Dec 01 ‘22
24 min read
Aon’s 2025 Global Risk Management Survey ranked cyberattacks and data breaches as the number one global risk in 2025 and forecasted that this risk would dominate through 2028. That makes cyber due diligence a deal-value issue, as in M&A, buyers typically inherit the target’s controls, vulnerabilities, vendors, incidents, and data obligations.
This guide explains what cybersecurity due diligence covers, which threats to assess, what to include in a checklist, how to act on findings, and how a VDR supports secure review.

Key takeaways
- Cyber security due diligence evaluates whether a target’s security controls, breach history, vendor exposure, and data practices can affect valuation, deal terms, or post-close liability.
- Buyers should treat cyber findings as deal inputs. Severe issues may require price adjustments, indemnities, escrow, closing conditions, or seller-funded remediation.
- A strong cybersecurity due diligence checklist should cover risk governance, access controls, security infrastructure, monitoring, incident history, vendor risk, compliance, and cyber insurance.
- Cyber risk is not limited to software companies. Healthcare, financial services, manufacturing, life sciences, and real estate targets may hold regulated data, customer records, or intellectual property.
- A secure virtual data room helps protect the diligence process by controlling access to sensitive files, maintaining an audit trail, supporting structured Q&A, and reducing uncontrolled document exchange.
What is cyber due diligence?
M&A cybersecurity due diligence is the deal-specific review of a target company’s specific security risks, security controls, incident history, vendor exposure, and data protection practices before an acquisition, merger, or investment. In mergers and acquisitions, cyber due diligence means testing whether cyber issues could affect valuation, deal terms, regulatory exposure, integration planning, or post-close liability.
Cybersecurity due diligence differs from general due diligence as it focuses on digital risk rather than the target’s full financial, legal, tax, commercial, or operational position. It also differs from a security audit because it is transaction-driven: the goal is not only to assess control maturity, but to identify risks and decide how cyber findings should affect the deal.
A buyer, private equity sponsor, investment bank, or legal adviser typically reviews the following aspects of the target company during cybersecurity due diligence:
- Security policies, governance, and CISO-level accountability
- Identity and access controls, including multi-factor authentication (MFA)
- Incident response plans, breach history, and notification procedures
- Vulnerability management, patching, penetration testing, and remediation records
- Cloud security, network architecture, endpoint protection, and backup controls
- Data privacy obligations under GDPR, HIPAA, CCPA, or sector-specific rules
- Cyber insurance coverage, exclusions, limits, and claim history
- Third-party vendor, subsidiary, outsourced IT, and software supplier risks
Cyber risk is not limited to technology companies. Healthcare, financial services, manufacturing, real estate, retail, and life sciences targets may hold customer data, intellectual property, employee records, payment information, or regulated data, which pose cybersecurity risks. A missed cyber issue can lead to breach costs, regulatory fines, delayed integration, reduced enterprise value, or reputational damage after close.
Why does mergers and acquisitions cybersecurity matter?
Cybersecurity in M&A is critical because an acquirer can inherit undisclosed breaches, weak controls, regulatory exposure, and post-close liabilities from the target firm. Cybersecurity due diligence helps buyers test whether M&A cybersecurity concerns should affect valuation, purchase price, indemnities, escrow terms, remediation budgets, or integration planning.
A focused cyber review helps buyers:
- Identify security gaps and uncover hidden vulnerabilities
- Detect undisclosed breaches and unresolved incidents
- Estimate remediation costs and inherited liabilities
- Adjust valuation, purchase price, or deal protections
- Reduce the risk of fines, litigation, and customer loss
- Protect intellectual property, customer data, and regulated records.
Emerging cyber threats in M&A transactions
Cyber risk in M&A is rising. In 2026, diligence teams should prioritize ransomware, supply-chain compromise, phishing, insider risk, and undisclosed breaches because each threat can affect valuation, deal protections, integration scope, and post-close liability.
Ransomware attacks
Ransomware creates deal risk when a target company has unpatched internet-facing systems, poorly secured VPN or remote desktop access, weak endpoint controls, unreliable backups, or incomplete incident response evidence.
Acquirers should test whether the target can detect intrusion, isolate affected systems, restore critical data, and prove recovery readiness before signing or closing. The World Economic Forum’s Global Cybersecurity Outlook 2026 identifies ransomware as a continuing top concern for CISOs.
Supply-chain cyber threats
Supply-chain cyber threats affect M&A deals when third-party software, managed service providers, cloud platforms, or outsourced IT vendors can access sensitive systems or regulated data.
Buyers should review vendor inventories, contract security clauses, software bills of materials, vulnerability exposure, and breach notification rights before assuming operational dependency.
