OUTSIDE-IN
External Exposure Review
An outside-in view of the target that needs no access to its systems: internet-facing assets and vulnerabilities, leaked credentials, dark-web mentions and indicators of past compromise. Useful early, before the target opens its data room.
What you get
- An external attack-surface summary
- Credential and dark-web findings
- Indicators that warrant follow-up questions
Talk to C3SA about External Exposure ReviewPROGRAM
Security Program Review
A review of the target's security governance, controls, architecture, operations and evidence, through documents and management interviews, to judge whether its stated maturity holds up.
What you get
- A maturity assessment
- Material control gaps
- Questions for the counterparty
Talk to C3SA about Security Program ReviewPRIVACY
Privacy & Data Risk
How the target collects, stores and shares personal and sensitive data, where it resides, what contractual and regulatory obligations apply, and any history of breaches or complaints.
What you get
- A data and obligations summary
- Privacy exposure findings
- Remediation cost indicators
Talk to C3SA about Privacy & Data RiskTECHNOLOGY
Technology & Cloud Risk
Identity, cloud, endpoints, applications and integrations, including technical debt and dependency on single providers that may affect integration or valuation.
What you get
- Technology risk findings
- Dependency and concentration risks
- Integration considerations
Talk to C3SA about Technology & Cloud RiskINTEGRATION
Post-Close Integration
A sequenced plan for bringing the acquired organization up to your security standards, with the first 100 days focused on the risks most likely to cause an incident.
What you get
- A 100-day security plan
- An integration and remediation roadmap
- Estimated effort and cost
Talk to C3SA about Post-Close Integration