For the investors who price that risk, the boards accountable for governing it, and the executives delivering it.
We provide extensive technology, cyber and AI due diligence to investors; board governance advisory and training that helps directors meet their duties on cyber and AI risk; and operator-level services that guide and govern technology, cyber and AI programmes of work. For organisations that need assurance they are operating safely, securely, and within the bounds of their compliance and governance obligations.
What is this technology actually worth, and what will it cost to fix? Are we, as directors, discharging our duty on cyber and AI risk? And is this programme of work delivering what it claims, safely and within our compliance obligations?
Most advisers answer one of those questions. Cyber Partners answers all three, because the evidence behind them is the same evidence: architecture, controls, delivery track record and governance. Read once, at the depth required to be credible, and reported to whoever has to act on it.
Five services across investment, governance and delivery. Technology, AI and cybersecurity assessed with enough technical depth to be credible, and reported in the terms the decision actually requires: dollar costs, valuation impact, deal structure, directors’ duties, and assurance that a programme of work is under control.
Technology, AI and cybersecurity due diligence for private equity and venture capital, with every finding translated into its effect on valuation and deal structure.
Operator-level guidance and governance of technology, cyber and AI programmes of work: sequencing, costing and assurance that delivery is under control.
Independent, senior-level advisory on technology, AI and cybersecurity strategy for boards, chief executives and investment committees.
Board and director training in cyber, technology and AI risk. Built for the board table rather than the server room, with crisis simulations that put directors in the decision seat.
Independent cyber, technology and AI governance for boards and risk committees: retained mandates, quarterly reporting and assurance the board can point to.
Senior-led throughout. No account managers, no junior teams, no handoffs.
Start a conversation →Three engagements across the practice. Client and target names are never disclosed.
A target’s proprietary AI credit-scoring platform was represented as a core competitive asset. Our assessment found that the claimed capability was a commercial API integration with no defensible intellectual property and no barrier to replication. Offshore development quality issues had caused an 18-month roadmap delay with no credible recovery plan. Our client withdrew from the transaction.
Commissioned to design and build a comprehensive cyber security training programme for businesses across the state, including the full training content and the technology platform used to deliver it. The programme’s success led to its expansion into a national offering for businesses across Australia.
Appointed as independent specialist advisor on technology, cyber and AI risk, providing quarterly risk updates to the board, reviewing progress against major programmes, and testing whether the risk register still reflected the business. Where programmes were drifting, the board received the evidence and the recommendations needed to bring them back under control.
Cyber Partners is led by Tony Barnes, with more than three decades of senior executive and non-executive experience across technology, critical infrastructure, and cybersecurity sectors.
Tony has founded, scaled, and exited technology businesses, served as chief executive of public companies on two continents, sat as a non-executive director of national critical infrastructure companies, and led technology and cyber due diligence on transactions from A$30M to US$3.5B.
About Tony Barnes →Whether the question is a transaction, a board’s oversight duty, or a programme of work that needs independent assurance. Initial conversations are confidential and without obligation.
Most technology due diligence produces a list of risks. Cyber Partners translates every significant finding into its precise financial consequence: what it costs, what it changes, and what it means for your deal.
Technology, AI and cyber due diligence for private equity and venture capital, across Australia, New Zealand, the United Kingdom and Europe.
Every deal now has a technology dimension. Platform scalability, cybersecurity posture, AI capability, technical debt, team execution risk: in many transactions, these are the deal thesis rather than peripheral concerns.
The typical technology diligence report catalogues findings and classifies risks, leaving the translation into financial consequences to others who are rarely equipped to perform it. Material risks are missed, or noted but not quantified, until they surface post-acquisition when the investor’s options have narrowed considerably.
Technology risk surfaces in the hold period: when the business plan is not delivering, the platform is not scaling, or a cybersecurity incident exposes a liability that was visible in the data room. Technology due diligence exists to find these issues before capital is committed.
