M&A security is a discipline that involves the assessment and management of the cyber risk of the target company prior to, during, and after an acquisition. When you purchase a company, you are buying in its flaws, its liabilities, and its adversaries. Strong M&A security can help identify those risks, and you would not have to deal with them if you decide you’ll walk away, demand fixes, or renegotiate the price.
Key Takeaways
- Verizon also eliminated $350 million from the Yahoo acquisition after two undisclosed issues came to light during the deal.
- Eight out of every ten dealmakers discover cybersecurity problems during at least 25% of their target sales.
- Over half of the participants have hit a cyber issue that put a deal in jeopardy.
- Regulators are held accountable to the acquirer for inherited violations even if they occurred prior to the acquisition.
- The best time to begin cybersecurity M&A is prior to the opening of the data room, not after signing.
Introduction
Verizon agreed to acquire Yahoo’s “core business” in 2017 for $4.48 billion. Later in the due diligence process, two additional leaks came to light. All 3 billion Yahoo accounts were impacted; it was the largest data breach in history. The response was swift, harsh, and to the extent of Verizon cutting the deal by $350 million, about 7% of the price (Reuters, via Cybri).
The story didn’t come to a stop at closing time. Yahoo was fined $35 million by the SEC for omitting to reveal the shortcomings. This was followed by an $80 million securities class action. Verizon had to shoulder the legal obligation, the cleanup bill, and the lost reputation for events that transpired years before it inked the deal. The principle of M&A security is at its heart. If you don’t know what you are purchasing from a security perspective, you don’t really know what it is you are purchasing.
This guide takes you on a journey through cybersecurity M&A as it really happens. Not as a checklist – and not as a separate checklist, but on a stage-by-stage basis, before the letter of intent, while undergoing diligence, at close range, and after integration. As you make your way through the book, real-life examples reveal what can go wrong and what can keep the deal safe. Written for the deal team, CISOs, private equity operators, and founders getting ready to sell.
Why M&A Security Can No Longer Be an Afterthought
For years, cybersecurity M&A activity has followed due diligence as an afterthought in the IT realm. They tested it using the tools that are used to check server inventories or software licensing. It’s not enough for a modern business that relies on data and connected systems for its value. The figures are clear evidence.
According to PwC (via Cybri), over 24 months, 80% of the global dealmakers detected cybersecurity problems in at least one-fourth of the targets. More than half of the M&A participants identified critical cyber risks that jeopardized deals in the Forescout survey. Similarly, 73% in the same research indicated that if a brand is not transparent about the breach, it is a deal-breaker to them.
It is a pressure that is very real. According to a FTI Consulting study released today, one in four CISOs noted that leadership is eager to close deals, rather than complete a comprehensive M&A cybersecurity assessment (FTI Consulting via Clearwater). That’s what the Yahoo case should cure. Typical data breaches cost $4.88 million to remediate, before fines, legal costs, or lost trust.
What You Actually Inherit in an Acquisition
The most important concept of M&A security is inheritance. At closing time, all of the target’s risks transfer to you. Regulators are not concerned with whether or not a breach occurred before or after the acquisition. It’s all the responsibility of the new owner. It’s automatic, and it is unforgiving.
Think about what it is that you’re transferring on Day One. You are inheriting undiscovered holes and any attackers remaining in the network. You are subject to regulatory liability under GDPR, CCPA, and HIPAA, but not the data collector. Breach notification timers kick in when you discover them, not when the incident occurred. You inherit technical debt, legacy systems, and every vendor relationship the target signed.
The Marriott-Starwood Case: Inheriting a Live Intruder
Starwood Hotels was acquired by Marriott in 2016 for a total of $13.3 billion. What it didn’t know, however, was that attackers had been inside Starwood’s reservation system since 2014 (ICO, via Auth0). The leak wasn’t found until 2018, after the dam had been closed for two years. By then, it had exposed some 339 million guest records, including 5.25 million unencrypted passport numbers.
