Skip to content
Insights
Market insights · 3 min read

What cybersecurity diligence actually looks for

Cybersecurity diligence changed from a questionnaire into something that moves price and structure. Buyers will find what is there. The choice is whether they find it from you.

Why this became a real workstream

Cybersecurity diligence used to be a questionnaire. It is now a workstream that changes price and structure, and the reason is that acquirers have been caught. A breach that originated before completion but surfaced afterwards belongs to the buyer, and several well-known cases have cost acquirers sums far larger than the diligence would have.

For a seller, the useful framing is that this is now something buyers will find. The choice is whether they find it from you during preparation or from their own consultants in week five.

What gets examined

Governance first, because it predicts everything else. Whether there are written policies, whether anyone owns security, whether the board sees anything, and whether the business holds a recognised certification such as SOC 2 or ISO 27001. A certification is not proof of security, but its absence in a business selling to enterprises raises the question of how they passed their customers' own diligence.

Technical controls. Network segmentation, endpoint protection, identity and access management, encryption at rest and in transit, patching cadence, and whether anyone would notice an intrusion. The last one is the important one, and the answer is frequently no.

Data protection. What sensitive data exists, where it lives, who can reach it, and whether the retention practice matches what the privacy notice claims. For businesses handling personal data at scale this is often where the material findings are.

Third-party exposure. Vendor assessments, cloud configuration, and which suppliers hold credentials into your systems. Supply chain compromise has become a common route in and buyers now ask about it directly.

The findings that change terms

The serious ones are an unreported incident, evidence of a current or past compromise, personal data held without a lawful basis, credentials or keys committed to a repository, and a certification claimed but lapsed.

Any of these can move a price, add an indemnity, or in the worst case end the process, because they represent liability of an unknown size.

The moderate ones, which inform the integration plan rather than the price, are unpatched systems, weak access management, absent logging, single points of failure in the security function, and inadequate staffing relative to the exposure.

How buyers respond

Reducing the price by an estimate of remediation cost plus a risk premium, which is the usual outcome for moderate findings.

Requiring a specific indemnity for the identified issue, since warranty insurance excludes known matters and a disclosed problem therefore has to be dealt with in the agreement.

Holding back consideration in escrow pending completion of agreed remediation.

Excluding cyber from the insurance policy, which shifts the general risk back to the seller.

Withdrawing, where the exposure is severe and cannot be quantified.

What a seller should do first

Run the assessment yourself during preparation, three to six months before going to market. That is enough time to fix the findings that can be fixed cheaply, which is most of them.

Patching, access reviews, removing credentials from repositories, turning on logging and multi-factor authentication. None of this is expensive and all of it appears in a buyer's report if left undone.

Prepare an honest incident history. If there has been an incident, disclose it with what was done afterwards. A disclosed and remediated incident is a risk a buyer prices. An undisclosed one that surfaces later is a warranty claim and a breakdown of trust in everything else you said.

Assemble the evidence: policies, certification reports, penetration test results and remediation records. A buyer who receives a coherent pack forms a different view than one who receives assurances.

The part sellers underestimate

Buyers are not looking for a business with no security findings, because it does not exist. They are trying to establish two things: whether there is an unknown liability, and whether this business is run by people who take the question seriously.

The second is answered by how the first is handled. A seller who produces their own assessment, including the uncomfortable parts, with a remediation plan and dates, has answered both. That is worth more than a clean report, and it is achievable in a quarter.

Editorial Team · Published for orientation, not as advice on a specific transaction. Any figure cited is orientation, not a valuation. See market notes.

Considering a transaction

Talk to an advisor, not a form.

Confidential, success-based, no retainer.