Skip to content
Skip to content

Security by design: Test how a target decides, not what it certifies

Security by design: Test how a target decides, not what it certifies

Security by design: Test how a target decides, not what it certifies

Security by design: Test how a target decides, not what it certifies

Headshot of Connor Hyatt

Connor Hyatt

Connor Hyatt

Share

A deal team deciding what to test before signing starts by asking the target for its certificates. The data room answers with an ISO 27001 certificate, a SOC 2 report and a penetration test summary, and the cyber workstream marks itself complete. That bundle answers a question no buyer has. The question is not whether a control was audited somewhere in the group, but whether it reaches the thing being bought.

We read 1 whole annual-report season, every Form 10-K filed between 2026-01-01 and 2026-06-30, and counted what 5,752 filings name. 2,118 of them name an incident response plan and 86 name least privilege. That ratio is the thesis: cyber diligence should test how a target makes security decisions and where it decided they stop, because since 2023 both have been public, and the loss sits in the exception estate that a certificate deliberately leaves out.

Incident history screens 57 companies, so it cannot be the test

Item 1.05 of Form 8-K has required a public report within 4 business days of a materiality determination since December 2023, which makes incident history the most tempting screen. It is also the thinnest. Across roughly 11 quarters, SEC reporting companies have between them produced 57 material-incident reports, from 56 filers, with 26 amendments following. Set that against the 5,752 annual reports filed in 1 season.

The run rate says the same. Quarterly volume has never exceeded 9 original reports and has sat between 2 and 7 for 2 years, and many of those reports were later corrected by amendment. A screen that fires this rarely is a tail event, not a diligence instrument.

What the reports contain is impact, not cause. The rule relieves a filer of technical detail about its systems, so an incident report never names the design failure. 1 company put the bill at approximately $180 million to $400 million for an incident where overseas contractors were paid to collect data from systems their jobs already let them reach; the filing's own words for the misuse are "accessing data without business need".

The rule already publishes how a company decides, and the SEC cut the control list on purpose

Regulation S-K Item 106 has applied to annual reports for fiscal years ending on or after 2023-12-15. It requires a description of the registrant's processes for assessing, identifying and managing material risks from cybersecurity threats, and the SEC chose that word on purpose: it substituted processes for the proposed policies and procedures to avoid requiring operational details that could be "weaponized by threat actors".

The disclosure was built the way diligence should be built. 8 proposed disclosure items became 3 in the final non-exclusive list, and across the 2 surviving lists, 3 on risk management and 3 on governance, not 1 asks for a control, a certificate or a test result.

That is a decision architecture, published annually, for every filer. It names who is accountable for security, how they learn about it and how far their writ runs over suppliers, and says nothing about configuration, the trade the SEC made. A buyer reading Item 1C for controls reads the wrong document.

The market filled that space with certificates the rule never asked for

Asked about decisions, filers answered with credentials. 638 name the NIST Cybersecurity Framework by its initials and 556 name it in full words, overlapping in only 7 filings, so 1,187 name that 1 framework. 397 name ISO 27001 and 424 name a SOC report. Counting each filing once, 1,671 of 5,752, more than 1 in 4, name a framework or a certificate.

The decisions are nearly absent. The most-named design decision of the season, multi-factor authentication, appears in 613 of 5,752 annual reports, which still sits below the 629 that name vulnerability management. Below that the vocabulary thins fast: 207 say anything about privileged access, 91 name network segmentation, 23 name encryption at rest and 39 of 5,752 use the phrase secure by design or security by design at all.

Of 5,752 annual reports filed this season, 1,671 name a framework or a certificate, and 1,240 of those name none of the 9 design decisions measured here.

Source: Lunon analysis of 5,752 Form 10-K filings filed January to June 2026, SEC EDGAR full-text search.

The 2 vocabularies barely overlap, which makes a certificate a poor substitute for a decision. Of the 1,671 filings that name a framework or a certificate, 1,240 never name 1 of the 9 design decisions we measured, almost 3 in 4. The 9 are multi-factor authentication, privileged access, zero trust, network segmentation, least privilege, bug bounty, secure by design, secure software development and encryption at rest. Only 971 filings name any of the 9, fewer than 1 in 5, and 13.8 times as many name the NIST Cybersecurity Framework as name least privilege.

Our analysis measures disclosure, not deployed coverage. A company that runs least privilege everywhere and never writes the phrase does not register here, and one that writes it once may run it nowhere. That is why the test belongs in diligence, on the decision and its exceptions, and not in a score read off the disclosure.

Both UK penalty notices issued in 2025 ran through the exception estate

In March 2025 the UK Information Commissioner fined a health and care software provider £3,076,320, settled without appeal from a notice of intent of £6,090,000. The notice records that the group's corporate IT infrastructure was accredited for Cyber Essentials Plus before the incident, and that the breached subsidiary health and care environment was not. The attacker entered that environment through a public-facing remote-access path with no multi-factor authentication.

The decision behind the gap is in the notice. An MFA solution had been developed and tested in 2021 and was not rolled out to all customers, partly because earlier interactions suggested customers would not accept the friction. The 2 applications that did have MFA processed approximately 95 percent of the personal data in that environment, and the Commissioner found the attacker reached the entire environment regardless.