Cyber Partners assesses the full technology, AI, and cybersecurity landscape of a target business and translates every significant finding into its effect on valuation, deal structure, and investment thesis: technical debt quantified in dollar terms, cybersecurity gaps mapped to insurance and remediation costs, AI capability claims tested against the underlying architecture, and execution risks identified and costed against the business plan.
“The question a PE partner needs answered is never ‘what is wrong with the technology?’ It is always ‘what does this mean for the deal?’”
Technology risk is distributed across infrastructure, code, security posture, team capability, regulatory exposure, IP defensibility, and the alignment between the technology and the investment thesis. Cyber Partners assesses each dimension and maps the findings to their effect on the deal.
Cyber Partners assesses whether the technology of the business, as it actually exists, supports the thesis the deal is being done to — on what conditions, and where the dependencies that have to hold are.
Technical debt, infrastructure investment requirements, licensing compliance exposure, and undisclosed capital requirements absent from management forecasts. Every material item is quantified in dollar terms and mapped to its effect on the valuation model.
Independent assessment of technology and AI claims against the evidence. Is the proprietary AI capability genuinely defensible intellectual property, or a commercial API integration with no barrier to replication? Can the platform scale to support the growth plan?
Cyber Partners assesses whether the technology assets underpin genuine competitive barriers. An AI architecture built on proprietary models is a fundamentally different asset from a product interface layered over a commercially available foundation model. That distinction is visible from the architecture.
Assessment of cybersecurity posture, breach history, incident response capability, and regulatory compliance across applicable frameworks including the Privacy Act, APRA CPS 234, NIST CSF, ASD Essential Eight, ISO 27002, PCI DSS, and GDPR where relevant. Liability quantification and remediation cost estimation.
Cyber Partners assesses the target’s existing coverage against the identified risk profile. Where gaps exist between the risk profile and the current policy, we quantify the exposure and advise on better-positioned coverage. In some mandates, this extends to supporting negotiation of improved terms as part of the transaction.
Can the technology team execute the roadmap presented to investors? Cyber Partners assesses key person dependencies, skill gaps, offshore development quality, delivery track record, and retention risk against the specific demands of the business plan.
Real costs and realistic timelines for technology integration: platform compatibility, data migration complexity, TSA duration, and the integration risks absent from the financial model.
A synthesis of all findings into a clear, evidence-based view of what the technology landscape means for the deal thesis and valuation. Red flags, deal-structuring recommendations, and upside opportunities, expressed in the terms the investment committee needs to make the decision.
A rapid assessment over two to four weeks. Identifies material technology, AI, and cybersecurity risks to inform the go/no-go decision and scope of Phase 2.
Comprehensive assessment over three to six weeks, covering all technology and cybersecurity matters with potential impact on the transaction. Final report covers material risks, remediation costs, and their effect on valuation and deal structure.
Advisory support through the negotiation and finalisation of transaction documentation, including Q&A from lenders and co-investors. The same practitioner throughout.
Independent due diligence for a specific transaction. Scoped to the deal, the target sector, and the investment thesis. One practitioner, one report, no handoffs.
Priority access, accelerated turnaround on initial assessments, volume pricing, and quarterly portfolio-level technology health reviews for firms with an active pipeline.
Pre-emptive identification of issues, remediation planning, and independent validation of technology capability claims ahead of the sale process.
The partner who leads the scoping call conducts the assessment and presents the findings to the investment committee. No account managers, no junior teams, no handoffs at any stage of the engagement.
Red Flags in two to four weeks. Full due diligence in three to six weeks. The engagement moves at the pace of the deal, not the pace of a consulting project.
No software vendor relationships. No implementation practice with an interest in the findings. No cross-selling. The assessment reflects what we find.
Every finding is expressed in the terms that matter: dollar costs, valuation implications, deal structure recommendations, and investment thesis impact. Senior practitioner economics, without Big 4 overhead.
Contact Cyber Partners to discuss the technology dimensions of your next deal. Initial conversations are confidential and without obligation.
hello@cyberpartners.com.auDue diligence identifies risks and opportunities. Cyber Partners provides post-acquisition advisory to support the acquired business in executing the recommendations — led by the same practitioner who conducted the diligence.
