What Buyers Don’t Check – and Sellers Hope They Won’t

Mergers & Acquisitions  ·  Cyber Due Diligence

What Buyers Don’t Check – and

Sellers Hope They Won’t

Undisclosed breaches, weak governance, and legacy vulnerabilities don’t disappear at completion. They transfer. Here’s what cyber due diligence actually looks like – and why it belongs at the heart of every deal.

CurveTech Editorial  ·  June 2026  ·  9 min read

M&A cyber due diligence is one of the most critical – and most frequently underestimated – elements of any acquisition. Every M&A deal involves a careful examination of financials, legal exposure, and operational risk. Cyber security is almost always on the checklist. But being on a checklist and being properly assessed are very different things – and the gap between them is where deals unravel, valuations erode, and post-close surprises become expensive problems.

For buyers, the risk is straightforward: acquire a company without understanding its cyber posture and you may be inheriting a breach that hasn’t been disclosed, a regulatory exposure that hasn’t been assessed, or a technical debt that will take years and significant investment to resolve. For sellers, the risk runs in the other direction – poor cyber maturity can delay deals, invite price chips, or deter interest from sophisticated acquirers who know what to look for.

Getting cyber due diligence right is not about producing a report that satisfies a checklist. It’s about surfacing the issues that matter, understanding their implications for deal value, and having a clear plan for what happens after completion. That’s the difference between due diligence as a process and due diligence as a strategic advantage.

53%
of acquirers discovered a cyber problem in the target after deal close

£18.4M
ICO fine issued to Marriott International for inherited data breach liabilities

73%
of respondents said an undisclosed data breach would be an immediate deal-breaker

“Cyber risk doesn’t disappear at completion. It transfers – along with the liability, the remediation cost, and the reputational exposure that comes with it.”

Why Cyber Is Different from Other Due Diligence

Financial due diligence has decades of established practice behind it. Audited accounts, standardised reporting, well-understood metrics. Cyber due diligence is still maturing as a discipline, and the absence of standardised disclosure means that what one organisation calls a ‘security incident’ another might never have logged at all.

This matters because cyber risk is asymmetric in ways that other forms of business risk are not. A target company could have strong financials, a solid management team, and a defensible market position – while simultaneously harbouring vulnerabilities that, once inherited, create regulatory exposure across multiple jurisdictions, customer notification obligations, or integration costs that fundamentally change the deal economics.

There are four failure modes that appear repeatedly in M&A transactions where cyber due diligence was either skipped or treated as a formality:

Undisclosed breaches
Historical incidents that were contained internally but never reported. Post-close, these can trigger notification obligations, regulatory investigations, and class-action exposure – all on the buyer’s watch.
Inherited compliance gaps
Targets operating under UK GDPR, NIS2, or sector-specific regulation without adequate controls. Once integrated, those gaps become the buyer’s compliance problem – and regulators don’t discount for good intentions.
Legacy technical debt
End-of-life systems, unpatched infrastructure, and decades of accumulated workarounds. The integration cost of bringing a target’s environment up to standard is routinely underestimated and rarely reflected in deal pricing.
Supply chain exposure
Third-party and supplier risks not visible from the outside. A target’s clean internal posture can mask significant exposure in the networks of partners, vendors, and managed service providers it relies on.

Cyber Risk Across the Deal Lifecycle

Effective cyber due diligence isn’t a single assessment at a single point in the deal timeline. The risks and priorities shift as a transaction progresses, and so should the approach. CurveTech structures its M&A cybersecurity support across three distinct phases, each with its own objectives and deliverables.

Before the Deal: Readiness & Cyber Due Diligence

Establish a clear baseline of the target’s security posture across key controls, vulnerabilities, incident readiness, and compliance status. Identify and prioritise material risks early – reducing surprises, deal friction, and valuation uncertainty. For sellers, this phase is equally valuable: understanding your own posture before an acquirer does is the difference between managing the narrative and reacting to it.

During the Deal: Transaction Security & Risk Control

As transactions progress, attention shifts to legal and commercial detail. At the same time, organisational change, expanded access rights, and third-party involvement increase cyber exposure significantly. Managing this window – maintaining control of data flows, access permissions, and sensitive communications throughout due diligence and negotiation – requires deliberate security oversight that most deal teams aren’t resourced to provide.

After the Deal: Post-Completion Integration

Integration is where inherited risk becomes operational risk. Network connections between two previously separate environments, merged identity and access systems, combined data estates, and unified security tooling all create exposure if not managed carefully. Post-completion security planning should begin before the deal closes, not after.

What a Proper Assessment Actually Covers

A meaningful cyber due diligence assessment goes well beyond asking a target to complete a security questionnaire and reviewing their ISO certificate. The following gives a sense of the areas that matter most, and the level of materiality that should determine how deeply each is examined.

Area What We Examine Materiality
Incident history Prior breaches, response effectiveness, notification obligations met or missed, regulatory correspondence HIGH
Regulatory compliance UK GDPR alignment, NIS2 applicability, sector-specific obligations, open regulatory investigations HIGH
Architecture & maturity Security controls, network segmentation, identity and access management, vulnerability management programme HIGH
Third-party risk Supplier and MSP assessment, contractual security obligations, critical dependency mapping MEDIUM
Standards alignment ISO 27001 status, Cyber Essentials certification, internal policy framework and evidence quality MEDIUM
Technical debt End-of-life systems, unpatched infrastructure, shadow IT, legacy integration complexity MEDIUM
People & process Security team capability, awareness culture, key-person dependency in security function LOWER

The output isn’t a pass or fail – it’s a risk-tiered picture of what’s present, what it means for deal value, and what remediation looks like in terms of time and cost. That picture can inform negotiation, deal structure, price adjustment mechanisms, or the conditions attached to completion.

