Book an Appointment

Security Due Diligence in Corporate Acquisitions

How to reliably assess the cyber security posture of an acquisition target under time pressure – and what the findings mean for purchase price, warranties and integration.

In an acquisition, it is not only assets and contracts that change hands, but also every undetected compromise, every piece of technical legacy and every compliance gap of the target company. Traditional financial and legal due diligence largely ignores this dimension, even though documented cases such as Yahoo/Verizon and Marriott/Starwood show that cyber incidents directly affect purchase prices, warranties and integration costs. Security due diligence therefore assesses the target's security posture systematically – from the external view without any system access to the forensic inside view. This article puts risks, assessment methods and contractual consequences into perspective.

The Essentials at a Glance

01

Why cyber risks determine deal value

When acquiring a company, the buyer takes over its entire IT landscape, data assets and security legacy – including every incident that no one knows about at signing. In a 2019 Forescout survey of 2,779 IT and business decision-makers, 53 percent reported having encountered a critical cybersecurity issue during an M&A deal that put the transaction at risk; 73 percent considered an undisclosed data breach an immediate dealbreaker. Traditional financial and legal due diligence does not make these risks visible – they require a dedicated, technically grounded assessment.

02

Undetected compromise: the Marriott/Starwood case

The single biggest risk is an attacker who is already inside the target company's network at the time of the acquisition. In 2016, Marriott acquired the Starwood hotel chain, whose systems had been compromised since 2014; the attack was not discovered until September 2018, affecting around 339 million guest records worldwide. In 2020, the UK data protection authority ICO imposed a fine of £18.4 million – relating to security failures after the GDPR took effect, i.e. long after closing. The compromise itself was something Marriott had unknowingly acquired along with the deal.

03

Technical debt, compliance gaps and IP exfiltration

Beyond active attackers, three further risk classes shape the picture. First, technical debt: systems without vendor support, unpatched infrastructure, historically grown permissions and undocumented shadow IT – remediation the buyer pays for after closing. Second, compliance gaps: obligations under the GDPR, NIS2, sector-specific frameworks such as DORA or product-related requirements such as the Cyber Resilience Act effectively transfer to the acquirer – as do ongoing or impending proceedings. Third, the exfiltration of intellectual property: if the target's core value – source code, engineering data, customer lists – has already been exfiltrated before the deal, the valuation basis of the transaction is damaged.

04

Assessment scope under time pressure: the outside view via EASM

Due diligence takes place under confidentiality and time pressure – often initially without any access to the target's systems. External Attack Surface Management (EASM) addresses exactly this: domains, exposed services, outdated software versions, misconfigurations and leaked credentials of the target company are gathered from publicly observable sources – without its involvement and without touching its systems. Complemented by a check against dark web and leak sources, this yields an early indicator of the actual security posture that is available even before access to the data room and sets the priorities for the further assessment.

05

Inside view: compromise assessment, ISMS maturity, interviews

Once access is granted, two questions matter: is the target already compromised, and how robust is its security organisation? A compromise assessment forensically searches for traces of active or past attacks – persistence mechanisms, suspicious accounts, known attack tools – and thus addresses exactly the Marriott scenario. In parallel, the maturity of the ISMS is benchmarked against ISO/IEC 27001:2022: through structured questionnaires, document review and interviews with key roles. Existing certificates are an indication, not proof – the scope and reliability of the audits must be verified.

06

Purchase price, warranties and post-merger integration

Solid findings translate directly into transaction mechanics. When Yahoo had to disclose two data breaches in 2016 affecting around 500 million and more than one billion accounts respectively, Verizon and Yahoo reduced the purchase price by US$350 million to around US$4.48 billion in February 2017 – and additionally agreed to share certain liability risks arising from the incidents. In the same way, findings can be secured through warranties, indemnities, escrow holdbacks or conditions precedent. After closing, the rule is: no network interconnection before the assessment is complete – identities, privileged access and monitoring are consolidated first, and the remediation of legacy issues follows a prioritised integration plan.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

TechCrunch · 2017

After data breaches, Verizon knocks $350M off Yahoo sale, now valued at $4.48B

Report on the contract amendment of 21 February 2017: purchase price reduction of US$350 million to US$4.48 billion and sharing of certain breach liability risks between Verizon and Yahoo.

Information Commissioner's Office (ICO) · 2020

ICO fines Marriott International Inc £18.4million for failing to keep customers' personal data secure

Press release by the UK data protection authority of 30 October 2020: attack on Starwood in 2014, undetected until September 2018 – by which time Starwood had already been acquired by Marriott – affecting around 339 million guest records worldwide.

Forescout Technologies · 2019

The Role of Cybersecurity in M&A Diligence

Survey of 2,779 IT and business decision-makers in seven countries: 53% experienced a deal-threatening cybersecurity issue during a transaction, 73% consider an undisclosed breach a dealbreaker.

ISO/IEC · 2022

ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection – Information security management systems – Requirements

Current version of the ISMS standard (incl. Amd 1:2024); serves in due diligence as the reference framework for assessing the maturity of the target's security organisation.

Need to assess an acquisition target at short notice?

We assess target companies from the outside via EASM and from the inside via compromise assessment and ISMS review – with results that hold up in negotiations and contract drafting. Contact us for a no-obligation initial consultation.