Translating the recommendations in the due diligence report into a sequenced, costed remediation plan: what to address before Day One, what to address in the first 100 days, and what forms part of the broader transformation programme.
Where cybersecurity gaps were identified during diligence, advisory support covers governance, policy, architecture, and control framework development, as well as vendor selection where external implementation resources are required.
Advisory on technology strategy decisions arising during the hold period, including platform modernisation, cloud migration, system replacement, and the technology changes needed to support scaling.
Where diligence identified technology leadership risk, Cyber Partners can provide interim advisory support and assistance with leadership assessment and recruitment brief development.
Transformation advisory engagements are structured to the needs of the portfolio company and the timeline of the investment thesis. They can be scoped as a discrete advisory programme with defined deliverables, or as an ongoing retainer providing senior technology advice throughout the hold period.
The client for this service is the acquired business. Instruction typically comes from the incoming management team, the portfolio company board, or the PE firm’s operating partner, acting on the recommendations in the due diligence report.
The practitioner who found the issues is best placed to advise on how to fix them.
Independent, senior-level advisory on technology, AI, and cybersecurity strategy for boards, chief executives, and investment committees.
Independent advisory on technology direction, architecture decisions, vendor strategy, and build-versus-buy choices for boards and leadership teams requiring an external perspective.
Independent assessment of how artificial intelligence can be applied effectively within a business, what genuine AI capability looks like versus marketing characterisation, and how to evaluate AI investment proposals critically.
Board-level advisory on cybersecurity strategy, governance, and investment decisions for boards and executive teams assessing their obligations, risk posture, and governance frameworks.
Technology and AI strategy advisory is most relevant to boards with limited technology representation; to investors assessing technology-intensive companies where a second opinion on the strategy is needed; and to executive teams at a point of significant technology investment requiring independent advisory support.
Engagements are structured to the specific requirement, from a single advisory session to an ongoing board-level advisory relationship.
Boards with limited technology representation
Investment committees requiring an independent view on technology strategy
Executive teams at a point of significant technology investment or transformation
Audit and risk committees assessing AI and cyber governance obligations
Cyber, technology and AI risk is now a director’s duty. Training built for the board table, not the server room, delivered personally by a practitioner who has held governance accountability as a director.
Since the Federal Court’s 2022 decision in ASIC v RI Advice Group, cyber risk sits squarely inside a director’s duty of care under section 180 of the Corporations Act. The AICD and Cyber Security Cooperative Research Centre’s Cyber Security Governance Principles, now in their second version, have become the benchmark against which that duty is assessed.
Training closes the gap between that standard and what directors are actually equipped to do in the room: what to ask, what a credible answer sounds like, and where the red flags sit.
The Federal Court found that reliance on digital systems means cybersecurity risk forms a significant risk connected with the conduct of a business, placing it firmly within the board’s duty of oversight.
One-off or programmed sessions, in person or remote, that build director fluency in cyber, technology and AI risk. Built for the board table rather than the server room: what to ask, what a credible answer sounds like, and where the red flags sit.
Board-level crisis simulations, including ransomware scenarios, that test the decisions directors actually have to make: whether to pay, when to notify, and what to tell the market, not only whether a technical playbook was followed.
Independent review of maturity against the NIST Cybersecurity Framework, the ASD Essential Eight, ISO 27001 and the ISM, translated out of technical language and into a position the board can state with confidence.
More than 1,000 board directors trained over the past decade. Two engagements illustrative of training designed and delivered directly to executives, directors and government stakeholders.
Commissioned by the Queensland Government to design and build a comprehensive cyber security training programme for businesses across the state. Personally developed the full training content and the technology platform used to deliver it, combining face-to-face and online delivery. The programme’s success led to its expansion into a national offering for businesses across Australia.