The key point: It is important to remember that the leak wasn’t from Marriott’s systems. It was acquired along with the purchase. Marriott wasn’t the only one to receive the legacy of Starwood’s hotels and its loyalty program; it has also received the intruders already in place in its loyalty program. The ICO has given Britain a £18.4m fine, and specifically cited the lack of proper due diligence during a corporate acquisition. Additionally, Marriott entered into a 20-year FTC information-security program. Here’s what unrecognized inherited risk will look like.
M&A Security Across the Deal Lifecycle
The ideal approach to cybersecurity M&A is to tie it into the deal calendar. The aim of each phase is different, the access is different, and the window of leverage is different. If you miss the window, your choices dwindle quickly. The following table outlines the four phases in order, which we will follow; before we get to the work, we will discuss them briefly. We will discuss the four phases briefly below the table, before we get to the work.
| Phase | Primary Goal | Security Focus |
| Before LOI | Understand inherent risk before committing | Passive, no-touch reconnaissance; public exposure |
| Due Diligence | Price the risk accurately or walk away | Documentation review, penetration testing, compromise assessment |
| Signing to Close | Stabilize and protect the deal | Identity lockdown, access control, deal-room security |
| Post-Close Integration | Merge safely without new exposure | Policy harmonization, credential cleanup, monitoring |
Phase 1: Before the Letter of Intent
The first period is the silent period. Typically, there is no inside access, and hence no-touch, passive security is used for M&A security here. The aim is a preliminary assessment of the “inherent risk” before you invest real money or effort. There is a lot of information to be gleaned, even by just looking at it from the outside.
In the case of external reconnaissance, it can help you to find exposed services, leaked credentials on the dark web, and the public data breach history of the target. Threat-intelligence sources indicate whether the company’s data is already being traded. This does not involve any cooperation from the target. It provides an early warning: Does this company demonstrate security maturity, or does it accumulate unknown risks?
Access is a risk, and this is an important phase. Once the data room opens, the exposure starts. It first allows you to create the deal structure and diligence plan without getting locked into them. You must make security a core part of the deal thesis, rather than treating it as an appendage after signing the term sheet.
Phase 2: Cybersecurity Due Diligence
At the core of any M&A security assessment. Once it is in, the objective is to find solid proof instead of signals. You’re attempting to price the risk correctly, or try to leverage a renegotiation, or to figure out if you should walk away. This work has three layers: documentation, validation, and compromise assessment.
Layer 1: Documentation Review
Begin with what the target can demonstrate to you on paper. Analyze security policies, audit reports, incidents, and compliance artifacts. The goal is to distinguish between ‘real controls’ and ‘paper policies. No matter how well you’ve written your MFA policy, if it is not followed, it isn’t worth anything. Request evidence of operations: security alerts, support tickets, audit trails, and system metrics to verify that the controls are operating.
One of the major red flags is when a target is unable to answer the fundamental question about its environment. Failure to know where sensitive information is actually residing is a finding by itself if the leader(s) do not know. But even if you face no material breaches, attackers trade compromised credentials on the dark web, and cybercriminals target executives’ inboxes daily. Don’t take his word for it; ask for proof. A written assurance is not as convincing as a dashboard or report.
Layer 2: Technical Validation
Documentation speaks to the target’s self-perception. Technical validation is telling you the truth. That’s where penetration testing, architecture review, configuration analysis, and vulnerability assessment come into play. They test the assets that have an actual impact on valuation and integration risk.
A penetration test is a practical demonstration of a risk. Assume a compromise around a laptop is followed by four steps to a production database by an attacker. An abstract worry turns into a rated, documented discovery with a remediation expense recognized. That’s the sort of proof that will work in a price negotiation. Aspirational representations in the data room (representations that do not necessarily reflect accuracy or truth, but rather those that teams can test against reality to verify).
