RDa

How to Calculate a Recommended Deal Adjustment for Cybersecurity Risks

July 13, 20266 min read

A professional office setting where diverse business professionals discuss a 'Cyber Deal Adjustment' on a laptop

For a long time, cybersecurity in a deal was treated like a checkbox. You would hire a technical team to run a scan. They would hand you a report full of "red flags" and "critical vulnerabilities." You would look at the list of acronyms and wonder: "So what?"

For a Private Equity deal team, a technical finding is only useful if it can be measured in dollars. Knowing that a target company has "unpatched servers" is interesting. Knowing that it will cost $450,000 to fix those servers: and that they represent a $2 million risk of business interruption: is actionable.

This is where the Recommended Deal Adjustment (RDA) comes in. It is the process of turning technical risk into financial intelligence. Instead of a list of problems, you get a line-item figure that can be used at the negotiation table.

In this guide, we will walk through how to calculate a specific dollar figure for cyber risk during M&A due diligence.

What is a Recommended Deal Adjustment?

An RDA is not a guess. It is a calculated estimate of what it will cost the buyer to bring a target company up to an acceptable security standard. It also accounts for the risk the buyer is absorbing during the investment period.

In private equity due diligence, an RDA serves three main purposes:

  1. It justifies a reduction in the purchase price.

  2. It helps size an escrow or indemnity.

  3. It creates a "Day 1" budget for the portfolio operations team.

When you move from qualitative labels (like "High Risk") to a cyber risk valuation, you gain leverage. You stop arguing about technical best practices and start talking about the impact on the deal's IRR.

A balanced set of scales comparing technical security icons with gold coins, representing cyber risk valuation

The Three Pillars of the Calculation

To arrive at a final number, we look at three specific buckets: Remediation, Risk Exposure, and Risk Transfer.

1. The Cost of Remediation (The "Fix-It" Bill)

This is the most straightforward part of the calculation. It answers the question: "What will it cost to get this company to where it needs to be?"

When we perform cybersecurity due diligence, we identify gaps in the target’s defenses. For every gap, there is a cost to fix it. This includes:

  • One-time costs (Capex): Buying new hardware, implementing multi-factor authentication (MFA), or hiring a consultant to rebuild an incident response plan.

  • Ongoing costs (Opex): Higher software licensing fees, increased headcount, or the cost of a managed security service.

We calculate the Net Present Value (NPV) of these costs over the expected hold period. This gives the deal team a clear figure for the "cyber debt" they are inheriting.

2. Risk Exposure (The "Liability" Estimate)

Fixing the problems takes time. Even after the fix, some risk always remains. This bucket quantifies the financial impact of cyber risk that could hit the company before or after the closing.

We look at common scenarios like:

  • Ransomware: If the target is hit, how many days of revenue are lost? What are the recovery costs?

  • Data Breach: If customer data is stolen, what are the legal fees, notification costs, and regulatory fines?

We use historical data and industry benchmarks to estimate the probability of these events. If a target has a high probability of a $5 million event, that exposure must be reflected in the deal terms.

3. Risk Transfer (The Insurance Offset)

The final step is looking at how much of the risk is covered by others. This primarily involves cyber insurance.

If a target has a $10 million insurance policy with a low deductible, your exposure is lower. However, in many deals today, target companies are under-insured or their premiums are about to skyrocket due to poor security.

We calculate the cost of "right-sizing" the insurance. If the buyer needs to spend an extra $100,000 per year on premiums to get adequate coverage, that cost is added to the RDA.

A close-up of professional hands holding a financial term sheet, representing the negotiation of deal adjustments

Putting the Formula Together

The Recommended Deal Adjustment is the sum of these parts. A simplified way to look at it is:

RDA = Remediation Costs + (Expected Loss - Risk Tolerance) + Incremental Insurance Costs

Let’s look at a quick example. Imagine a mid-market manufacturing company.

  • Remediation: They need $300,000 in new software and $200,000 in consulting to fix legacy issues. ($500,000).

  • Exposure: They have a high risk of business interruption. We estimate the expected loss over five years is $1.2 million. The buyer is willing to tolerate $200,000 of that risk. ($1,000,000).

  • Insurance: Their current policy is invalid due to poor controls. A new policy will cost $50,000 more per year. Over a five-year hold, that is $250,000.

In this scenario, the Recommended Deal Adjustment is $1.75 million.

Turning Findings into Line Items

The goal of cyber risk assessment in M&A is to move technical findings into the financial model. When you have a $1.75 million figure, you can take it to the seller and say:

"We found $1.75 million in unfunded cyber liability. We would like to adjust the purchase price by this amount, or place it into a specific indemnity escrow to be released as remediation milestones are met."

This approach changes the dynamic of the conversation. It is no longer about the IT department’s opinions. It is about the financial reality of the acquisition.

Abstract digital risk representation with a protective gold shield and dollar sign

Why This Matters for Private Equity

In today’s market, multiples are high and margins are tight. A major cyber incident post-close can wipe out years of growth. By performing rigorous private equity due diligence that includes a quantified RDA, you protect your investment from the start.

It also helps with the "Exit" in mind. If you buy a company with poor security, fix it, and can prove the improved valuation through a lower risk profile, you create tangible value. You aren't just buying a company; you are de-risking an asset.

Strategic Negotiation Levers

Using an RDA gives the deal team several levers to pull:

  • Direct Price Reduction: Lowering the Enterprise Value (EV) based on the inherited "cyber debt."

  • Indemnity Escrows: Setting aside funds specifically for known security gaps.

  • Representations and Warranties (R&W) Insurance: Using the RDA data to negotiate better terms or lower exclusions with your insurance carrier.

Final Thoughts

Cybersecurity is a financial risk, not just a technical one. If your due diligence process only gives you a list of "red flags," you are missing the clarity needed to make a sound investment.

By calculating a Recommended Deal Adjustment, you transform vague technical concerns into actionable financial intelligence. You protect your value, secure better terms, and ensure that your portfolio company is set up for success from Day 1.

CyberSweep Gold Shield Logo

To Protect Your Deal

Before you dive into deep technical testing, it helps to know if the risk is even worth the effort.

  1. Try the Cyber Risk Self-Assessment: Use our simple, 12-question tool to determine if there is enough risk in your target company to warrant a deeper engagement. You can find it on our homepage.

  2. Request a Sample Redacted Report: See exactly how we turn technical findings into financial line items. This report demonstrates the clarity we provide to deal teams during the negotiation process.

At CyberSweep, we specialize in helping Private Equity firms navigate these complexities. We don't just find problems; we find the dollar value of those problems so you can fund remediation and protect your deal.

blog author avatar

Bob

Owner of CyberSweep

Back to Blog