Cyber due diligence is the part of a merger or acquisition that tells you what you are actually buying. Financial diligence values the earnings, legal diligence values the contracts, and commercial diligence values the customer base — but none of them tells you whether the target has been quietly compromised for eight months, whether its crown-jewel data sits on an unpatched server in a cupboard, or whether the “proprietary platform” in the investment memo is three unsupported systems held together by a single contractor who leaves at completion.

That gap matters because cyber risk does not stay with the seller. Liability, regulatory exposure and remediation cost all transfer with the shares. A buyer who skips cyber due diligence and treats IT security as a post-completion problem inherits every unmanaged endpoint, every shared admin password and every unreported incident, and finds out about them after the money has moved. Acquirers increasingly treat cybersecurity assessment as a standard workstream alongside tax and employment, not an optional technical extra.

This guide sets out what proportionate cyber due diligence looks like on a real transaction: the phases, the evidence to request, the red flags that justify a price adjustment, the way findings translate into warranties and indemnities, and the first hundred days after completion when most of the actual risk crystallises. It is written for buyers, but sellers preparing for exit will find the same checklist useful in reverse — a target that can answer these questions quickly closes faster and defends its valuation better.

What cyber due diligence really covers in a deal

cyber due diligence mergers acquisitions b secure filing cabinet

Cyber due diligence is a structured assessment of a target company’s security posture, data handling, technology debt and incident history, carried out before completion so the findings can influence price, structure and post-close planning. It is not a penetration test, and it is not an audit against a single standard. It is a risk exercise scoped to the deal.

The four questions it has to answer

Every cyber due diligence exercise, whatever its size, exists to answer four things. First, is the target compromised right now, or has it been? Second, what would a serious incident cost this business, given its data, its customers and its regulatory footprint? Third, how much investment is needed to bring the estate to an acceptable standard? Fourth, does anything here break the deal thesis — a synergy that assumes system integration, a customer contract that assumes a certification the target does not hold?

What it is not

A common failure is scoping cyber due diligence as a technical inventory. A list of firewalls and antivirus licences tells you nothing about risk. Equally, a target that produces an ISO 27001 certificate is not thereby safe: certification covers a defined scope that may exclude the very systems the deal depends on. Read the statement of applicability, not the certificate.

Where it sits alongside other workstreams

The exercise overlaps heavily with legal and financial diligence, and works best when those teams share findings. Data protection exposure is a legal question informed by technical facts. Technology debt is a financial question — deferred patching is a liability that appears in no balance sheet. Good cyber due diligence sits at that intersection rather than in a silo, which is why it belongs in the wider IT governance conversation rather than in a technical appendix.

Why weak cyber due diligence destroys deal value

cyber due diligence mergers acquisitions c shield with keyhole

The argument for spending money on cyber due diligence is not theoretical. Value leaks in four distinct ways, and only one of them is the headline breach everyone remembers.

Inherited breach liability

Regulators assess the acquiring group. A personal data breach that began before completion but is discovered afterwards is reported by the buyer, investigated against the buyer’s group, and remediated at the buyer’s cost. Under UK GDPR the buyer becomes the controller for the acquired data set, with all the accountability that carries. Where consideration is already paid, recovery depends entirely on whether the warranties and indemnities were drafted with cyber due diligence findings in mind.

Remediation capital nobody budgeted

The most common outcome of a serious cyber due diligence exercise is not a dead deal — it is an unbudgeted capital requirement. Replacing end-of-life infrastructure, rolling out multi-factor authentication across a neglected estate, rebuilding a flat network and hiring the people to run it can run to a material fraction of enterprise value in a small deal. Discovered before signing, that number is a negotiating position. Discovered afterwards, it is a write-off.

Integration delay and synergy slippage

Most acquisition models assume systems merge on a timetable. If cyber due diligence shows the target’s identity platform cannot be federated safely, or that its network must be segmented before any connection is permitted, the integration plan stretches by quarters and the modelled synergies slip with it. Deals are frequently disappointing for exactly this reason rather than for any dramatic security event.

Customer and certification risk

Enterprise customers increasingly require suppliers to hold Cyber Essentials or equivalent assurance, and to notify them of a change of control. A target whose certification lapses at completion, or whose contracts allow termination on ownership change, can lose revenue the model treats as recurring. This is where cyber due diligence and commercial diligence must talk to each other.

Where deal value typically leaks after a weak security review
Unbudgeted remediation capital Very common
Integration delay and synergy slippage Common
Key-person and capability gaps Common
Certification or customer contract loss Occasional
Inherited breach and regulatory action Rare but severe
Indicative pattern across mid-market transactions. Frequency, not severity — the rarest category is the most expensive.

