The Business of Cyber Security

Commercial Due Diligence (Cyber)

Commercial due diligence for cyber targets covers the diligence checklist, the red flags, and the post-close operating model. It relates to Valuation, Value Creation, and Product & Competitive Strategy. (Book: enriches Part III, Ch. 11 & Part IV, Ch. 18.)

The CDD checklist

1. Revenue quality - ARR mix: recurring vs. one-time/services; multi-year vs. annual contracts. - NRR / GRN (net & gross retention); cohort retention curves — the truest quality signal. - Customer concentration (top-10 % of ARR); logo vs. dollar churn. - Billings vs. revenue (deferred-revenue health); RPO trend.

2. Growth durability - Growth rate and its source (new logos vs. expansion); Rule of 40. - Pipeline coverage and conversion; sales-cycle length trend. - Net-new ARR trajectory (accelerating or decelerating).

3. Unit economics & efficiency (growth-stage focus) - CAC payback (months); magic number; sales & marketing efficiency. - Gross margin (and software-vs-services mix — the multiple driver). - Burn multiple / FCF trajectory.

4. Product & moat (see 33) - Differentiation type (data/workflow/distribution vs. raw tech); pricing power. - Platform-bundling exposure; category life-cycle (filling/draining). - Second-product progress; integration/marketplace breadth.

5. Go-to-market (see 19) - Channel vs. direct mix; partner concentration; channel conflict. - Marketplace traction; regional coverage (channel-enabled vs. fragile-direct).

6. AI exposure (2026 essential) - Does AI strengthen or erode the moat? (data/automation vs. commoditization) - Is the product AI-native or retrofitting? "Analytical SaaS" risk. - For services: agentic-SOC adoption status (manual = margin risk).

7. People & retention (see 25) - Founder/key-person dependence and lock-ups; engineering attrition. - Org scalability; security-talent access.

8. Tech, security & compliance - Architecture scalability; technical debt; the vendor's own security posture (a breached security vendor is an existential risk). - Certifications held (FedRAMP/CMMC/SOC2/ISO) — moats and gating.

9. Legal/structural - Customer contract assignability; IP ownership; open-source exposure. - Deal-completion risk: antitrust/CFIUS/financing (see 29).

Top red flags (deal-killers / price-breakers)

The 100-day plan and portfolio KPIs (post-close)


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.