Cyber Due Diligence in M&A: What Buyers Must Know Before They Sign
Cyber due diligence tells a buyer what they are actually acquiring before a deal closes. Here is what it covers, the red flags that reprice a deal, and why it now sits on the board's desk.
Tyson Martin
8/20/20265 min read


Cyber due diligence in M&A is the structured assessment of a target company's security posture, breach history, regulatory exposure, and data risk before a deal closes. It tells a buyer what they are actually acquiring, what it will cost to fix, and whether the finding should change the price, the terms, or the decision to proceed. Done well, it converts technical risk into a number a board and a regulator can both act on.
In 2017, Verizon agreed to buy Yahoo's operating business. Then Yahoo disclosed a series of data breaches that eventually touched all three billion of its accounts. Verizon did not walk away. It repriced. The final deal closed $350 million lower, roughly seven percent off the original price, with the two sides agreeing to share future liability.
That remains the clearest lesson in modern dealmaking. You do not just buy a company's revenue. You buy its security posture, its unreported incidents, and its regulatory exposure. Cyber due diligence is how you learn what you are buying before you sign, instead of after.
What is cyber due diligence in M&A?
Cyber due diligence is the part of the deal process that answers one question: what security and data risk are we taking on with this company? It sits alongside financial, legal, and operational diligence, but it looks at a different balance sheet. Where a target keeps sensitive data. Whether it has been breached and whether it would tell you if it had. Who has access to what. Which regulators care, and what they would find. What it will cost to bring the target up to the acquirer's standard.
The output is not a threat briefing. It is a priced, prioritized view of exposure that the deal team can use at the negotiating table.
Why cyber risk now sits on the board's desk, not just IT's
In July 2023, the U.S. Securities and Exchange Commission adopted rules requiring public companies to disclose material cybersecurity incidents on Form 8-K within four business days of deciding the incident is material, and to describe their cyber risk management, strategy, and board oversight in their annual report.
Read that through a deal lens. The moment a target sits inside a public acquirer, the acquirer inherits the obligation to disclose, and inherits the risk that a pre-existing, undisclosed incident becomes a public-company problem on day one. A breach the seller never mentioned does not stay the seller's problem. Cyber risk is now a governance question, and governance questions belong to the board.
How common are cyber problems in deals?
Common enough that treating diligence as a formality is a bet against the odds. Forescout surveyed more than 2,700 IT and business decision-makers across seven countries for its report on the role of cybersecurity in M&A. The findings:
53 percent had encountered a critical cybersecurity issue during a deal that put the transaction in jeopardy.
65 percent felt buyer's remorse after closing, because of security concerns they inherited.
73 percent said an undisclosed data breach is an immediate deal breaker.
Forescout's chief technology officer at the time, Julie Cullivan, summarized the risk memorably. In an acquisition, she said, you inherit not just a company but its security posture and "a potential trojan horse."
What the cyber due diligence process actually covers
A serious assessment goes past the security questionnaire and looks at evidence across these areas:
Breach and incident history. Not just "have you been breached," but how they detect, respond, and document. How they answer matters as much as what happened.
Data inventory. Where PII, PHI, and cardholder data actually live, across file shares, cloud storage, backups, and endpoints. Not where IT believes it lives.
Identity and access. Who has access to what, how privileged accounts are controlled, and how quickly access is revoked.
Third-party and vendor risk. The target's suppliers become your suppliers, and their weaknesses become your entry points.
Cloud and architecture. How the environment is built, segmented, and monitored.
Regulatory and compliance exposure. Which regimes apply, and whether compliance exists in evidence or only on paper.
Security governance and ownership. Whether anyone actually owns the risk, with named accountability.
Remediation backlog. The known problems nobody has yet costed.
The red flags that reprice a deal
Some findings should slow a deal down, change the terms, or change the price. The most common:
Incidents that were disclosed late, partially, or not at all.
No credible data inventory, which means no one can tell you where the liability sits.
No named security owner, which means the risk has been nobody's job.
Compliance that passed an audit but cannot produce evidence on request.
Sprawling, unmanaged third-party access.
A remediation backlog that no one has translated into a dollar figure or a timeline.
None of these necessarily kills a deal. Each one should change what a buyer is willing to pay, or what protections they demand before they sign.
A cyber diligence report has one job: to tell the buyer, the seller, and the regulator the same true thing about the risk, in language a board can act on.
Buy-side and sell-side are two different jobs
On the buy-side, diligence exists to price the risk and protect the buyer's leverage. Find what is there, cost it, and feed it into the terms while you still can.
On the sell-side, the job is the opposite: remove the surprises before the data room opens. Every company carries trust debt, the gap between the security posture it presents and the one it can actually defend. A transaction is the moment that debt comes due. Sellers who close that gap early keep control of the narrative and the price. Sellers who do not hand that control to the buyer's advisor.
Why this is hard to do with an internal team alone
In the same Forescout survey, only 37 percent of IT decision-makers strongly agreed their team had the skills to run a cybersecurity assessment for an acquisition. That is not a criticism of internal teams. It is a description of the problem. Deal timelines are short. The target has every incentive to present well. And the person reading the risk has to translate it into terms a board, a lawyer, and sometimes a regulator will all accept. That translation, from technical finding to defensible decision, is the actual product.
Frequently asked questions
How long does cyber due diligence take? Most buy-side assessments run two to four weeks. A focused sprint can compress that when the deal timeline is tight, as long as the target gives reasonable access.
Who is responsible for cyber due diligence in a deal? The buyer commissions it, usually the deal team or corporate development, and it is frequently run by an independent advisor rather than the buyer's internal IT, both for capacity and for objectivity.
Does cyber due diligence kill deals? Rarely. It reprices them far more often than it ends them. The value is in adjusting the price and the terms to reflect real exposure, not in walking away.
What is the difference between cyber due diligence and a security audit? An audit measures controls against a standard. Diligence prices deal risk and translates it into negotiating terms. Passing an audit is not the same as surviving a buyer's review.
Tyson Martin is a cybersecurity and AI governance executive. He has served as CISO and CTO across public, regulated, and high-scrutiny environments, and currently sits as CISO of record through a cross-border sale under SEC, FCA, and BaFin oversight. He advises boards, private equity firms, and executive teams on M&A cybersecurity, regulatory readiness, and AI governance. More at TysonMartin.com.
Tyson Martin is the executive public and pre-IPO companies in financial services, AI/data, SaaS, and cloud hire to make trust a measurable asset, one accountable answer to Is it secure? Is it resilient? Is the AI governed?
© 2026. All rights reserved.
Navigation
Free Resources
Contact


Stay ahead of your next board agenda
Sign up for Reports & Learnings From the Boardroom. Plain-English AI and cyber governance insights, biweekly. No pitch.
No spam. Unsubscribe anytime. · Or download the Director's AI Question Pack — 25 questions free
