Acquirers routinely discover, after close, that the target company they bought was either mid-breach at the time of signing, had concealed a regulatory investigation, or carried security debt so severe that remediation costs materially exceeded what was priced into the deal. These discoveries are expensive. They are also largely preventable with a structured cyber due diligence process conducted before close.
The Marriott acquisition of Starwood is the most cited example: the $13.6 billion deal closed in 2016 with an active breach already underway in the Starwood systems — one that went undetected for two further years before disclosure in 2018, resulting in a £99 million ICO fine, a $23.8 million SEC settlement, and years of litigation. The acquiring company inherited the liability entirely.
The legal and governance landscape has tightened significantly since then. The SEC’s cyber disclosure rules require material cybersecurity incidents to be disclosed within four business days. NIS2 imposes strict reporting timelines on essential entities in the EU. GDPR and UK GDPR liability does not stay with a target company — it transfers to the acquirer. In this environment, treating cyber due diligence as a checkbox rather than a structured assessment is a governance failure with direct financial consequences.
Why Cyber Due Diligence Is Structurally Underweighted
Traditional M&A due diligence covers financial statements, legal exposures, commercial contracts, regulatory filings, and HR liabilities in considerable depth. Cyber risk tends to receive far less attention for predictable reasons: it requires specialist expertise that most deal teams don’t carry in-house, quantifying cyber liabilities is less straightforward than financial ones, and sellers have incentives to minimise disclosure.
The result is that deals regularly close with three categories of undisclosed cyber risk:
Active or recent breaches: Incidents that haven’t yet been discovered, reported, or disclosed. A company that has been sitting on an undetected compromise for six months is not obligated to disclose it pre-close unless there is a specific contractual representation covering cybersecurity.
Regulatory exposure: Ongoing ICO investigations, unresolved NIS2 notification requirements, SEC correspondence about prior disclosures. These create successor liability that the acquirer inherits.
Accumulated technical debt: Legacy infrastructure, unpatched critical systems, missing MFA, absence of endpoint detection, and an IT estate that will require material investment to bring to an acceptable security baseline. This isn’t always disclosed because sellers don’t necessarily know their own security posture in detail.
What a Cyber Due Diligence Assessment Should Cover
1. Historical Breach and Incident Review
Request and review:
- Incident logs and forensic reports from the past three years
- Insurance claims with cyber components
- Board-level incident reports
- Any law enforcement or regulatory correspondence related to security incidents
- Dark web monitoring results from the target’s domain and key credentials
The absence of documented incidents does not mean no incidents occurred — it may mean incidents weren’t detected or recorded. Threat intelligence from commercial providers (Recorded Future, Flashpoint, KELA) can surface indicators of compromise associated with the target’s IP ranges and domains that wouldn’t appear in internal records.
2. Regulatory and Legal Exposure
Map the target’s regulatory footprint:
- Which EU member states process personal data (NIS2 and GDPR jurisdiction)
- Whether the target qualifies as an “essential” or “important” entity under NIS2 (and whether they have registered accordingly)
- US state privacy law coverage — California CPRA, Texas, Virginia
- Sector-specific obligations: DORA (financial services), HIPAA (healthcare), FCA requirements (UK financial sector)
- Pending investigations, regulatory correspondence, or consent orders
Ask for representations and warranties on completeness of disclosure. Cyber insurance policies, with their documentation of security controls at time of application, can be informative about the state of security at a specific point in time.
3. Third-Party and Vendor Risk
Supply chain exposure is increasingly the mechanism through which acquired companies bring hidden risk:
- Map critical third-party software and service dependencies
- Identify any vendors subject to sanctions or geopolitical risk
- Review SaaS access management — particularly whether departing employees’ access has been revoked across third-party platforms
- Assess managed service provider relationships and whether those providers have their own material incidents in the past two years
4. Technical Security Assessment
An independent technical assessment should cover at minimum:
- External attack surface — automated scanning of internet-facing assets, including acquired subsidiaries and historical acquisitions the target itself made
- Identity and access management — MFA coverage, privileged access management, service account sprawl, Active Directory health
- Endpoint security — EDR coverage, patch status on internet-facing and critical systems
- Network segmentation — particularly relevant for manufacturing, healthcare, and OT-heavy targets
- Cloud security posture — IAM configuration, exposed storage, security monitoring coverage
This assessment is typically conducted by a specialist third party under NDA as part of the due diligence process. The target company may resist granting access; deal terms can be structured to require it, or access can be scoped to documentation review and evidence-based assessment where live access isn’t feasible.
5. Security Programme Maturity
Evaluate the organisation’s security programme, not just its current controls:
- Does a CISO or equivalent role exist, and how long have they been in post?
- What is the security budget as a percentage of IT spend and of revenue?
- Are staff phishing-tested and security-trained? When did the most recent test occur?
- Is there a documented and tested incident response plan?
- Have third-party penetration tests been conducted, and what were the findings?
A mature programme with documented processes, recent third-party validation, and evidence of ongoing improvement is a materially different risk profile from an organisation that passes security controls on paper but has never tested them.
Structuring Findings for the Deal Team
The due diligence output needs to translate cyber findings into deal terms. The conversation between the CISO and the deal team should produce:
Price adjustments: Material remediation requirements — say, a legacy ERP system on an unsupported OS with no path to replacement — have a quantifiable cost that should factor into deal pricing.
Representations and warranties: Specific cyber representations in the purchase agreement — no undisclosed breaches, no regulatory proceedings, all regulatory notifications have been made — create contractual recourse if material issues emerge post-close.
Escrow arrangements: For deals where cyber risk is assessed as elevated but not a dealbreaker, escrow arrangements that hold back a portion of the purchase price pending resolution of specific security items provide protection.
Cyber-specific R&W insurance: Representations and Warranties (R&W) insurance is increasingly extended to cyber-specific representations. Dedicated cyber due diligence insurance can cover losses arising from undisclosed pre-breach conditions for a defined period post-close.
Walk rights or deal conditions: If the technical assessment uncovers evidence of an active breach, an ongoing regulatory investigation that wasn’t disclosed, or material misrepresentation in the seller’s security questionnaire, these may warrant requesting additional disclosure, restructuring deal terms, or in significant cases, exercising walk rights.
The CISO’s Role in Post-Close Integration
Due diligence assessment ends at close, but the security work continues. The CISO should have a day-one integration plan ready that covers:
- Network isolation protocols until the acquired company’s security posture is assessed and remediated
- Identity federation timeline — when will the acquired workforce be on MFA and the acquiring company’s IdP?
- Incident response clarity — which team handles incidents in the acquired entity during the integration period?
- Communication to the target’s security team about governance and escalation paths
Acquisitions that fail to plan the integration period often find that the security debt they identified in due diligence worsens in the gap between close and integration completion — a period when organisational accountability is unclear and attacker attention is elevated by public announcements of the deal.