When acquiring a company, the buyer takes over its entire IT landscape, data assets and security legacy – including every incident that no one knows about at signing. In a 2019 Forescout survey of 2,779 IT and business decision-makers, 53 percent reported having encountered a critical cybersecurity issue during an M&A deal that put the transaction at risk; 73 percent considered an undisclosed data breach an immediate dealbreaker. Traditional financial and legal due diligence does not make these risks visible – they require a dedicated, technically grounded assessment.
Security Due Diligence in Corporate Acquisitions
How to reliably assess the cyber security posture of an acquisition target under time pressure – and what the findings mean for purchase price, warranties and integration.
53%of decision-makers encountered a deal-threatening cybersecurity issue during M&A (Forescout, 2019)
73%considered an undisclosed data breach an immediate dealbreaker
~339 millionguest records affected worldwide — a compromise Marriott unknowingly acquired with Starwood
350 millionUS dollars off the purchase price — agreed by Verizon and Yahoo in February 2017
In an acquisition, it is not only assets and contracts that change hands, but also every undetected compromise, every piece of technical legacy and every compliance gap of the target company. Traditional financial and legal due diligence largely ignores this dimension, even though documented cases such as Yahoo/Verizon and Marriott/Starwood show that cyber incidents directly affect purchase prices, warranties and integration costs. Security due diligence therefore assesses the target's security posture systematically – from the external view without any system access to the forensic inside view. This article puts risks, assessment methods and contractual consequences into perspective.
The Essentials at a Glance
Six topic blocks — tap to expand.
Assessment methods at a glance
From the external view without system access to the forensic inside view — tap a method.
- Domains, exposed services, outdated software versions, misconfigurations and leaked credentials are gathered from publicly observable sources — without the target's involvement and without touching its systems.
- Complemented by a check against dark web and leak sources, this yields an early indicator of the actual security posture — available even before access to the data room.
- The results set the priorities for the further assessment.
DomainsExposed servicesOutdated software versionsMisconfigurationsLeaked credentialsDark web check
- Forensically searches for traces of active or past attacks — persistence mechanisms, suspicious accounts, known attack tools.
- Addresses exactly the Marriott scenario: is the target already compromised?
Persistence mechanismsSuspicious accountsKnown attack tools
- The maturity of the ISMS is benchmarked against ISO/IEC 27001:2022 — through structured questionnaires, document review and interviews with key roles.
- Existing certificates are an indication, not proof: the scope and reliability of the audits must be verified.
Structured questionnairesDocument reviewInterviewsKey rolesCertificates
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
After data breaches, Verizon knocks $350M off Yahoo sale, now valued at $4.48B
Report on the contract amendment of 21 February 2017: purchase price reduction of US$350 million to US$4.48 billion and sharing of certain breach liability risks between Verizon and Yahoo.
ICO fines Marriott International Inc £18.4million for failing to keep customers' personal data secure
Press release by the UK data protection authority of 30 October 2020: attack on Starwood in 2014, undetected until September 2018 – by which time Starwood had already been acquired by Marriott – affecting around 339 million guest records worldwide.
The Role of Cybersecurity in M&A Diligence
Survey of 2,779 IT and business decision-makers in seven countries: 53% experienced a deal-threatening cybersecurity issue during a transaction, 73% consider an undisclosed breach a dealbreaker.
ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection – Information security management systems – Requirements
Current version of the ISMS standard (incl. Amd 1:2024); serves in due diligence as the reference framework for assessing the maturity of the target's security organisation.
Need to assess an acquisition target at short notice?
We assess target companies from the outside via EASM and from the inside via compromise assessment and ISMS review – with results that hold up in negotiations and contract drafting. Contact us for a no-obligation initial consultation.