Cyber M&A · Diligence · Value creation

Cybersecurity investments fail for reasons most diligence never uncovers.

We identify the operational risks, GTM gaps, leadership blind spots, and growth constraints that decide whether an acquisition creates value or destroys it.

Carlyle
Led the sale of ICSynergy International to The Carlyle Group (2021).
Global M&A
Headed worldwide M&A at iC Consult, a Carlyle-backed cybersecurity services advisory.
500+
Delivery leadership and partner management behind 500+ IAM projects across IGA, AM, PAM, and Managed Services.
30+ yrs
Founder and operator experience across cybersecurity, identity, and telecom.

Where we sit

Three questions decide a cyber deal. We answer all three.

Most advisors answer one. The deals that create enterprise value, and the ones that destroy it, turn on all three at once.

Traditional diligence

“Is this company healthy?”

Financials, legal, and compliance. Essential, but it tells you where a company has been, not where it can go.

Operator diligence

“Can this company scale?”

Product maturity, go-to-market, leadership, and integration. The questions you can only answer if you have run the playbook yourself.

Investor diligence

“Will this create enterprise value?”

Thesis, value-creation levers, and the path to exit, tying the operating reality to the return.

SME sits exactly at that intersection: operator judgment most diligence teams do not have, applied to the investor question of whether the deal actually makes money.


Why SME

Operators on your side of the deal, not generalists.

Most cyber diligence is run by analysts who have never carried a number, shipped a product, or integrated an acquisition. We have.

Every principal has founded or led a cybersecurity or identity business, owned a P&L, and lived through the transactions that follow. We have sold a company to a global private-equity leader, headed up Global M&A at iC Consult, a Carlyle Group company, and built and scaled professional services organizations at Okta, Tealium, and beyond.

That means we read a target the way an operator does: where the product really sits, whether the go-to-market actually scales, what integration will cost, and where the value is hiding. Pattern recognition you can only get from having done it.

Why we built SME →


The bench

Senior operators, not a generalist read.

Three principals, each with more than two decades building and running cybersecurity and identity businesses.

Mike Thompson
Mike Thompson
Founder & Managing Partner

Built and sold ICSynergy to The Carlyle Group, then headed Global M&A at iC Consult, a Carlyle company. 30+ years across cyber, identity, and telecom.

Dr. Shaibal Chakrabarty
Dr. Shaibal Chakrabarty
Partner & CTO

Ph.D. in cybersecurity. Led enterprise security architecture and FFIEC compliance at Silicon Valley Bank and ran managed security with full P&L at AT&T.

Erin Tiedeman
Erin Tiedeman
Partner & COO

Scaled professional services and customer success at Okta and Tealium, with delivery leadership behind 500+ IAM projects across IGA, AM, PAM, and Managed Services.

Meet the full team →


How we engage

How we plug into the deal lifecycle.

Scoped engagements with a clear deliverable, built for the speed of a live process.

Pre-deal

Commercial & technical diligence

An operator's read on a cyber or identity target: product maturity and defensibility, go-to-market scalability, competitive position, customer concentration, and technical debt. We pressure-test the thesis before you commit capital.

When: evaluating a target, on IC timelines.
Post-close

Cyber value creation

Sector-specific value creation for cybersecurity and identity portfolio companies: positioning, product roadmap, packaging, and competitive differentiation tied to the investment thesis.

When: sharpening a cyber or identity portfolio company. For cross-sector commercial-execution and GTM work, see GSCE Partners.
Sourcing & integration

M&A targeting & integration

Thesis-driven target identification, market mapping, and bolt-on sourcing, then post-merger integration that actually captures the synergy across technology, leadership, and operations.

When: building a platform or executing a roll-up.
Fractional leadership

Operating bench on demand

Fractional CISO, CTO, and COO support for portfolio companies that need senior cyber and operating muscle without a full-time hire, including board-ready reporting.

When: a portfolio company has a leadership gap.

See the full advisory framework →


Track record

What it looks like when it works.

Anchor engagement

ICSynergy International → The Carlyle Group

Built ICSynergy into a top-tier identity and access management advisory firm, then led the process that ended in its acquisition by The Carlyle Group in 2021. Operator-led growth, positioned and sold to one of the world's leading private-equity investors.

2021
Acquisition by Carlyle
IAM
Pure-play specialization
Founder-led
Built and exited
Who we work with

Built for investors in the cyber and identity sector.

Private equity

Platform and bolt-on diligence, value-creation planning, and integration for control investors building in cybersecurity and identity.

Growth & venture

A technical and commercial read on earlier-stage cyber companies, plus GTM and scaling support for portfolio founders.

Investment banking

Sector expertise and operator perspective to support sell-side positioning and buy-side target assessment.

Beyond cyber · with Fortis Innovators

When the gap is commercial execution, not cyber-sector strategy.

For broader growth and go-to-market work outside cyber-sector diligence, we partner with GSCE Partners, our joint practice with Alicia Dietsch of Fortis Innovators.

GSCE Partners →
Considering a cyber investment?

Get an operator's read before you commit.

We work with a select group of sponsors. If the situation fits, a short conversation tells us both.