IT Due Diligence is a technical assessment of a target company's information systems, cybersecurity posture, and digital assets, designed to uncover critical vulnerabilities, technical debt, and hidden modernization costs. It helps determine the true value of technology assets and identify the scope of investment required after deal closing.
Key areas within the scope:
1. IT solution landscape and architecture
- An analysis of the overall IT system landscape of the Target (core IT system, remote IT systems, call centre, CRM, etc.);
- Technology overview of the Platform (website, mobile apps, related software and applications) from the perspective of the overall architecture, the use of modern vs. outdated technologies, microservice architecture, level of documentation, product strategy, development backlog;
- Analysis of the architecture and the integration capabilities of the system;
- Identification of architectural limitations (scalability potential, bottlenecks).
2. Business continuity and disaster recovery
- Analysis of business continuity and disaster recovery plans, testing results, if any);
- Assessment of infrastructure backup arrangements;
- Analysis of the resilience of information systems and IT infrastructure;
- Assessment of the capacity management process.
3. IT security
- Analysis of the organisational arrangements made to ensure the appropriate security level;
- Assessment and analysis of the operational IT rules and security policies;
- Assessment and analysis of the relevant security aspects in the standard processes of the Target’s IT operations (user management, access and authentication management, issue management), as well as service and support models;
- Analysis of the certification details provided (e.g. ISO27001).
4. Software development process
- Analysis of the software development methodology used;
- Assessment of the change management process and configuration management process;
- Assessment of the release and rollout process management;
- Assessment of the system testing process (performance testing, integration testing and user acceptance testing);
- Analysis of the change management request prioritisation process, assessment of the tasks completed, analysis of the KPIs used;
- Assessment of the system documentation.
5. Human resources (IT)
- Analysis of the IT department organisation structure;
- Analysis of dependency on key IT personnel, dependency on the holding company IT personnel;
- Analysis of dependency on outsourcers in the development and support of systems and infrastructure.
- Assessment of in-house IT competencies;
- Employment status of key IT personnel (e.g. Diia City special tax regime), remuneration policy.
6. Software and IT asset management
- Identification of potential risks of breaching vendor licensing policies;
- Analysis of intellectual property rights to in-house developed software solutions;
- Analysis of IT operating expenditure (OPEX: servicing, licensing, lease, IT costs, consulting fees), IT capital expenditure (CAPEX: IT equipment purchased and IT projects, with supporting contractual documentation and comments on changes in expense reporting). Analysis of key trends and significant short-term and medium-term IT capital investment requirements.
Optional modules
7. Technical cybersecurity overview
- Analysis of network architecture and infrastructure (including an overview of network topology, segmentation, firewall rules, network device configurations, etc.);
- Technical security* testing of high-risk applications (may include solution architecture overview, secure configuration overview, black-box testing, automated vulnerability scanning, manual penetration testing using valid user credentials simulating an insider threat, etc.);
- Monitoring of public sources and the dark web for compromised company and customer data, including leaked trade secrets, user credentials, financial information, personal data, etc.
8. Confidentiality and data protection overview
- A high-level assessment of records of processing activities, data inventories and data flow maps;
- Data Protection impact assessment;
- High-level overview and assessment of data protection documentation (e.g. data breach documentation and plans, privacy policy, terms of business, etc.);
- Review of selected technical and organisational GDPR compliance activities;
- Analysis of processes, procedures and technologies, particularly on the transferability of data and rights of data subjects;
- Analysis of the data breach notification process and incident and breach response.
9. Source code review
10. DevOps Scan
- Focus on the development processes within the organisation in terms of capability and effectiveness in achieving the defined future goals;
- Deep dive into the working methods:
- Requirement processes;
- Operating processes;
- Selection of tools;
- Release processes;
- Change management processes;
- Development processes.
11. Open-source licences
- Open-source licence scanning can provide visibility into the usage, versions and security implications of open-source libraries;
- Deep dive into:
- Libraries and releases used;
- Operating risk;
- Licensing risk;
- Security risk.
✓ Deliverable
A report with an assessment of the company’s technology maturity and a list of critical risks. It typically covers the following elements:
-
- Bill of materials: an overview of what is included in the code and all external dependencies (i.e. a full list of the integrated third party libraries).;
- Licence overview: an inventory of licences (both open-source and commercial) for each integrated library and software component used.
- Product architecture: an overview and analysis of the product architecture, design principles and specifications. This helps evaluate compatibility with the target integration platform;
- Technical debt: a list of key areas of non-compliance with programming good practices (i.e. defects, overlapping code, excessively complex code structures);
- Vulnerabilities and risks: a list of identified vulnerabilities and mitigating controls;
- Work approaches: an analysis of the processes and tools used by development/ops teams.