The Cyber Risk That Surfaces After the Deal Closes
In mergers and acquisitions, the value of a target is scrutinised from every angle. Financials are audited, contracts are reviewed, liabilities are quantified, and growth assumptions are stress-tested. Yet one category of risk still routinely slips through the process, only to surface once the deal is done and the acquirer owns the consequences: the state of the target’s cybersecurity.
Cyber risk in M&A is no longer a niche technical concern for the IT function to sort out during integration. It is a material factor in valuation, a potential deal-breaker in negotiation, and a liability that transfers, in full, to the buyer at completion. Acquirers who treat it as an afterthought are, in effect, buying an unknown, and occasionally that unknown turns out to be very expensive.
When you buy a company, you buy its breaches
The uncomfortable principle at the heart of M&A cyber risk is simple: an acquirer inherits not only a target’s assets and revenue, but its security weaknesses and its undisclosed, or undiscovered, incidents. A breach that occurred before completion does not stay with the previous owners. It becomes the buyer’s problem, along with the regulatory exposure, remediation costs, and reputational damage that follow.
The most cited illustration remains a large hospitality acquisition in which the buyer completed the deal only to discover, afterwards, that the target’s systems had been compromised for years, exposing the records of hundreds of millions of guests. The resulting regulatory penalty and clean-up landed squarely on the acquirer. The lesson that reverberated through boardrooms was not about that specific company; it was that cyber due diligence had become as essential as financial due diligence, and that skipping it could turn a promising acquisition into a costly one.
Why the risk hides so well
Cyber weaknesses are peculiarly difficult to see from the outside, which is exactly why they survive a due diligence process that catches so much else.
A target’s financial position leaves a paper trail. Its cybersecurity posture often does not. Weaknesses may be entirely invisible until they are actively looked for, and a management team is unlikely to volunteer, or may not even be aware of, the gaps in their own defences. Standard due diligence questionnaires can be answered reassuringly without ever revealing whether controls actually work in practice.
Some of the most consequential weaknesses are also the least glamorous, and therefore the easiest to overlook. Acquirers may ask about firewalls and data protection policies while never probing how the target actually controls the movement of data in and out of its systems. In sectors that handle sensitive information or run isolated operational technology, such as manufacturing, energy, healthcare, and defence, one of the most persistent exposures is the humble removable device: the USB drives and portable media that move data physically, bypassing the network defences entirely and leaving little trace. A target may have invested heavily in network security while leaving this physical route almost entirely uncontrolled, and a due diligence process focused only on the obvious will never notice.
Cyber due diligence as a value lever
Handled well, cyber due diligence is not merely a defensive box-ticking exercise. It is a lever that can protect and even improve deal value.
A rigorous assessment of a target’s security posture gives an acquirer several advantages. It surfaces liabilities before they become the buyer’s problem, allowing them to be priced into the deal or addressed as conditions of completion. It provides negotiating leverage, since discovered weaknesses can justify a lower price or specific warranties and indemnities. And it produces a clear remediation roadmap for the integration phase, so that known gaps are closed deliberately rather than discovered through a post-acquisition incident.
The categories that deserve scrutiny go beyond the obvious. Alongside the target’s breach history, regulatory compliance, and data-protection practices, a thorough review examines how access is controlled, how the supply chain is managed, and how data physically moves within and out of the organisation. It is in this last category that many acquirers find unpleasant surprises. Organisations that take the issue seriously deploy dedicated controls such as USB decontamination stations that scan and clean removable media before it can reach sensitive systems, precisely because the removable-media route is both a common weakness and an easy one to demonstrate control over. A target that can show such controls is a lower-risk proposition; one that cannot has a gap the acquirer will need to close.
The integration window is its own risk
Even where due diligence is thorough, the period immediately after a deal completes carries elevated cyber risk in its own right. Integrating two organisations means connecting systems, merging networks, migrating data, and reconciling different security cultures, often at speed and under pressure to realise synergies quickly.
Attackers are well aware of this. The disruption and distraction of integration create openings, and the newly combined entity may temporarily operate with inconsistent controls, unclear ownership, and data moving between environments that were never designed to connect. An acquirer who has mapped the target’s weaknesses in advance can manage this window deliberately, prioritising the controls that matter most and ensuring that the act of integration does not itself become the source of a breach.
A board-level discipline, not a technical footnote
The through-line is that cyber risk in M&A has graduated from a technical detail to a board-level discipline. It affects what a target is worth, whether a deal should proceed on its original terms, and what liabilities the acquirer takes on. It belongs in the same tier of due diligence as financial and legal review, and it deserves the same rigour.
For acquirers, the practical takeaway is to treat cybersecurity as a standard, non-negotiable workstream in every transaction of consequence, to look past the reassuring surface answers to how controls actually function, and to pay particular attention to the unglamorous, easily-overlooked routes, such as removable media, that so often turn out to be where the real exposure lies. The deals that go wrong are rarely undone by the risks everyone examined. They are undone by the ones nobody thought to look at until it was too late.
This article is for general information and does not constitute specific security, legal, or financial advice. Organisations should assess their own risks and seek professional guidance where appropriate.



















