Sample Deliverable ยท Illustrative

A sample technology due diligence deliverable

This is what a Vertex CIO Advisory technology due diligence produces. The target company, findings, and figures below are representative composites drawn from patterns observed across mid-market environments — no client information is reproduced. Every real engagement produces a document in this format, sized to the deal.

Format Findings register + deal-model memo
Engagement window 3–4 weeks, pre-LOI or post-LOI
Real engagement fee $10K–$40K fixed
Sample target Meridian Packaging Holdings (composite)
Note: This sample is illustrative. Findings, figures, and target are composites drawn from patterns we see across mid-market environments. No client information is reproduced. Real diligence reports are proprietary to the sponsor who commissioned them.

Section 01

Executive summary

The read the sponsor gets on day one of the readout.

Prepared for: Illustrative Sponsor, L.P. · Target: Meridian Packaging Holdings (composite)

The environment is functional. The environment is not sound.

Vertex CIO Advisory was engaged to assess the technology estate of Meridian Packaging Holdings ahead of a proposed acquisition. The assessment covered infrastructure, security posture, identity and access, licensing, vendor relationships, and continuity capability across three facilities and approximately 170 users.

The environment is functional and the business is running. That is not the same as the environment being sound. Ten findings were identified, two of them Critical. The aggregate first-year remediation cost falls in a range of $142,000 to $242,000, of which approximately $95,000 to $150,000 should be treated as non-discretionary within the first 180 days post-close.

None of the two Critical findings appear in the quality of earnings analysis, and neither would be visible from financial statements or a management presentation. Both were identified through direct inspection of the environment.

65 / 100

Technology Risk Score · Elevated

Material remediation required. Deal proceedable with price or escrow adjustment and a funded 100-day plan. Scoring begins at 100 with per-finding deductions (Critical −8, High −4, Medium −2, Low −0.5). Scores below 70 indicate remediation cost material to the deal model.

Critical

2

High

3

Medium

3

Low

2

Section 02

Scope & method

Conducted over three weeks with read-only access to the production environment and interviews with internal IT and the incumbent managed services provider. No changes made to any system. All collection performed under signed NDA with MNPI protocols in place before access began.

In scope

  • Active Directory: domain and forest configuration, privileged group membership, account hygiene, password policy, Group Policy inventory
  • Server and endpoint estate: hardware age, OS versions, patch currency, support status
  • Security controls: endpoint protection deployment and configuration, exclusion sets, email security posture, external attack surface
  • Identity: M365 tenant configuration, conditional access, MFA coverage across remote access and privileged accounts
  • Continuity: backup configuration, retention, offsite replication, documented and tested recovery capability
  • Licensing: server, database, and productivity licensing reconciled against available purchase records
  • Vendor: managed services agreement terms, SLA definition and measurement, exit provisions
  • Documentation: network diagrams, asset inventory, credential management, change history

Out of scope

Application-level code review, ERP business process assessment, and penetration testing were excluded from this engagement. Where findings indicate the need for deeper review, that is stated in the finding.

Method

Collection performed using a proprietary assessment toolset run from a domain-joined host with a read-only service account, supplemented by external attack-surface testing from outside the network perimeter. Findings normalized to a common schema — severity, category, finding, evidence — then reviewed manually. Automated collection identifies conditions; severity and deal-model impact are assigned by the assessor, not by the tool.

Section 03

Findings register

Ten findings, ordered by severity. Each carries an estimated remediation cost and timeline. Cost ranges reflect third-party labor and hardware at Dallas–Fort Worth market rates and exclude internal staff time.

F-01 ● Critical Infrastructure

Domain controller consolidated with file, print, and ERP database roles

Observed

A single physical host (2016 vintage, out of manufacturer hardware support) runs Active Directory, the primary file share, print services, and the SQL instance backing the ERP. Loss of this host halts all operations. Restore has not been tested against the current backup set since 2024.

Impact

Single point of failure for the entire operating environment. A hardware failure or ransomware event produces an outage of days, not hours, with no verified recovery path.

Remediation

Separate roles across virtualized hosts; establish and test a documented restore. 4–6 weeks.

Estimated cost: $38,000 – $52,000

F-02 ● Critical Cyber Insurance

Cyber policy renewal contingent on MFA coverage the company cannot evidence

Observed

The current policy application attests to multi-factor authentication on all remote access and privileged accounts. MFA is enforced on the M365 tenant but not on VPN, not on the ERP application, and not on four domain administrator accounts.

Impact

Attestation gap exposes the buyer to policy rescission in the event of a claim — the coverage is effectively unpriced. Remediation cost pulls forward into the deal model.

Remediation

Enforce MFA across remote access and privileged accounts; re-attest before renewal. 2–3 weeks.

Estimated cost: $6,000 – $11,000

F-03 ● High Endpoint Security

Endpoint protection exclusions applied at drive root

Observed

Antivirus exclusions are configured at the root of the data volume on eleven servers, disabling scanning across the accounting and engineering file shares. The exclusion set predates the current MSP relationship and no documented business justification exists.

Impact

The most valuable data in the environment is unmonitored. Standard ransomware tradecraft targets exactly these paths.

Remediation

Scope exclusions to specific process and file paths with documented justification. 1–2 weeks.

Estimated cost: $3,000 – $6,000

F-04 ● High Key Person Risk

Undocumented environment with single-person institutional knowledge

Observed

No current network diagram, no asset inventory, no documented change history. Credentials for the firewall, the ERP database, and three line-of-business applications are held by one internal administrator with no documented handoff.

Impact

Departure of one employee converts a manageable environment into a forensic exercise. Materially raises integration cost and timeline.

Remediation

Full environment documentation, credential vaulting, and knowledge transfer. 3–5 weeks.