The cyber due diligence process, phase by phase

cyber due diligence mergers acquisitions d hourglass on plinth

A proportionate cyber due diligence process runs in five phases, and each one gates the next. Compressing them all into a single week of document review is how buyers end up with a report that lists observations but recommends nothing.

Phase 1: scoping against the deal thesis

Before a single document is requested, agree what the deal depends on. A buyer acquiring a customer list has a different exposure from a buyer acquiring a software platform it intends to resell. Scope the cyber due diligence to the assets that carry the value, and say explicitly what is out of scope so the report is not read as broader assurance than it is.

Phase 2: document and evidence review

This is the data room phase. The target supplies policies, certifications, risk registers, penetration test reports, incident logs and supplier lists. Most of the initial cyber due diligence findings come from what is missing rather than what is provided.

Phase 3: management interviews

Documents describe intent; interviews reveal practice. Ninety minutes with whoever actually runs IT — often not the person with the title — surfaces more than a full data room. Ask how the last incident was handled, who can approve a payment change, and what keeps them awake at night. This is where cyber due diligence usually finds its real story.

Phase 4: technical validation

Where the deal justifies it, validate the claims. External attack surface scanning, breach-data checks against corporate domains, and a review of identity configuration can all be done without touching production. Intrusive testing normally waits until exclusivity, and always needs written authorisation from the target.

Phase 5: reporting and quantification

The output is not a list of vulnerabilities. It is a small number of deal-relevant findings, each with an estimated remediation cost, a timescale, and a recommendation: accept, price in, indemnify, or condition. A cyber due diligence report that cannot be read by a deal lawyer has failed.

PhaseTypical durationWho leadsPrimary output
Scoping2-3 daysDeal team and adviserAgreed scope and information request list
Document review1-2 weeksSecurity adviserGap analysis and follow-up questions
Management interviews2-4 sessionsSecurity adviserPractice-versus-policy findings
Technical validation1-2 weeksTechnical specialistEvidence-backed exposure assessment
Reporting3-5 daysLead adviserCosted findings mapped to deal actions

The cyber due diligence data room checklist

cyber due diligence mergers acquisitions e interlocking puzzle blocks

The information request list is where a cyber due diligence exercise succeeds or fails. Ask for too much and the target stalls; ask for the wrong things and you get a filing cabinet instead of an answer. The list below is the proportionate core for a mid-market deal.

Governance and accountability

Request the security policy set with review dates, the risk register, board or management papers covering security in the last twenty-four months, and the name of the individual accountable for security. A policy set last reviewed four years ago is itself a cyber due diligence finding, because it shows nobody has owned the subject.

Certifications and assessments

Ask for Cyber Essentials or Cyber Essentials Plus certificates, any ISO 27001 certificate together with the statement of applicability and the most recent surveillance audit report, SOC 2 reports where relevant, and every penetration test report from the last two years — including the retest evidence that closed the findings.

Identity, access and endpoints

Request the identity platform configuration, multi-factor authentication coverage figures, the privileged account inventory, joiners-movers-leavers evidence, endpoint protection coverage and patch compliance reporting. Coverage percentages matter more than product names.

Data, privacy and third parties

Ask for the record of processing activities, the data map showing where personal and commercially sensitive data lives, data processing agreements with material suppliers, the supplier register with criticality ratings, and evidence of supplier assurance. Strong vendor management is one of the clearest signals of overall maturity, so third-party exposure deserves real weight in any cyber due diligence.

Resilience and incident history

Request the incident register for at least three years, any breach notifications made to the ICO or affected individuals, backup and restore test evidence, the business continuity and disaster recovery plans, and cyber insurance policies with their claims history and any exclusions.

Evidence requestedWhat it provesRed flag if absent
Backup restore test logRecovery actually worksHigh
MFA coverage reportAccount takeover resistanceHigh
Incident registerHonest history and learningCritical
Penetration test retestFindings were closed, not filedMedium
Record of processingData footprint is understoodHigh
Supplier register with ratingsThird-party exposure is managedMedium
Leaver access removal evidenceAccess control is operationalHigh

Red flags that should reprice or restructure the deal

cyber due diligence mergers acquisitions f vault door on plinth

Not every cyber due diligence finding changes a deal. Experienced buyers separate the routine from the material, and the distinction is usually about whether the finding indicates a systemic failure or an isolated gap.

