M&A cybersecurity diligence has spent most of this decade as a checklist item somewhere behind the environmental report. That is changing, and it is changing because acquirers have now watched enough money disappear after signing to accept the uncomfortable principle underneath it: when you buy a company, you buy its intrusions, its unpatched estate, its undisclosed incidents and its regulatory exposure, whether or not anybody involved knew they existed. The case that moved the conversation is still Verizon and Yahoo. The acquisition was agreed, and then two historic breaches surfaced — half a billion accounts disclosed in September 2016, a billion more that December, restated last year as approximately three billion — both dating from years before the deal. The price came down by around $350 million and the parties restructured how liabilities would be shared. Whatever one thinks of the numbers, the precedent is now established in every deal room: undisclosed historic compromise is a valuation input, and it is discoverable late. The second lesson came from last year's NotPetya event, which demonstrated the other half of the risk. Acquired businesses are connected to the acquirer, and the connection runs both ways. Where integration has flattened networks and shared directories, an inherited weakness becomes a group-wide weakness, and the loss lands on the parent's income statement.
Why security diligence is genuinely difficult
Four features of the transaction process work against it. The information you need is the information the target cannot give you. Meaningful assessment means examining logs, configurations, identity systems and incident history. In a competitive process, a seller will offer a policy pack, a penetration test summary and a completed questionnaire. None of those establish whether the environment is currently compromised. Nobody can prove absence of compromise. Even with full access and generous time, the honest output of a technical assessment is a set of findings and a residual uncertainty. Given that dwell time in serious intrusions is routinely measured in months, a target can be compromised today by an actor nobody will detect for a year. The seller's incentives are clear, and often the seller genuinely does not know. Undisclosed incidents are not always concealment. A company with no centralised logging, no detection capability and no incident history to speak of is not hiding anything. It simply cannot see. Timing is against you. Diligence happens in weeks, under exclusivity pressure, with technical specialists engaged late and rarely given the access their conclusions would require.
The three risks that are actually inherited
It helps to separate what you are buying into three categories, because they are priced and mitigated differently. An active intrusion. The most acute and the hardest to detect. If the target is compromised at closing, the acquirer owns the incident, the notification obligations and the remediation cost — and integration is the mechanism by which it spreads. This is the risk that argues for compromise assessment rather than questionnaire review. A historic breach not yet surfaced. Data already exfiltrated, not yet discovered or disclosed. The cost arrives later as notification, regulatory attention, litigation and reputational damage, and it is the category most amenable to contractual allocation through warranties, indemnities and escrow. A structurally weak estate. No undisclosed event at all — simply unpatched systems, flat networks, shared administrator credentials, no logging, and third-party access with no controls. This is the most common finding by a wide margin, and it is not a liability to be indemnified. It is remediation capital expenditure that belongs in the integration budget and in the model. The practical failure in most deals is treating all three as one line in the risk register, which produces a warranty where a budget was needed, or a budget where a walk-away was warranted.
| Risk category | Decision to resolve |
|---|---|
| Active intrusion | Assess available evidence and sequence connectivity cautiously. |
| Undiscovered historic breach | Review disclosure uncertainty and contractual risk allocation with counsel. |
| Structurally weak estate | Carry remediation effort and cost into the integration plan. |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for M&A Security Diligence
- Engage security diligence at the same stage as financial diligence, not after signing. Findings that arrive post-signature can only be absorbed, not priced.
- Ask for evidence, not assertions. Patch status on internet-facing systems, privileged account inventories, log retention periods, the last three incidents and how they were closed — the gaps in the answers are the finding.
- Request a compromise assessment where the target's data or connectivity is material. A time-boxed hunt across endpoints, identity and egress is the only diligence step that speaks to current compromise.
- Price a structurally weak estate into the integration budget explicitly. Remediation is capital expenditure, and discovering it after completion means funding it from synergies you have already promised.
- Do not connect the networks on day one. Segment, verify, then integrate; the fastest route to inheriting someone else's incident is a trust relationship established for convenience.
- Rotate every privileged credential at closing, including third-party and service accounts. Outgoing owners, former consultants and integrators frequently retain access nobody has documented.
- Get specific security warranties, and check the insurance behind them rather than the wording in front of them. An indemnity from a seller who has distributed the proceeds is a piece of paper.
- Treat post-closing detection capability as the priority investment. You cannot retroactively see the past; you can make sure the next twelve months are visible.
