What Boards Miss in Cyber Risk During M&A

The diligence report said, “no material findings.” Six months later, the integration budget tripled, a legacy vendor contract surfaced with no security terms at all, and the newly combined company disclosed an incident the target had never reported to anyone. None of this showed up in the data room. All of it showed up in the numbers.

This happens more often than boards realize, and less often than it should to firms that know where to look. Cyber risk has become deal risk — it reprices transactions, triggers indemnity claims, and quietly inflates the cost of the first hundred days. Yet most diligence processes still treat it as a compliance checkbox: a vendor questionnaire, a penetration test summary, a SOC 2 letter stapled to the back of the data room. That approach answers the wrong question. It confirms the target has paperwork. It does not tell you whether the target has exposure.

Here is what boards consistently miss — and the three questions that close the gap.

The Diligence Trap: Compliance Isn’t Resilience

A clean SOC 2 report or ISO certification tells you a target passed an audit on a specific day, against a specific scope, defined by the target. It does not tell you:

 Whether the certified scope covers the systems that touch customer data, IP, or the crown-jewel process being acquired

 Whether findings from that audit were remediated or simply accepted as residual risk

 What sits outside the certified boundary — the shadow IT, the acquired subsidiary from three years ago that was never fully integrated, the founder’s personal AWS account still running production workloads

Boards that stop at “do they have a certification” are buying a document, not an assessment. The diligence question that matters is narrower and harder: if this target were attacked tomorrow, what would break, and what would it cost us after close?

Blind Spot One: Inherited Third-Party Risk

Every acquisition inherits the target’s vendor ecosystem — and with it, every unmanaged risk sitting inside that ecosystem. A target with strong internal controls can still carry catastrophic exposure through a payment processor, a cloud subcontractor, or an offshore development shop with no meaningful security oversight.

This is where third-party risk management and M&A diligence should intersect and almost never do. Standard financial and legal diligence asks whether vendor contracts are assignable and whether pricing holds. It rarely asks whether the vendor has ever had a breach, whether the target has any visibility into that vendor’s security posture, or whether the vendor relationship creates a single point of failure for a process the acquirer is paying a premium for.

The question to ask: Who is the target’s critical third parties, and what evidence exists — beyond a signed contract — that those relationships are actively monitored?

Blind Spot Two: The Undisclosed Incident

Sellers are not always lying when they say, “we’ve had no material security incidents.” Often, they genuinely don’t know. Immature security programs frequently lack the logging and detection capability to know whether they’ve been compromised — which means a clean incident history in the data room can reflect an absence of evidence, not evidence of absence.

This distinction matters enormously for representations and warranties. A rep that says “no known breaches” is only as strong as the target’s ability to know. Confirmatory diligence should test detection capability directly: can the target show you evidence of active monitoring, or are they relying on the fact that nothing bad has been reported to them?

The question to ask: Does the target have the technical capability to know if they’ve been breached — and can they show us, not just tell us?

Blind Spot Three: The Integration Bill Nobody Modeled

This is the blind spot that shows up in the numbers, not the report. Security and risk integration costs are consistently underestimated in deal models because they are rarely scoped before signing. Common surprises include:

 Incompatible identity and access management systems that require a parallel, months-long migration

 Licensing overlap or gaps discovered only after the acquirer tries to consolidate tools

 A target’s security team sized for a standalone company, not for the compliance obligations of the acquirer’s regulatory footprint

 Cyber insurance that doesn’t transfer, or transfers at a materially worse rate once the combined entity’s risk profile is underwritten

None of this is exotic. It is knowable before the deal closes, if someone models it before close instead of discovering it during Day-100 planning. The firms that do this well treat security and risk integration cost as a line item in the deal model, sized during diligence — not a surprise absorbed by the operating budget afterward.

The question to ask: What would it cost to bring this target’s security and risk posture to our standard within 100 days — and is that cost reflected anywhere in this deal?

A Better Diligence Rhythm

The fix is not more diligence. It is diligence sequenced to the decisions the deal actually requires:

Pre-LOI / red-flag review — A rapid, high-level pass focused on deal-breakers: undisclosed incidents, critical third-party concentration, and any regulatory exposure material enough to affect valuation. This should take days, not weeks, and should produce a short list the investment committee can act on before spending more diligence budget.

Confirmatory diligence — A deeper pass once the deal is likely to proceed: testing detection capability, reviewing the actual third-party risk register (not just the vendor list), and pressure-testing the representations being negotiated into the purchase agreement.

Day-1 / Day-100 integration planning — Security and risk integration should be scoped during diligence, not after signing. The team that finds the risks should be the team that prices the fix, so the number that goes into the model is real.

Boards that build this rhythm into every deal stop discovering integration costs after the fact. They start negotiating from a position where the risk — and its price — is already on the table.

The Real Cost of Getting This Wrong

The most expensive cyber risk in any transaction is never the one that gets caught. It’s the one nobody looked for because the diligence process was built to confirm the deal, not to test it. A board that asks the three questions above — before the LOI, before confirmatory diligence closes, and before Day-1 planning begins — buys itself something no compliance certificate can offer: the ability to price risk instead of inheriting it.

Previous
Previous

The Board Presentation That Changed the Budget

Next
Next

AI Governance Without the Theater