← Back to the cybersecurity blog

Cyber due diligence in M&A: valuing technology risk before you buy a company

By Adrián González · CEO · Published: 08 August 2026 · Updated: 08 August 2026
Executive team assessing technological risk in an M&A transaction prior to closing AI-generated image

In February 2017, Verizon closed its purchase of Yahoo for US$350m less than agreed. The price fell from US$4.83bn to US$4.48bn after two breaches came to light that had not been disclosed during the initial negotiation, as TechCrunch reported. A year later, Marriott discovered that the reservation network of Starwood — the chain it had bought in 2016 — had been compromised since 2014.

The two deals teach the same lesson from opposite ends: in one, the risk came off the price; in the other it was inherited, along with the penalty and the crisis. The technology risk of the company you buy does not stay on its balance sheet, it moves to yours. Which is why cyber due diligence is no longer settled by a last-minute technical check: it belongs in the valuation.

What you need to know

A certificate does not evidence that the network is clean on signing day. It evidences that a management system was assessed, within a defined scope, on a given date.

Technical risk has a price, and that price is negotiable. The evidence feeds the price, the warranties and the payment schedule, or it feeds nothing at all.

The UK regulator has already treated thin due diligence at acquisition as a relevant factor in its assessment.

Without access to the target's systems you can still assess a great deal: internet-facing exposure, critical third parties, and evidence that controls are genuinely in use.

Two deals that frame the problem

Yahoo: risk that comes off the price

Verizon's purchase of Yahoo was announced in July 2016 at US$4.83bn. That autumn two breaches became public: one of roughly 500 million accounts, another of more than a billion. The outcome was a US$350m reduction and a split of liabilities, with Verizon taking half the cost of third-party claims and of government investigations other than those by the US securities regulator. One detail tends to get lost: as reported at the time, the buyer pushed for a discount closer to US$925m and did not get it. A risk discount is negotiated.

Marriott: liability that comes with the keys

Marriott bought Starwood in 2016. In 2018 it found that the reservation database had been compromised since 2014 — before the acquisition. The UK data protection authority announced in July 2019 its intention to fine the group £99m and closed the case in November 2020 with an £18.4m penalty, having weighed the company's cooperation and the pandemic context.

For an investment committee the final figure matters less than the reasoning: the regulator pointed to insufficient due diligence at acquisition as a factor. The pre-deal review had rested on contractual representations and warranties, a SOC 2 attestation, a PCI DSS compliance report and conversations with technology leadership, with no technical testing of the reservation infrastructure. The point is worth holding on to: a certificate evidences that a management system existed, not that the network was clean.

Why technology risk lands in the valuation

Valuation rests on growth, margins, quality of earnings and cost of capital, and technology touches all four. If the architecture cannot carry the markets the plan promises, forecast growth loses credibility. Where technical debt has piled up, corrective investment nobody budgeted for surfaces, along with the recurring spend of keeping operations steady. And if the target sells into regulated sectors or large accounts, weak maturity threatens the renewal of exactly those contracts. In those markets, security is already a precondition for winning business. All that uncertainty ends up in the risk premium applied to the business.

Which gives you the test that matters: if the report changes no economic or contractual decision, it was not due diligence. It was a technical review with no translation into the deal.

The honest objection: no time and no access

Any deal principal will reasonably object that a competitive process leaves no weeks for auditing, and that a vendor will not open its systems to a buyer who may never complete. No deal pauses for an exhaustive technical review, and asking for deep access mid-process can be unworkable.

That said, what most buyers fall back on — contractual representations and the certificates supplied — is the same documentary basis the regulator found wanting in Marriott. Between auditing everything and checking nothing there is middle ground that does fit a deal timetable.

What can be assessed with limited access

Plenty can be reviewed without ever touching the target's network. Internet-facing exposure — domains, published services, certificates, credentials leaked in third-party breaches — is analysed from outside and says a great deal about the state of the house. Mapping critical third parties, their contracts and their access brings out the share of risk the company does not manage directly; the same problem we examined in our work on digital supply-chain risk.

To that you add documentary review done with judgement, which looks for evidence of application — logs, incident tickets, minutes, restore-test results — rather than the mere existence of a policy. And targeted interviews with the security and technology leads, where the quality of the answers about past incidents is usually more revealing than any questionnaire. That is the scope that fits transaction timescales, and what a cybersecurity audit built around a deal is meant to cover.