The Regional Angle
Gulf deal activity has its own version of this problem, and the differences are structural rather than cultural. Start with what is being bought. A great deal of regional M&A involves family-owned groups, distributors and contractors — businesses whose value sits in relationships, agency agreements and long-cycle contracts, and whose IT estate is typically small, integrator-operated and undocumented. The realistic finding is not an advanced intrusion but a flat network, an ERP nobody has patched in three years, administrator passwords shared across a finance team, and a former integrator with standing remote access. That is the structurally weak estate category, and it should be modelled as remediation spend before completion rather than discovered afterwards by a group CIO. The entity structure complicates both diligence and remediation. Targets frequently comprise several legal entities across mainland, free zone and offshore jurisdictions, with a shared ERP instance, one email tenant and one integrator serving all of them. Diligence scoped to the entity being acquired will therefore miss systems it depends on, and carve-outs are harder than they look: separating one entity from a shared tenant, a shared master data set and a shared support contract is a project, not a cutover. That is what makes the transitional services agreement a security document as well as a commercial one — during the transition the seller's staff and the seller's integrator retain access to your data, and the TSA needs to say who, from where, under whose supervision, and how quickly access can be revoked. The data being inherited is also more sensitive here than the equivalent Western target. Because residency is tied to employment, a target's HR files hold passports for employees and dependants, visa documentation, Emirates ID and Iqama numbers, labour cards and medical fitness results, often scattered across email and the ERP attachment tables, and often shared with PROs, typing centres and visa agents outside any contractual framework. The misuse profile is impersonation and immigration fraud, and it is rarely on a regional diligence checklist at all. Two final regional specifics. There is no general federal data protection statute in the UAE or Saudi Arabia, so the regulatory exposure you inherit arrives through other doors: DIFC or ADGM regimes where the target has entities there, sector rules from central banks and health regulators, national authority expectations for critical entities, and — increasingly since May — European contractual obligations flowing through the target's customer base. Acquiring a target with European customers now means acquiring its position under the new regime, including any breach it has not yet found. And regional boards are, in general, more willing to fund security remediation than the global average, a legacy of the destructive attacks that hit the energy sector here; a well-evidenced diligence finding is unusually likely to get funded if it is presented before completion rather than after.
The objection worth taking seriously
The strongest criticism is that security diligence produces findings nobody acts on, and that in a competitive process it is theatre with an invoice attached. There is a great deal of truth in this. Deals are done for strategic reasons, and a security report has almost never stopped one. Findings get summarised into a risk register, priced at a fraction of their real remediation cost, covered by a warranty that will be difficult to enforce, and then filed. The integration team inherits the estate anyway, discovers the same problems in the first month, and funds the fix out of a budget that assumed none of it. Meanwhile the assessment itself is constrained to what a seller will permit, which in a competitive auction is very little — so what is actually being bought is a document that demonstrates the acquirer asked. There is a sharper version. Because absence of compromise cannot be demonstrated, a clean report is close to meaningless, while a report with findings tends to be read as a negotiating instrument rather than an operational plan. That is a poor return on specialist fees, and it explains why seasoned acquirers increasingly skip the assessment and simply assume the target is weak, budgeting accordingly. The honest counter is that the assumption approach works only for buyers large enough to absorb the surprise, and that diligence earns its cost in three specific places. It sets the integration sequence, which is the single largest controllable risk in the whole transaction. It identifies the handful of findings that genuinely change price or structure — an undisclosed incident, regulated data in an unexpected place, an unresolvable third-party access dependency. And it establishes, at the only moment when the buyer has leverage, what the seller knew and warranted. The defensible position is to run diligence for decisions rather than for documentation: a short, evidence-based assessment focused on current compromise, regulated data and third-party access; a remediation number carried in the integration budget rather than the risk register; and a deliberately slow integration plan. If the process cannot accommodate that, assume weakness, budget for it, and spend the fee on post-closing detection instead.
Common Questions
Can diligence establish that a target has not been breached?
No. It can establish whether detection capability exists, whether known exposures are unpatched, and whether evidence of compromise is present in the environment now. Absence of evidence in a business with no logging is not evidence of absence.
What is the most common serious finding?
Third-party and privileged access with no inventory and no expiry — former integrators, departed consultants and service accounts nobody owns. It is also among the cheapest things to fix at closing, provided you rotate everything rather than only what is documented.
Warranties, indemnities or price adjustment?
Use allocation for historic breach risk, where the liability is genuine but unquantified, and use price or budget for structural weakness, where the cost is knowable. And check the insurance sitting behind the warranty, because enforceability against a distributed seller is the weak point.
What changes from here?
The new European regime is the variable to watch over the next year or two. Exposure that was previously reputational and litigious now carries turnover-based penalties, and it attaches to the acquired business and, after integration, to the group. That will push three things into standard practice: specific data protection warranties covering incidents the seller has not discovered, escrow sized against a regulatory rather than a contractual worst case, and much closer attention to whether an acquired customer base brings European obligations with it. Expect the insurance market to follow, with cyber and warranty cover priced on the strength of the diligence performed — which is the point at which this work stops being theatre, because somebody else will be pricing the same risk and will want to see the evidence.
M&A Security Diligence — price the weak estate, hunt for the live intrusion, and never connect the networks on day one.
