| "What are they actually running on the internet?" | Every hostname that answers across the apex domains named in the information memorandum — and the ones underneath them nobody named: dormant brands, regional sites, and estates the target itself acquired years ago and never migrated. Discovery starts at an apex domain and keeps whatever responds. | Anything that does not answer from the public internet. Internal segmentation, the endpoint estate, backup design and the privileged-access model are out of reach from outside and stay out of reach until you have access. | Attack Surface Management |
| The delta runs in both directions, and both directions matter in a negotiation. Assets answer that appear nowhere in the schedule — dormant brands, regional sites, estates the target itself acquired and never migrated — and scheduled entries turn out to have stopped answering long ago. A seller can overstate an estate as easily as understate it, and the two errors are priced differently: one is exposure nobody has costed, the other is an asset register that will not survive its first reconciliation after close. |
| "Whose credentials are already in criminal hands, and since when?" | Credential and breach artefacts attributed to the target's domains, read out of source material already held — the identities, the services they reach, and the date each artefact entered the corpus. Where the material came from an infected machine rather than a combolist, the artefacts belonging to that one device are assembled into a single case. | Whether any of it still opens anything. A credential attributed to a target is not probed before an authorised scope exists, so it reaches you with no working state asserted and none implied. | Dark Web Monitoring |
| Retention is what makes this a diligence instrument rather than a lookup. Raw source material is kept permanently and re-read as extraction improves, so a machine compromised long before the term sheet can yield an artefact this month. Nothing new was stolen — we simply became able to read what we already held. |
| "Which of their suppliers are we inheriting?" | The hosting, DNS, mail, certificate and authentication providers the target actually resolves to, plus the same outside-in read run against any named supplier you nominate — scored with the identical categories, maths and bands applied to your own estate. | Contract terms, sub-processor disclosures and data-processing obligations. Those live in the data room. Outside-in observation cannot see a clause. | Third-Party Risk Management |
| Concentration is the supplier finding that most often survives the deal. Where the target and your own group already depend on the same upstream provider, an acquisition raises your exposure to that provider without anybody adding a supplier — and it is a quarterly agenda item with a number behind it rather than an assumption inside a continuity plan nobody has tested. |
| "Are we buying a brand that is already being abused?" | Look-alike and permutation domains registered against the target's marks, impersonating profiles on social platforms, and app-store listings carrying its name, including ones the target has never had cause to look for. | Whether the target holds the trade mark registrations that would give you standing to act. That is a question about paperwork, and paperwork is a data-room artefact. | Brand Protection |
| Worth pricing rather than noting. Abuse of a mark you are about to own becomes your remediation backlog on day one, and nothing gets removed until somebody owns the work. |
| "Is any of it exploitable today?" | Reachability, software versions, exposed administrative interfaces, and whether the sign-in path in front of them presents a second factor. All of that is observation, and observation is where a pre-signature read stops. | Exploitability itself. Establishing it means testing, testing means an authorised scope, and before signature that authorisation is not the buyer's to give. Nothing is exploited and nothing is modified. | Continuous Automated Red-Teaming, once a scope exists |
| This is the row a diligence report gets challenged on. Anyone asserting that a target is exploitable before signature is describing either a test nobody authorised or an inference they have decided to call a finding. |
| "Is what we are seeing normal for this sector?" | The target's external estate set against comparable estates of similar size in the same sector, using the same categories on both sides — so a first read is interpretable before you have a portfolio to compare it against. | Whether normal is acceptable. A benchmark tells you if the target is unusual. It does not tell you whether this is exposure you are willing to own. | Manufacturing and industrial groups |
| Acquisitive industrial groups are the hardest version of this job and the most common one: plants, joint ventures and entities absorbed over decades, each with its own IT, most of them still invisible from the centre long after the deal that brought them in. |
| "Have they already been breached?" | That material attributable to the target is in circulation, dated to when it entered the corpus. That is a fact about exposure, not a conclusion about how the target was run or about what its controls did or did not do. | Whether an incident occurred, was contained, was reported internally, or was disclosed to a regulator. Nothing observed from outside answers any of those, and a read that claims to is guessing in a document that will be relied on. | Not establishable — a data-room question |