News and Insights

The Due Diligence Question You’re Not Ready For

Written by Rod Loges | Jul 31, 2026, 4:00:00 AM

Why Cybersecurity Is Now a Capital Readiness Issue 

The Bottom Line

Cybersecurity is now a capital readiness issue. Investors, acquirers, and government contract officers are evaluating security posture during due diligence, and founders who aren't prepared are losing deals. Rod Loges, CEO of One Degree Financial, breaks down why Q-Day and AI-driven threats should be on every founder's radar, with insights from George Hyek, fractional CISO at TRINSEC7 and former US Army intelligence officer.

How Is Cybersecurity Affecting Deals and Valuations?

A founder Rod Loges works with was deep in due diligence with a potential acquirer. The numbers were strong, revenue was growing, and the deal was moving. Then the acquirer's team asked a question the founder wasn't expecting: "Walk us through your cybersecurity posture."

He didn't have an answer. Not a real one. He had antivirus software and a firewall, and he thought that was enough. It wasn't.

The acquirer paused the process. The revenue was fine. The margins were fine. But they couldn't verify that the data, the IP, and the customer information they were buying would be protected after the transaction closed. That was enough to stop everything.

That founder scrambled. He brought in a security professional, ran a vulnerability assessment, and spent six weeks getting his house in order. The deal eventually closed, but at a lower valuation and on a longer timeline. The cost of not being ready wasn't stress. It was real money.

What Is Q-Day and What Does It Mean for Founders?

Q-Day is the moment when quantum computers become powerful enough to break the encryption that protects nearly everything online. Financial transactions, customer data, email, contracts, intellectual property. All of it is currently protected by encryption standards that a sufficiently powerful quantum computer could crack.

Most experts place Q-Day somewhere in the early 2030s. Google has warned it could come as early as 2029. Adversaries are already running "harvest now, decrypt later" operations, stealing encrypted data today and storing it until they can unlock it. If customer data, financial records, or trade secrets need to stay confidential for more than five years, the threat is current, not future.

How Are AI-Driven Threats Changing the Security Landscape?

On the MilCom Founders Podcast, Loges sat down with George Hyek, a former US Army intelligence officer and federal law enforcement special agent who now runs TRINSEC7 as a fractional CISO for small businesses. Hyek explained that Anthropic developed an AI platform called Mythos that identifies security vulnerabilities and writes the code to exploit them, both in record time.

As Hyek put it:

It's happening instantly and at a scale that the companies simply can't patch. They cannot come up with the time to make the patch, to remediate it, to fix it. To lock the door.

Anthropic chose not to release Mythos publicly, instead launching Project Glasswing to give companies like Google, Microsoft, Amazon, and CrowdStrike access to develop responses. The tools exist, and the security landscape that founders thought they understood is shifting.

Hyek also shared a number that underlines the risk for smaller companies:

43% of cyber attacks right now are on small businesses, and unfortunately, people don't realize that they're in the fight. They just don't know.

Why Is Cybersecurity a Capital Readiness Issue?

Pillar 6 of the Ready Founder™ framework is Capital Readiness, and Loges argues that capital readiness goes beyond clean books and strong cash flow. Can the business survive scrutiny?

Investors ask about cybersecurity posture during due diligence. Acquirers evaluate data protection as part of their risk assessment, and government contract officers now require security compliance before founders can even bid. In regulated industries with HIPAA, CMMC, or other compliance frameworks, security posture is directly tied to the ability to win and keep contracts.

If your security isn't in order, you're not capital ready. It doesn't matter how good your revenue looks. A breach can wipe out years of value in a single incident.

Hyek's philosophy aligns with the Ready Founder approach:

I see the security through your lens. I try to make the security a business asset for you that supports your business objectives. The minute security becomes an obstacle for people, they're gonna go around it, which just creates a bigger vulnerability.

Financial readiness means building systems that support business goals instead of getting in the way. Security works the same way. Done right, it becomes a competitive advantage.

What Should Founders Do to Protect Their Businesses?

1. Get a vulnerability assessment. Find a qualified security professional and let them show you where the gaps are. If the idea of that assessment feels uncomfortable, that's exactly why it's needed.

2. Ask vendors the hard questions. What are they doing about post-quantum encryption? What's their incident response plan? If they can't answer clearly, that's a red flag.

3. Think of security as protection for what you've built. Revenue, customer data, IP, valuation. A breach costs more than money. It costs trust. And trust is what makes deals happen.

4. Build security into the capital readiness checklist. Right next to clean financials, strong cash flow projections, and investor materials.

Listen to the full conversation: Episode 45: George Hyek, TRINSEC7

FAQ

What is Q-Day?

Q-Day is the projected moment when quantum computers become powerful enough to break current encryption standards. Most experts estimate it will occur in the early 2030s, though some projections place it as early as 2029.

What is "harvest now, decrypt later"?

A strategy where adversaries steal encrypted data today and store it, waiting for quantum computing capabilities that will allow them to decrypt it in the future.

Why should small business founders care about cybersecurity threats?

According to George Hyek of TrinSec Seven, 43% of cyber attacks currently target small businesses. A breach can cost customer trust, contract eligibility, and potentially the deals tied to a company's growth or exit.

How does cybersecurity affect capital readiness?

Investors, acquirers, and government contract officers increasingly evaluate cybersecurity posture during due diligence. Founders who cannot demonstrate adequate data protection and security compliance risk lower valuations, paused deals, or disqualification from contracts.

What is a fractional CISO?

A fractional Chief Information Security Officer provides security leadership to companies on a part-time or contract basis, giving small businesses access to enterprise-grade security strategy without the cost of a full-time executive hire.

Want the visual summary? Download the PDF version here.

The Ready Founder™ is part of One Degree Financial's commitment to helping founders gain the financial clarity and confidence they need to scale and exit successfully.

Ready to see where your business stands? Take the Ready Founder™ Assessment to find out where your financial leadership is strong and where the gaps are. Ready to make sure your business can withstand scrutiny? Book a Financial Clarity Call with our team.

Hear George Hyek's full story on the MilCom Founders Podcast: Episode 45

Want our monthly newsletter delivered to your inbox? Sign up here: readyfounder.substack.com

About the Author: Rod Loges is CEO of One Degree Financial and host of the MilCom Founders podcast, where he helps veteran entrepreneurs build businesses with strong financial foundations.

One Degree Financial | Financial Leadership for Founders
onedegreefinancial.com
Lead · Adapt · Thrive