Technology Due Diligence
Cybersecurity Due Diligence: Assessing Security Posture Before You Sign
A breach discovered after close is the buyer's to manage. Posture is assessable before signing, and most of the signal sits outside the pen-test report.
Why Cybersecurity Due Diligence Is Deal Work, Not IT Work
Security liability transfers at close. A breach that began before signing but surfaces after is the buyer's problem to manage, whatever the indemnities later recover: the response, the disclosure obligations, the customer conversations. That alone earns cybersecurity due diligence a place in the deal workstream rather than a line in an IT appendix.
Exit adds a second reason. Strategic acquirers and public-market buyers increasingly expect recognized certifications, clean audit trails and demonstrable security practice. A company that needs 12 to 18 months of remediation before it can clear a security-sensitive buyer's review carries a real cost, on a real timeline, that belongs in today's price.
The good news: posture is assessable before signing. Not perfectly (no diligence process guarantees the absence of a breach) but well enough to price the risk and plan the fixes. Most of the signal sits in two places: the artifacts the company can produce, and the operational habits those artifacts are supposed to represent.
The Artifact Review: What to Request
Start with documents, but read them for follow-through rather than existence:
- Penetration test reports, plus the remediation trail. The finding list matters less than the retest evidence. A two-year-old report with open criticals says more than no report at all.
- Certification reports (SOC 2, ISO 27001): scope and exceptions first. A report scoped to one product or one office can be entirely true and nearly meaningless for the deal.
- Incident and breach history, including near misses, and what changed after each event.
- Access records: who holds production access, how often the list is reviewed, and evidence that departing employees actually lose access.
- The vendor and data-processing inventory: which third parties hold customer data, and under which agreements.
- Cyber insurance: policy scope, exclusions, and claims history.
Each artifact is testimony. The next step is checking whether operations agree.
Operational Signals of Security Maturity
Paperwork describes intent. Day-to-day records reveal posture.
Incident response is the clearest window. How fast does the organization move from alert to first response? Do post-incident reviews happen at all, and do they produce visible changes: new controls, new tests, updated runbooks? An organization that learns from incidents leaves a paper trail of improvements. One that doesn't leaves a trail of repeats.
Compliance rhythm distinguishes practice from performance. Steady cadences (periodic access reviews, scheduled policy updates, routine audit preparation) indicate security as an operating habit. A burst of activity compressed into the weeks before an audit indicates security as an annual scramble, and scrambled configurations are where audits fail.
Infrastructure discipline compounds everything else. Environments defined as code can be reproduced, reviewed and audited. Hand-managed environments drift, and drifted configurations are where vulnerabilities hide. Patch cadence is visible in change history: dependencies updated on a rhythm, or left to age until an incident forces the issue.
Questions That Separate Posture From Paperwork
Four questions do disproportionate work:
- 'When was your last security incident, and what changed because of it?' A company that reports zero incidents isn't demonstrating strength. It's demonstrating that nothing is being detected, or nothing is being recorded.
- 'Who can access production data today, and when was that list last reviewed?' The pause before the answer is part of the answer.
- 'Walk me through remediation from your last penetration test.' Findings closed, findings accepted, findings quietly forgotten: the distribution tells you how security work actually gets prioritized.
- 'Which vendors hold customer data, and would you know if one of them was breached?' Third-party exposure is the risk most often left unowned.
Pricing the Findings
Cybersecurity findings rarely kill deals. Unpriced findings do the damage, surfacing after close as remediation bills, delayed exits and uncomfortable board conversations.
Translate findings into three numbers. Remediation cost: the engineering and tooling work to close material gaps, estimated the way any technical workstream is estimated. Timeline cost: if the exit thesis assumes a security-sensitive buyer, certification and audit-trail work runs in quarters, not weeks, and it has to start early enough to finish. Residual risk: what stays exposed after remediation, which is a conversation about deal mechanics (holdbacks, specific indemnities, closing conditions) between counsel and the deal team.
Handled this way, security stops being a pass-or-fail gate and becomes what it actually is: one more operational liability to measure, price and plan against, before it becomes the buyer's surprise.
Frequently asked questions
Does a SOC 2 report mean the company is secure?
It means an auditor examined specific controls, in a specific scope, over a specific period. Read the scope and the exceptions before drawing conclusions. A clean report on a narrow scope can coexist with material gaps elsewhere, which is why the operational signals matter alongside the certificate.
Is a past breach disqualifying?
Rarely, on its own. The more useful signal is the response: how fast it was detected, how honestly it was disclosed, and what verifiably changed afterward. A well-handled breach with a documented remediation trail can say more for a company than a spotless history that nobody was checking.
Who should run cybersecurity due diligence?
The artifact review and the operational reads sit comfortably inside a standard technology diligence workstream. Deep testing (a fresh penetration test, forensic review of a past incident) is specialist work, brought in when the deal size or the data sensitivity warrants it.
References
- Don't Acquire a Company Until You Evaluate Its Data Security · Harvard Business Review (accessed August 2026)
- Cybersecurity Risks in M&A Transactions · Harvard Law School Forum on Corporate Governance (accessed August 2026)
- Moving Left and Right: Cybersecurity Processes and Outcomes in M&A Due Diligence · UC Berkeley Center for Long-Term Cybersecurity (accessed August 2026)
- Mergers and Acquisitions: Bracing for the Information Security Aftershock · ISACA (accessed August 2026)
- SOC 2 - SOC for Service Organizations: Trust Services Criteria · AICPA & CIMA (accessed August 2026)
- Cyber due diligence in M&A · Control Risks (accessed August 2026)