An incident register that is suspiciously clean

A trading company with a hundred staff and no recorded security incidents in three years has not been lucky; it has not been looking. Absence of detection capability is a finding in its own right, and it means cyber due diligence cannot rule out a live compromise.

Undisclosed incidents surfacing late

If a material incident emerges during management interviews that was not in the data room, the issue is no longer the incident. It is disclosure. That single fact should change the warranty package and, on a private deal, may justify walking.

Single points of failure in people

One contractor holding the only administrative credentials, no documented recovery process, and no second person who understands the environment is a common small-company pattern and a serious one. It converts a technology risk into a retention negotiation.

Flat networks and unsupported systems

A network with no segmentation, or a business-critical application running on an operating system past end of support, tells you both the current exposure and the likely capital requirement. It also directly constrains integration — you cannot safely connect a flat estate to a corporate network on day one.

Certification that does not cover the deal asset

An ISO 27001 scope limited to a head office function, while the acquired platform runs elsewhere, is a presentational control rather than a real one. Reconciling certification scope against the assets the deal is buying is one of the highest-value checks in the whole cyber due diligence exercise.

How deal size and sector change cyber due diligence

Proportionality is the whole game. The same cyber due diligence checklist applied identically to a five-million-pound bolt-on and a two-hundred-million-pound platform acquisition will be wrong in both cases.

Small and lower mid-market deals

Below roughly ten million pounds of enterprise value, cyber due diligence is usually a two-week desktop exercise with interviews and external validation. The realistic goal is to find the deal-breakers and size the remediation, not to achieve assurance. Expect the target to have no dedicated security function at all — that is normal, and the finding is about what compensating arrangements exist.

Mid-market and platform deals

Here the exercise justifies technical validation, a review of the software development lifecycle if the target builds product, and a genuine quantification of remediation. Buyers frequently pair cyber due diligence with a broader technology consulting review because the technology roadmap and the security roadmap are the same document.

Regulated and data-heavy sectors

Healthcare, financial services, legal and education targets carry regulatory obligations that survive the transaction. Cyber due diligence must cover the sector regime as well as general data protection, and the buyer’s own compliance obligations may be triggered by the acquisition itself.

Deal profileTypical scopeEffortMain focus
Small bolt-onDesktop and interviews5-8 daysDeal-breakers and basic hygiene
Mid-market trading businessDesktop, interviews, external scanning10-15 daysRemediation cost and integration risk
Software or platform targetAdds product and code review15-25 daysProduct security and technology debt
Regulated sector targetAdds sector regime review20-30 daysRegulatory exposure and data handling
Carve-out from a groupAdds separation analysis25-40 daysStandalone capability and transition services

Turning cyber due diligence findings into deal terms

A cyber due diligence report that does not reach the lawyers has wasted its budget. Findings translate into four broad mechanisms, and choosing the right one is a commercial judgement rather than a technical one.

Price adjustment

Where remediation cost can be estimated with reasonable confidence — replacing end-of-life hardware, deploying identity controls, buying two years of a managed service — the cleanest treatment is a reduction in consideration. The number is defensible because it is a quotation produced by cyber due diligence, not a probability.

Warranties and disclosure

Cyber-specific warranties should cover compliance with data protection law, absence of unreported material incidents, adequacy of the security control set, and validity of certifications. The value of a warranty lies mostly in the disclosure it forces: a seller who will not warrant an absence of incidents is telling you something.

Specific indemnities

Where a known issue has uncertain cost — a historical breach whose regulatory outcome is unresolved, or a legacy system of unknown exposure — a specific indemnity is the right instrument. Cap it, time-limit it, and define the trigger tightly enough that both sides recognise it when it happens.

Conditions and post-completion covenants

Some findings are better handled as conditions to completion, such as the removal of a specific administrative access path, or as covenants requiring remediation within a defined window after close, backed by retention.

Finding typeCost certaintyBest mechanism
End-of-life infrastructureHighPrice adjustment
Missing identity controlsHighPrice adjustment or covenant
Historical unresolved incidentLowSpecific indemnity
Lapsing certificationMediumCondition to completion
Key-person dependencyMediumRetention and covenant
Live or suspected compromiseUnknownPause, investigate, then reprice

The first 100 days after completion

Completion is when the risk becomes yours, and the hundred-day plan should read as the direct continuation of cyber due diligence rather than a fresh start. The temptation is to connect everything immediately so the synergies begin. Resist it. The most damaging post-acquisition incidents come from rushed network connection between an assured environment and an unassessed one.