Layer 3: Compromise Assessment
This layer is necessary because of the Marriott case. A target may be able to pass through a posture review while an attacker quietly lurks inside its network. Compromise assessment specifically seeks out the following: current or past evidence of intrusion, unusual dwell, evidence of an active adversary. Posture review: Check doors for locking. The question of compromise assessment is, “Is there anyone already in the house?
In this step, the difficulty is getting access. The deployment of a monitoring platform for 6 months cannot be done on a deal timeline. The targets are also quite sensitive about going deep into a competitive process. Teams typically solve this using lightweight, containerized scanning on the local device, ensuring no data ever leaves the target’s network. The objective is to achieve a clear view prior to signing, not to see clearly. The objective is not to see clearly, but to see clearly before signing. It is sufficiently visible for them to cost it, or to move on if the exposure is not acceptable.
The Questions That Actually Matter
One of the most common questions that deal teams have is what to offer the target. Below you will find the questions that will determine the difference between a Security Maturity and a good compliance paper. Each of these groups is assigned according to what it shows. The nuts and bolts of any M&A cybersecurity assessment.
1. On Risk Governance
- How do you discover, value, and claim cyber risks? Do you maintain a risk register over time, or do you manage risks on an ad hoc basis?
- Do you carry out formal cyber risk assessments regularly, and what changed as a result of your last assessment?
- To whom does the Security function report, and does the board discuss Cyber Risk?
2. On Incident History
- What was the experience with security incidents in the last three years, in terms of incident number, response time, and remediation costs?
- If there was a breach, has the vulnerability been resolved or contained?
- What are the documented procedures for breaking the bad news of a breach, and have they been tested?
3. On Operational Maturity
- What detection and response capabilities do endpoint, network, and email threats fall under?
- Is MFA enforced across the board, including with executive email and privileged accounts?
- What percentage of the IT budget is spent on security, and is it increasing?
4. On Third-Party and Supply-Chain Risk
- 62% of breaches are from third parties – how are vendors evaluated before they are onboarded?
- Are there breach-notification timelines, audit rights, and data-protection obligations outlined in vendor contracts?
- What does the target track do to open source and ensure its CI/CD pipeline?
Weighing a deal and unsure what the target is really carrying? Now Qualysec is a CREST-accredited Penetration Testing company that transforms a targeted company’s security assertions into substantiating actual evidence. You receive an attack-path proof, attack severity, and remediation costs for direct use in a price negotiation. Talk to Qualysec about M&A security due diligence.
Turning Findings Into Deal Leverage
Diligence findings are only of benefit if they have an impact on the deal. This is where M&A security is not just a tech thing, but a commercial one. Prior to close, findings emerged giving the buyer leverage. That leverage is gone when it comes to close, and costs go up. It’s a lot more valuable the day before than the day after.
Four principal ways of responding to what diligence finds. They each correspond to different levels of discovery.
| Lever | When to Use It |
| Price adjustment | Quantifiable remediation cost or inherited liability; reduce the purchase price to match, as Verizon did |
| Indemnification clauses | Undisclosed or uncertain liabilities: hold the seller financially responsible for issues that surface later |
| Conditions precedent | Fixable critical issues require specific remediation before the deal can close |
| Walk away | Exposure that cannot be priced or fixed; the deal destroys more value than it creates |
Cybersecurity M&A is a two-way street. There is a flip side for sellers. A target with strong, evidenced security can command a clean report and a higher valuation. A seller who performs the assessment prior to listing can make the necessary repairs quietly and on their own schedule. That’s better than having the buyer find them at the last minute. Security maturity is becoming more than a risk to be managed; it’s now a value driver in cybersecurity M&A.
Phase 3: From Signing to Close
Signing to close represents a very risky period in M&A transactions, which explains why experts do not cite it as a common point of concern. The deal is open or semi-open. Enemies are aware of it. They go from offensive mass attacks to a more targeted approach during high-profile corporate events, targeting specific individuals involved in the transaction.