A Note for Sellers

A note for sellers: preparing for scrutiny is a competitive advantage

Organisations that understand their own cyber posture before entering a transaction are in a fundamentally stronger position. Surprises that emerge during a buyer’s due diligence process create uncertainty, invite price chips, and, in some cases, derail deals entirely. Commissioning an independent cyber readiness assessment before going to market means you control the narrative: issues are understood, remediated where appropriate, and presented with context rather than discovered and reacted to under deal pressure. The cost of that preparation is almost always a fraction of the deal impact it prevents.

The Integration Risk Nobody Plans For

The period between deal completion and full technical integration is consistently the highest-risk window in any M&A transaction and consistently the least resourced for cyber purposes. The deal team has moved on to the next opportunity. The integration team is focused on operational continuity. Security is assumed to be someone else’s problem.

The reality is that connecting two organisational environments, even temporarily and with the best intentions, creates attack surface that didn’t previously exist. Credentials inherited from the target. Network bridges that bypass existing controls. Privileged access granted during the deal process and never revoked. In the absence of deliberate, sequenced integration planning, these aren’t edge cases. They’re the norm.

  • Conduct a post-completion cyber assessment before connecting any environments – treat the target as untrusted until validated
  • Validate patching, backup integrity, and access controls independently before integration begins
  • Remove all unnecessary or inherited privileged access granted during the deal process
  • Run joint incident response exercises before integration, not after – test readiness before the environment is live
  • Align policies, monitoring, and security tooling across both organisations before full network connectivity
  • Establish clear cyber ownership on both sides from the moment heads of terms are signed

How CurveTech Supports M&A Transactions

CurveTech provides end-to-end cybersecurity support across the full M&A lifecycle, from initial readiness assessments and cyber due diligence through to secure post-deal integration. The service is designed for both sides of the transaction: buyers who need an honest, evidence-based picture of what they’re acquiring, and sellers who want to enter the market with a mature, well-documented security posture that withstands scrutiny.

Whether you are preparing for a transaction, evaluating an acquisition, or integrating a newly acquired entity, CurveTech brings the expertise to manage cyber risk with clarity and confidence – without slowing the deal down.

CurveTech M&A Cybersecurity Services

  • Baseline security posture assessment
  • Evidence validation
  • Risk prioritisation
  • Regulatory compliance status review
  • Incident history review
  • Third-party risk assessment
  • ISO 27001 & Cyber Essentials alignment
  • Secure data exchange protocols
  • Access management
  • Post-completion assessments
  • Incident response exercising
  • Integration security planning

Getting the Timing Right

The most common mistake in M&A cyber due diligence isn’t what gets examined – it’s when. Cyber assessment is frequently commissioned late in the process, after commercial terms are largely agreed and deal momentum is established. At that point, findings create friction: unwelcome surprises that neither party has the time or inclination to address properly, leading to either price adjustment mechanisms that compensate financially without fixing the underlying issues, or issues being downplayed to keep the deal moving.

Commissioning cyber assessment early, at the same time as financial and legal due diligence, changes the dynamic entirely. Issues are surfaced when there is still time to understand them properly, negotiate around them if necessary, and plan remediation before completion rather than inheriting it afterwards. For private equity firms and sophisticated acquirers making multiple transactions, embedding cyber due diligence as a standard pre-signing workstream is increasingly becoming the norm.

The question for buyers isn’t whether cyber risk exists in a target. It always does. The question is whether you understand it well enough to price it correctly, structure the deal around it appropriately, and integrate the business without it becoming your problem before you’ve had the chance to fix it.

Preparing for a Transaction?

Whether you are a buyer conducting cyber due diligence or a seller preparing for scrutiny, CurveTech can help you move forward with clarity. Request a confidential conversation with our M&A cybersecurity team at info@curvetech.io or visit www.curvetech.io.

Sources

  1. Forescout Technologies, The Role of Cybersecurity in M&A Diligence (2019). Survey of 2,700+ IT and business decision makers across seven countries.
  2. UK Information Commissioner’s Office, Penalty Notice: Marriott International Inc (October 2020). ICO reference: COM0804139.
  3. Forescout Technologies, ibid. – 73% of respondents said an undisclosed data breach would be an immediate deal-breaker in their M&A strategy.

CurveTech and Aristos Partnership Achieve NCSC Cyber Incident Exercise Certification

Speak Up with Confidence: A Practical UK Whistleblowing Guide for Employers

Operational Data Protection: How SMEs Turn Requirements into Routine

If you want to find out more about how we can help you contact us.

Relevant Blogs

Relevant content for you to explore

CurveTech and Aristos Partnership Achieve NCSC Cyber Incident Exercise Certification

Speak Up with Confidence: A Practical UK Whistleblowing Guide for Employers

Operational Data Protection: How SMEs Turn Requirements into Routine

Get In Touch With Us!

Connect with our team to explore how our solutions can elevate your business. Schedule
a personalised demo and see the difference first hand!

CurveTech Ltd — cyber security and compliance consultancy
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.