Cyber due diligence has moved from a technical footnote to a valuation input. The reason is precedent: acquirers have discovered material breaches after closing, adjusted prices, and in some cases inherited regulatory liability for incidents that occurred before they owned the business. What you fail to find becomes yours at completion.
What to establish before signing
Incident history - the question that matters most
Ask directly for all security incidents in the past three to five years, including those assessed as not notifiable, and for any regulatory correspondence. Then look for corroboration rather than accepting the answer: unexplained gaps in logging retention, sudden infrastructure changes, unusual professional fees, an abruptly departed security lead.
Also ask whether the target has ever been notified of a breach by a third party, or appeared in credential dumps. A target that has never had an incident either has excellent security or no detection capability, and the second is far more common - it is worth establishing which.
The estate
- Asset inventory completeness - if they cannot produce one, that is itself the finding.
- End-of-life systems, unsupported software and technical debt requiring investment.
- Cloud posture and where data actually resides.
- Identity architecture, privileged access, and MFA coverage.
- Backup and recovery capability, tested rather than claimed.
Compliance and data
- Certifications held - and their scope, which is frequently far narrower than the marketing implies. Read the certificate, not the badge.
- What personal data is held, where, under which regimes, and on what lawful basis.
- Data transfer arrangements and residency commitments that may constrain integration.
- Open regulatory matters, and security commitments in their customer contracts - those obligations transfer to you.
- Contractual security obligations they are currently failing, which becomes your breach on day one.
Assess an acquisition against a real control set
GRC Copilot runs a structured assessment against any framework and produces a scored, evidence-backed gap list - a defensible basis for a diligence finding or an integration plan.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Working within diligence constraints
You will not get the access you want. Targets limit technical testing, competitors cannot be shown sensitive detail, and timelines are short. What works within those limits:
- External attack surface assessment - entirely passive, needs no cooperation, and frequently the most revealing single input.
- Structured questionnaire plus interviews with the people who operate the controls, not only the CTO.
- Document review - policies, audit reports, penetration test reports including the remediation evidence, which is the part usually missing.
- Threat intelligence on the target's exposure and leaked credentials.
- Technical testing post-signing, pre-closing where the deal structure allows it.
Findings translate into three levers: price adjustment, escrow or indemnity for identified exposures, and conditions precedent requiring specific remediation before completion. Quantify remediation cost - a gap list without a number rarely moves a deal team.
Integration is the dangerous phase
The highest-risk moment is not diligence, it is connection. Joining two networks merges two threat surfaces, and if the target is already compromised, integration hands the attacker your environment.
What disciplined integration looks like:
- Do not connect immediately. Keep environments separate until a security assessment - ideally including compromise assessment - is complete.
- Assume compromise on a poor-posture target and hunt before trusting.
- Prioritise identity. Federating identity is usually the first integration step and the most consequential; do it after cleaning up their privileged accounts, not before.
- Segment at the boundary and open specific flows deliberately.
- Retain their key people. Institutional knowledge of an unfamiliar estate is worth more than documentation, and it walks out during integration.
The first 100 days
Sequence: complete asset discovery, deploy your endpoint detection to their estate, enforce MFA on privileged and remote access, close internet-facing critical vulnerabilities, get logs flowing into your monitoring, revoke dormant and orphaned accounts, and reconcile their supplier list into your vendor risk process.
These are deliberately blunt, high-coverage actions. Cultural alignment and policy harmonisation matter, but they come after the estate is visible and the obvious exposure is closed.
Frequently asked questions
Does a breach kill a deal?
Rarely by itself. Concealment is the greater problem - an undisclosed incident found in diligence damages trust across every other representation.
Can we test their systems before closing?
Only with explicit written authorisation, and usually limited. Passive external assessment needs no access and is often the most informative step available.
Who should run cyber diligence?
Your security team with external specialist support. Financial diligence teams are not equipped to evaluate a security posture, and generic checklists miss the material issues.
What about divesting?
The mirror problem: separating identity, extracting data, terminating shared access and ensuring the divested entity cannot reach your environment. Transitional service arrangements are a common source of lingering, unmonitored access.
Key takeaways
- Ask for full incident history and corroborate it - "no incidents" often means no detection.
- Read certificate scope; contractual security obligations transfer to you at completion.
- Quantify remediation cost so findings become price, escrow or conditions precedent.
- Integration is the dangerous phase - assess and hunt before you connect.