Estimated cost: $14,000 – $22,000

F-05 ● High Licensing

Server and database licensing not reconcilable to purchase records

Observed

Nine Windows Server instances and two SQL Server instances are in production. Purchase documentation was located for six server licenses and one SQL license. No Software Assurance and no volume licensing agreement of record.

Impact

True-up exposure on audit. Licensing is commonly excluded from QoE scope and lands on the buyer post-close.

Remediation

License reconciliation and remediation purchase. 2–4 weeks.

Estimated cost: $25,000 – $60,000

F-06 ● Medium Vendor Risk

MSP agreement auto-renews with no termination-for-convenience clause

Observed

The managed services agreement renews annually with 90-day notice and no convenience termination. Response-time SLAs are defined but not measured or reported. No exit or data-return provisions.

Impact

Constrains post-close vendor consolidation and removes leverage in renegotiation.

Remediation

Renegotiate at renewal or serve notice. Timing-dependent.

Estimated cost: Negotiation-dependent

F-07 ● Medium Infrastructure

Network equipment past end-of-support

Observed

The core switch stack and both edge firewalls reached vendor end-of-support in 2024. No firmware updates or security patches are available. Wireless infrastructure is consumer-grade across two of three facilities.

Impact

Unpatchable devices at the network perimeter. Refresh is a capital requirement in year one, not a discretionary upgrade.

Remediation

Network refresh across three sites. 6–8 weeks.

Estimated cost: $45,000 – $70,000

F-08 ● Medium Identity

Stale privileged accounts and oversized administrator groups

Observed

Domain Admins contains fourteen members against an IT headcount of two. Six enabled accounts have not authenticated in over 180 days, including two belonging to former employees. No periodic access review.

Impact

Expands the attack surface and complicates identity migration during integration.

Remediation

Privileged access review and account cleanup. 1–2 weeks.

Estimated cost: $4,000 – $8,000

F-09 ● Low Email Security

SPF configured; DKIM and DMARC absent

Observed

The sending domain publishes an SPF record ending in a soft fail. No DKIM signing and no DMARC policy are published.

Impact

Domain is spoofable for business email compromise against customers and vendors.

Remediation

Publish DKIM and staged DMARC. 1–2 weeks.

Estimated cost: $2,000 – $4,000

F-10 ● Low Continuity

Backup retention below stated recovery objectives

Observed

Local backups retain 14 days; offsite replication retains 30. Management stated a 90-day recovery objective. No documented RTO or RPO exists.

Impact

Actual recovery capability is narrower than management believes. Relevant to any ransomware scenario with delayed detection.

Remediation

Extend retention and document RTO/RPO. 2 weeks.

Estimated cost: $5,000 – $9,000

Section 04

Deal-model impact

The findings translate into three categories of financial consequence. Only the first is typically visible in a quality of earnings analysis.

One-time remediation — year one

Category Low High
Infrastructure remediation & network refresh$83,000$122,000
Licensing true-up$25,000$60,000
Security & identity remediation$13,000$25,000
Documentation & knowledge transfer$14,000$22,000
Continuity & email security$7,000$13,000
Total$142,000$242,000

Recurring cost normalization

Current IT operating spend understates a sustainable run rate. The environment carries no budget line for hardware refresh, licensing is under-provisioned, and the MSP agreement is priced below the service level the business actually consumes. A normalized run rate is approximately $85,000 to $110,000 per year above current spend. This is an EBITDA adjustment, not a one-time cost.

Contingent exposure

The cyber insurance attestation gap (F-02) is not a cost until it is a claim, at which point it is the full uninsured loss. The licensing position (F-05) is not a cost until audit. Neither belongs in the base case; both belong in the risk section of the investment committee memo.

Recommended deal treatment

  • Price adjustment or indemnity escrow sized to the non-discretionary remediation range of $95,000 to $150,000.
  • EBITDA normalization of $85,000 to $110,000 annually for sustainable IT run rate.
  • Close condition: MFA remediation (F-02) completed or contractually committed prior to cyber policy renewal.
  • Funded 100-day plan with named accountability for F-01 and F-04. These two findings drive integration timeline more than any other factor in the estate.

Section 05

100-day remediation sequence

Sequencing is driven by risk reduction per week, not by cost. The order below closes the largest exposures first and defers work that can safely wait.

Window Workstream Findings closed
Days 1–15MFA enforcement across remote access and privileged accounts; privileged group cleanup; disable stale accountsF-02, F-08
Days 1–30Scope endpoint protection exclusions; verify coverage across all serversF-03
Days 15–45Environment documentation, asset inventory, credential vaulting, knowledge transferF-04
Days 30–75Role separation off the consolidated host; virtualization; tested restoreF-01, F-10
Days 45–90Network refresh across three sitesF-07
Days 60–100Licensing reconciliation and remediation purchase; DKIM and DMARC publicationF-05, F-09
Day 90+MSP agreement renegotiation at renewal windowF-06

Prefer the PDF?

Everything above — executive summary, ten findings, deal-model impact, 100-day sequence — packaged as an 8-page PDF for offline review or forwarding to the deal team.

How this sample compares to a real diligence engagement

Sample

Illustrative composite

8 pages. Executive summary, method, findings register, and deal-model impact. Enough to show format, depth, and voice — not a replacement for the real work.

Real engagement

20–35 page memo + supporting artifacts

Full seven-area assessment, prioritized risk register, post-close remediation roadmap, capex/opex forecast, and one-page vendor summaries.

Timing

3–4 weeks, fixed fee

Standard engagement runs three to four weeks from data-room access to findings readout. Larger and multi-entity deals scoped individually. Fixed project fee, known upfront.

Have a live process?

Send the deal profile and the timeline. Vertex CIO comes back with a scoped fixed fee and a schedule that fits the LOI-to-close window.