
A dental laboratory group with locations across the country was preparing for its sale to a private equity buyer, with reps and warranties insurance underwriting ahead. Growth by acquisition had left it with 44 web domains across its brands, more than one managed service provider, and a mix of email, lab production, and remote access systems. Counsel wanted to know what an attacker, or the buyer's underwriter, would find before either of them looked.
The engagement ran under a three-party agreement directed by counsel, which kept the work privileged. Over a weekend we ran an external penetration test mapped to MITRE ATT&CK, together with a vulnerability assessment of exposed services, a review of directory services, access testing against the email platform and the lab production software, and a review of externally hosted portals. A dark web sweep checked every brand's domains for exposed credentials. Where the test found a usable path, we built a proof of concept showing how a ransomware group would use it, so each critical finding read as a scenario a deal team could weigh.
The test produced 10 critical and 10 high findings. Two were on CISA's Known Exploited Vulnerabilities catalog, including a SonicWall firewall flaw that Akira ransomware affiliates have used for initial access. Others included an exposed mail server, a publicly reachable hosting control panel, and missing SPF, DKIM, and DMARC records, which left the group's domains open to spoofing.
The group fixed the two most serious exposures, the SonicWall and the mail server, within 24 hours of the Saturday night discovery, and both fixes were retested the same week. Counsel received an oral briefing and a written report, with risk ratings and remediation priorities, prepared for a deal audience. The group's leadership has since referred other companies to us.
In a deal with reps and warranties insurance, the policy generally excludes problems the deal team already knows about, and findings that a buyer's diligence turns up tend to come back as exclusions, special indemnities, or price adjustments. A seller that tests first decides what gets fixed before anyone else sees it and arrives at underwriting with remediation evidence in hand. The cost of a weekend test is small next to any of those outcomes.
Client details in this case study are generalized, and in places combined across engagements, to protect confidentiality. Sell-side testing like this runs through our penetration testing and sell-side M&A advisory teams, and our guide to sell-side due diligence explains why sellers should find problems before buyers do. We are glad to walk through comparable work under NDA.