Skip to main content

M&A Cyber Due Diligence: The Hidden Liabilities Acquirers Miss

6 min read
CISO Daily
M&A Cyber Due Diligence: The Hidden Liabilities Acquirers Miss

The Marriott-Starwood breach — where a breach in the target company’s systems went undiscovered for over two years before acquisition and continued undetected for another two years after close — established the template for M&A cyber liability. The acquiring company inherited not just the breach but the regulatory investigation, the ICO fine, and the class action litigation. The pattern has repeated across dozens of acquisitions since.

In 2026, regulatory obligations make inherited cyber liability even more expensive. UK GDPR and NIS2 in Europe impose breach notification obligations that don’t care who was responsible for the original compromise. SEC disclosure rules mean that material cyber incidents in recently acquired subsidiaries can become public company disclosure events. DORA’s requirements around ICT third-party risk apply to entities absorbed into regulated financial sector groups.

CISOs involved in M&A activity need to make cyber risk legible to deal teams and boards before signing — not as a reason to block transactions, but to price the risk accurately and structure remediation obligations into the deal.

What Standard Financial Due Diligence Misses

Financial due diligence will surface obvious cyber incidents — SEC-reportable breaches, major regulatory fines, publicly disclosed ransomware payments. What it won’t surface:

Active but undetected compromise. Mandiant’s M-Trends 2026 report documents a global median dwell time of 14 days for 2025 incidents, with espionage operations averaging 122 days. A target company with a nation-state intruder present in its network before deal close may have no idea. You inherit the intruder.

Credential exposure from historical breaches. Leaked credential databases from incidents three or four years ago may contain current employee credentials that were never rotated. Have I Been Pwned and commercial credential intelligence services can surface this, but financial due diligence doesn’t run those checks.

Accumulated technical debt in security configuration. Unpatched external-facing systems, misconfigured cloud environments, legacy authentication protocols, and dormant privileged accounts accumulate over years and represent exploitable attack surface that a competent threat actor will find faster than an integration team.

Contractual cyber obligations the target has already accepted. Supply chain contracts, SaaS agreements, and insurance policies often contain cyber representations and warranties. If the target has represented to customers that it meets certain security standards, those representations transfer to the acquirer.

The Due Diligence Scope That Matters

Effective cyber due diligence has three components: posture assessment, incident history review, and regulatory exposure mapping.

Posture assessment requires technical access — you cannot adequately assess cyber risk from documentation alone. The minimum scope should include:

  • External attack surface scan (all externally reachable systems, open ports, certificate information, historical DNS)
  • Review of identity architecture: Active Directory configuration, MFA coverage, privileged access management, service account inventory
  • Cloud environment configuration review against CIS benchmarks or equivalent
  • Endpoint detection and response coverage and alert volumes (gap in EDR coverage suggests areas where threat activity is invisible)
  • Third-party access review: how many external vendors have active connections, through what mechanisms, and with what authentication controls

This typically requires two to four weeks for a mid-size organisation, depending on technical complexity.

Incident history review should ask for more than the target will volunteer. Request:

  • All security incidents in the past three years, including those that didn’t trigger disclosure obligations
  • Insurance claims history for cyber events
  • Threat intelligence vendor reports or managed detection and response reports from the past 12 months
  • Results of any penetration tests or red team exercises in the past two years
  • Vulnerability scanning results and remediation timelines

The gap between “incidents we reported to regulators” and “incidents we were aware of internally” is often significant. Structure the data room request to surface both.

Regulatory exposure mapping requires legal and compliance input, but the CISO should drive the scope. Key questions:

  • Does the target process personal data of EEA or UK data subjects? What is the legal basis, and have all required data protection impact assessments been conducted?
  • Is the target subject to NIS2 as an essential or important entity? If so, what obligations has it accepted and where are the gaps?
  • Has the target experienced any incidents that should have been reported to regulators but weren’t?
  • Does the target have any ongoing regulatory investigations or open enforcement actions it hasn’t disclosed?

Structuring Risk in the Deal

Cyber risk should appear in deal documents in three places.

Representations and warranties from the seller regarding the accuracy of cyber disclosures, the absence of undisclosed breaches, and the validity of stated security control claims. Representations and warranties insurance (RWI) increasingly covers cyber reps in M&A transactions, but the policy requires the representations to be accurate at signing — misrepresentation voids coverage.

Indemnification for pre-close incidents. Negotiate specific indemnification for regulatory fines, litigation costs, and remediation expenses arising from incidents that occurred before deal close but are discovered after. Cap structures vary, but an uncapped indemnity for regulatory fines (which are government-imposed and not fully foreseeable) is worth pursuing.

Remediation obligations and timelines. If due diligence surfaces material deficiencies — significant EDR gaps, known unpatched vulnerabilities in production systems, absence of MFA for privileged access — these should appear as closing conditions or post-close remediation milestones with associated escrow. Deal teams often resist this level of specificity, but a defined remediation plan with a timeline is the only mechanism for ensuring inherited risk gets addressed rather than absorbed indefinitely.

Post-Close Integration Risk

Integration creates new attack surface that neither the acquirer nor target would face independently. Identity federation between two Active Directory environments expands trust relationships in both directions. Network interconnections required for ERP integration create new lateral movement paths. A shared Microsoft 365 tenant means the target’s phishing risk becomes the acquirer’s phishing risk.

For the first 90 days post-close, the integration team’s default posture should be network segmentation with monitored, controlled interconnections — not immediate full trust. Threat actors monitor M&A announcements and specifically target integration periods because the security posture of both organisations is temporarily degraded by operational disruption.

Board Governance

Boards in 2026 are increasingly asked to sign off on acquisition risk, and cyber risk is now a material factor in that sign-off. The CISO’s role in deal governance is to translate technical findings into financial exposure estimates — not to block deals, but to ensure the board is approving the risk it is actually acquiring.

The framing that works: cyber due diligence findings should be presented as a dollar range of potential future costs (regulatory fines at GDPR scale, breach notification costs, remediation, litigation) under different scenarios (no undisclosed incident exists; a significant undisclosed incident exists; a nation-state intruder is present). That range, compared against deal price and indemnification coverage, gives the board the information it needs to make an informed decision.