At this time, a hacked executive inbox can result in wire fraud, deal terms leakage, or even regulatory inquisition. The Asco case bears witness to this. But the Belgian aerospace company fell victim to ransomware during the negotiations. This caused the closure of factories in four countries and temporarily interrupted the transaction. The usual polite treatment of a cyber incident when a deal is ongoing does not apply. It corrupts the data room and gives the other party an advantage at the last moment.
It’s easy to stabilize practically during this window, but necessary. Implement MFA for all data and restrict privileged access. Securing the executives and deal-team members who are now targets for business – right on their mobile devices and home networks. Ensure all parties with access to deal-sensitive systems are properly credentialed and de-provision those access credentials on a formal basis when the party no longer needs them. The data room is not simply a file-storing area; it is an asset that must be safeguarded.
Phase 4: Post-Close Integration
A time of risk is when integration is at its highest. Two sets of networks, identities, and tools link, and gaps that were acceptable on their own can now become tangible. Cybersecurity isn’t just a close-range affair – it gets serious closer. That’s where a lot of the theoretical risks that you see in due diligence become real exposure.
An organized integration plan deals with multiple items simultaneously. Synchronize security policies, tools, and protocols between both entities. Revalidate all user permissions and delete out-of-date or duplicate accounts. Rotate the target’s credentials and keys. Extend endpoint detection and response coverage to virtually all endpoints across the estate. Roll out threat detection fine-tuned for the integration period, when unusual activity across environments is not unusual and is dangerous.
This is the same as the Marriott lesson. Teams took two years to find the breach. Marriott had not yet ported Starwood’s reservation system. Slow integration will prolong the number of years that inherited weaknesses are alive. Good governance is also a requirement: define the governance structure, the owner of security for the combined organisation, and put that into the deal from the beginning.
How M&A Security Plays Out by Industry
Security requirements and details vary significantly across industries. The following are some industry snapshots of what deal teams should be looking out for in each.
Financial Services
Bank M&A is at an all-time high, and regulators are paying special attention to technical checks. The problem here is to join a facility that has good compliance documentation but poor security. A small bank that has made a simple evaluation could be more mature than a large bank with complex frameworks that it does not execute. Diligence should be applied to see if no controls are running, but if there are. The responsibilities of GLBA requirements pass with the sale.
Healthcare and MedTech
Healthcare targets possess guarded healthcare data, and a violation results in HIPAA fines, lawsuits, and lost patient trust. Teams typically make this mistake. Strong HIPAA controls might protect clinical systems, while employees store PHI all over email archives and shared drives. Private equity physician practice roll-ups are particularly vulnerable because legacy systems are often full of undocumented PHI. A three-year-old “post-close” breach triggers a 72-hour notification clock, even if the three-year period has elapsed.
SaaS and Technology
Teams measure the value of technology by its code, its data, and increasingly, its AI footprint. You should take this newer risk into consideration. Any AI system that has access to customer information or financial systems without permission is a liability, not a feature. Now is the time to inventory the AI tools teams are using and the AI they are building into the target’s own products. You should also include any models you deem to be valuable and proprietary IP. Auditors frequently detect SaaS sprawl and inconsistent MFA coverage.
Manufacturing and Industrial
Manufacturing targets include a mix of IT and operational technology, and often, it’s much less developed. In the Asco incident, a ransomware attack paralyzed operations across a series of states in the middle of the transaction. The attack highlighted how ransomware can paralyze physical production across multiple countries during a deal. Because legacy industrial systems typically don’t support modern security controls, you need to account for them when evaluating and integrating systems. You also inherit additional risk from supply chain dependencies.
Frameworks That Make Diligence Repeatable
Using a recognized framework enhances cybersecurity assessment for an M&A transaction, providing a common language for both technical and business teams. There are three of them that are important to know. The key principles of the NIST Cybersecurity Framework are: Govern, Identify, Protect, Detect, Respond, and Recover. This structure allows remediation to be expressed in a quantitative manner – in time, cost, and priority. Objectively demonstrating process maturity, ISO/IEC 27001:2022 certification can speed up diligence and integration.