Verizon’s 2026 Data Breach Investigations Report reveals that 31% of breaches in 2026 start with software vulnerabilities, making third-party software exposure a material diligence issue for targets with complex vendor, cloud, or application dependencies.
Phishing and social engineering
Phishing and social engineering attacks exploit deal complexity because M&A creates unusual communication patterns, new counterparties, urgent requests, and sensitive document exchanges. Attackers can impersonate executives, advisers, vendors, or data room users to obtain credentials or payment instructions.
This malicious activity has become increasingly sophisticated due to the use of AI. The European Union Agency for Cybersecurity (ENISA) Threat Landscape 2025 Report stated that AI-supported phishing accounted for more than 80% of observed social engineering activity between September 2024 and February 2025.
Insider threats
Insider threats increase during M&A when employees face uncertainty, role changes, retention pressure, or access to confidential deal information. Buyers should review privileged access, offboarding controls, logging, data loss prevention, and access reviews for employees, contractors, and administrators. IBM’s 2025 Cost of a Data Breach Report identifies malicious insider attacks as one of the costliest breach vectors, averaging $4.92 million per attack.
Inherited / undisclosed breaches
Undisclosed breaches can expose the buyer to post-close allegations from customers, lawsuits, regulatory scrutiny, remediation costs, and reputational damage.
Buyers should review breach history, regulator correspondence, cyber insurance claims, litigation exposure, endpoint telemetry, and incident response records. This review helps acquirers price remediation, negotiate indemnities, and plan secure integration.
Read more: Learn how to identify potential risks with our expert guide on red flag due diligence
Cybersecurity due diligence checklist
A cybersecurity due diligence checklist helps buyers assess whether a target company’s cyber controls, data practices, vendor dependencies, incident history, and compliance posture create deal risk.
The most useful cyber due diligence questions connect technical findings to valuation, remediation costs, regulatory exposure, purchase agreement protections, and post-close integration priorities.
| Assessment area | What to review |
| Risk governance and policies | 🔸 Cybersecurity policies 🔸 Board or executive reporting 🔸 CISO ownershipSecurity budget 🔸 Employee training 🔸 Acceptable use policies 🔸 Risk management framework 🔸 Risk assessment processes 🔸 Third-party risk management 🔸 Alignment with NIST Cybersecurity Framework or ISO/IEC 27001 |
| Data management and access controls | 🔸 Data inventories 🔸 Data classification 🔸 Data flow diagrams 🔸 Least-privilege access 🔸 Privileged access management 🔸 Multi-factor authentication (MFA) 🔸 Access review frequency 🔸 User offboarding controls |
| Security infrastructure | 🔸 Network architecture 🔸 Cloud configuration 🔸 Endpoint protection 🔸 Firewall coverageIntrusion detection systems 🔸 Patch management 🔸 Vulnerability scanning and risk monitoring 🔸 Encryption at rest and in transit 🔸 Backup resilience |
| Logging and monitoring | 🔸 SIEM coverage 🔸 Endpoint detection and response (EDR) 🔸 Alert escalation rules 🔸 Log retention periods 🔸 Security operations workflows 🔸 Suspicious activity reports 🔸 Monitoring gaps across cloud, network, and endpoint environments |
| Breach and incident history | 🔸 Incident response plans 🔸 Incident reporting mechanisms 🔸 Incident management procedures 🔸 Breach records 🔸 Forensic reports 🔸 Regulatory notifications 🔸 Customer notifications 🔸 Unresolved incidents 🔸 Remediation status 🔸 Lessons learned from prior cyber events |
| Third-party and vendor risk | 🔸 Vendor inventory 🔸 IT partner agreements 🔸 Managed service provider access 🔸 Cloud provider dependencies 🔸 Software supplier controls 🔸 Data processing agreements 🔸 Breach notification clauses 🔸 Vendor security questionnaires |
| Regulatory compliance and security standards | 🔸 GDPR 🔸 HIPAA 🔸 CCPA 🔸 NIST 🔸 ISO/IEC 27001 🔸 SOC 2 Type II reports 🔸 Sector-specific rules 🔸 Privacy policies 🔸 Audit results 🔸 Compliance gaps 🔸 Regulator correspondence 🔸 Whether certifications and compliance claims apply to the target’s actual product, platform, or services rather than only to a hosting provider, cloud vendor, or other third party |
| Cyber insurance | 🔸 Policy coverage 🔸 Exclusions 🔸 Limits 🔸 Deductibles 🔸 Claim history 🔸 Ransomware coverage 🔸 Notification obligations 🔸 Insurer security requirements 🔸 Whether known incidents could affect coverage |
| Remediation cost estimate | 🔸 Required security investments 🔸 Urgent control gaps 🔸 Legacy system replacement 🔸 Licensing issues 🔸 Staffing needs 🔸 Vendor changes 🔸 Incident response improvements 🔸 Integration-related security costs |
The full scope of the cybersecurity due diligence checklist should depend on the transaction type, target company size, industry, data sensitivity, regulatory exposure, IT maturity, and integration plan.
