Cyber due diligence in M&A: what buyers actually check

By the QuantumSec team

If you're on the buying side of an acquisition, technical cybersecurity due diligence is where problems surface that even the seller didn't know they had: active vulnerabilities, former employee accounts that still have access, or a security incident never formally reported. This guide explains what a well-run cyber due diligence should cover and how to translate findings into business decisions — price, terms, or walking away.

The four areas a complete cyber due diligence covers

Technical posture: active vulnerabilities in infrastructure and applications through analysis and, if timing allows, a scoped pentest. Access management: orphaned accounts, excessive privileges, shared or unrotated credentials. Incident history: past breaches, whether they were properly notified to the relevant data protection authority when required, and whether they were genuinely remediated. Regulatory compliance: exposure to pending fines under NIS2, GDPR or other sector regulations.

Why security debt costs more after closing

A finding discovered during due diligence is negotiable: it adjusts the price, part of the payment is held in escrow conditional on remediation, or it's included as a warranty in the purchase agreement. The same finding discovered after closing is entirely the buyer's responsibility, with no negotiating leverage. The cost difference between the two scenarios can be substantial.

Red flags that justify digging deeper

A total absence of security documentation (no policy, no incident log), a technical team that cannot explain who has administrative access to critical systems, systems running outdated software with no upgrade plan, or reluctance to grant full access for the review. Any of these justifies expanding the scope of analysis before closing.

How to translate findings into the negotiation

Not every finding carries the same weight: a critical vulnerability in the revenue-generating core product matters far more than a minor weakness in a secondary internal system. A useful due diligence report doesn't just list findings — it prioritizes them by impact on the real value of the asset you're buying, with a cost and remediation timeline estimate for each.

FAQ

How long does a cyber due diligence take in an M&A deal?

It depends on scope and the access the seller provides, but a reasonably complete analysis typically takes 1 to 3 weeks.

Can I request one even if the seller already presents their own report?

Yes, and it's advisable. The seller's report is a good starting point, but as a buyer it's worth validating findings independently, especially when there's a lot at stake in the deal.

What if I find something serious mid-negotiation?

It becomes a negotiation point: price adjustment, part of the payment held in escrow conditional on remediation, or specific warranty clauses in the purchase agreement.