Book an Appointment

Security Due Diligence in Corporate Acquisitions

How to reliably assess the cyber security posture of an acquisition target under time pressure – and what the findings mean for purchase price, warranties and integration.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

53%of decision-makers encountered a deal-threatening cybersecurity issue during M&A (Forescout, 2019)
73%considered an undisclosed data breach an immediate dealbreaker
~339 millionguest records affected worldwide — a compromise Marriott unknowingly acquired with Starwood
350 millionUS dollars off the purchase price — agreed by Verizon and Yahoo in February 2017

In an acquisition, it is not only assets and contracts that change hands, but also every undetected compromise, every piece of technical legacy and every compliance gap of the target company. Traditional financial and legal due diligence largely ignores this dimension, even though documented cases such as Yahoo/Verizon and Marriott/Starwood show that cyber incidents directly affect purchase prices, warranties and integration costs. Security due diligence therefore assesses the target's security posture systematically – from the external view without any system access to the forensic inside view. This article puts risks, assessment methods and contractual consequences into perspective.

The Essentials at a Glance

Six topic blocks — tap to expand.

Assessment methods at a glance

From the external view without system access to the forensic inside view — tap a method.

no system access
  • Domains, exposed services, outdated software versions, misconfigurations and leaked credentials are gathered from publicly observable sources — without the target's involvement and without touching its systems.
  • Complemented by a check against dark web and leak sources, this yields an early indicator of the actual security posture — available even before access to the data room.
  • The results set the priorities for the further assessment.
DomainsExposed servicesOutdated software versionsMisconfigurationsLeaked credentialsDark web check

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

TechCrunch · 2017

After data breaches, Verizon knocks $350M off Yahoo sale, now valued at $4.48B

Report on the contract amendment of 21 February 2017: purchase price reduction of US$350 million to US$4.48 billion and sharing of certain breach liability risks between Verizon and Yahoo.

Information Commissioner's Office (ICO) · 2020

ICO fines Marriott International Inc £18.4million for failing to keep customers' personal data secure

Press release by the UK data protection authority of 30 October 2020: attack on Starwood in 2014, undetected until September 2018 – by which time Starwood had already been acquired by Marriott – affecting around 339 million guest records worldwide.

Forescout Technologies · 2019

The Role of Cybersecurity in M&A Diligence

Survey of 2,779 IT and business decision-makers in seven countries: 53% experienced a deal-threatening cybersecurity issue during a transaction, 73% consider an undisclosed breach a dealbreaker.

ISO/IEC · 2022

ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection – Information security management systems – Requirements

Current version of the ISMS standard (incl. Amd 1:2024); serves in due diligence as the reference framework for assessing the maturity of the target's security organisation.

Need to assess an acquisition target at short notice?

We assess target companies from the outside via EASM and from the inside via compromise assessment and ISMS review – with results that hold up in negotiations and contract drafting. Contact us for a no-obligation initial consultation.