For example, a healthcare target requires a deeper review of HIPAA and protected health information practices. A SaaS target, on the other hand, usually requires investigating its source code for critical technical vulnerabilities.
Read more: Use this due diligence checklist template to compare cybersecurity findings with the broader M&A due diligence framework.
How to act on M&A cyber due diligence findings: remediation and integration
An M&A security assessment should turn cyber findings into specific deal, remediation, and integration actions. Buyers should decide whether each issue affects price, stock purchase agreement (SPA) terms, closing conditions, remediation budgets, or the secure integration roadmap before the target’s technology stack, users, and data are connected.
Classify findings by deal impact
Buyers should classify each cybersecurity finding by severity, business impact, timing, and ownership. This helps the deal team decide which risks must be resolved before closing and which risks can move into post-close remediation.
Key actions include:
- Mark critical unresolved breaches as potential closing conditions
- Link known security gaps to indemnities, escrow holdbacks, or seller-funded remediation
- Separate urgent control failures from lower-priority technical debt
- Estimate remediation costs for legacy systems, tooling gaps, and staffing needs
- Assign every finding to an accountable owner, such as the CISO, CTO, legal counsel, privacy lead, or integration management office
Read more: Use this due diligence report format to structure cybersecurity findings, remediation priorities, and deal-impact recommendations after the review.
Convert findings into SPA protections
Deal teams should connect cyber findings to the purchase agreement so the buyer does not inherit avoidable liability without contractual protection. The SPA should reflect known cyber risks, unresolved incidents, data protection duties, and regulatory exposure.
Common protections include:
- Specific representations and warranties on security controls, breaches, and data handling
- Indemnities for known incidents, regulatory claims, or customer notification duties
- Closing conditions tied to critical remediation or incident disclosure
- Cyber insurance requirements and evidence of coverage
- Data protection covenants for GDPR, HIPAA, CCPA, or sector-specific obligations
Build a remediation plan
A remediation plan should convert each finding into an owner, deadline, cost estimate, evidence requirement, and escalation path. The buyer should use this plan to track which cyber risks affect Day 1 readiness, 100-day priorities, and longer-term security maturity.
The plan should cover:
- Multi-factor authentication (MFA)
- Encryption and key management
- Endpoint protection and patching
- Vulnerability remediation
- Privileged access management
- Logging and monitoring gaps
- Incident response playbooks
- Employee security training
Create a secure integration roadmap
Secure integration should begin before the buyer connects networks, migrates data, or grants employees access to new systems. Newly combined environments typically become exposed when teams integrate identity systems, cloud accounts, endpoint fleets, and sensitive data without verified controls.
The integration roadmap should define:
- Which systems can connect on Day 1
- Which systems should remain isolated until controls are verified
- Where the combined environment will be hosted
- How customer data, intellectual property, and regulated records will move
- Which backups must be created before migration
- Which users need access, and which accounts should be removed
- How security teams will monitor integration progress and new risks
Track progress after close
Post-close monitoring should continue until the buyer verifies that critical findings have been remediated and integration risks are under control. The deal team should review remediation status, control gaps, security incidents, vendor dependencies, and new issues as the target’s systems move into the combined operating environment.
Lessons learned from real M&A cyber failures
Real M&A cyber failures show that merger and acquisition security affects price, liability, integration risk, and regulatory exposure. Buyers should treat cyber diligence as a value-protection workstream because undisclosed breaches, weak identity controls, inherited platforms, and unresolved privacy failures can create measurable financial impact before and after closing.