The five areas that move the price

Dependencies and operational resilience

You need to know which systems the revenue and the operation actually depend on, whether single points of failure exist, and whether continuity has been tested or merely documented. A profitable target with fragile resilience passes to the buyer a structural volatility that does not show up in the accounts until it bites.

Technical debt and obsolescence

Technical debt is rarely declared clearly in the data room, and it drives investment, integration speed and exposure to incidents: the remaining life of core platforms, dependencies on unsupported software, the quality of development and deployment, and a realistic phased cost of modernisation. It is the line item that usually explains why a cheap deal turns out expensive.

Data and regulatory exposure

Without a reliable inventory of sensitive data — its legal basis, access, retention and transfers — legal exposure cannot be estimated. It is the line that sets the size of that exposure: in Marriott, the volume and nature of the data involved shaped the scope of the enforcement action. Read it alongside NIS2 readiness where the target or its customers fall within the directive's scope.

Digital supply chain

A substantial share of the risk sits with third parties: cloud providers, integrators, critical software and partners with remote access. Without visibility over them, the buyer takes on commitments it does not control from day one, which is why third-party risk management belongs in the scope of the review rather than in the post-deal plan.

Detection and response capability

The useful question is not whether they have had incidents — everyone has — but how long they take to detect and contain them, whether the playbooks show evidence of use, and whether the lessons were actually built into the process. As an economic anchor, IBM puts the global average cost of a security breach at US$4.44m in its 2025 report — an average that hides very wide regional differences — and credits the first fall in five years largely to faster detection and containment. Where the target runs plant or machinery, IT/OT convergence is assessed separately: treating a factory floor like an office estate skews the valuation.

Signals that call for a second look at the thesis

Some findings justify pausing, repricing or restructuring on their own. These are the ones that change deals most often:

There is no reliable inventory of critical assets and data. If the company does not know what it holds or where it sits, nobody can size the exposure — least of all within a deal timetable.

The operation depends on two or three individuals, with no documentation and no segregation of duties. That is a continuity risk and a fraud risk at once, and it sharpens right after completion, when those people are most likely to leave.

There were material incidents with no root-cause analysis and no evidence of remediation. An incident closed without knowing how they got in may still be open.

Critical systems are out of support with no modernisation plan carrying dates and a budget. The bill exists; the only question is who pays it.

Third parties hold privileged access without adequate contractual or technical control. That is inherited risk, and it cannot be closed off unilaterally after the purchase.

Security metrics are built for the slide deck, with no operational evidence behind them. A green scorecard nobody can rebuild from logs usually points to a governance problem rather than a tooling one.

None of these signals kills a deal on its own. All of them make completion more expensive if they surface afterwards. And one timing rule is worth respecting: a review that begins once the deal structure is settled can only document what is no longer negotiable.

From findings to figures

A finding without a number does not reach the committee. The economic translation sits in four blocks: mandatory remediation to reach an acceptable threshold, operational disruption — downtime, service-level failures, commercial friction — regulatory and legal exposure, and commercial impact in the form of customer losses or delayed enterprise sales.

What survives scrutiny is a set of scenarios — base, severe and extreme — over 12, 24 and 36 months, stating honestly which parts are estimates. A reasoned range with explicit assumptions holds up under committee questions far better than a single figure with no traceability. That material then feeds the cyber-resilience dashboard used to track the integration.

How it lands in the agreement

The output should be visible in the terms. The price is adjusted where material unplanned corrective investment appears. Part of the consideration is held back in escrow where the cost of an identified risk is uncertain. Critical continuity or compliance gaps are closed before completion, as conditions precedent. Specific warranties cover past incidents, data integrity and regulatory obligations, each with its own duration and cap. And an earn-out is tied to verifiable stabilisation milestones where uncertainty is high but the asset is attractive.

None of this penalises the deal; it makes it executable. A risk that is identified and allocated by contract is manageable. One discovered after completion is no longer negotiated — it is paid.

After completion

It is not unusual for a deal to clear due diligence and then lose value in the first months to poor integration. The sensible priorities are stabilising critical assets and privileged access, unifying monitoring and governance — in-house or through a managed SOC — closing urgent regulatory gaps, and sequencing modernisation in waves the business can absorb.

