Why IT due diligence matters
Financial and legal due diligence are standard. Technology often gets a single page in the information memorandum and a reassuring call with the target's MSP. Yet IT is where some of the most expensive post-deal surprises sit: unlicensed software, an unsupported platform at the heart of operations, a security incident that hasn't been disclosed, or a key system that only one person understands.
What we assess
- Infrastructure and platforms. What exists, how old it is, what's out of support and what it will cost to bring up to standard.
- Security posture. Identity, device management, backups, incident history, Cyber Essentials or ISO 27001 status and insurance position.
- Licensing and contracts. Microsoft and other licensing compliance, supplier contracts, notice periods and change of control clauses.
- Key person risk. Where knowledge sits with one employee or one supplier.
- Software and data. Bespoke systems, technical debt, data protection compliance and where the data actually lives.
- Integration. What it will take to bring the business onto your platforms, with a rough cost and timeline.
What you get
A short written report that ranks findings by risk and cost, so the deal team can use it in negotiation. Every red flag comes with an estimate of what it would cost to fix and how urgent it is. We present the findings in a call and answer the deal team's questions.
Engagements are fixed scope and fixed fee, and can be turned around in days where the deal timetable demands it. Everything is under NDA.
After the deal
The same consultant can lead the integration or provide fractional IT leadership to the acquired business for the first year, so the findings turn into a plan rather than a filed report.