Supply-chain guidance can help with targets in complex vendor ecosystems. NIST SP 800-161 covers threats from technology vendors and foreign ownership or control. It doesn’t matter which framework you choose: Structure, repeat, and make the assessment readable for the security team and the deal team. A common model is the key to turning a technical discovery into a business decision.
Conclusion: Price What You Can See
All acquisitions now become a cybersecurity choice. A modern enterprise’s worth is in its data, systems, and connections. All three have transfer risk, which starts Day One. These Yahoo and Marriott cases are no longer “edge” cases. Directors share these usual warning stories in every boardroom where teams consider a deal.
A robust M&A security program follows the deal. This requires passive discovery prior to the LOI, thorough validation during diligence, stabilization prior to closing, and disciplined integration thereafter. It turns hidden liabilities into priced and negotiable facts. The price of a comprehensive evaluation is insignificant. An isolated flaw in one’s genes requires a much greater amount for repair, fines, legal liability, and reputation loss.
The deals are growing larger, and the threats are coming at a brisk pace. What you don’t know is closing in on you at a quarterly pace. Can’t see, don’t price, can’t protect. Its discipline is easy to explain: Scan Before Sign, Validate Before Value, and Secure Before Integrate.
Protect your next deal from inherited cyber risk. Qualysec provides M&A penetration testing and security assessment with attack-path evidence, materiality-mapped findings, and remediation estimates to buyers and sellers. Contact Qualysec to request an M&A security assessment today.
Frequently Asked Questions
Q.What is M&A security?
M&A security is the process of determining and mitigating the target company’s cyber risk during the acquisition process. It includes discovering hidden vulnerabilities, lax controls, and regulatory risks that the seller can pass on to the buyer. If done properly, it safeguards the worth of deals and keeps you from inheriting an energetic security issue.
Q.What is cybersecurity due diligence in M&A?
It’s a systematic effort to see what security posture, security controls, and incident history exist in the target prior to signing or closing. Cybersecurity due diligence involves documentation, penetration testing of controls, and active compromise evidence. The objective is to value risk fairly or to exit simply.
Q.When should the cybersecurity M&A assessment start?
At the very least, you should perform passive reconnaissance prior to the letter of intent, and definitely before the target opens the data room. Once they give access, your exposure starts. A timely M&A cybersecurity assessment will provide buyers with the greatest leverage to negotiate a price, request fixes, or restructure.
Q.Who is liable for a breach that happened before the acquisition?
The acquirer. A breach before the deal does not matter; the new owner is responsible for it. GDPR, CCPA, and HIPAA requirements are not tied to the data’s originator. If the breach at Marriott is any indication, then this is why the breach of Starwood Hotels became Marriott’s issue.
Q.How can a cyber issue affect deal value?
It can reduce the price, as when Verizon cut $350 million from Yahoo. Can invoke indemnification, conditions precedent, or walk away. The number of dealmakers who have encountered a cyber issue that threatened a deal is more than 50%, indicating that it’s not unusual.
Q.Is a penetration test the same as cybersecurity due diligence?
No. One type of due diligence is a penetration test. It verifies the security assertions of a target in a real attack scenario. A comprehensive M&A cybersecurity assessment also involves documentation review, compromise assessment, vendor risk assessment, and compliance evaluation.
Q.How long does M&A cybersecurity due diligence take?
It will be dependent on the scope and complexity of the target. Typically, the longest variable is the one related to low-friction access and deployment of monitoring. After determining that a good view is possible, teams require a few weeks. They analyze, validate, and document findings so negotiators and integration planners can use them.
Q.What happens if you skip cybersecurity due diligence?
You get what you seek: active intruders, concealed gaps, regulatory non-compliance, and remediation expenses. Only about 40% of acquirers find cyber issues before integration starts, after they have secured leverage and maximized costs. The Yahoo and Marriott cases reveal just how much that exposure was.






