A Canadian mid-market M&A advisor engaged LeakTrace to conduct a pre-listing cyber review of an accounting firm about to enter a competitive sale process. The engagement identified exposure conditions the seller closed before listing, and the sale process completed without cyber diligence findings materially affecting the transaction.
Engagement origin
The advisor was preparing to list a mid-market Canadian accounting firm serving corporate clients across two Canadian provinces. The firm had approximately fifty professional staff and was expected to attract interest from consolidation buyers and from strategic acquirers. The advisor had recently seen comparable accounting firm sales where buyer-side cyber diligence had produced findings the seller had not disclosed in the confidential information memorandum, resulting in purchase-price adjustments. The advisor engaged LeakTrace on the seller's behalf to identify and close such exposure conditions before listing.
Discovery scope
LeakTrace conducted a seventy-two-hour external attack surface audit covering the seller's registered domains, partner and staff email patterns, public directory records associated with the seller's Chartered Professional Accountants of Canada registration, and vendor mapping. The engagement was scoped to complete before the confidential information memorandum was finalized.
Findings summary
- Partner and staff credential exposure. Several partners and staff had personal email addresses appearing in monitored breach databases. Reuse patterns extended into the firm's tax preparation platform and client portal.
- Client portal exposure. The seller's client portal was reachable without geographic access controls. The vendor's version disclosure indicated the portal was running a release the vendor had issued a security advisory on in the prior quarter.
- Tax preparation platform exposure. The seller's tax preparation platform vendor had received a public security update the seller had not yet applied. The exposure was standard for firms in the seller's class but represented a diligence finding a competent buyer would identify.
- Vendor concentration risk. DNS records disclosed the seller's outsourced information-technology provider serviced several client relationships as well as the seller's own operations. The concentration created a diligence-relevant disclosure the confidential information memorandum had not referenced.
Seller actions
The seller executed remediation before the confidential information memorandum was finalized. Credentials were rotated across all identified exposures and multi-factor authentication was enforced on client-facing platforms. Client portal geographic access controls were configured and the vendor's security advisory was applied. Tax preparation platform updates were installed. Vendor concentration risk was disclosed in the confidential information memorandum with the seller's proposed mitigation.
Outcome
The sale process attracted competitive interest and closed with the strategic acquirer. Buyer-side cyber diligence identified substantively the same exposure conditions LeakTrace had already documented and the seller had remediated. No purchase-price adjustment was requested on cyber diligence findings. The advisor engaged LeakTrace as a standing pre-listing referral partner on subsequent professional services sales.
All findings were derived from public and monitored sources only. No portion of this engagement required access to the seller's internal systems or any client file. This case file documents the pattern of pre-listing cyber review engagements LeakTrace conducts with Canadian M&A advisors on professional services sales, and is not attributed to the specific advisor, seller, buyer, or transaction referenced.