Designed and personally facilitated more than twenty cyber crisis simulations for TEC and Vistage, Australia’s peer advisory networks for chief executives and senior leaders, reaching several hundred participants nationally. Each simulation placed executives in the decision seat of a live ransomware or major incident scenario, rather than as an audience for a technical briefing.
Structured around the board’s cycle rather than a project timeline, individually or in combination.
A single director briefing, or a structured programme delivered across the year. In person or remote, sized to a single board or a portfolio of boards.
A ransomware or major incident simulation built around your organisation, run at the board table with the directors themselves in the decision seat, not a technical team.
A one-off review of cyber, technology or AI governance maturity, benchmarked against the frameworks below and delivered as a board-ready report.
A three-page overview of the training and advisory practice, including track record, engagement models and practitioner background. Suitable for circulating to a board or nominations committee ahead of a conversation.
Most boards have no independent cyber, technology or AI expert in the room. Independent advisory to boards and risk committees, on appointed mandates with quarterly board reporting.
Since the Federal Court’s 2022 decision in ASIC v RI Advice Group, cyber risk sits squarely inside a director’s duty of care under section 180 of the Corporations Act. The AICD and Cyber Security Cooperative Research Centre’s Cyber Security Governance Principles, now in their second version, have become the benchmark against which that duty is assessed.
Most cyber advice that reaches a board arrives either from a technical vendor running a programme built for an IT audience, or filtered upward through the same management the board is meant to be overseeing. Neither is independent, and neither is built for the boardroom.
The Federal Court found that reliance on digital systems means cybersecurity risk forms a significant risk connected with the conduct of a business, placing it firmly within the board’s duty of oversight.
Ongoing, independent advice to the board or risk committee across cyber, technology and AI governance. Priority access between meetings, briefing papers ahead of board cycles, and a standing point of independent expertise the board can call on.
External expert assurance where the board has a gap in its own cyber, technology or AI governance capability: a named, independent practitioner the board can point to as evidence it has taken its oversight duty seriously.
Independent review of maturity against the NIST Cybersecurity Framework, the ASD Essential Eight, ISO 27001 and the ISM, translated out of technical language and into a position the board can state with confidence, to itself, to regulators and to the market.
Two engagements illustrative of advisory work delivered directly to boards and audit and risk committees. Further detail available on request.
Appointed as an independent specialist board advisor on technology, cyber and AI risk and governance, providing quarterly risk updates to the board, written, in person or both. Reviews progress against IT, AI and cyber programmes, tests risk documentation and register currency, and gives the board assurance that complex technical programmes are on track, or, where they are drifting, the evidence and recommendations needed to bring them back under control.
Engaged as an independent expert contributor to Audit and Risk Committees, providing assessment of technology control gaps, cyber programmes, digital transformation initiatives, and third-party vendor and major programme oversight. Appointed on a retained or ad hoc basis to augment existing committee and director expertise wherever independent technical assurance is required.
Training delivered at state and national scale, including the Queensland Government’s CyberFi programme and more than twenty crisis simulations for TEC and Vistage, is set out under Director Training.
Four ways to engage, individually or in combination, structured around the board’s cycle rather than a project timeline.
Ongoing appointment to the board or risk committee. Quarterly briefings as a minimum, direct access between meetings, and input ahead of major technology or AI decisions.
A one-off review of cyber, technology or AI governance maturity, benchmarked against the frameworks below and delivered as a board-ready report.
A ransomware or major incident simulation built around your organisation, run at the board table with the directors themselves in the decision seat, not a technical team.
A single director briefing, or a structured programme delivered across the year. In person or remote, sized to a single board or a portfolio of boards.
A three-page overview of the advisory and training practice, including track record, engagement models and practitioner background. Suitable for circulating to a board or risk committee ahead of a conversation.
Deal values from A$30M to US$3.5B across Australia, New Zealand, the United Kingdom, Germany, and continental Europe. Client and target names are never disclosed.
