Cyber Due Diligence in M&A: Assessing Security Risk Before You Buy It
Acquirers model revenue, churn and tax exposure in detail, then inherit a compromised identity estate they never examined. Cyber due diligence is the cheapest line item in the deal.
In an acquisition, the financial model is examined line by line, the customer contracts are read twice, and the tax structure is stress-tested by specialists. The target's security posture is frequently covered by a questionnaire the seller completed themselves.
The asymmetry is hard to defend. An acquirer inherits not only a target's systems but its breach history, its data liabilities, and — on the day networks are joined — its compromises. Cyber due diligence is a small, time-boxed piece of work that routinely changes deal terms.
What cyber due diligence actually covers
| Area | What is examined | Deal consequence |
|---|---|---|
| External attack surface | Internet-facing systems, exposed services, expired certificates, leaked credentials | Immediate risk; often visible before access is granted |
| Identity architecture | Privileged accounts, MFA coverage, shared credentials, trust relationships | Day-one integration risk and remediation cost |
| Cloud posture | IAM breadth, public data stores, logging coverage, tenancy separation | Frequently the largest single finding category |
| Incident history | Past breaches, notifications made, regulatory correspondence | Warranties, indemnities, disclosure obligations |
| Data liability | What personal data is held, on what basis, with what retention | Regulatory exposure transferred with the asset |
| Security debt | Unsupported platforms, absent patching, undocumented custom systems | Capital expenditure the model did not include |
| Third-party risk | Vendor access, unmanaged integrations, expiring dependencies | Inherited supply chain exposure |
The three phases that fit a deal timetable
Phase 1 — Outside-in, before access
Everything observable without cooperation: exposed infrastructure, technology fingerprinting, credential exposure in public breach corpora, certificate and DNS hygiene, and public evidence of past incidents. This can run during early diligence and frequently produces the first material question to put to management.
Phase 2 — Inside-out, during confirmatory diligence
With access granted: identity and privilege review, cloud configuration assessment, logging and detection coverage, patch and lifecycle status of critical systems, and interviews with whoever actually operates security — often one overworked engineer rather than a function.
Phase 3 — Costing and integration planning
The output that matters commercially: what must be fixed before integration, what can wait, and what each item costs in money and elapsed time. This is what turns a risk register into a negotiating position.
What we find most often in mid-market targets
- Shared and orphaned privileged accounts. Administrator credentials known to former staff, service accounts with passwords set years ago and never rotated.
- Cloud identity sprawl. Roles granted broadly during a migration and never narrowed, plus long-lived access keys in developer hands.
- Logging that cannot answer questions. Logs exist for cost reasons, not investigative ones — so the question "were we already breached?" is unanswerable.
- Undocumented custom systems maintained by one person, with no source control history and no security review in their lifetime.
- Personal data held without a defensible basis — old marketing databases, exported customer lists, historical support attachments.
- Deep trust relationships with the seller's parent estate, which turn "separation" from a formality into a project with its own budget.
How findings translate into deal mechanics
Cyber findings rarely kill a transaction. They adjust it. A material remediation programme becomes a price adjustment or an escrow. Evidence of an undisclosed incident becomes a specific indemnity rather than a general warranty. Identity separation complexity becomes a revised integration timeline — and revised synergy assumptions. Data held without lawful basis becomes a pre-closing condition. In each case the value of diligence is not the discovery itself but the fact that it arrived before signature rather than after.
Day one and the first hundred days
The riskiest moment in any acquisition is network integration, because it merges two risk postures into one. A defensible sequence: establish independent logging over the acquired estate before joining anything; remove shared and orphaned privileged accounts; enforce multi-factor authentication on all administrative and remote access; federate identity rather than flattening domains; and only then begin connecting environments, in the order the remediation plan specified.
Organisations that skip this sequence learn its value the hard way, usually within the first quarter, when an intrusion that existed in the target before the deal reaches the acquirer's core systems through a trust relationship created for convenience.
Assessing a target before you own its risk
Cyber due diligence is one of the few diligence workstreams that regularly pays for itself several times over in a single negotiation — and one of the few whose absence is only discovered after completion.
Kinematic Digital runs independent security assessments for mid-market and enterprise organisations — scoped in days, delivered with prioritised remediation plans your engineers can actually execute, not a PDF of raw scanner output. See our cybersecurity services and preemptive security programme, or book a scoping call.
Frequently Asked Questions
What is cyber due diligence in an acquisition?
A technical and governance assessment of a target company's security posture, breach history, data liabilities and remediation cost, conducted before a transaction closes so that findings can affect price, warranties or integration planning.
Why is standard IT due diligence not enough?
Standard IT due diligence reviews contracts, licences and headcount. It rarely examines identity architecture, cloud permissions, undisclosed incidents, unpatched internet-facing systems or the true cost of separating a target from a parent company's shared infrastructure.
What are the biggest cyber risks found in acquisitions?
Undisclosed or undetected historical compromise, unsupported legacy systems, personal data held without a lawful basis, shared credentials and trust relationships with the seller's estate, and security debt whose remediation cost materially changes the deal model.
When should cyber due diligence happen?
Ideally during confirmatory diligence, with enough time for findings to inform the purchase agreement. A limited external-only assessment can be run earlier, using only publicly observable data, before access is granted.
What happens after the deal closes?
Day-one priorities are identity separation or federation, removing shared credentials, establishing logging over the acquired estate, and executing the remediation plan agreed during diligence — before integrating the two networks.