The fine was the small number. Remediation and response costs were in excess of £21 million, and the data of 79,404 people was taken, including details of how to enter the homes of 890 people receiving care. The Commissioner's framing is the one a buyer should borrow: the lack of complete coverage, not the absence of the control, let the attacker in.

In October 2025 the same regulator fined a business-process outsourcer £14 million, reduced from a provisional £45 million, after 6,656,037 individuals' data was exfiltrated. The regulator's published findings are a failure to prevent privilege escalation and unauthorised lateral movement, a failure to respond appropriately to security alerts, and inadequate penetration testing and risk assessment: 2 design decisions and 2 process failures, and no certificate. The notice records the company as an ISO 27001 accredited organisation and measures the failure against that standard.

The timeline is the lesson for a deal team. The alert was generated at 08:00, the attacker logged on with a domain administrator account at 12:21 the same day, and the device was quarantined approximately 58 hours after initial access. The deficiency behind it had stood from 2018-05-25 to 2023-03-31, almost 5 years, and privileged access management was a live project, not a control in place. The project was the exception estate.

American enforcement reads the same. Of the 5 failures the FTC lists in 1 sentence of its Blackbaud case, 2 are design decisions, segmentation and multi-factor authentication, 2 are process, monitoring and testing, and the 5th a retention choice, deleting unneeded data. In its GoDaddy case they are asset inventory, risk assessment, logging and segmentation of shared hosting from less-secure environments. The final order bars the company from misrepresenting compliance with any "program sponsored by a government, self-regulatory, or standard-setting organization": the claim, not the control, is what the remedy reaches.

Federal law already writes the questions, and the written exception is the one that matters

A buyer need not invent the question set. 16 CFR 314.4(c) requires a covered financial institution to design, implement and document 8 safeguards, and 4 of them name a design decision outright: access controls, encryption of customer information in transit and at rest, secure development practices, and multi-factor authentication. Any buyer can put these questions to a target, covered or not.

CISA asks the same question in a different register. Its Secure by Design pledge sets 7 goals and asks a signatory to document measurable progress publicly within 1 year of signing, and goal 1 asks for a measurable increase in multi-factor authentication coverage, not its presence. The pledge is voluntary, and its 3 principles are ownership of customer security outcomes, radical transparency and leading from the top, none of them a control.

The sponsor sits inside the same rule, which makes the test symmetrical

This is not only a question a buyer puts to a seller. Regulation S-P now requires SEC-registered advisers to adopt written policies and procedures for "incident response programs" and to notify affected individuals as soon as practicable and not more than 30 days after becoming aware. 1,941 advisers sit inside that rule, and between them they run 25,155 private equity funds holding just under $8 trillion of gross assets.

The largest listed United States sponsors show both answers. 1 of the 5 largest, Carlyle, names design decisions anywhere in its FY2025 annual report, listing multi-factor authentication for remote access and privileged access management for system administrators. The other 4, Blackstone, KKR, Apollo and Ares, all name the National Institute of Standards and Technology, while the 1 that names decisions names none.

The symmetry is conceded in those filings. All 5 disclose that they assess the cybersecurity of third parties with access to their systems or data: Carlyle, Blackstone, KKR, Apollo and Ares. A sponsor that runs that test on a software vendor and not a platform acquisition has the blast radius backwards.

The next annual reports are being drafted now, and they are free diligence

The cheapest cyber diligence a buyer can run before signing is already written and public. 1 FY2025 annual report states the principle and the access model in a single line, global policies based on the guiding principles of security by design and least-privilege access. Another names 3 frameworks and then lists 9 control domains, and not 1 decision. Those paragraphs tell a reader which kind of seller they have before the data room opens.

Then ask for the rest in writing. The exception estate is the list a certificate's scope statement hides: every system, subsidiary, environment and third party a named control does not cover, the date each exclusion was approved, and the person who approved it. A target that can produce that list in a week runs security as a set of owned decisions. A target that answers with a certificate has told a buyer where the loss will come from.

Related posts

Related posts

Palantir alternatives

Best Palantir alternatives for mid-market companies in 2026

Best Palantir alternatives for mid-market companies in 2026

Eight Palantir alternatives for companies of 100 to 2,000 people and PE portfolios: what each one is, who it fits, what it publishes about price, and where it falls short.

Eight Palantir alternatives for companies of 100 to 2,000 people and PE portfolios: what each one is, who it fits, what it publishes about price, and where it falls short.

Diligence before IC

Commercial diligence before IC: What converges in 30 days and what never will

Commercial diligence before IC: What converges in 30 days and what never will

Sponsor buyers set their own decision window at about a month, so the work that matters before IC is classifying the thesis variables rather than collecting more of them.

Sponsor buyers set their own decision window at about a month, so the work that matters before IC is classifying the thesis variables rather than collecting more of them.

Thesis to execution

From investment thesis to execution: The variables to re-measure after close

From investment thesis to execution: The variables to re-measure after close

2 operating variables carry 93 percent of the unlevered gain in the current-cycle attribution of buyout value creation, yet after close the scoreboard becomes adjusted EBITDA.

2 operating variables carry 93 percent of the unlevered gain in the current-cycle attribution of buyout value creation, yet after close the scoreboard becomes adjusted EBITDA.

Start with the decision in front of you.

Tell us what your team needs to understand, evaluate, or deliver.