Business interruption
Name the critical service, operating dependencies, and outage-cost basis. Request dated recovery-test evidence and the actual scope tested. An assertion that backups exist does not establish a restore time.
Free investment committee resource
Copy a cyber section that separates diligence findings, assumptions, funding choices, and the post-close handoff. Keep incomplete evidence visible. The template is ungated.
INVESTMENT COMMITTEE MEMO — CYBER RISK SECTION Target / scope / evidence cut-off: [company, services and date] Deal sponsor / evidence owner / reviewer: [names and roles] DECISION REQUESTED [Proceed subject to conditions / obtain further diligence / other decision] Cyber funding envelope and cost horizon: [amount, currency and period] WHAT IS KNOWN [material finding] — [source, collection date, coverage and limitation] Business service and plausible loss scenario: [description] Controls actually tested: [test, scope, result and date] WHAT IS STILL ASSUMED OR MISSING [input or gap] — [assumption, source basis, owner and due date] Effect on the decision: [what could change / hold condition] FINANCIAL ANALYSIS, IF SUPPORTED Annual gross loss: [mean and selected percentile, or not modeled] Model / inputs / uncertainty / exclusions: [version and source links] Priced alternatives: [cost, horizon, implementation assumptions] Required spend: [source of obligation and cost] Insurance recovery: [separate analysis or not modeled] Do not subtract annual loss from EBITDA or multiply it by an exit multiple. POST-CLOSE HANDOFF Action | fund / defer / validate | owner | first-year cost | evidence | review date [row] Conditions requiring escalation before close: [specific conditions] First post-close funding review: [date and approver] Next evidence review and unresolved owner: [date and name]
Diligence before precision
Name the critical service, operating dependencies, and outage-cost basis. Request dated recovery-test evidence and the actual scope tested. An assertion that backups exist does not establish a restore time.
Request identity and privileged-access scope, exceptions, and the evidence collection date. Outside-in signals can guide questions; they do not by themselves establish internal control effectiveness.
Separate implementation, recurring licenses, internal labor, transition costs, and dependencies. Compare the same currency and first-year horizon. Label a vendor quote separately from an internal estimate.
Distinguish per-event loss from annual aggregate loss and gross exposure from any separately analyzed insurance recovery. Unknown frequency or severity stays an explicit assumption with a source and owner.
Document the decision impact of each gap: no impact on the current choice, requires sensitivity analysis, or holds the recommendation. Use the CRQ data requirements checklist for the input record.
From committee to operator
The memo can include modeled annual cyber loss and an explicit remediation budget. Neither is automatically an EBITDA adjustment, a valuation haircut, or a price recommendation. Any transaction treatment requires its own analysis by the relevant deal advisers.
In the fictional worked example, the $100,000 first-year envelope becomes a $90,000 proposed plan for the P95 objective. The pre-close memo should carry the assumptions and unresolved segmentation evidence into the 100-day plan, where the company approver confirms cost, owner, and review date. It is not a promise that a demo produces an IC-final report.

See the workflow
A free 30-minute platform demo uses illustrative data. Adil reviews requests personally and replies within two business days. Agree company scope, users, evidence handling, supported workflows, onboarding, and terms before evaluation access.