Cyber M&A · Diligence · Value creation

Cybersecurity investments fail for reasons most diligence never uncovers.

We identify the operational risks, GTM gaps, leadership blind spots, and growth constraints that decide whether an acquisition creates value or destroys it.

Carlyle
Led the sale of ICSynergy International to The Carlyle Group (2021).
Global M&A
Headed worldwide M&A at iC Consult, a Carlyle-backed cybersecurity services advisory.
500+
Delivery leadership and partner management behind 500+ IAM projects across IGA, AM, PAM, and Managed Services.
30+ yrs
Founder and operator experience across cybersecurity, identity, and telecom.

Where we sit

Three questions decide a cyber deal. We answer all three.

Most advisors answer one. The deals that create enterprise value, and the ones that destroy it, turn on all three at once.

Traditional diligence

“Is this company healthy?”

Financials, legal, and compliance. Essential, but it tells you where a company has been, not where it can go.

Operator diligence

“Can this company scale?”

Product maturity, go-to-market, leadership, and integration. The questions you can only answer if you have run the playbook yourself.

Investor diligence

“Will this create enterprise value?”

Thesis, value-creation levers, and the path to exit, tying the operating reality to the return.

SME sits exactly at that intersection: operator judgment most diligence teams do not have, applied to the investor question of whether the deal actually makes money.


What gets missed

The risks that surface after the wire clears.

None of these show up cleanly in a data room. Each one can reset the model. These are investment risks, not consulting services, and we find them while you can still act on them.

Hidden technical debt

Re-platforming costs that stay invisible until the roadmap stalls.

Founder dependency

Relationships, knowledge, and momentum that walk out with one person.

Channel weakness

A pipeline that looks diversified but rests on a few fragile partners.

GTM scalability

A motion that works at this size and quietly breaks at the next.

Customer concentration

Revenue that reads recurring until the top logo renegotiates.

Sales process maturity

Forecasts built on heroics instead of a repeatable engine.

Product-market fit erosion

A category shifting underneath a product that used to win.

Leadership gaps

A team that got the company here but cannot get it there.

Cyber market positioning

A story that does not survive contact with a sophisticated buyer.

The cheapest time to find these is before the LOI. The most expensive is after close. Bring us in while the findings can still change the price, the terms, or the decision.


Why SME

Operators on your side of the deal, not generalists.

Most cyber diligence is run by analysts who have never carried a number, shipped a product, or integrated an acquisition. We have.

Every principal has founded or led a cybersecurity or identity business, owned a P&L, and lived through the transactions that follow. We have sold a company to a global private-equity leader, headed up Global M&A at iC Consult, a Carlyle Group company, and built and scaled professional services organizations at Okta, Tealium, and beyond.

That means we read a target the way an operator does: where the product really sits, whether the go-to-market actually scales, what integration will cost, and where the value is hiding. Pattern recognition you can only get from having done it.

Why we built SME →


The bench

You are not hiring one advisor. You are hiring a bench.

A specialist operating platform with decades building, running, and exiting cybersecurity and identity businesses, including a founder-led exit to The Carlyle Group, and deep delivery inside the identity platforms your targets are built on.

Mike Thompson
Mike Thompson
Founder & Managing Partner

Built and sold ICSynergy to The Carlyle Group, then headed Global M&A at iC Consult, a Carlyle company. 30+ years across cyber, identity, and telecom.

Dr. Shaibal Chakrabarty
Dr. Shaibal Chakrabarty
Partner & CTO

Ph.D. in cybersecurity. Led enterprise security architecture and FFIEC compliance at Silicon Valley Bank and ran managed security with full P&L at AT&T.

Erin Tiedeman
Erin Tiedeman
Partner & COO

Scaled professional services and customer success at Okta and Tealium, with delivery leadership behind 500+ IAM projects across IGA, AM, PAM, and Managed Services.

Operating and leadership experience across
Okta iC Consult · Carlyle Tealium Cisco AT&T Silicon Valley Bank BMC Software Nortel ICSynergy → Carlyle exit
Identity ecosystem depth
SailPoint CyberArk Okta Saviynt Microsoft Entra

Meet the full team →


How we engage

How we plug into the deal lifecycle.

Scoped engagements with a clear deliverable, built for the speed of a live process.

Pre-deal

Know the real risks before you commit.

An operator's read on a cyber or identity target: product maturity and defensibility, go-to-market scalability, competitive position, customer concentration, and technical debt. We pressure-test the thesis while the findings can still change the price or the decision.

When: evaluating a target, on IC timelines.
Post-close

Accelerate revenue growth after close.

Sector-specific value creation for cybersecurity and identity portfolio companies: positioning, product roadmap, packaging, and competitive differentiation, tied to the investment thesis and the value-creation plan.

When: sharpening a cyber or identity portfolio company.
Sourcing & integration

Find the targets competitors overlook.

Thesis-driven target identification, market mapping, and bolt-on sourcing, then post-merger integration that protects enterprise value through the first 180 days and captures the synergy across technology, leadership, and operations.

When: building a platform or executing a roll-up.
Fractional leadership

Close the leadership gap, fast.

Fractional CISO, CTO, and COO firepower for portfolio companies that need senior cyber and operating muscle without a full-time hire, including board-ready reporting that keeps the thesis on track.

When: a portfolio company has a leadership gap.

See the full advisory framework →


Track record

What it looks like when it works.

Anchor engagement

ICSynergy International → The Carlyle Group

Built ICSynergy into a top-tier identity and access management advisory firm, then led the process that ended in its acquisition by The Carlyle Group in 2021. Operator-led growth, positioned and sold to one of the world's leading private-equity investors.

2021
Acquisition by Carlyle
IAM
Pure-play specialization
Founder-led
Built and exited
Who we work with

Built for investors in the cyber and identity sector.

Private equity

Platform and bolt-on diligence, value-creation planning, and integration for control investors building in cybersecurity and identity.

Growth & venture

A technical and commercial read on earlier-stage cyber companies, plus GTM and scaling support for portfolio founders.

Investment banking

Sector expertise and operator perspective to support sell-side positioning and buy-side target assessment.

Strategic delivery partners

You engage SME. We bring the right bench.

Where a mandate needs commercial execution beyond cyber-sector diligence, we bring in strategic partners like GSCE, our joint practice with Fortis Innovators. One relationship, the right specialists behind it.

GSCE Partners →
Considering a cyber investment?

Get an operator's read before the LOI.

The earlier we look, before LOI, before signing, the more the findings can still change the price, the terms, or the decision. We work with a select group of sponsors. If the situation fits, a short conversation tells us both.