Days 1 to 14: contain and see

Take control of privileged access before anything else. Rotate administrative credentials, remove the leaver accounts cyber due diligence identified, and deploy logging so the acquiring group can actually see the new estate. Do not connect the networks yet.

Days 15 to 45: close the critical gaps

Work the remediation plan cyber due diligence produced, in severity order: multi-factor authentication everywhere, endpoint protection coverage to one hundred per cent, patching brought current, backups tested with a real restore. This is also when managed IT services arrangements are usually extended to the acquired entity.

Days 46 to 100: integrate deliberately

Only now should identity federation and controlled network connection happen, segment by segment, with the riskiest legacy systems isolated behind their own controls until they are replaced. Update the group risk register, bring the acquired entity into group incident response and reporting, and confirm insurance covers it.

Where post-completion effort typically goes, by share of the 100-day plan
Identity and access remediation 30%
Monitoring, logging and detection 22%
Patching and end-of-life replacement 20%
Backup and recovery assurance 16%
Policy, training and governance 12%
Indicative allocation for a mid-market integration where diligence found no live compromise.

Who should run cyber due diligence, and what it costs

Buyers have three realistic options for resourcing cyber due diligence, and the right answer depends on deal frequency more than deal size.

The in-house route

An acquirer with its own security function can run cyber due diligence internally, which is cheap and deeply informed by how the group actually operates. The weakness is independence and capacity: the same people are usually running business-as-usual security, and a live deal has no slack.

Specialist advisers

Independent advisers bring pattern recognition from many transactions and a report written in language a deal team recognises. For a first acquisition, or any deal where the technology is the asset, this is normally the right call. Expect a proportionate fee against a defined scope rather than an open-ended engagement.

Blended model

The most effective pattern for serial acquirers is a standing framework — a fixed information request list, an agreed scoring model, and a retained adviser who scales in when a deal moves. It makes cyber due diligence findings comparable between targets, which matters more than any single report.

Budgeting realistically

As a rough planning figure, a proportionate cyber due diligence engagement on a lower mid-market deal sits in the low tens of thousands of pounds, rising with technical validation and regulated-sector scope. Set against a remediation bill that routinely runs several times higher, and against the cost of discovering it after completion, it is one of the better-value workstreams in the process.

Cyber due diligence mistakes that keep repeating

Starting too late

Beginning cyber due diligence after heads of terms are agreed leaves no room to act on the findings. The exercise should start when exclusivity does, so there is still time to reprice.

Accepting documents as evidence

A policy is a statement of intent. Ask for the operational artefact instead — the actual coverage report, the actual restore log, the actual leaver ticket.

Scoping to the target’s org chart

Deals rarely buy a whole company cleanly. Scope to the assets and data being acquired, including anything provided today by a parent group that will disappear at completion.

Producing findings nobody can act on

A severity rating without a cost and a recommendation cannot be negotiated. Every finding needs a number and a proposed mechanism.

Treating completion as the finish line

The report is an input to the integration plan, not an archive document. If the hundred-day plan does not trace directly to the findings, the exercise was ornamental.

Cyber due diligence FAQs

How long does it take?

A proportionate cyber due diligence exercise runs two to four weeks end to end for a mid-market deal, assuming the target responds to the information request promptly. Slow data room responses are the usual cause of delay, and are themselves a mild finding.

Can it be done without alerting the target’s staff?

Largely, yes. Document review, management interviews under NDA and passive external assessment need no wider disclosure. Anything intrusive requires written authorisation and normally involves a small number of named people on the target side.

What if the target refuses to provide evidence?

Refusal is information. Distinguish genuine confidentiality concerns, which can be handled through a clean team or redaction, from evasion. Persistent refusal on incident history or access control evidence should be treated as an adverse cyber due diligence finding and reflected in the warranty package.

Does an ISO 27001 certificate remove the need for it?

No. Certification confirms a management system exists within a declared scope. It says nothing about whether that scope covers the acquired asset, whether controls are effective in practice, or whether an incident has occurred. Read it as a positive signal and a starting point, not a substitute.

Is it different for a share purchase versus an asset purchase?

Yes, materially. A share purchase inherits the legal entity and its history, including regulatory exposure. An asset purchase can leave some liabilities behind, but data transferred as part of the assets still brings obligations, so the data-focused parts of the review remain essential.

Should sellers run it on themselves?

Increasingly, yes. Vendor-side cyber due diligence shortens the buyer’s process, removes surprises that trigger price chips, and lets the seller fix cheap issues on its own timetable rather than under deal pressure.

References