Engaged by a global private equity firm to assess an Australian telecommunications infrastructure business. Identified that recent changes to the Telecommunications Act had brought the target into the scope of the Telecommunications Sector Security Reforms — an aspect initially missed by legal due diligence. Identified over $1M in previously unquantified cybersecurity costs and produced 47 recommendations with detailed costings, presented to the investment committee.
Engaged by a London-based energy infrastructure investor to assess one of Germany’s largest smart metering service providers. Assembled a multilingual specialist team. Assessed technology strategy, AI and ML capability, operational performance, infrastructure scalability, cybersecurity maturity, data management, privacy compliance, and technology cost projections.
Engaged by a major utility services business to assess an innovative data services SaaS platform providing enhanced analytics for integrated smart metering, solar, and EV charging infrastructure. Assessment covered IT platform architecture, scalability, cybersecurity posture, technical debt, team capability, and key person risk.
Engaged by a London-based member-owned SaaS business operating across 180 countries to support a vendor due diligence process. Assessed technology roadmap, platform scalability, cybersecurity posture, and team capability. Identified cybersecurity gaps and provided a remediation strategy to bring the security posture to investor-expected standards. The fundraise was completed with investment by a UK private equity firm.
Assessed a FinTech platform whose proprietary AI credit-scoring system was positioned as a core investment thesis driver. Identified that the claimed AI capability was a commercial API integration with no defensible intellectual property. Offshore development quality issues had produced an 18-month roadmap delay. Our client withdrew from the transaction prior to commitment.
Assessment identified a $12M ERP replacement requirement absent from management forecasts and payment card processing compliance gaps requiring immediate remediation. Our client renegotiated the valuation with structured earnout provisions protecting downside risk.
Assessment of a technology programme comprising fifty concurrent in-flight projects, half materially delayed with no dedicated programme leadership. A critical system replacement was 36 months behind schedule with an $8M cost overrun. A further $3M cybersecurity gap identified. Our client added deal conditions with milestone gates and structured quality requirements.
Technology due diligence on a complex multi-platform enterprise software acquisition covering technical debt quantification across legacy platforms, programme governance, compliance status, and cybersecurity posture. Findings informed significant deal restructuring with technology-focused earnout provisions.
Assessment of platform architecture, scalability, integration complexity, and technology team capability. Identified key person dependencies and delivery risks material to the investment thesis.
Vendor due diligence support for an HR technology platform preparing for a sale process. Pre-emptive identification of technology and cybersecurity issues and remediation planning to protect valuation through the sale process.
Every Cyber Partners engagement is led by a senior practitioner with direct operating experience in technology and M&A contexts. The person who leads the engagement is the person who presents the findings to your investment committee.
Tony Barnes is the founder and lead practitioner of Cyber Partners, and the person who leads every technology and cyber due diligence engagement the firm undertakes. He brings to each mandate a combination of technical depth, commercial judgement, and direct experience on both sides of the investment committee table.
Tony’s career spans more than three decades of senior executive and non-executive roles across technology, critical infrastructure, telecommunications, software, and cybersecurity sectors in Australia, New Zealand, the United Kingdom, Europe, and the United States. He has founded, scaled, acquired, and exited technology businesses, including serving as chief executive of a public technology company ranked sixth in the Deloitte UK Fast50 and 17th in the EMEA Fast500.
In parallel with his executive career, Tony has served as a non-executive director of national critical infrastructure companies, including a major electricity distribution network and a fibreoptic telecommunications network, and currently serves as a non-executive director of RSPCA Queensland and RSPCA Australia.
Tony is a Certified Information Systems Security Professional (CISSP), a Fellow of the Governance Institute of Australia. He has led technology and cyber due diligence on transactions from A$30M to US$3.5B across multiple sectors and geographies. Every Cyber Partners engagement is led by Tony personally — there is no delegation to junior practitioners and no handoff between diligence and reporting.
Contact Cyber Partners to discuss the technology due diligence requirements of your next transaction.
Cyber Partners works with private equity and venture capital firms across Australia, New Zealand, the United Kingdom, and Europe, and with international firms active in these markets. Initial conversations are confidential and without obligation.