org/standard/27001
- International Organization for Standardization, ISO/IEC 27035-1 Incident management, https://www.iso.org/standard/78973.html
- PCI Security Standards Council, PCI DSS, https://www.pcisecuritystandards.org/standards/pci-dss/
- Financial Stability Board, Cyber Lexicon Updated 2023, https://www.fsb.org/2023/04/fsb-cyber-lexicon-updated-in-2023/
- Committee of Sponsoring Organizations of the Treadway Commission, Enterprise Risk Management, https://www.coso.org/enterprise-risk-management
- IFRS Foundation, IAS 37 Provisions, Contingent Liabilities and Contingent Assets, https://www.ifrs.org/issued-standards/list-of-standards/ias-37-provisions-contingent-liabilities-and-contingent-assets/
- IFRS Foundation, IFRS 3 Business Combinations, https://www.ifrs.org/issued-standards/list-of-standards/ifrs-3-business-combinations/
- International Valuation Standards Council, International Valuation Standards, https://www.ivsc.org/standards/