It is also worth deciding in advance who gets the call if an incident lands during integration, precisely when access is at its most disorderly. Having incident response retained before you need it beats improvising in the worst possible week.

The decision that belongs to the committee

Cyber due diligence is not about finding every flaw in the target, because no company has them all closed. It is about separating the risk you can carry from the risk you cannot pay for, putting a defensible number on it and deciding who bears it.

It is worth being honest about what the two opening cases show: at Yahoo the problem became public before completion, at Marriott it surfaced two years after signing. That difference was set by the disclosure timetable, not by the quality of the technical review. And precisely because a committee cannot count on that luck, the questions get asked beforehand.

The cases cited draw on public information and supervisory authority decisions available at the date of publication: the price revision in the Verizon-Yahoo transaction (2017) and the UK data protection authority's case against Marriott International (notice of intent in 2019, final penalty in 2020). This article is professional commentary and not legal or financial advice; every transaction requires its own analysis with specialist advisers.

Frequently asked questions

What is cyber due diligence in an M&A deal?

It is the assessment of the technology and cybersecurity risk of the company you intend to buy, carried out before signing and with commercial judgement. It does not only ask whether controls exist: it estimates what could interrupt cash flow, which regulatory obligations may create cost and what corrective investment will be needed, so that all of it shows up in the price and in the agreement.

Why are the target's certifications not enough?

Because a certificate evidences that a management system was assessed within a defined scope on a given date, not that the network is clean on signing day. In the Marriott case the pre-deal review rested on contractual warranties, a SOC 2 attestation and a PCI DSS report, with no technical testing of the reservation infrastructure; the UK authority later found that review insufficient.

Can cyber risk really change the purchase price?

Yes, and there is well-known precedent. Verizon cut US$350m from the Yahoo price after two breaches came to light that had not been disclosed in the initial negotiation, leaving the deal at US$4.48bn and splitting some later liabilities. As reported at the time, the buyer pushed for a considerably larger reduction and did not get it: a risk discount is negotiated.

What can be assessed if the vendor will not grant system access?

Considerably more than people assume. Internet-facing exposure is analysed from outside; the map of critical third parties and their access is reviewed through contracts; evidence that controls are genuinely applied — logs, incident tickets, restore tests — is requested in the data room; and targeted interviews with the security lead provide signal. It does not replace a full audit, but it avoids signing blind.

Which risks does the buyer inherit at completion?

Effectively all of the target's: latent incidents not yet detected, technical debt and the corrective investment it implies, regulatory obligations and open enforcement matters, third-party contracts granting access to its systems, and service-level commitments to customers. What was not negotiated before completion is paid afterwards.

How do you turn a technical finding into a defensible number?

By sorting it into four blocks — mandatory remediation, operational disruption, regulatory and legal exposure, and commercial impact — and building base, severe and extreme scenarios over 12, 24 and 36 months. The key is making assumptions explicit: a reasoned, traceable range stands up to committee questions far better than a single unexplained figure.

Which contractual mechanisms cover the risk identified?

The usual set: a price adjustment where unplanned corrective investment appears, a holdback or escrow for risks of uncertain cost, conditions precedent for critical gaps, specific warranties on past incidents and data integrity, and an earn-out tied to verifiable stabilisation milestones. Used well they do not block the deal; they make it executable.

Is this worth doing on the sell side too?

Yes. A vendor that arrives with a self-assessment done, evidence in order and a credible roadmap reduces the precautionary discount a buyer applies against uncertainty, and shortens the process. Transparency about known risks under active management usually reads better than a data room that looks immaculate until the first technical question.

Not sure which EU rules reach you — or what meeting them costs?

NIS2 and DORA reach further than most companies expect, usually through a contract with a customer already in scope. We work out what genuinely applies to you in a 30-minute call with a technical consultant, not a salesperson, and you leave with priorities ranked and a price range. With what comes out of that call, we turn it into a fixed proposal. ISO 27001, NIS2, DORA and ENS — Spain's framework for suppliers to the public sector.

If your situation is different, tell us anyway — we also take one-off questions on cybersecurity and regulatory compliance.

Based in Spain · Working across the EU and LATAM · ENS High · ISO 27001 · We usually reply in under 24 business hours