| Deal | Cyber issue | Material impact, financial |
| Verizon — Yahoo ($4.48 billion, 2017) | Yahoo disclosed major data breaches during late-stage diligence | Verizon required a $350 million price reduction, according to Wharton’s 2025 analysis of why M&A deals fail. (Knowledge at Wharton, 2025) |
| Marriott — Starwood ($13.6 billion, 2016) | Starwood had security weaknesses that contributed to data breaches | The U.S. Federal Trade Commission (FTC) alleged in 2024 that Marriott’s and Starwood’s cybersecurity failures led to three breaches affecting more than 344 million customers worldwide. State attorneys general also reached a $52 million settlement (Federal Trade Commission, 2024) |
| Optum — Change Healthcare ($13 billion, 2022) | Change Healthcare suffered a 2024 ransomware attack after its acquisition by UnitedHealth Group’s Optum | Reuters reported in 2025 that approximately 190 million individuals were impacted. UnitedHealth said in 2024 that PHI or PII may have been exposed, and the incident disrupted U.S. healthcare payments and claims processing (Reuters, 2025) |
| T-Mobile — Sprint ($26 billion, 2020) | T-Mobile experienced three FCC-investigated data breaches after the Sprint merger, with incidents in 2021, 2022, and 2023 | T-Mobile reached a $500 million class action settlement in 2022, including $350 million for the class and $150 million for data security improvements. The FCC also reached a $31.5 million settlement in 2024 over breaches from 2021–2023 (Cybersecurity Dive, 2024) |
| PayPal — TIO Networks ($233 million, 2017) | PayPal suspended TIO’s operations on November 10, 2017, after finding security vulnerabilities, and confirmed on December 1, 2017, that unauthorized access affected systems storing customer personal information | A 2021 case summary written by Liisa M. Thomas at Sheppard notes that confidential information of 1.6 million TIO customers was potentially compromised, and PayPal’s stock price fell 5.75% after disclosure. (Sheppard, 2021) |
How a data room supports cybersecurity due diligence
A secure virtual data room supports cybersecurity due diligence by giving buyers, sellers, legal counsel, and security teams a controlled workspace for sensitive security documentation. A leaked vulnerability report, network diagram, incident timeline, or customer data inventory can expose the target to additional cyber, legal, or commercial risk.
Secure data rooms reduce that exposure by combining document control, user access management, audit trails, and structured Q&A in a controlled environment.
| VDR security measure | Its role in cybersecurity due diligence |
| Centralized secure repository | Keeps cybersecurity diligence files in one controlled workspace |
| Granular permissions | Allows administrators to assign document access at the user level. It allows teams to match access rights to reviewer roles, from view-only access to broader document control where appropriate |
| Multi-factor authentication (MFA) | Requires an additional authentication factor beyond a password, reducing the risk of access through stolen or guessed credentials |
| Time, IP, and domain restrictions | Limits access by approved time windows, IP addresses, or email domains |
| Dynamic watermarks | Adds user-identifying details to documents so exported or viewed files remain traceable |
| Screen shield / restricted viewing mode | Limits the visible area of a document or adds a protective viewing layer to reduce unauthorized visual capture during review |
| Remote information rights management (IRM) | Helps administrators maintain control over encrypted PDF and Microsoft Office documents after access is granted |
| Audit trail | Provides a chronological record of auditable events, such as document views, downloads, permission changes, Q&A activity, and user access events during the diligence review |
Read more: Review data room security controls that help protect sensitive diligence documents.
Final words
Cybersecurity due diligence is no longer a technical review performed alongside the deal. It is part of the investment decision itself. As cyber threats become more sophisticated and regulators place greater scrutiny on data protection, buyers need to understand not only whether security controls exist, but whether they are strong enough to protect the value being acquired.
A disciplined cyber review, supported by clear deal protections and a secure integration plan, helps buyers reduce uncertainty before closing and avoid costly surprises after the transaction is complete.
Category
Due diligenceMergers and acquisitionsSecurity & risksFAQ
Cybersecurity due diligence in M&A is the review of a target company’s cyber risks, security controls, incident history, vendor exposure, and data protection practices. Buyers use the findings to assess valuation impact, deal terms, regulatory exposure, integration risk, and post-close liability.
A cybersecurity due diligence checklist usually covers the target’s security posture, data protection practices, incident history, vendor exposure, and remediation needs. Common review areas include access controls, cloud and network security, compliance evidence, cyber insurance, and breach response records. The final scope depends on the target’s industry, systems, data sensitivity, and transaction structure.
Cyber due diligence questions should test whether the target has known breaches, weak access controls, unresolved vulnerabilities, vendor dependencies, regulatory gaps, cyber insurance limits, and realistic remediation plans. Buyers should also determine how security findings affect price, indemnities, escrow, closing conditions, and integration priorities.
The cybersecurity due diligence process is important in acquisitions because buyers can inherit undisclosed breaches, regulatory exposure, weak controls, and integration risks at close. A focused review helps buyers identify liabilities, estimate remediation costs, protect customer data, negotiate deal protections, and reduce post-close disruption.
Cybersecurity due diligence assessments usually take several weeks, depending on the deal timeline, target size, IT complexity, data sensitivity, and document readiness. A software, healthcare, financial services, or cross-border target may require deeper review than a low-risk business with simple systems.
Cybersecurity due diligence is typically performed by the buyer’s security team, IT leaders, external cybersecurity assessors, legal counsel, privacy specialists, and M&A advisers. Private equity firms may also involve operating partners, CISOs, CTOs, and compliance experts when cyber findings could affect valuation or integration.