01Why cyber risks determine deal value
When acquiring a company, the buyer takes over its entire IT landscape, data assets and security legacy – including every incident that no one knows about at signing. In a 2019 Forescout survey of 2,779 IT and business decision-makers, 53 percent reported having encountered a critical cybersecurity issue during an M&A deal that put the transaction at risk; 73 percent considered an undisclosed data breach an immediate dealbreaker. Traditional financial and legal due diligence does not make these risks visible – they require a dedicated, technically grounded assessment.
02Undetected compromise: the Marriott/Starwood case
The single biggest risk is an attacker who is already inside the target company's network at the time of the acquisition. In 2016, Marriott acquired the Starwood hotel chain, whose systems had been compromised since 2014; the attack was not discovered until September 2018, affecting around 339 million guest records worldwide. In 2020, the UK data protection authority ICO imposed a fine of £18.4 million – relating to security failures after the GDPR took effect, i.e. long after closing. The compromise itself was something Marriott had unknowingly acquired along with the deal.
03Technical debt, compliance gaps and IP exfiltration
Beyond active attackers, three further risk classes shape the picture. First, technical debt: systems without vendor support, unpatched infrastructure, historically grown permissions and undocumented shadow IT – remediation the buyer pays for after closing. Second, compliance gaps: obligations under the GDPR, NIS2, sector-specific frameworks such as DORA or product-related requirements such as the Cyber Resilience Act effectively transfer to the acquirer – as do ongoing or impending proceedings. Third, the exfiltration of intellectual property: if the target's core value – source code, engineering data, customer lists – has already been exfiltrated before the deal, the valuation basis of the transaction is damaged.
04Assessment scope under time pressure: the outside view via EASM
Due diligence takes place under confidentiality and time pressure – often initially without any access to the target's systems. External Attack Surface Management (EASM) addresses exactly this: domains, exposed services, outdated software versions, misconfigurations and leaked credentials of the target company are gathered from publicly observable sources – without its involvement and without touching its systems. Complemented by a check against dark web and leak sources, this yields an early indicator of the actual security posture that is available even before access to the data room and sets the priorities for the further assessment.
05Inside view: compromise assessment, ISMS maturity, interviews
Once access is granted, two questions matter: is the target already compromised, and how robust is its security organisation? A compromise assessment forensically searches for traces of active or past attacks – persistence mechanisms, suspicious accounts, known attack tools – and thus addresses exactly the Marriott scenario. In parallel, the maturity of the ISMS is benchmarked against ISO/IEC 27001:2022: through structured questionnaires, document review and interviews with key roles. Existing certificates are an indication, not proof – the scope and reliability of the audits must be verified.
06Purchase price, warranties and post-merger integration
Solid findings translate directly into transaction mechanics. When Yahoo had to disclose two data breaches in 2016 affecting around 500 million and more than one billion accounts respectively, Verizon and Yahoo reduced the purchase price by US$350 million to around US$4.48 billion in February 2017 – and additionally agreed to share certain liability risks arising from the incidents. In the same way, findings can be secured through warranties, indemnities, escrow holdbacks or conditions precedent. After closing, the rule is: no network interconnection before the assessment is complete – identities, privileged access and monitoring are consolidated first, and the remediation of legacy issues follows a prioritised integration plan.